---
title: "AI System Handoff: Transfer the Repo and Prove Access."
description: "Test an AI system handoff with source history, runbooks, a credentials map, receipts, and a clean start. Prove another authorized operator can run it."
canonical: "https://scalewithsearch.com/articles/transfer-the-repo-client-handoff"
date: "2026-08-17"
modified: "2026-09-19"
---
## Site navigation

- [Scale With Search](https://scalewithsearch.com/)
- Real estate
  - Real estate
    - [Real estate](https://scalewithsearch.com/for/real-estate)
- Work
  - Start here
    - [Send your brief](https://scalewithsearch.com/work#send-your-brief)
    - [Prepare your six-question brief](https://scalewithsearch.com/work#prepare-your-six-question-brief)
  - Build
    - [Site build, content library with SEO, signal desk](https://scalewithsearch.com/work)
- For your business
  - Trades and home services
    - [Auto body and collision shops](https://scalewithsearch.com/for/auto-body-and-collision-shops)
    - [Foundation and home repair contractors](https://scalewithsearch.com/for/foundation-and-home-repair)
    - [Garage door and fencing contractors](https://scalewithsearch.com/for/garage-door-and-fencing-contractors)
    - [HVAC contractors](https://scalewithsearch.com/for/hvac-contractors)
    - [Janitorial and commercial cleaning companies](https://scalewithsearch.com/for/janitorial-and-commercial-cleaning)
    - [Locksmiths](https://scalewithsearch.com/for/locksmiths)
    - [Moving companies](https://scalewithsearch.com/for/moving-companies)
    - [Pest control companies](https://scalewithsearch.com/for/pest-control-companies)
    - [Plumbing and electrical contractors](https://scalewithsearch.com/for/plumbing-and-electrical-contractors)
    - [Restoration and water or fire damage companies](https://scalewithsearch.com/for/restoration-and-water-fire-damage)
    - [Roofing companies](https://scalewithsearch.com/for/roofing-companies)
    - [Towing companies](https://scalewithsearch.com/for/towing-companies)
    - [Tree services and landscaping companies](https://scalewithsearch.com/for/tree-services-and-landscaping)
    - [Solar installers](https://scalewithsearch.com/for/solar-installation)
    - [General contractors](https://scalewithsearch.com/for/general-contractors-and-construction)
    - [Paving, concrete, and flooring contractors](https://scalewithsearch.com/for/paving)
  - Practices and professional services
    - [Bookkeeping and tax practices](https://scalewithsearch.com/for/bookkeeping-and-tax-practices)
    - [Dental practices](https://scalewithsearch.com/for/dental-practices)
    - [Family and criminal defense law firms](https://scalewithsearch.com/for/family-and-criminal-defense-law-firms)
    - [Med spas and aesthetics practices](https://scalewithsearch.com/for/med-spas-and-aesthetics)
    - [Personal injury law firms](https://scalewithsearch.com/for/personal-injury-law-firms)
    - [Veterinary clinics](https://scalewithsearch.com/for/veterinary-clinics)
    - [Gyms and fitness studios](https://scalewithsearch.com/for/fitness)
    - [Therapy and outpatient health practices](https://scalewithsearch.com/for/therapy-and-outpatient-health)
    - [Medical billing companies](https://scalewithsearch.com/for/medical-billing)
    - [Insurance agencies](https://scalewithsearch.com/for/insurance-agencies)
    - [Financial advisors](https://scalewithsearch.com/for/financial-advisors)
    - [Property management companies](https://scalewithsearch.com/for/property-management)
    - [Recruiting and staffing agencies](https://scalewithsearch.com/for/recruiting-and-staffing)
    - [Architects and interior designers](https://scalewithsearch.com/for/architects-and-interior-designers)
    - [Logistics and supply chain companies](https://scalewithsearch.com/for/logistics-and-supply-chain)
  - Agencies, MSPs, and manufacturing
    - [IT and managed service providers](https://scalewithsearch.com/for/it-and-managed-service-providers)
    - [Machine shops and precision manufacturers](https://scalewithsearch.com/for/machine-shops-and-precision-manufacturing)
    - [Marketing agencies and freelancers](https://scalewithsearch.com/for/marketing-agencies-and-freelancers)
    - [SEO agencies and consultants](https://scalewithsearch.com/for/seo-agencies-and-consultants)
    - [Small manufacturers and fabricators](https://scalewithsearch.com/for/small-manufacturers-and-fabricators)
  - Restaurants, shops, studios, and nonprofits
    - [Restaurants and hospitality businesses](https://scalewithsearch.com/for/restaurants-and-hospitality)
    - [Retail stores and ecommerce sellers](https://scalewithsearch.com/for/retail-and-ecommerce)
    - [Photographers, event planners, and travel agents](https://scalewithsearch.com/for/photographers)
    - [Churches and nonprofits](https://scalewithsearch.com/for/churches-and-nonprofits)
  - [All industries](https://scalewithsearch.com/for/)
- Learn
  - For your office
    - [Office job guides](https://scalewithsearch.com/guides/)
    - [Browser calculators](https://scalewithsearch.com/tools/)
  - Start here
    - [How it works](https://scalewithsearch.com/how-it-works)
    - [Free Starter Kit](https://scalewithsearch.com/kit/business-memory-starter-kit.zip)
    - [Synthetic specimen](https://scalewithsearch.com/specimen/working-session-specimen.zip)
  - Guides
    - [The Complete Guide to Business Memory for AI Agents](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [The Complete Small-Business Guide to AI Agent Governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [The Complete Guide to Leaving Vendor AI Memory](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - Articles by cluster
    - [Business memory](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [Agent governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [Migration and ownership](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - For machines
    - [llms.txt](https://scalewithsearch.com/llms.txt)
    - [llms-full.txt](https://scalewithsearch.com/llms-full.txt)
    - [Machine view](https://scalewithsearch.com/?view=machine)
- Company
  - Evidence
    - [Proof](https://scalewithsearch.com/proof)
  - Company
    - [About](https://scalewithsearch.com/about)

