
Managing multiple client websites stops scaling when every project has unique tools, private knowledge, shared credentials, and alerts routed to whoever happens to notice. The solution is a portfolio operating model: service classes, a complete inventory, standard checks, named owners, controlled exceptions, one work queue, and capacity reserved for incidents.
At ten sites, memory can conceal process gaps. At fifty, those gaps become daily noise. At one hundred, the agency needs platform ownership, automation, access governance, and portfolio-level evidence.
To scale website maintenance:
| Portfolio | Main risk | Minimum operating model |
|---|---|---|
| 1–10 sites | Knowledge stays in one person's head | checklist, named owner, password manager, basic monitoring |
| 11–50 sites | Alert and configuration inconsistency | service classes, central inventory, templates, help-desk routing, rota |
| 51–100 sites | Manual toil and shared blast radius | platform owner, configuration as code/API, exception governance, capacity planning |
| 100+ sites | Portfolio behaves like a managed platform | dedicated operations function, automation testing, reliability/product management |
Headcount and complexity matter more than the exact number. Ten high-traffic stores may require more structure than one hundred brochure sites.
Example:
| Class | Typical service | Coverage | Required journeys | Recovery expectation | Review |
|---|---|---|---|---|---|
| A Critical | ecommerce, booking, account | 24/7 option | 2–5 | tested RTO/RPO | monthly |
| B Business | lead generation, active marketing | extended/business hours | 1–3 | documented restore | quarterly |
| C Standard | brochure/content | business hours | 1 | documented backup | twice yearly |
| D Observe only | legacy/out-of-scope | alerts only | agreed minimum | explicitly limited | annual |
Service class should affect price, staffing, frequency, communication, and recovery—not just a label in a spreadsheet.
The inventory should answer:
Use the client website inventory template. A monitor list is not a complete inventory, and a billing list is not an operational inventory.
Templates need controlled per-site parameters, not copy-pasted monitors that drift silently.
| Role | Portfolio responsibility |
|---|---|
| Client service owner | scope, client priorities, approvals, reporting |
| Site technical owner | architecture, changes, risks, runbooks |
| On-call responder | incident acknowledgement and escalation |
| Monitoring/platform owner | templates, integrations, alert quality, tooling |
| Access owner | accounts, privilege reviews, offboarding |
| Operations lead | capacity, portfolio review, standards, exceptions |
One person may hold several roles at a small agency, but the responsibility still needs a name and backup.
Use different paths:
Never let a chat channel become the only system of record. Link each confirmed incident to the website inventory and client record.
Track at least:
If every engineer is allocated to planned project work, incident response will always break delivery promises. Reserve explicit capacity or price a separate response function.
| Question | Useful indicator |
|---|---|
| Do we know our responsibility? | sites without owner/scope |
| Are critical journeys observed? | required checks missing by class |
| Can we recover? | overdue/failed restore tests |
| Are alerts useful? | actionable rate, repeated noise, unowned alerts |
| Are renewals controlled? | domain/TLS/licence risk by horizon |
| Is risk ageing? | accepted exceptions past expiry |
| Are we learning? | overdue incident actions/repeat incidents |
| Is workload sustainable? | interruption load and queue age |
Avoid celebrating total checks or total alerts. Those are activity measures, not reliability outcomes.
# Client website portfolio standard
Owner: [operations role]
Version: [number]
Review: [monthly/quarterly]
## Admission
No site enters active maintenance without:
- accepted scope and service class;
- inventory record and named owners;
- controlled access;
- baseline and known-issues register;
- recovery status;
- required monitoring and escalation.
## Templates
- Class A: [template ID/version]
- Class B: [template ID/version]
- Class C: [template ID/version]
## Exceptions
Every exception requires reason, risk owner, approval, expiry, and compensating control.
## Work routing
- P1/P2: [route]
- P3: [queue]
- P4/preventive: [backlog]
- fallback: [route]
## Reviews
- Weekly: incidents and unowned alerts
- Monthly: critical sites, renewals, overdue actions
- Quarterly: access, recovery, templates, service classes
## Exit
Offboarding follows [handover checklist] and removes monitoring only after accepted transfer.
Without service classes, the agency updates all sites in one batch and discovers a checkout conflict after clients complain. In the portfolio model, the platform owner tests the change on a representative canary set, Class A stores require journey checks and longer observation, unsupported sites remain explicit exceptions, and rollout stops automatically when the failure threshold is met.
Scale comes from controlled sameness plus visible exceptions—not from treating every client identically.
The operating model matters first. You normally need an inventory, secret manager, help desk, monitoring platform, repository/automation, and reporting—not necessarily one product that controls everything.
When recurring response, preventive work, platform standards, and client reporting can no longer be reliably owned alongside project delivery.
No. Use service class and acceptable detection delay. Standardise the decision rule, not every value.
Confirm failures, group dependencies, route by severity, make every alert owned, measure repeated noise, and fix the monitoring system as a product.
Reviewed: 8 August 2026.
Next: Client website inventory template and monitoring as code.
Pingvera is designed to centralise deep external checks across a client portfolio. The agency still needs service classes, owners, access governance, and a work queue around those checks.
Pingvera watches whether an online business actually works — uptime, checkout, orders, domain, SSL and server — and alerts you in Telegram, email or a webhook before a customer has to tell you.
Start freeRead next: Client Website Outage Communication Templates · Malicious Redirect Monitoring for Client Websites · Client Website Inventory Template for Agencies · Monitor 50 Client Websites Without Alert Fatigue · Run a free site check.