There's a version of this conversation that goes badly, and it's the one where nobody has it until something has already gone wrong.
These five questions take a good developer about five minutes. Asked at the end of a project, while everyone is still on friendly terms and everything still works, they are ordinary project admin. Asked two years later, in an email that starts "sorry to bother you", they are a favour.
Ask them now. Most developers are relieved to be asked, because it means they get to stop holding something they never wanted to hold.
1. Which of these accounts are in my name?
Your website isn't one account. It's usually five or six: the domain, the hosting, DNS, email, analytics, and whatever else the project needed. Each one has an owner, and they are frequently not the same owner.
Ask for the list. "Do I own my website" is too big a question to answer usefully. Ask which of those specific accounts are registered to your business and which are on your developer's.
A good answer names each one, and is honest about the ones that aren't yours yet. A vague answer almost never means something is wrong. It usually means nobody has ever written it down, which is exactly the situation you're trying to fix.
2. What email address owns each account?
This is the question that matters most, and almost nobody asks it.
Every provider on earth resolves a lost account the same way: they send a reset link to the address on the account. Not to whoever paid the invoice, and not to whoever is legally entitled to it. To that address.
So the answer to "could I recover this on my own?" comes down to one field. A domain registered to admin@yourbusiness.com is yours to recover on a Sunday afternoon. The same domain under dev@someagency.com is yours to recover only if somebody answers the phone.
While you're at it, ask what the recovery email and phone number are. Those are separate fields, and a personal mobile number on a business account walks out of the door with the person attached to it.
3. If you stopped working with me tomorrow, what would I need to do?
Phrase it exactly like that. The flippant version, the one about buses, invites a flippant answer, and this is the question with the most information in it.
You're not asking whether they plan to leave. You're asking them to walk the recovery path out loud, and the useful part is where they hesitate. A developer who says "you would log into the registrar with your own account, and everything else resets through your email" has already done the work. A developer who pauses and says "hm, the DNS is on my Cloudflare, let me think" has just found the gap for both of you, which is the entire point of asking.
Nothing about this is an accusation. Everyone who does this work has at least one account like that.
4. Who pays for the renewals, and what happens when that card expires?
Domains expire. So do hosting plans, SSL certificates on some setups, and email subscriptions. Something in your stack renews every few months, and it renews against a card and notifies an inbox.
Ask which card and which inbox. If the answer is your developer's card and your developer's inbox, that arrangement works right up until the card expires, they change email providers, or the relationship ends quietly and nobody thinks about the domain until the site goes dark.
An expired domain is recoverable, but it goes through stages. There's a short grace period where you renew at the ordinary price, then a redemption period where you can still get it back but pay a fee that commonly runs eighty to two hundred dollars, and after that it's deleted and released to anyone. Domains with real traffic get registered within seconds of becoming available, by services that exist to do exactly that.
None of that happens if the renewal notice arrives somewhere you actually read.
5. Can I have that in writing?
The first four questions produce answers that live in someone's memory and in one email thread. Ask for a document.
It doesn't need to be formal. One page is enough, and it should record, for each account: what it is, which provider, which email address owns it, whether it has actually been transferred to you, when it renews, and where the password is kept.
Where the password is kept, not the password itself. A document with live credentials in it gets forwarded and left in inboxes, and it goes wrong the first time anyone changes anything. "In the shared 1Password vault" or "reset via admin@yourbusiness.com" stays true for years.
If your developer already has something like this, you'll have it the same day. If they don't, you have given them a reason to make one, and they will be a better supplier to you for it.
What if the answers aren't what I hoped?
Then you have found something worth an hour, and you have found it on a normal Tuesday rather than during an emergency.
Almost none of this is anyone behaving badly. The domain sits in the developer's account because on the day the project started you didn't have a registrar account and somebody had to register it. The Workspace is under their login because the business had no email address yet, which was the problem being solved. Each of those was the sensible choice that afternoon. They only become problems because nobody revisits them.
Ask the five questions while it's still a conversation.