
Open the visual model ↗
Read the exit clock and assign decision rights
Start with the signed agreement and amendments, not the sales page. Record renewal date, notice window, termination route, minimum spend, outstanding invoices or credits, export assistance, data return or deletion language, domain and account ownership, post-termination access, and dispute contact. Put a named internal owner beside each unresolved term. This is an operational inventory for contract and legal review, not contract advice.
UK ICO accountability guidance includes return or deletion at the end of certain processing arrangements, illustrating why exit handling belongs in the original contract. The applicable obligation depends on role and jurisdiction. Ask the responsible reviewer to interpret the actual agreement. Send no notice during planning; the plan should first make the consequences visible and identify the authorized person who can later act.
| Item | Evidence | Owner | Decision date |
|---|---|---|---|
| Renewal and notice | Signed order form | Business owner | Before notice window |
| Export entitlement | Contract and help page | Data owner | Before access ends |
| Final invoice/credit | Billing ledger | Finance reviewer | Close period |
| Deletion/return | Applicable clause | Privacy reviewer | After verified cutover |
Source notes: Contracts and data sharing
Inventory portable assets and nonportable behavior
List content records, media originals, taxonomies, authorship, URLs and redirects, subscriber or customer records, consent and suppression state, templates, code, configuration, analytics history, billing references, ad tags, API credentials, domains, certificates, and documentation. For each asset, record source of truth, export format, approximate count, stable identifiers, attachments, and who can validate it. Export availability alone does not establish completeness or restorability.
Vendor documentation can reveal boundaries. Ghost, for example, documents different exports for content, members, themes, and analytics. That product-specific fact is a prompt to inspect separate asset classes, not proof that another vendor behaves the same. Also record workflows that cannot be exported: automation logic, deliverability reputation, model output, reporting definitions, historical permissions, and proprietary audience segments. These need replacement decisions, not just files.
| Asset | Format/key | Dependency | Validation |
|---|---|---|---|
| Articles | JSON + stable slug | Media URLs | Count and sampled render |
| Media | Original files + paths | Storage/CDN | Checksum and sampled open |
| Members | CSV + internal ID | Consent/suppression | Counts by status |
| Redirects | CSV source→target | Routing layer | Sample chains and loops |
| Reports | CSV/PDF + definitions | Vendor taxonomy | Totals and period |
Source notes: Exports
Map dependencies and design a quiet cutover
Draw inbound and outbound dependencies: DNS, single sign-on, webhooks, payment provider, email sender, tag manager, CDN, search, mobile apps, analytics, support forms, and downstream warehouses. Mark which credentials the departing vendor can use and which systems point back to its domains. The exit is not complete while an overlooked webhook can publish, charge, send, or overwrite records.
Define a parallel validation environment and a cutover sequence. Freeze only the data classes that require it, capture a final delta, reconcile counts, switch one dependency at a time, and keep a time-limited rollback path. Prevent test systems from emailing real readers, charging accounts, serving production ads, or writing into the old source of truth. This plan is broader than newsletter migration because it covers the publication's entire vendor dependency graph.
- Map every domain, credential, API, and webhook.
- Separate test credentials and recipients.
- Choose a final-delta method for changing records.
- Preserve redirects and public identifiers.
- Define rollback authority and an expiry for the rollback path.
Verify service, evidence, and access before closing
Run count checks and sampled editorial checks on the destination. Verify login, publishing, accessibility, feeds, forms, payments, unsubscribe or suppression behavior, analytics, ad delivery, and error monitoring as applicable. Compare a representative set of old and new URLs. Archive configuration and final reports in publisher-controlled storage with a retention owner.
A vendor-provided archive is not automatically a business-continuity backup. Ghost explicitly distinguishes its service archives from a backup solution for continued service, which is a useful caution even when using another platform. After authorized termination, rotate or revoke credentials, remove webhooks, confirm billing status, document returned or deleted data as required, and retain the evidence. Do not claim the exit succeeded until the publication works and the dependency register is closed.
Source notes: Automatic backups · Contracts and data sharing
Continue the work
Sources & limits
Contract, privacy, tax, and retention duties vary. Use this inventory with the publication's qualified reviewers and actual agreements.
- Contracts and data sharing
UK regulator guidance · Publication date not stated · Primary source checked · 19 September 2026 - Exports
Ghost documentation · Publication date not stated · Primary source checked · 19 September 2026 - Automatic backups
Ghost documentation · Publication date not stated · Primary source checked · 19 September 2026
Source claims and editorial judgments remain separate. Send a correction with the passage and supporting evidence.

