Branding & Identity

The Files and Licences to Secure Before a Designer or Agency Leaves

An open archive box on a warm cream desk holding neatly filed unlabelled folders, with a small stack of blank keys and a plain unmarked external drive beside it

An open archive box on a warm cream desk holding a row of neatly filed unlabelled folders, with a small stack of blank keys and a plain unmarked external drive resting beside it in soft natural light

The email is always polite. Someone is moving on, the retainer is ending, the agency is restructuring, the freelancer has taken a full-time role. There is a friendly note about how much they have enjoyed working with you, an offer to help with the transition, and a final invoice.

You reply saying thank you and asking them to send over the files.

They do. It is a Dropbox link with 340 items in it, and for about a week everything seems fine.

Then, at some point over the following two years, one of these happens. A printer asks for the packaging artwork and the layered file opens with eleven missing links and a font warning. Your new designer opens the logo file and finds live text in a typeface nobody can identify. A plugin licence expires on a website you cannot log in to as an owner, only as an editor. Meta asks you to verify a business you do not own. Your domain quietly lapses because the renewal notice went to an inbox at a company that no longer exists. Or you receive an invoice from a stock library for an image that has been on the front of your brochure for three years.

None of these is dramatic. All of them are the same failure: the relationship ended on the day the work stopped, rather than on the day the assets, the rights and the keys finished moving. Those are different days, and almost nobody schedules the second one.

What makes it expensive is the asymmetry. While you are a paying client, everything on the list below is a ten-minute request. The moment you are not, every one of them becomes a favour — and a favour asked of somebody whose Adobe seat has lapsed, whose laptop has been wiped, whose subcontractor has moved on, and whose inbox has entirely reasonably deprioritised you. Nothing malicious has to happen for the assets to become unrecoverable. Ordinary entropy is enough.

Why every offboarding checklist you can find is written from the wrong side of the table

Search for a design offboarding checklist and you get four kinds of result, none of which is about you.

The first, and the largest group, is agency-side process content: how a studio should offboard a client. Review the statement of work, send the final invoice, deliver the files, ask for a testimonial, send a thank-you gift, ask for a referral. This is genuinely useful content — for the agency. It is written by studios, for studios, about protecting the studio's reputation and pipeline. The client is the object of the process, not the reader.

The second is HR and IT offboarding: an employee is leaving, revoke their accounts, collect the laptop, disable SSO. Close, and structurally useful, but built for a world where the leaver is inside your identity system and you are the administrator of everything. In a design relationship the opposite is usually true. The leaver is outside your systems, and on several platforms they are the administrator and you are not.

The third is asset handover forms: templates for recording the transfer of physical equipment between a company and a person. Serial numbers, condition, signature. The word "asset" matches; nothing else does.

The fourth is logo-project file lists: which formats a client should receive at the end of an identity project. AI, EPS, SVG, PNG, a colour spec. Accurate and far too narrow. It covers one deliverable from one project, and says nothing about the licences underneath it, the accounts around it, or the two years of collateral built on top of it.

So the join is missing, and the join is where every real problem lives. A file list with no licences attached gives you documents you are not permitted to open. A rights assignment with no file list gives you a legal entitlement to something you cannot produce. Full admin access to a platform whose owner has left the industry gives you a dashboard you cannot ultimately control.

What follows is the other side of the table: a complete offboarding built for the party who is losing the assets, not the party who is handing them over.

The four ledgers

The reason "did we get everything?" is such a hard question to answer is that it is really four questions, each governed by different mechanics, each capable of failing while the other three are fine.

Four columns labelled Files, Licences, Accounts and Record showing what is typically handed over in each — nearly all of the files, almost none of the licences, admin but not ownership on accounts, and none of the production record

Ledger 1 — Files. What you can open, edit and output. This is the only ledger anyone actually thinks about, and it is the one most likely to be at least partly complete.

Ledger 2 — Licences. What you are permitted to keep using. Fonts, stock imagery, video, music, icons, templates, themes, plugins, commissioned photography, subcontracted illustration, AI tool outputs. Licences attach to a licensee, not to a file. Files travel; permissions do not travel with them.

Ledger 3 — Accounts. What you can log into and, more importantly, control. Domain, DNS, hosting, CMS, design tools, cloud storage, business managers, ad accounts, analytics, tag containers, email platform, vendor portals. The distinction that matters here is not access, it is ownership.

Ledger 4 — The record. What you can prove and what you know. The signed assignment. The written disclosure of third-party elements. The governing documents — which of guidelines, style guide and design system actually exists, and which is current. The production notes — which stock, which press, which die number, which Pantone, which vendor rep, which decisions and why. Institutional memory, in other words, most of which lives in one person's head and none of which is in the Dropbox link.

