Independent comparison · no paid rankings
Home / Blog / Host, client, agency: where does each responsibility begin?
Guide

Host, client, agency: where does each responsibility begin?

Outage, data breach or illegal content — everyone points elsewhere. Without a written matrix, the client assumes "everything is included" and the host points to "your application".

3 min read Updated Jul 19, 2026

The client site is defaced. Client calls host. Host refers agency. Agency says maintenance contract excludes security. Client pays three vendors and nobody has the runbook. This chaos is not technical — it is missing written boundaries.

Three actors involved: host (infra, network, sometimes OS), agency / integrator (site, code, sometimes ops), client (content, business data, sector compliance). Host terms limit liability; agency contract must complement, not assume.

Simplified RACI matrix

DomainHostAgencyClient
Datacenter / hypervisor uptimeRII
OS / patches (managed VPS)R/A per offerCI
CMS, plugins, themeIR/AC
Tested business backupsCR/AA
SSL certificate (auto Let's Encrypt)RCI
Published content (text, images)ICR/A
GDPR register / DPAICR/A
Incident communicationCRA
Abuse reportR technicalCR editorial

R = responsible, A = accountable, C = consulted, I = informed — adapt to your actual contract.

Managed offers: read the depth

  • Shared — host: platform, PHP, limited mail. You: site, updates, business backups.
  • Unmanaged VPS — you or agency: everything except hypervisor.
  • Managed VPS / server — OS patches, infra monitoring — not necessarily WordPress code.
  • Managed WordPress — core updates sometimes included — third-party plugins often excluded.

Compare in the directory crossing offer type and internal skills. For shared access, see Team SFTP access.

Avoid grey zones

  1. Written doc — one page "who does what in incident".
  2. Access — no shared single account between agency and client.
  3. Tested backup restore quarterly — named owner.
  4. Escalation — host + agency + client numbers on one sheet.

Every grey zone becomes a post-incident dispute. Courts do not philosophise: they read host terms and agency order form.

The peak: "all inclusive" does not exist — only "all vague"

Here is what the words "all inclusive" actually hide.

Decide and move forward without blind spots

In half a day you can clarify boundaries:

  1. Write a one-page RACI matrix.
  2. Align host terms, agency contract, client expectations.
  3. Test a restore and incident communication.
  4. Review on every offer change (shared → VPS).

Start with a three-way meeting — client, agency, host if possible — to validate who patches, who restores and who communicates. Without that written page, every incident becomes responsibility ping-pong. See also Disaster recovery plan to formalize backups.

Frequently asked questions

Is the host responsible for WordPress hack?

Generally not for application code and CMS updates — except proven infrastructure flaw on host side. Client or agency maintains the app; host provides OS or hypervisor per subscribed offer.

Who must run backups?

Double vigilance: host "best effort" backup does not equal business continuity. Controller or client must have a regularly tested copy of their own.

Web agency — typical scope?

Deploy, theme, plugins, sometimes maintenance — rarely full infrastructure MSP unless explicit contract. Clarify scope in the order form, not after the incident.

Illegal content reported — who answers?

Site publisher (client) first; host acts as technical intermediary (takedown, suspension) per law and terms. See the abuse report guide.


Before the next outage, one three-way question: who patches, who restores, who communicates? If everyone looks at others, you do not have three vendors — you have nobody.

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →