T−14: inventory authority and dependencies
List the production hostname, legal client, service owner, WordPress administrators, agency dashboard users, plugin version, current Activation Code state, provider project and key owner, scheduled jobs, alert recipients, and evidence-retention obligations. Mark whether each item is transfer, revoke, export, retain, or delete.
Confirm who has authority to accept the handover and who can approve revocation. A contract ending does not by itself prove that a technician may delete client data or rotate a client-owned provider key. Record decisions and exclusions.
T−7: export the minimum useful evidence
Export settings, usage summaries, incident records, and a hostname/license status record needed by the client. Exclude raw prompts, secrets, unrelated client records, and internal commercial notes unless specifically authorized and necessary. Hash the delivered archive and record the transfer channel.
Obtain client acknowledgement of the inventory, transfer contents, cutover time, expected behavior, and post-handover responsibility. Resolve unknown owners before T0; an unsigned spreadsheet is not acceptance.
| Time | Required action | Evidence | Pass condition |
|---|---|---|---|
| T−14 | inventory and authority | named owner per asset | no critical unknowns |
| T−7 | export and client sign-off | archive hash and acknowledgement | scope accepted |
| T0 | remove/replace hostname and invalidate code | old code test | fails immediately |
| T+1 hour | remove access and validate site state | login and public-path checks | no agency access or unintended outage |
| T+7 days | usage and dashboard review | zero-use or assigned exception | certificate signed |
T0: revoke in the order that avoids an orphan
First confirm the client has received any needed replacement access and understands the cutover. Then remove or replace the managed hostname and invalidate the old Activation Code through the supported workflow. Test the old code from an authorized test context; it must fail immediately after replacement.
Remove agency WordPress and dashboard access, rotate agency-owned integration secrets, disable agency callbacks, and update alerts. Do not email or archive the old plaintext code as revocation evidence. Record only its non-secret identifier or hash and the invalidation result.
T+1 hour: prove both security and continuity
Verify former agency accounts cannot authenticate and that no agency job continues to call the site or provider. Separately test the public customer path and the client's new administration path so access removal is not mistaken for a successful handover if production is broken.
Document any intentionally retained access with purpose, approver, minimum privilege, and expiry. An informal promise to remove it later does not pass the checklist. Escalate unknown activity before signing the certificate.
T+7: issue a revocation certificate
Review provider usage, Agency dashboard membership, hostname state, scheduled jobs, callbacks, and access logs for the week after handover. Expected customer-owned usage may continue; the objective is zero residual agency-owned authorization and no calls from retired agency paths.
The certificate names the hostname, client, transfer archive hash, code invalidation time and test, access removals, remaining client-owned activity, exceptions, evidence locations, and both approvers. The Agency page is the correct next step for managing replacements; the certificate remains the proof that this relationship ended cleanly.
Use the license revocation certificate from “Client offboarding: revoke the old Activation Code before the handover closes” on a real first installation. Download AI Cost Circuit Breaker for free, begin in Monitoring, and move to enforcement only after the expected signals and rollback are verified.