Two of these fail silently. You will notice a missing file the first time you try to open it, and you will notice a lost account the first time you try to log in. You will not notice a missing licence or a missing production record until somebody else notices it for you — a foundry's compliance email, a stock library's invoice, a printer asking a question nobody can answer.

The rest of this article works through all four, in the order that gives you the best chance of getting them.

The leverage curve: why timing beats thoroughness

Before any of the lists, the single most important idea in an offboarding.

Your ability to obtain any of this is not constant. It decays, sharply, and it decays on a schedule set by commercial obligation rather than goodwill. A thorough checklist worked at the wrong moment recovers less than a mediocre checklist worked at the right one.

A declining curve showing recovery leverage by stage, from full leverage before the final invoice down to archive-dependent after six months, annotated with the mechanism at each stage

Stage Your position What still works
Before the final invoice Contractual. They are obliged. Everything. Any reasonable request is part of the job.
Notice given, work continuing Contractual, with a deadline Everything, if you ask in writing and early
Final week Goodwill plus a live invoice Most things, if the list is already written
0–30 days after Goodwill only Small, specific, low-effort requests
30–180 days after You are an unpaid support ticket Whatever they can answer without opening a file
6 months and beyond Dependent on their archive existing Luck

The operational consequence is a single rule that changes the whole exercise:

Define the handover as a deliverable, and tie a defined portion of the final payment to it — at the start of the relationship, not the end.

A retention of 10 to 20 per cent of the final invoice, released on sign-off of a named manifest, is ordinary commercial practice. Sprung at the end of a project it reads as a hostage negotiation and poisons the relationship. Written into the engagement at the start it reads as professionalism, and good studios accept it without argument — partly because it protects them too. It converts an open-ended "the client keeps asking for more stuff after we finished" into a finite, defined, invoiceable list.

If you are reading this because someone has already given notice, you are somewhere in the middle of that table. Skip to the 30-day exit sequence below and work backwards. If they have already gone, skip to the triage section.

Ledger 1: the file manifest

The reason "please send me all the files" reliably fails is that it is not a specification, and in the absence of a specification the sender resolves the ambiguity in the cheapest direction. They send you what they would send a client who wants to look at the work, which is the bottom tier of three.

The three tiers, and why you keep getting the wrong one

Three stacked tiers showing source files, production files and exports, with the note that a request for the files usually returns only the bottom tier

Tier 1 — Source. The editable working document with its layers, its type still live, its links and its history. This is the only tier from which a future change is cheap. It is also the tier most likely to be withheld, most likely to be unusable without the right software and the right licences, and most likely to be genuinely regarded by the studio as their own apparatus rather than your deliverable.

Tier 2 — Production. The self-contained output built for a specific process: a press-ready PDF with fonts embedded and bleed applied, a cut file, a packaged folder with links and fonts collected, an exported and versioned web asset set. Portable, complete, and editable only within limits.

Tier 3 — Export. JPG, PNG, a flattened presentation PDF, a screenshot in a slide. Fine for looking at. Useless as a starting point for anything.

Ask for "the files" and you get tier 3, with some tier 2 if you are lucky. You have to name all three.

What to request, by asset class

The manifest below is the request, not the wish list. Adapt the rows to what actually exists in your relationship, delete what does not apply, and send it as a table rather than a paragraph — a table gets filled in, a paragraph gets summarised.

Asset class Source (tier 1) Production (tier 2) Export (tier 3) The specific trap
Logo and identity Layered master vector, all lockups Vector per lockup, print and screen, plus one-colour and reversed Raster at named sizes, transparent and on-white Type must be outlined in production files; ask whether the master has live text and which typeface
Brand guidelines Editable layout document, linked assets Print-ready and screen PDF Guidelines built in a subscription tool you do not have a seat for
Print collateral Layered layout per piece Packaged folder: links, fonts, press-ready PDF with bleed and marks Links that resolve on their machine and nowhere else
Packaging Layered artwork on the supplied dieline Separated press file, dieline, spot and finish layers The dieline itself belongs to the converter and may never have been yours
Signage and large format Scaled working file Cut file, production PDF at correct scale Cut paths and spot colours defined per fabricator, not portable
Web and UI Design tool file with components and library published to you Exported assets, icon set, spec Screens as images The file sits in an individual's personal drafts, not a team space
Motion and video Project file, compositions, plus every piece of source footage Master render, plus per-platform renders Social crops Plugins and effects that will not open without their licences
Presentation and templates Editable master with layouts and theme Locked distribution copy PDF Templates depending on fonts your team does not have
Internal and HR documents Editable master per document Distribution PDF The set nobody owns, so nobody notices it left
Photography and video Raw or full-resolution originals with edits Retouched masters, colour profile embedded Web-sized derivatives Usage rights, term and territory (see Ledger 2)
Social and ad creative Layered masters per concept Per-platform sized exports, all live variants Live ads whose creative exists only inside an ad account you do not own
Email Editable template, modular blocks Tested HTML with inlined CSS Templates that live only inside a platform account

The verification protocol

This is the part that separates a handover from a folder. You do not have a file until someone who has never worked on the project has opened it, on a machine that has never had that designer's software or fonts installed, and produced the same output.