# Your AI System Is Not Yours Until You Can Transfer It.

A builder sends you a ZIP, a few login notes, and a message saying the AI system is yours. Six months later, you need to change the model or deploy a fix. Nobody can identify the canonical source, the live commit, the required secrets, or the command that starts the system.

You received files. You did not receive an operable system.

## Ownership must survive a different operator

An owned system has a source record that another authorized operator can inspect. It also has a documented path from source to a working result.

For code, the repository is usually that source record. Git records project history, branches, tags, and changes. A ZIP preserves one snapshot of files. It does not preserve the full repository relationship or tell the next operator which snapshot produced the live system.

Transfer the repository. Do not ship a ZIP and call it ownership. Then finish the handoff around that rule.

Create an inspectable `handoff-receipt.md` containing:

- canonical repository URL;
- owner account or organization;
- accepted transfer date;
- production branch and live commit;
- local setup command;
- test command;
- build and deploy commands;
- hosting and domain owners;
- environment variable names and custody locations;
- backup and rollback paths;
- manual steps and known defects;
- support boundary and stopping point.

This receipt must name locations. "Ask the developer" is not a location.

## Transfer the project as a project

[GitHub documents repository transfer](https://docs.github.com/en/repositories/creating-and-managing-repositories/transferring-a-repository) as an ownership operation. A transfer can preserve repository content, issues, pull requests, releases, settings, commit information, and other project state, subject to platform rules and account permissions. GitHub also warns that Pages, packages, policies, permissions, and plan features can behave differently after transfer.

Those warnings are useful. They force the handoff to address the system around the code.

The receiving business should own the target organization when practical. A repository under one employee's personal account can become stranded when that employee leaves. Organization ownership makes membership and responsibility explicit.

