Ownership

You own it. This is the architecture that makes that true.

Every provider tells you that you own your systems. Almost none can show you the structure behind the sentence, because most of them do not work that way. Here is the structure, in enough detail that you could check it yourself.

Why it matters

Most businesses find out how this works at the worst possible moment.

Not through malice, usually. Someone built the website years ago and registered the domain on their own account because it was quicker. The hosting went on their card. The mail tenant was set up under their login. Everything worked, so nobody looked.

01

They stop answering

Not always deliberately. People move overseas, change careers, get sick, or simply lose interest in a job they finished four years ago. The domain renewal notice goes to an inbox nobody reads.

02

Nothing can be changed

You cannot point the domain somewhere new, cannot add a staff mailbox, cannot move the hosting. Every path forward runs through one person who is not replying, and no amount of paying someone else fixes it.

03

The rebuild is the cheap option

Eventually it is less painful to buy a new domain and start again than to recover the old one. That is the point at which the business pays twice for something it thought it already owned.

The test that matters

What happens the day you want me gone.

This is the only question worth asking a provider, and the answer should be boring. Everything is registered to you. I am attached by a single line of delegated access. Cut it and nothing else moves — because nothing else was ever attached to me.

Your company ACCOUNT OF RECORD DELEGATED ACCESS Domain name Microsoft 365 tenant Cloud hosting Password vault Source repository Your data

Leapfrog holds administrative access for exactly as long as you want it to.

How it is put together

Seven decisions, made once, at the start of every engagement.

None of this is expensive or clever. It is just decided deliberately at the beginning, when it costs nothing, rather than discovered later when it costs everything.

Every account in your company's name

The domain, the mail tenant, cloud hosting, the code repository. Registered to your business, billed to you, at cost. Not resold through me, so there is no account of mine for them to sit behind.

A role address, never a person's

Accounts are registered to something like it@yourdomain, not to you personally and not to me. People leave and roles do not. Verification mail reaches both of us, so you are not interrupted for every signup — and the account is still unambiguously yours.

You remain the top administrator

Always, on every system. Two reasons: if I lose access you can restore it, and a client who cannot remove their provider is in exactly the position they hired one to fix.

My access is named, never shared

I work under my own account with my own credentials, so the audit trail shows who changed what and when. It also means revoking me is disabling one account, not rotating a password everybody knew.

Break-glass credentials stay in your safe

Your master password and recovery codes go on paper, in your office, in your possession. Not in a file, not in my vault, not anywhere I can reach. If I vanish tomorrow you can still get into everything.

A register of what exists — never of what unlocks it

You get a written record of every service, who the account of record is, and where the credential lives. The register never contains the credential itself. It is the map, not the keys.

Your own vault, not a folder in mine

Your credentials live in a tenant your business owns, and I am invited in. The alternative — one provider vault with a folder per client — makes that provider the highest-value target in their own industry, and means no client truly holds their own keys.

Said out loud, before you have to ask

Administrative access is a serious power. Here is exactly what it means.

To do this work I usually need administrator rights on your mail tenant. That role can reset any password, which means it can reach any mailbox and any file in your organisation. You deserve to hear that from me rather than work it out later. So: the account carries two-factor authentication from the moment it is created, it is recorded in your register, removing it is step one of offboarding, and my boundary is administration rather than correspondence. I am there to configure the system, not to read your mail.

Leaving

Removing me is one action, on your side.

Disable my account in your directory and I am gone. Every account stays live because it was always registered to you, the code is already in your repository, and your data exports in open formats whenever you ask, at no charge. There is no handover ceremony, because there is nothing to hand over. That is the whole design.

1Action to remove me
Next step

Ask your current provider the same question.

"If I wanted to remove you tomorrow, what would I have to do?" You will learn more from the answer than from any proposal. And if you would like to talk about what you actually own right now, the first conversation is free.

Perth & Western Australia · On-site discovery preferred · Remote available