
Access is not ownership, and only one of the two survives the agency exit.
A login someone shared with you is revocable by whoever shared it. Every line here carries a test that reads the ownership record, not whether the password works. Where those answers differ, the account is not provisioned.

Every account registers to systems@spireacademy.com, never an individual. Anything created on a personal address and moved later is the migration that never happens. Order binds once: GitHub must exist before Vercel connects to the repo.
Create systems@spireacademy.com in Google Workspace, forwarding to Nathan and the contractor. Every verification email and billing notice below lands here. TEST a message reaches both forwarding addresses.
One shared business vault named SPIRE Systems. Every credential below goes in it, nothing in a spreadsheet or a message. TEST both parties can read the vault.
Create the org, invite the developer, ask him to migrate the existing project in. Never accept a transfer of his own org. TEST project sits under SPIRE's org and SPIRE holds Owner.
Developer transfers the repository in, then gets added back as a write collaborator. TEST the repo URL shows the SPIRE org in its path.
Developer gets a deploying seat. Connect to the repo only after C2. The build targets Vercel, not Cloudflare, and already compiles clean with no code changes. TEST a deploy runs from the SPIRE-owned repo.
A new container, never the outgoing agency's. The developer needs the container ID for the site-wide install ticket. TEST container ID vaulted and sent to the developer.
Two seats, annual billing is cheaper, every seat includes Claude Code. TEST both seats active, shared mailbox as billing owner.
Starter now, Pro when volume requires it around the camp launch. TEST both parties can sign in to the workspace.
Private network between the office machine and both laptops. No ports opened, no router changes. TEST two devices on different networks reach each other.
If SPIRE lacks account-level admin on the existing property, build fresh under SPIRE. Historical data is worth less than clean ownership before launch. TEST Administrator at account level, not property level.
Assets get transferred into it, never shared into it. Shared assets vanish when the agency's business removes them. TEST pixel, page and catalog list SPIRE as owner.
These exist already. The question is never whether someone can log in. It is whose name sits on the ownership record once the agency's access is removed.
SPIRE has this. Confirm it is a domain property, not URL-prefix, and that SPIRE is Owner rather than Full User. ALSO export the full URL list this week. Nothing else unblocks the redirect map.
Shared credentials are not the same as holding the account. Admin → Account Access Management → confirm Administrator at account level. The runbook flags this as the known unresolved item from the agency exit. IF IT FAILS C8 applies, new property before launch.
SPIRE's own billing entity, and the agency's manager account removed, not downgraded. A manager link left in place keeps their claim. TEST SPIRE is the payments profile, no external manager linked.
Read the owner column on the pixel, page and catalog. Anything owned by the agency's business with SPIRE as partner is borrowed, and it stops working the day they leave. TEST every asset lists SPIRE's business as owner.
Who is registrant of record for spireacademy.com, and which account changes the A record on launch day? The runbook covers ten systems and skips the registrar. The developer's launch list assumes the record can simply be updated. TEST SPIRE holds the registrar login, lock on, TTL lowered before cutover.
Everything else here has a workaround that costs hours. A registrar you cannot reach on cutover day costs the launch date, and those credentials sit with the agency being removed. Resolve it before their access is cut.
After the accounts exist. A token is the third form of access, and it fails differently from a password: a token issued to a person dies when that person changes role, and a token that leaks cannot be un-leaked.
Scoped to contacts, deals, forms, lists, timeline and automation. TEST a read call returns one contact.
Vault it, then add to n8n as a credential. TEST n8n writes one test row and deletes it again.
Analytics and Ads, authorised as the shared mailbox so it survives a person changing role. TEST the consent screen shows systems@.
A system user, never a personal token. Personal tokens die when the person changes role. TEST issued to a system user, not a profile.
A refurbished or sale M4 at $480–600 is adequate. Runs Claude Desktop, Claude Code and local tooling, not a rendering machine. Company card, SPIRE's address, serial into the asset register. Not a blocker for section 02. ONE ADDITION disk encryption stays on since the vault lives here, so an unattended reboot needs a typed password. Run every service as a background daemon, not a desktop app, and put it on a UPS.
What the outgoing agency and the developer hold today. All three buckets must move before VividFront's access is cut, not after.
Who is the registrant of record for the domain, and can someone send the Search Console URL export. Everything else here has a workaround. Those two do not, and both are free to answer.