
A client website inventory is the agency's authoritative record of every production service it supports: purpose, ownership, domain and infrastructure, application stack, critical journeys, dependencies, monitoring, recovery, access references, service class, and lifecycle status. It should answer operational questions during an incident without storing plaintext secrets.
The inventory is not the same as a list of monitors, hosting accounts, invoices, or portfolio screenshots. Those systems each show only part of responsibility.
For every site, record:
| Field | Example | Why it matters |
|---|---|---|
| Site ID | WEB-0042 |
stable references across tools |
| Client | Northwind Retail Ltd | contract and communication |
| Production URL | https://shop.example |
canonical service |
| Purpose | ecommerce | impact classification |
| Service class | A | monitoring/coverage standard |
| Service owner | client ecommerce lead | decisions and approvals |
| Agency owner | maintenance lead | accountability |
| Platform | WooCommerce | change/recovery context |
| Domain owner/expiry | client / date | continuity risk |
| Hosting/DNS/CDN | providers + owners | incident escalation |
| Critical journey IDs | CJ-01, CJ-02 |
monitoring and validation |
| Monitoring template | store-a@v3 |
required control set |
| Recovery status | tested/date | readiness evidence |
| Lifecycle | active | tool cleanup and billing |
site_id;# WEB-[ID] — [service name]
Status: [onboarding/active/suspended/transfer/archived]
Client: [organisation]
Production: [URL]
Service class: [A/B/C/D]
Purpose: [value]
Support schedule: [value + time zone]
## Owners
- Client service owner: [role/contact reference]
- Emergency approver/fallback: [roles]
- Agency service owner: [role]
- Technical owner: [role]
- Security escalation: [role/process]
## Platform
- Domain/registrar/owner/expiry: [values]
- DNS: [provider/owner]
- Hosting/cloud: [provider/account reference]
- CDN/WAF/TLS: [values]
- CMS/framework/runtime/database: [values]
- Repository/deployment/rollback: [links]
## Critical journeys
- [CJ-ID]: [journey] — [success condition]
## Dependencies
- [system]: [purpose, owner, status link]
## Monitoring
- Template/version: [value]
- Check IDs: [list]
- Alert/fallback: [routes]
- Exceptions: [ID/expiry]
## Recovery
- Backup scope/retention: [value]
- RTO/RPO: [values]
- Last restore test: [date/result/link]
## Access
- Secret-manager collection: [reference]
- Privileged roles: [list]
- Last review: [date]
## Risks and decisions
- [risk, impact, owner, decision, expiry]
site_id,status,client,service_name,production_url,purpose,service_class,support_schedule,time_zone,client_owner,agency_owner,technical_owner,domain_registrar,domain_owner,domain_expiry,dns_provider,hosting_provider,cdn_waf,cms_framework,runtime,repository,critical_journey_ids,monitor_template,alert_route,backup_scope,rto,rpo,last_restore_test,last_access_review,risk_count,next_review
Keep multi-value operational details in linked records once the spreadsheet becomes difficult to review. The inventory should not become a giant unstructured cell.
Assign one inventory owner. Require updates after:
Automate discovery where useful, but do not overwrite reviewed ownership or accepted-risk decisions blindly.
Examples:
tested, partial, failed, or untested, never simply yes.With a structured inventory, the agency can answer:
Use the simplest tool that supports ownership, validation, history, access control, and automation needs. The model matters more than the brand.
Limit editing to operational owners and use change history. Broader teams may need read access with sensitive fields separated.
Update on change and run a portfolio review at least quarterly; critical renewal and ownership fields should be checked more frequently.
It can discover technical fields and check state. Human-reviewed business purpose, responsibility, SLA, and accepted risk still need authoritative ownership.
Reviewed: 8 August 2026.
Next: Web agency access control matrix and managing multiple client websites.
Pingvera can contribute monitor IDs, status, observed domains, TLS data, and external evidence. Keep the inventory broader than any monitoring vendor.
Pingvera watches whether an online business actually works — uptime, checkout, orders, domain, SSL and server — and alerts you in Telegram, email or a webhook before a customer has to tell you.
Start freeRead next: Website Maintenance SLA Template for Agencies · Blameless Postmortem Template for Web Agencies · Website Incident Report Template for Agencies · Client Website Monitoring Policy Template · Run a free site check.