The client site is defaced. Client calls host. Host refers agency. Agency says maintenance contract excludes security. Client pays three vendors and nobody has the runbook. This chaos is not technical — it is missing written boundaries.
Three actors involved: host (infra, network, sometimes OS), agency / integrator (site, code, sometimes ops), client (content, business data, sector compliance). Host terms limit liability; agency contract must complement, not assume.
Simplified RACI matrix
| Domain | Host | Agency | Client |
|---|---|---|---|
| Datacenter / hypervisor uptime | R | I | I |
| OS / patches (managed VPS) | R/A per offer | C | I |
| CMS, plugins, theme | I | R/A | C |
| Tested business backups | C | R/A | A |
| SSL certificate (auto Let's Encrypt) | R | C | I |
| Published content (text, images) | I | C | R/A |
| GDPR register / DPA | I | C | R/A |
| Incident communication | C | R | A |
| Abuse report | R technical | C | R editorial |
R = responsible, A = accountable, C = consulted, I = informed — adapt to your actual contract.
Managed offers: read the depth
- Shared — host: platform, PHP, limited mail. You: site, updates, business backups.
- Unmanaged VPS — you or agency: everything except hypervisor.
- Managed VPS / server — OS patches, infra monitoring — not necessarily WordPress code.
- Managed WordPress — core updates sometimes included — third-party plugins often excluded.
Compare in the directory crossing offer type and internal skills. For shared access, see Team SFTP access.
Avoid grey zones
- Written doc — one page "who does what in incident".
- Access — no shared single account between agency and client.
- Tested backup restore quarterly — named owner.
- Escalation — host + agency + client numbers on one sheet.
Every grey zone becomes a post-incident dispute. Courts do not philosophise: they read host terms and agency order form.
The peak: "all inclusive" does not exist — only "all vague"
Here is what the words "all inclusive" actually hide.
Decide and move forward without blind spots
In half a day you can clarify boundaries:
- Write a one-page RACI matrix.
- Align host terms, agency contract, client expectations.
- Test a restore and incident communication.
- Review on every offer change (shared → VPS).
Start with a three-way meeting — client, agency, host if possible — to validate who patches, who restores and who communicates. Without that written page, every incident becomes responsibility ping-pong. See also Disaster recovery plan to formalize backups.
Frequently asked questions
Is the host responsible for WordPress hack?
Generally not for application code and CMS updates — except proven infrastructure flaw on host side. Client or agency maintains the app; host provides OS or hypervisor per subscribed offer.
Who must run backups?
Double vigilance: host "best effort" backup does not equal business continuity. Controller or client must have a regularly tested copy of their own.
Web agency — typical scope?
Deploy, theme, plugins, sometimes maintenance — rarely full infrastructure MSP unless explicit contract. Clarify scope in the order form, not after the incident.
Illegal content reported — who answers?
Site publisher (client) first; host acts as technical intermediary (takedown, suspension) per law and terms. See the abuse report guide.
Before the next outage, one three-way question: who patches, who restores, who communicates? If everyone looks at others, you do not have three vendors — you have nobody.