Direct transfer is not always the right mechanism. [Git documents bundles](https://git-scm.com/docs/git-bundle) for offline transfer of Git objects and refs. A mirror, bundle, or new client-owned remote can preserve repository history when a platform transfer is unavailable. The handoff receipt must still name which remote is canonical.

## Keep secrets separate from source

Repository ownership does not mean credentials belong in the repository.

[GitHub describes Actions secrets](https://docs.github.com/en/actions/concepts/security/secrets) as protected values stored at organization, repository, or environment scope. Environment secrets can also use required reviewers before a job receives access. The exact control depends on the host, but the ownership principle stays stable: the client controls the account and the builder documents what each secret enables.

The receipt should list `PROVIDER_API_KEY`, `DEPLOY_TOKEN`, or another required variable by name. It should say where the value is held and who may rotate it. It should never include the value.

Rotate builder-owned credentials during handoff. Do not leave production dependent on a personal token whose owner expects to revoke it later.

## Run a transfer test

A transfer is incomplete until the receiving owner proves it works outside the builder's machine.

Use this acceptance sequence:

1. The receiving owner accepts repository ownership.
2. An authorized person uses a clean machine or clean working directory.
3. They clone from the canonical remote.
4. They follow the written setup instructions without unpublished help.
5. They supply credentials from the documented custody locations.
6. They run the stated tests.
7. They produce a local build or bounded test output.
8. They compare that output with the acceptance list.
9. They verify that the live commit named in the receipt exists in the transferred history.
10. They record the result in `transfer-test.md`.

The test receipt should record the clone URL, commit, commands, test result, missing dependencies, credential gaps, and final owner decision.

Do not use production as the first transfer test. A local build, staging environment, or dry-run output should prove the path before any live deploy.

## Transfer the business memory too

The code can move cleanly while the operating knowledge remains trapped with the builder.

An agent system also needs readable sources, task briefs, correction records, approval rules, and stopping points. If these exist only in the builder's chat history, the client will reconstruct the system after transfer.

Include the buyer-owned context files in the repository when their sensitivity permits it. Otherwise, point to the client-owned record system that stores them. The runbook must explain how the agent retrieves them.

Model-specific adapters may remain in code. Business rules should not be buried inside one provider prompt when they can be expressed as readable files. This makes replacement work narrower: update the adapter, then rerun the acceptance tests against the same source record.

## Name what does not transfer

Repository transfer does not automatically transfer every external account or prove a deployment.

Domains, hosting organizations, billing accounts, OAuth applications, analytics properties, email services, databases, and vendor workspaces may each require separate ownership changes. Some integrations may retain old webhooks or credentials. Some features can change under the receiving account's plan.

Add each dependency to `ownership-map.md` with four fields: object, current owner, intended owner, and transfer status.

The system must stop and ask for approval before:

- transferring a repository or organization;
- changing billing ownership;
- rotating or revoking a live credential;
- changing DNS or a production deployment;
- adding a new administrator;
- deleting the builder's remaining access;
- moving restricted business records into the repository.

These are ownership and production actions. A handoff plan can prepare them. It cannot treat them as implied.

## Name who maintains the system after handoff

Transfer without maintenance ownership creates a slower version of the same dependency.

The buyer should own business facts, approved decisions, user access, and external-action authority. A system owner should maintain the repository, adapters, tests, and deployment record. A workflow owner should review task briefs, corrections, and acceptance changes. One person may hold several roles, but each responsibility needs a name.

Add a maintenance table to `ownership-map.md`:

```text
object:: client-context.md
maintenance_owner:: account owner
review_trigger:: scope or account status changes

object:: model adapter
maintenance_owner:: system owner
review_trigger:: provider, model, tool schema, or error behavior changes

object:: task brief and acceptance list
maintenance_owner:: workflow owner
review_trigger:: output, approval, or stopping point changes

object:: secrets and billing accounts
maintenance_owner:: business account owner
review_trigger:: access change, rotation, or vendor change
```

The runbook should say how each owner proposes and approves a change. It should also say what happens when the owner leaves or the support relationship ends.