Six steps, applied to a sample from each asset class rather than to everything:

  1. Open it cold. A different machine, a clean user account, no shared cloud drive mounted.
  2. Read the warnings. Missing fonts, missing links, missing plugins. Record each one — those warnings are your licence gap list for Ledger 2, arriving free of charge.
  3. Make a trivial change. Change one word. If the type is outlined, or the font substitutes, you have found a real limit on what you were handed.
  4. Export to the real format. Press-ready PDF, cut file, whatever that asset is actually for. Not a preview.
  5. Compare against the last known-good output. Overlay it on the last thing that was actually printed or published. Colour shifts and reflowed text show up here and nowhere else.
  6. Send one item to the real vendor. Ask your printer to preflight one file. They will find in four minutes what you would not find in four months, and they will do it for nothing because they want the reprint.

A six-step verification sequence for a design handover, from opening a file on a clean machine through to sending one item to the vendor who actually produces it, with the failure each step catches

Run this while you still have someone to ask. Doing it in the week the relationship ends turns four vague worries into four specific questions, and specific questions get answered even by people who have stopped answering vague ones.

If your handover comes back clean against a preflight, you are in better shape than most. If you want the standard your files should be meeting, our print-ready file checklist is the same list a production studio runs internally, and vector versus raster covers why a 4,000-pixel PNG of your logo is not a substitute for the vector you did not receive.

Ledger 2: the licence manifest

This is the ledger nobody runs, and it is the one that cannot be fixed quietly later.

The mechanic is simple and consistently misunderstood. A licence attaches to a licensee — a named person or company, with a defined seat count and a defined scope of use. It does not attach to the file. When a designer hands you a document containing a licensed typeface, a licensed photograph or a licensed icon set, the file moves and the permission does not. You are now in possession of work that somebody else is licensed to use.

For most small businesses this is a dormant risk for years and then an email. For anyone doing anything at scale — a multi-location or franchise system, a product line, a merchandise run, an acquisition — it becomes a due-diligence finding.

A matrix of asset types showing which licences transfer with a file, which never transfer, and which require a fresh purchase, with the cost of fixing each one after the fact

What is inside the work Does it transfer? What you actually need Cost of fixing it later
Retail typeface, desktop use Never Your own desktop licence, seats matched to your team Buy the licence; foundries sell them and some will settle a past-use gap
The same typeface, on your website Never A separate webfont licence, usually priced by pageview Buy it; the gap is visible in your page source to anyone who looks
The same typeface, inside your logo Never, and sometimes not permitted at all Check the EULA — some prohibit trademark use without an extended licence Extended or bespoke licence, or redraw the wordmark
Font bundled with a subscription tool Only while the subscription is live Your own seat, or a substituted typeface Every file using it reflows on the day the seat lapses
Stock photograph, standard licence Licence is to the buyer; not assignable in most cases Your own licence, and an extended one for merchandise or resale Buy it; back-dating is not possible but going forward is
Stock illustration or icon inside a logo Usually prohibited outright A bought-out or commissioned redraw Redraw, then reregister anything filed with the old artwork
Stock video or music Rarely transferable; often per-project Your own sync or project licence Takedowns and claims arrive automatically on social platforms
Theme or template from a marketplace Per-site, tied to the purchasing account A licence in your account for your site Repurchase, usually inexpensive
Premium plugin or extension Key sits in their account; updates stop when it lapses Your own key, renewed on your card Repurchase, plus whatever broke while it was unpatched
AI-generated elements Depends on the tool's tier and terms at the time Written confirmation of tool, tier and date Usually fine; occasionally means a redraw. Note that purely AI-generated output may carry no copyright anyone can own
Commissioned photography Only to the extent of the shoot's usage grant Term, territory and media in writing, plus model and property releases Re-licence for the new use, or reshoot
Subcontracted illustration, motion or copy Only if the agency took an assignment from the subcontractor Written confirmation of the chain of title Trace the subcontractor, or commission a replacement

Three questions extract almost all of this, and all three are reasonable to ask a vendor in good standing:

  1. Which typefaces are used in this work, and which licence category does each one sit under? Names, not "a Google font, I think." One line per typeface.
  2. Which third-party assets are embedded in the work, from which library, under which licence, and on whose account were they bought? This is also the question that surfaces the extended-licence problem before your merchandise run, not after it.
  3. Which parts of this work were made by someone other than you, and do you hold a written assignment from them?

