Who actually owns your website, and why it's often not you
The domain, the DNS, the hosting and the Google profile are four separate accounts, and on most small business sites at least one of them is in someone else's name. You find out at the worst possible moment.
A business came to us wanting a new site. Straightforward job, we'd quoted it, everyone was happy. Then we went looking for who held the domain so we could point it at the new build, and the answer was a bloke who'd made their original website in about 2016.
Not his company. Him. His name in the registrant field, his personal email address as the contact, an email address that had stopped existing when the business he'd been running at the time folded.
The new site sat finished for close to a month while we worked through it. It got sorted in the end. But everyone involved spent that month feeling slightly ill, because for a while there it wasn't obvious that it would.
You don't own a .au domain at all
Start here, because the language everyone uses is wrong and it matters.
Nobody owns a .com.au. You hold a licence to use it, issued for a period, subject to conditions, and auDA's licensing rules say so in about as many words: a registrant "does not legally own a Domain Name". What you have is a licence and a record in a registry saying who the licence holds for.
Which sounds like a technicality until you notice that the entire question of who controls your web address comes down to one field in that record. Whoever is named as the registrant is, for practical purposes, the person the system will listen to. Not whoever paid the invoice, and not whoever the business obviously is.
You can go and look at your own right now. The .au WHOIS lookup is run on auDA's behalf, it's free, it takes about a minute, and it'll show you the registrant name on your domain. I'd do it before reading the rest of this, honestly. Half the people who do it get a small surprise.
Four accounts, and they're not the same account
The other thing that trips people up is thinking of "the website" as one thing they either have or don't.
It's at least four separate logins, usually held in four different places, and they can each end up with a different owner. The domain licence is one. The DNS, which is the bit that decides where the domain actually points, sometimes lives with the registrar and sometimes doesn't. The hosting is a third, wherever the site's files and database sit. And then there's the code itself, which on a custom build lives in a repository somewhere, and which you'd want if you ever changed developers.
People often have two of the four and assume that's the set. The classic version is a business with full access to their hosting account, feeling in control, who can't move anywhere because the domain is somewhere they've never seen.
The Google profile is the one that bites hardest
Your Google Business Profile belongs on that list and it's the one I've seen cause the most grief, partly because it isn't obviously a piece of infrastructure.
What happens is that a marketing company sets the profile up for you, under their own Google account, because that's the quickest way to do it. Years later you part ways, and the profile that carries your reviews, your photos and your position in the map pack is sitting in the account of a company you no longer speak to. You might have manager access. Manager isn't owner.
Google has a process for this. You request access through the profile, the current owner gets an email, and they have three days to respond. If they respond and say no, you're into appeals and suggested edits, and if the email address on file is dead you're waiting out the clock and then verifying the business yourself. None of it is fast, and all of it happens while your listing is out of your hands.
Same story with analytics. Not as painful, because you can start a new one, but you lose the history, and you don't get it back.
It's almost never malice
Worth saying, because the story above sounds like a villain and it usually isn't one.
The person who put your domain in their own name almost always did it to be helpful. You were busy, they were setting things up, they had a registrar account open, and asking you to create your own and forward them the login would have added a week to a job everyone wanted finished. So they used theirs. At the time it was a favour.
The failure mode isn't dishonesty, it's time. Businesses close. People move overseas, change email addresses, get sick, lose interest in the web work they used to do on weekends. The arrangement that was fine for six years stops being fine on the day you need something from a person who has moved on with their life.
Which is why I'd frame this as bookkeeping rather than as a trust problem. You're not accusing anyone of anything by wanting your own name on your own asset.
Sorting it out, which is duller than it sounds
Make a list. Four or five lines in a document, one per account, with where it lives, whose name and email is on it, and what the renewal situation is. Nobody has this. It takes an afternoon to build and it's the single most valuable page of documentation a small business can keep about its website.
Get the registrant details corrected to the business itself, with an email address that belongs to the company rather than to a person, and ideally one that more than one person can read. A shared address that survives someone leaving. Same for the billing on renewals, because a domain lapsing quietly on an expired card is a genuinely common way to lose one, and recovering it after the fact is a bad week.
Then apply the obvious test. If the person who currently holds each of those accounts vanished tomorrow, could you still get in? If any line fails that, fix that line first.
If you're moving between developers, this is also exactly the moment to get it right, because access has to change hands anyway and it's much easier to correct a registrant record during a handover than to raise it out of nowhere two years later. Same if you're about to rebuild, where you'll want the old URLs and redirects as well, or changing your domain name entirely.
Do the WHOIS check
If you take one thing from this, do the lookup on your own domain and see whose name comes back.
It's a minute, it's free, and it either confirms everything is fine or it tells you about a problem while there's no deadline attached. Which is the only good time to find out.
We check ownership as a matter of course when we look at a site, and we'll go through yours for free if you'd rather someone else did the digging. There's no charm to any of this work. It's just the difference between an asset you control and one you're borrowing.