What to do in the first 48 hours
Three things, in this order. Access: change the passwords on the domain registrar, the server or cloud account, the code repository and any app store accounts. If those accounts are not in your name, start the transfer request today.
Backup: download a copy of the code and the database to your own machine. Billing: if servers, domains or third-party services are paid on someone else’s card, move them to yours. An unpaid server invoice means the system disappears one morning.
What is the one loss you cannot undo?
The data. Code can be rewritten, a design remade, a server rebuilt — but customer records, orders and history, once gone, do not come back.
So the question for day one is: where does the backup live and who can reach it? If the only copy sits in the account of the person who left, there is no backup.
Whose name should the accounts be in?
The rule is simple: if you pay for it, it should be registered to you. Domain, servers, database, email, payment provider, app store accounts and analytics all belong in that category.
What a developer receives is not ownership of the account but access to it. With that separation, changing team means removing access; without it, the asset itself stays on the other side.
What to do before hiring a new team
Have the system’s condition assessed. Without knowing the state of the codebase, what still runs and what is worth keeping, every quote you receive rests on a guess — and guesses get overrun.
That assessment is not a commitment to a takeover. It can conclude "do not continue with this", and knowing that costs less than spending months on a rescue that ends in a rebuild anyway.