The third one is the chain-of-title question. Nobody can transfer a right they never held, so if your agency subcontracted the illustration and never took an assignment, their assignment to you is worth nothing over that portion. A studio with clean paperwork answers this in a sentence. A hesitant answer is a finding rather than an accusation — and it is far better to have it while you are still a paying client.

Then add the item nobody records at all: an expiry ledger. Licences with a term — commissioned photography usage windows, music sync licences, model releases, stock subscriptions, plugin renewals — die on a date, and the date is the one piece of information that never survives a handover. One table, one row per licence, one column for the expiry date and one for what breaks when it passes.

The two deepest layers here have their own guides: font licensing covers the seven licence categories and who in a chain has to hold each one, and stock asset licensing for print runs and merchandise covers the volume and resale permissions that are sold separately and that a standard licence does not fix.

Ledger 3: the account manifest

Here the failure is not that you lack access. You almost certainly have access — that is why this one hides so well. The failure is that access is not control.

An admin can do the work. An owner decides who is an admin, including whether you are one. On most platforms an owner can remove an admin and an admin cannot remove an owner. On several, the last remaining owner cannot be removed at all, which means that if your agency holds sole ownership, you cannot fix it without their cooperation — the exact thing you are about to stop having.

So the audit question is never "do I have access?" It is:

If this vendor stopped replying today, could I remove them?

Every place the answer is no is an open item.

A table of common platforms showing what ownership means on each, whether an admin can remove an owner, and what breaks if the owner disappears

Platform What "owner" means there The failure you are looking for
Domain registrar The registrant controls the name; the admin contact does not The domain sits in their account, and renewal notices go to their inbox
DNS host Whoever holds the zone controls where your traffic and email go DNS at a third place nobody has documented
Web hosting and CDN Account holder controls the server and the backups Hosting resold to you through their reseller account
WordPress Administrator role, plus the hosting underneath it Your admin account exists but the plugin keys are on theirs
Shopify Store owner is one person; staff and collaborators are not Collaborator access that vanishes when their partner account closes
Webflow, Squarespace, Wix Site ownership is separate from workspace membership Site inside their workspace, billed to their card
Figma Files in an individual's drafts are personal property, not team property The library everything depends on is published from a personal draft
Adobe Creative Cloud Libraries and cloud documents belong to the seat Shared libraries disappear when the seat is reassigned
Canva Team ownership plus brand kit ownership Brand kit inside their team, your logins as guests
Dropbox, Google Drive The folder owner holds the storage and the sharing rights A "shared with you" folder that leaves when their account does
Meta Business Manager Assets are owned by a Business, and Businesses own Pages Your Page owned by the agency's Business Manager
Google Ads Manager accounts link to, but do not own, an ad account Ad account created inside their MCC, with your history in it
Google Analytics Account, property and user roles are three separate layers Property inside an account you do not administer
Google Tag Manager Container ownership sits above publish rights You can edit tags, they can delete the container
Google Business Profile One primary owner; ownership transfer needs their action Primary ownership never handed back after a listing fix
Search Console Verification method determines who can be removed Verified via a DNS record only they can change
Mailchimp, Klaviyo Account ownership plus the billing relationship Your list living in their agency account
App stores Developer account holds the listings App published under their developer account
Print and vendor portals The account holder is the customer of record Your artwork history and reorder rights sit with them

Two rules cut through most of this.

The billing rule. Whoever's payment method is on an account is, in practice and often in policy, treated as its owner. Moving billing to your own card is the single most reliable ownership marker available to you, it is reversible, it usually requires no cooperation beyond a login, and it is the first thing to do rather than the last. It also stops the quiet failure mode where an account lapses six months later because a card expired at a company that no longer exists.

The recovery rule. On any account with two-factor authentication, real ownership is whoever controls the recovery email and phone number. An account where you are nominally the owner but the recovery contact is their address is not an account you control. Check and change the recovery contacts on everything, and check them again after any ownership transfer, because some platforms do not move them with the role.

The access-transfer order of operations

The order matters more than the list, because a wrong order produces a lockout that no amount of diligence afterwards can undo.

