What you’ll be able to do
By the end of this you’ll know where your website actually lives, who holds the keys, and whether you’re updating it or starting again. You’ll have every login sitting in one place, not scattered across an old inbox and someone’s memory. And you’ll have a way of using AI to read the current site, spot what’s wrong with it, and draft new pages from facts you actually supply, rather than facts it makes up.
You don’t need to become the IT department. You just need to be organised about it, which, let’s be honest, is probably why this landed on your desk in the first place.
Before you start
Here’s the bit nobody explains properly: a website isn’t one thing. It’s three things, and they’re often owned by three different companies, none of whom talk to each other.
There’s the domain, which is just the name, like yourcompany.co.uk. That’s bought from a registrar, somewhere like GoDaddy, 123-reg, Namecheap or Cloudflare. Then there’s the hosting, which is where the actual files sit and get served to visitors. And then there’s the site itself, the thing people see, which might be WordPress, Squarespace, Wix, or in the worst case, a folder of plain files nobody currently working at your company knows how to touch.
Three things. Possibly three different logins, three different renewal dates, three different companies who couldn’t care less about the other two.
Before you go anywhere near AI or a rebuild, you need to know what the site legally has to carry, because this bit’s non-negotiable. If you’re a limited company, the site must show your registered company name, company number, place of registration, and registered office address, under the Companies (Trading Disclosures) Regulations 2008. If the site collects any personal data at all, and a contact form counts, you need a privacy policy. And you need an accessible way for someone to actually contact you. Not a decorative email icon that goes nowhere.
The previous person or the agency will usually have left something behind, even if it’s not obvious. Old invoices, a card statement with a recurring charge on it, an email thread from three years ago. These are your clues. Keep them.
Get set up
Start with discovery, not building. This is the step people skip and then regret.
Go to lookup.icann.org or who.is and type in your domain name. This is free and takes seconds. It’ll show you the registrar (who the domain is bought through) and the nameservers, which usually point at whoever’s hosting the site. Write both down.
If that doesn’t tell you enough, go looking through the finance team’s card statements or old invoices for anything that mentions hosting, WordPress, Squarespace, Wix, or a web agency’s name. Someone, somewhere, is paying a small recurring amount for something. That’s usually the thread to pull.
Once you know who holds what, you need the actual logins. Get every single one, domain registrar, hosting, the website platform itself, into a proper password manager. Bitwarden is free and does the job. 1Password is paid but also fine. The important bit isn’t which one, it’s that the accounts belong to a company email address, not someone’s personal Gmail from 2019, and that at least two people have access. Not one. Two.
Now the actual decision: update, or rebuild?
If the site has a login and something resembling an editor, WordPress, Squarespace, Wix, whatever, then you update it there. That’s the quicker, cheaper route almost every time.
But if it’s plain files that nobody currently at your company can edit, or you’re paying a monthly platform bill for something that isn’t even being used properly, rebuilding is usually faster than trying to rescue it. A tool like Lovable lets you build a site by chatting with it, it’s credit-based with a free tier, and you publish it first at a lovable.app address before pointing your actual company domain at it once you’re happy. Genuinely often quicker than untangling five years of someone else’s decisions.
Try it yourself
Right, this is where the AI part actually earns its keep. Don’t start by asking it to write anything. Start by asking it to read what’s already there.
Read [company website address] and list every page, the contact details you find, and anything that looks out of date (years, names, prices, "coming soon"). Do not guess, say what you could not load.
Paste that into ChatGPT, Claude or Gemini with your actual site address swapped in. There’s a separate guide on this site, “How to get AI to read my website”, if you want to go deeper on that step specifically. But even this one prompt will usually surface an out-of-date copyright year, a staff member who left two years ago, or a “coming soon” page that’s been coming soon since 2021.
Once you know what’s wrong, don’t let the AI invent the fix. Give it facts and ask it to write from those facts only.
Rewrite this About page from these facts only, in plain English, 150 words: [paste facts]
This matters more than it sounds like it should. AI is very good at writing something plausible and very bad at knowing whether it’s true. If you don’t give it real facts, staff names, prices, dates, it will happily make some up that sound entirely reasonable and are entirely wrong. Feed it what you know. Let it do the sentence-building, not the fact-finding.
And before you hand this whole thing over to whoever comes after you (because someone will, eventually, be sat where you’re sat now), get AI to help you build a proper handover document.
Write a website checklist for handover: domain registrar, renewal date, hosting, platform, logins location, who receives the contact form, last content review date.
Fill in the answers yourself. Keep it with the password manager. Future you, or future whoever, will be grateful.
Check the result
Once anything’s changed, whether that’s a quick update or a full rebuild, go through it properly. Don’t assume it works because it looks right on your screen.
Click every link on every page. Every single one. Broken links are the fastest way to look neglected, and they hide in places you’d never think to check, an old PDF, a footer, a “read more” from three years ago.
Test the contact form yourself. Submit it with a real message and confirm exactly who receives it. This one’s caught people out badly, a form that’s been quietly emailing an address nobody checks for two years, while the company wonders why nobody’s getting in touch.
Check the phone number and address on the site actually match what’s on Google and what’s registered at Companies House. These drift apart more than you’d think, especially after an office move nobody updated everywhere.
Look at the site on your phone. Not just imagine what it looks like, actually open it on your phone. Plenty of older sites were built before anyone much cared about mobile, and it shows.
And check the domain renewal date, plus who’s actually paying for it. A lapsed domain is a genuinely awful problem to have, and it’s entirely avoidable if someone just knows the date and has it in a calendar.
If it doesn’t work
Sometimes none of this goes smoothly. That’s normal, not a sign you’re doing it wrong.
If nobody knows the registrar, go back to the WHOIS lookup and the card statements. Between the two, you’ll almost always find it.
If the agency won’t hand things over, put it in writing. Ask for the domain transfer code and admin access, plainly and specifically. The company owns its own domain, full stop, regardless of who built the site or how the relationship ended. You’re not asking for a favour.
If the site simply can’t be edited, no login exists, nobody knows the platform, the files are just sitting there, then stop trying to rescue it and rebuild instead. It’s usually faster and it saves you a lot of frustration chasing something that was never going to give.
On privacy: be careful what you paste into an AI chat. Don’t hand over staff personal details, customer lists, or internal documents, ever. If you’re rewriting a team page, get the OK from the actual people on it before you publish anything about them, even something as harmless-sounding as a rewritten bio. It’s their information, not yours to hand to a chatbot without asking.
Keep exploring
“How to get AI to read my website” goes deeper into that first discovery step. If it ends in a rebuild, “How to get AI to build me a website” lays out the routes and “How to get AI to build me a website with Lovable” is the one this guide leans on. And “How to get AI to summarise a document” is the same trick for the pile of old agency contracts you will find along the way.
Sources and review notes
https://lookup.icann.org https://www.who.is https://bitwarden.com https://1password.com https://www.legislation.gov.uk/uksi/2008/495/contents/made (Companies (Trading Disclosures) Regulations 2008) https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ https://lovable.dev
Review date: 2026-09-16