The buyer's files do not require a continuing service to remain readable. If support stops, the handoff receipt and support boundary control what the buyer maintains next.

## Test a support-free run

The clean-start test should include one run without live guidance from the builder.

The receiving operator follows the runbook, records missing steps, and stops rather than asking for undocumented commands in the middle. The builder may answer after the test, then update the runbook and rerun the failed step.

This is not a test of whether the buyer can become a developer in one afternoon. It tests whether the handoff names every dependency required for the accepted outcome.

## The finish line

The finish line is not "client downloaded source." It is this: the client controls the canonical source, an authorized operator completes the clean-start test, the ownership map has no hidden dependency, and the receipt states what support continues.

## Sources

- [GitHub: Transferring a repository](https://docs.github.com/en/repositories/creating-and-managing-repositories/transferring-a-repository)
- [Git: git-bundle documentation](https://git-scm.com/docs/git-bundle)
- [GitHub: Secrets](https://docs.github.com/en/actions/concepts/security/secrets)


## Questions about Your AI System Is Not Yours Until You Can Transfer It

### Does anyone have experience moving Repositories to another account or organization?

Transfer the repository to the receiving owner, then run a clean-start test from a clean machine or working directory. The handoff receipt should identify the canonical remote, live commit, setup and test commands, dependencies, credentials custody locations, rollback path, and support boundary.

### How do I transfer a repository, I created, to an organisation, I am 'owner' of?

A repository transfer moves project ownership, but it does not prove that hosting, domains, billing, OAuth apps, databases, webhooks, or deployment credentials transferred. Record each external dependency in an ownership map and test the receiving operator's setup before any production change.

### How do you build applications that require zero maintenance?

The handoff should name maintenance responsibilities rather than imply that the system needs no future owner. Assign ownership for business facts, adapters, tests, deployment records, task briefs, corrections, secrets, and billing accounts.

## Related: Ownership and Migration

- [How to Preserve Context From AI Design Sessions: Decisions, Constraints, and Handoff](/articles/preserve-context-ai-design-sessions)
- [What a Build Acceptance List Contains](/articles/what-a-build-acceptance-list-contains)
- [Your AI Remembers You. Do You Own the Memory?](/articles/do-you-own-ai-memory)

----

```text
                  .|########||.                                       .|########||.                                       .|########||.
               |##||.      .||##|.                                 |##||.      .||##|.                                 |##||.      .||##|.
             |#|.              .|#|.                             |#|.              .|#|.                             |#|.              .|#|.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
        .#.                          .#|                    .#.                          .#|                    .#.                          .#|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
      |#             ......             #|                |#             ......             #|                |#             ......             #|
     .#           ||#########|           #|              .#           ||#########|           #|              .#           ||#########|           #|
    .#.         |######||######|.        .#.            .#.         |######||######|.        .#.            .#.         |######||######|.        .#.
    #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#
   ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||
   #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #
 ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||
 #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#
 #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.
.|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||
||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||
#.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#
#    .||####|###########################|.     #    #    .||####|###########################|.     #    #    .||####|###########################|.     #
#      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #
#      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #
#      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #
#      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #
#   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #
#. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#
|| |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||
|| ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||
.# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.
 #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#
 ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||
  #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.
   ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||
    #.        .######|#|#########|        .#            #.        .######|#|#########|        .#            #.        .######|#|#########|        .#
    .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.
     |#           ||########||           #.              |#           ||########||           #.              |#           ||########||           #.
      |#             ......             #|                |#             ......             #|                |#             ......             #|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
        |#.                          .#.                    |#.                          .#.                    |#.                          .#.
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
            .|#|.              .|#|.                            .|#|.              .|#|.                            .|#|.              .|#|.
               |##||.      .||##|                                  |##||.      .||##|                                  |##||.      .||##|
                 .||########||.                                      .||########||.                                      .||########||.

Scale With Search  2026  [scalewithsearch.com](https://scalewithsearch.com)
```