A numbered sequence for transferring account access safely, beginning with an inventory and billing move and ending with revocation only after verification

  1. Inventory before you touch anything. List every platform, every account, every login, and who holds which role on each. You cannot sequence what you have not enumerated.
  2. Add yourself as an owner everywhere you can, before removing anyone from anywhere. Elevation is safe. Removal is not.
  3. Move billing to your own payment method. Early, on everything, for the reasons above.
  4. Fix the recovery contacts. Email and phone, on every account, to addresses you control and that are not one person's personal inbox.
  5. Secure the domain and DNS first among the technical assets. Everything else — email, site, verification records, certificate renewals — hangs off these. Note the 60-day ICANN transfer lock on any domain that has been transferred or registered recently, and the lock some registrars apply after a registrant change; if you only need control, an account-to-account push inside the same registrar avoids both.
  6. Transfer platform ownership, in writing, one platform at a time. Confirm each one visibly in the interface before moving to the next. "I've done that" is not confirmation; seeing your own name in the owner field is.
  7. Take a full export of anything exportable. Email lists, analytics history, product catalogues, ad creative, form submissions. Exports are cheap now and impossible later.
  8. Verify the files before you revoke anything. Run the verification protocol. Revocation is the point of no return, and the only reason to do it before verification is impatience.
  9. Then revoke — completely, and in one pass. Every platform, every shared folder, every password manager entry, every forwarding rule and API key. Partial revocation is worse than none, because it leaves you believing the job is done.
  10. Rotate shared credentials. Anything that was ever in a shared vault, sent over email, or typed into a screen share.

The one rule underneath all ten: transfer, verify, then revoke. The common failure is doing it in reverse — cutting access on the last day as a matter of tidy housekeeping, then discovering on day forty that the packaging source file was never in the folder and the only person who can find it can no longer log in to look.

The 30-day exit sequence

If notice has been given and the relationship is still functional, this is the sequence that gets the most out of the leverage you have left.

A thirty-day timeline showing five phases from notice and inventory through manifest agreement, delivery in tranches, access transfer and close-out

Days 0–3 — Inventory and freeze. Write down everything you can think of that exists: every asset class, every platform, every recurring obligation. Ask them for their own list too; theirs will contain items yours does not. Freeze new work that is not already in flight, so the manifest stops being a moving target.

Days 4–10 — Agree the manifest. Turn the inventory into a table with one row per item and columns for format, licence status, location and verification. Send it, get it agreed as the definition of a complete handover, and get the final invoice and any retention explicitly tied to it. This is the highest-value week of the whole process, and it is the one that people skip because it feels like admin rather than progress.

Days 11–20 — Delivery in tranches, verified as they land. Not one delivery at the end. Take the highest-risk asset classes first — packaging, identity masters, anything with a print vendor attached — verify each tranche as it arrives, and raise gaps immediately while there is still time and obligation to fix them. Ask the three licence questions in writing this week.

Days 21–25 — Access transfer. Work the order of operations above. Domain and DNS first, ownership before removal, billing and recovery contacts as you go.

Days 26–30 — Close-out. The signed assignment and third-party disclosure. The production record: vendors, contacts, die numbers, stock and press notes, the reasoning behind the decisions somebody will otherwise re-litigate in a year. A written statement of what they are keeping, for how long, and how you request it. Then the full revocation pass, and a final cold-machine verification.

One meeting, recorded. Somewhere in the last week, take an hour of their time, share their screen, and have them walk through the folder structure and the production history. Record it. This single hour reliably captures more institutional knowledge than any document either of you would have written, and it is the cheapest insurance in the entire sequence.

When they have already gone

If you are reading this after the fact, chasing has probably already stopped working. Switch from chasing to triage, because triage ends and chasing does not.

Split everything missing into two columns.

Recoverable means somebody other than your former designer holds it, and that somebody has a commercial reason to help you:

  • Your printer very often still has the last press-ready PDF and sometimes the packaged folder. They want the reprint. Ask.
  • Your sign fabricator, converter or garment decorator has the cut file, the dieline and the separations for anything they produced.
  • Your web host has the site, the database and the backups, independent of who built it.
  • The stock library or foundry can tell you what was bought on an account, if you can identify the account, and will sell you a licence going forward without much interest in the past.
  • Platform support will arbitrate a business account ownership dispute — Meta, Google and Shopify all have processes for it — if you can evidence that the business is yours. Slow, bureaucratic, and it works.
  • Your own inboxes. Search everything for attachments, proofs, review links and delivery notifications. Approval threads routinely contain the last good PDF of things nobody can otherwise find.
  • The wayback and your own published assets. Not source files, but usable references for a redraw and sometimes higher resolution than what you have kept.

