A launch date does not transfer responsibility to the internet. A dependable website needs named owners for content, software, hosting, domains, backups, access, monitoring and incident decisions from its first day in service.
The most common maintenance failure is not a missing tool. It is an unnamed responsibility. The host assumes the agency updates the application. The agency assumes the client renews the domain. Marketing publishes content, but nobody checks broken forms. Backups exist, but nobody has restored one. A maintenance plan turns these assumptions into owned, testable work.
Define four roles for every responsibility
For each maintenance area, name the person who performs the work, the person accountable for the result, the specialists who must be consulted and the stakeholders who must be informed. One person may hold several roles in a small organisation, but the names should still be explicit. Record contact details and a backup owner, not only a department.
| Area | Performs | Accountable | Evidence |
|---|---|---|---|
| Content accuracy | Content editor | Business owner | Review date and approval |
| Application updates | Technical maintainer | Service owner | Change log and test result |
| Hosting and uptime | Hosting operator | Service owner | Monitoring and incident record |
| Backups and restore | Technical maintainer | Service owner | Successful restore test |
| Domain and DNS | Named administrator | Executive owner | Registrar access and renewal record |
| Security response | Technical lead | Incident owner | Incident log and closure review |
| Privacy requests | Data protection lead | Data controller | Request and response record |
Updates are a controlled change, not a button
Inventory the framework, content system, plugins, integrations and runtime. Monitor supported versions and security notices. Test material updates in a safe environment, confirm forms and integrations, take a usable backup, schedule the release and record the outcome. WordPress sites should follow the official updating guidance, including backup precautions, rather than enabling changes without an owner.
A backup is credible only after a restore test
Define what is backed up, how often, where copies are stored, how long they are retained, who can access them and the maximum acceptable data loss. Then restore the site and its database into an isolated environment on a schedule. Record duration, missing dependencies and the person who verified the result. Screenshots of a green backup job do not prove recovery.
Monitor the customer journey
- Availability and certificate expiry.
- Critical page response and visible rendering.
- Contact, quote, application and checkout submissions.
- Payment and notification integrations.
- Search indexing and accidental noindex changes.
- Broken internal links and missing media.
- Performance trends on representative mobile pages.
- Unexpected administrator and configuration changes.
Monitoring should create an actionable alert with a priority, owner and escalation route. A weekly report that nobody reads is not incident detection. Test the alert path during business hours and confirm the out-of-hours expectation in writing.
Protect access as staff and suppliers change
Use individual accounts, strong authentication and the least access needed for each role. Review administrators, hosting users, analytics users, domain access, repository access and integration credentials on a schedule and at every joiner, mover or leaver event. The OWASP Application Security Verification Standard is a useful source of testable application security requirements.
Plan the first response to an incident
Write down who can take the site offline, restore a version, contact the host, notify customers, preserve logs and make regulatory decisions. Keep the plan outside the system it may need to recover. After an incident, document cause, impact, timeline, actions and prevention instead of closing the ticket when the page returns.
What a useful monthly report contains
- Changes released and their verification results.
- Updates applied, deferred and the reason for deferral.
- Availability, significant performance changes and failed journeys.
- Backup status and latest restore-test evidence.
- Security events, access changes and unresolved risks.
- Content due for review and broken links corrected.
- Open actions, owner, priority and due date.
Avidni's website care and support turns maintenance into a visible operating rhythm with clear ownership, verification and practical reporting.
Plan Website Care