Reduce the privilege surface

Use individual accounts, phishing-resistant multi-factor authentication where available, and the smallest role each operator needs. Do not share the registrar, DNS, hosting, and application passwords. A compromise should not hand over every recovery channel at once.

Review active sessions, API tokens, SSH keys, and delegated users on a schedule and immediately after team changes.

Create a change trail

Record the reason, owner, time, affected service, expected result, and rollback for DNS, runtime, certificate, database, and file changes. Export configuration before editing it. Screenshots help, but machine-readable exports are better when the platform provides them.

Avoid editing production code through a panel. Deploy versioned artifacts from source control so a rollback reproduces a known state.

  • Take a targeted backup before destructive changes.
  • Change one layer at a time.
  • Verify from outside the provider network.
  • Close temporary access when work is complete.

Know what the provider does not back up

A dashboard labeled backup may exclude mailboxes, DNS zones, external databases, large objects, or recent snapshots. Read the scope and retention policy, then test a restore to a separate location.

Keep at least one recoverable copy outside the failure and billing boundary of the hosting account.

Verification checkpoint

Review accounts and tokens, export current configuration, and restore a selected file plus a database into a disposable destination without modifying production.