Reconstructible means rebuilding is cheaper than retrieving. This is truer more often than people expect, and pricing it honestly is what ends the paralysis:

What is missing Rebuild route Rough effort
Vector logo, from a clean high-resolution export Redraw and re-space; identify or substitute the typeface Hours, not days
Brand guidelines Re-document from existing assets — often better than the original, because it now reflects reality 1–2 days
Print collateral layout Re-typeset from the PDF; the text and much of the geometry are inside it Half a day to a day per piece
Packaging artwork Re-artwork on a dieline from the converter, who still holds it Days per SKU
Email or web templates Rebuild from the rendered output 1–2 days
Photography Reshoot, or licence replacements Varies; the honest answer is usually reshoot

Two columns splitting missing assets into recoverable, held by printers, fabricators, hosts and platforms, and reconstructible, where rebuilding is faster than retrieving

A high-resolution PDF is a far better starting point than most people realise: vector geometry and often the live text survive inside it, which is why the reconstruction column is measured in hours for several rows rather than weeks.

For the rights side of the problem — an unreachable designer, an unsigned assignment, a logo whose ownership was never documented — the two workable routes are a confirmatory assignment signed now and expressed to be effective from the original date, or a clean redraw commissioned under proper paperwork, which extinguishes the question instead of arguing about it. What a client actually owns after a logo project covers both routes and the six separate things bundled inside the word "ownership."

And if the reconstruction list is long, treat it as the rebuild it actually is rather than a series of favours. The rebrand rollout inventory is the surface-area map for finding every place an asset lives, which is the same problem in a different order, and a brand audit is the honest way to decide which of the missing items are worth reconstructing at all — because some of what you lost, you were going to replace anyway.

The one-page manifest

If you take one thing from this article and send it as an email this week, send this. One row per item, one column for who verified it and when, and nothing marked done until somebody has opened it cold.

Files

  • Source files, per asset class, in named editable formats
  • Production files: packaged folders, press-ready PDFs, cut files, separations
  • Exports at named sizes, transparent and on-white
  • Every source file opened on a clean machine with no warnings
  • One file per class preflighted by the vendor who actually produces it

Licences

  • Every typeface named, with its licence category and who holds it
  • Every stock asset named, with library, licence type and purchasing account
  • Every template, theme, plugin and extension, with the account its key sits on
  • Commissioned photography: term, territory, media, plus model and property releases
  • Subcontracted work: written confirmation of the chain of title
  • AI-generated elements: tool, tier and date
  • Expiry ledger — every licence with a date, and what breaks when it passes

Accounts

  • Domain registrant and DNS control confirmed in your name
  • Hosting, CMS and CDN ownership, not admin
  • Design tool files out of personal drafts and into a space you own
  • Business manager, ad accounts, analytics, tag container, business profile, search console
  • Email platform, app stores, vendor and print portals
  • Billing moved to your payment method on everything
  • Recovery email and phone changed to addresses you control
  • Full exports taken of everything exportable
  • Revocation completed in one pass, after verification

The record

  • Signed assignment of rights, with a fallback licence
  • Written third-party element disclosure
  • Production notes: vendors, contacts, die and plate numbers, stock, press, colour references
  • Recurring obligations and renewal dates
  • One recorded walkthrough of the folder structure and the decisions behind the work
  • Written statement of what they are retaining, for how long, and how you request it

The clauses that make this a non-event

The whole of this article is a recovery operation. The alternative is four paragraphs in a contract, agreed by people who are pleased to be working together, which cost nothing and turn the entire exercise into an afternoon of paperwork.

Deliverables manifest. Name the source, production and export formats you will receive for each asset class as contractual deliverables, released on final payment — not as a courtesy at the end. Add that the manifest is signed off by both parties as the definition of completion.

Third-party disclosure. Require a written statement, updated on delivery, of every typeface, stock asset, template, plugin, subcontracted contribution and AI-generated element inside the work, with the licence category and the account it was bought on. This one clause is the entire licence ledger, obtained for free, continuously.

Access custody. Nothing is registered, purchased or opened in the vendor's name on your behalf. Every account is created by you; access is granted to them. Every subscription is billed to your payment method. This is the clause that eliminates Ledger 3 completely, and it is the one that saves the most pain per word.

Assignment with a fallback licence, plus transition assistance. Pair the copyright assignment with a fallback: if the assignment fails or is found ineffective for any reason, you hold a perpetual, worldwide, irrevocable, sublicensable licence to use and modify the work. Then add a transition assistance clause — a named number of hours at a named rate, available for a named period after the engagement ends — so that post-departure questions have a defined commercial answer instead of depending on goodwill.

If you are choosing a partner rather than leaving one, these four clauses are also a diagnostic. Studios with clean operations agree to all of them without a conversation, because they already work this way. Our guide to vetting a white-label design partner covers what a good answer to each of these sounds like, and what a rehearsed one sounds like — and if you are an agency doing the leaving rather than the losing, the same four clauses are what a clean white-label arrangement looks like from your side of it.

The mistakes that cost the most

Revoking access before verifying files. Tidy, satisfying, and the single most expensive move on this list.

Asking for "the files." Unspecified requests get resolved in the cheapest direction. Name the tiers.

Treating admin access as ownership. The distinction is invisible until the day it is the only thing that matters.

Accepting a folder instead of a manifest. A folder tells you what you received. Only a list of what you were supposed to receive can tell you what is missing.

Ignoring the licence ledger because nothing has gone wrong. Nothing going wrong is the normal state of an unlicensed font for years, right up until a compliance email or a due-diligence question.

Letting one person hold the institutional memory. If the answer to "why is the packaging that specific green" exists only in a departing person's head, that is not knowledge, it is a dependency.

Starting the offboarding after the last invoice is paid. Every stage on the leverage curve is worth more than the one after it, and this puts you at the bottom by choice.

How to know your handover was actually complete

Not by the size of the folder. Four tests, all of which produce a yes or a no:

  1. The stranger test. Can a designer who has never seen your business produce a corrected, press-ready version of your most complex printed asset, from what you hold, without asking anyone a question?
  2. The clean-machine test. Does every source file open on a machine that has never had your former designer's software or fonts, with no missing links and no font substitutions?
  3. The removal test. On every platform, could you remove your former vendor today, without their cooperation?
  4. The expiry test. Can you name every licence in your brand that has an expiry date, and the date?

Four yeses means the relationship actually ended. Anything else is an open item with a countdown on it, and the countdown is running whether or not anyone is watching it.

Where the next set of files comes from

Most of what makes an offboarding painful is not the departure. It is that the assets were never organised as a system in the first place — they accumulated as a series of projects, in whoever's account was convenient, under whatever licence was to hand that day.

The fix on the other side of a transition is to set the new arrangement up so that this cannot recur: every account in your name, every licence disclosed as it is used, every deliverable specified in three tiers, and a manifest that is a living document rather than an end-of-relationship scramble. That is how a design partner should operate by default, not as a concession.

That is how our unlimited design plans are structured — source files with every deliverable, third-party elements disclosed as standard, and nothing registered in our name that belongs in yours. Rebuilding an identity from a reconstruction list is brand identity work rather than a favour, and it is worth scoping it as such. If you are mid-transition and staring at a reconstruction list, our pricing page shows what a flat monthly rate covers, and how the model works explains the request-to-delivery process — including the handover standard every file leaves under.

If you are earlier than that and simply want the departure to go well, take the manifest in this article, send it as a table this week, and tie it to the final invoice. It is a twenty-minute email, and it is the difference between a transition and a two-year recovery.

Frequently asked questions

What should I ask my designer for before they leave?

Four separate things, and most people ask for one. The files, meaning layered source documents rather than exports. The licences, meaning a written statement of every font, stock asset, plugin, template and piece of commissioned photography inside the work, with who holds each licence and when it expires. The accounts, meaning ownership transfer rather than admin access, starting with the domain. And the record, meaning the signed assignment, the third-party disclosure and the production notes that let a stranger reprint your work without asking a question. Ask for all four in one written manifest, and make sign-off on that manifest a condition of the final payment rather than a favour requested afterwards.

Can a designer refuse to give me the source files?

Usually yes, unless your contract says otherwise. There is no default rule entitling a client to working files, and even a full copyright assignment does not compel delivery of them — assignment transfers rights in the work, not artefacts. Many studios legitimately treat the layered working file as their own apparatus and price accordingly. The fix is contractual and has to happen before the project: name the master source file, in a named format, as a deliverable released on final payment. If you are already past that point, offer to buy the files at a fair price rather than argue about entitlement. It is almost always cheaper and faster than the alternative.

Do font licences transfer when a designer hands over the files?

No. A font is licensed software, and the licence attaches to the licensee — a named person or company with a seat count — not to the file the font was used in. A layered file with live text in a retail typeface is a document you are not licensed to open, edit or output. Three fixes, in descending order of cost: buy your own licence in the categories you need (desktop, webfont, app, and sometimes a separate logo or trademark licence); accept outlined type and lose editability; or substitute the typeface, which means reworking everything it appears in. Find out which fonts are in your work while you can still ask — identifying a typeface from a flattened PDF two years later is its own project.

How do I transfer a domain name from my web designer?

Establish first whether they are the registrant or merely the administrative contact; only the registrant controls the name. If the domain sits in their registrar account, open your own account, have them unlock the domain and release the authorisation code, then initiate the transfer from your side. Two timing traps: a domain transferred or registered within the last 60 days is locked by ICANN policy, and changing the registrant's contact details can itself trigger a 60-day lock at some registrars. If you only need control rather than a change of registrar, an account-to-account push inside the same registrar is faster and avoids both. Do this before anything else, because every other digital asset depends on it.

What is the difference between being an owner and an admin on a platform?

An admin can do the work. An owner decides who is an admin, including whether you are one. On most platforms an owner can remove an admin and an admin cannot remove an owner, and some platforms will not let the last remaining owner be removed at all — meaning that if your agency holds sole ownership, you cannot fix it without their cooperation. The audit question is not "do I have access?" but "if this vendor stopped replying today, could I remove them?" Anywhere the answer is no is an open item.

How long should a design agency keep my files after we stop working together?

Whatever your contract says, and if it says nothing, assume nothing. Studios archive project files for a period and then clear them; there is no obligation to hold them indefinitely. A reasonable contractual retention is 12 to 24 months after the final deliverable, with written notice before deletion and an option for you to take a full archive copy. In practice the deeper risk is not deliberate deletion but attrition — a lapsed subscription, a wiped laptop, a subcontractor who has moved on. Treat the archive as yours to hold rather than theirs to keep.

What do I do if my designer has already gone and is not replying?

Stop chasing and start triaging, because only one of those ends. Split what is missing into recoverable and reconstructible. Recoverable means someone else holds it: your printer very often still has the press-ready PDF, your fabricator has the cut file, your host has the site, and platform support will arbitrate a business account dispute with evidence of ownership. Reconstructible means rebuilding is faster than retrieving — a vector redraw from a high-resolution export, a re-typeset document, new photography. Work the recoverable list first because it is nearly free, then price the reconstruction against the cost of continuing to chase. The rebuild usually wins, and it leaves you with files you own outright.

Should I withhold final payment until I get the files?

Structure it so you never have to. Withholding payment already due, against deliverables never specified, is a dispute — you may be in breach, and it burns a relationship you might still need. What works is a retention agreed at the start: 10 to 20 per cent of the final invoice, released on sign-off of a named handover manifest. This is ordinary commercial practice and good studios accept it readily, because it also protects them by converting an open-ended stream of post-project requests into a finite, invoiceable list. Sprung at the end it reads as a hostage negotiation; written in at the start it reads as professionalism.

What is a brand asset handover manifest?

A single signed document listing every asset that changes hands, in what format, with what licence status, and where it lives — one row per item, with a column for who verified it and when. It is not a delivery folder. The difference matters because a folder tells you what you received, and only a manifest tells you what you were supposed to receive, which is the only way to notice what is missing. A workable one has four sections mirroring the four ledgers: files, licences, accounts and the record. Agree it as the definition of a complete handover while the relationship is healthy, then sign off against it.

Who owns work made by a subcontractor my agency hired?

Nobody can transfer a right they never held, so this depends on a contract you have never seen. If your agency subcontracted the illustration, photography, motion work or copy and did not take an assignment from that subcontractor, their assignment to you is worthless over that portion of the work. Ask it as a plain factual question rather than a legal one: which parts of this work were made by someone other than you, and do you hold a written assignment from them? A studio with clean paperwork answers immediately. A hesitant answer is a finding rather than an accusation, and it is far better to have it while you are still a paying client.

Do I need the working files if I have the PDFs?

For anything that will never change again, no — a correctly built press-ready PDF is a complete production asset, and printers work from them all day. For anything that will change, yes, and the boundary is narrower than people assume: a PDF with a new address, price, claim or translated line is a rebuild, not an edit. Where the source is genuinely gone, a high-resolution PDF is a far better reconstruction starting point than a JPG, because vector geometry and often the live text survive inside it. Keep the PDFs as production assets and as insurance, and get the source files for anything with a foreseeable next version.

How do I stop this happening with the next designer?

Move the handover from the end of the relationship to the beginning. Four clauses do almost all the work: name the deliverables manifest in formats as a contractual deliverable; require written disclosure of every third-party element and its licence, updated on delivery; require that nothing be registered, purchased or opened in the vendor's name on your behalf; and pair the copyright assignment with a fallback licence so that if the assignment fails, you may still use and modify the work. None of these is adversarial, all of them are standard, and together they turn an offboarding from a recovery operation into an afternoon of paperwork.

WhatsApp
WhatsApp$399/mo