Stedra
Sign inCheck my business
BlogHOW-TO7 min read

How to build a digital asset register (in one afternoon)

Steps verified against the official documentation below · last checked 2026-07-18

Nearly every guide on this blog ends the same way: put it in your register. This is the guide to building that register — the single document that answers, for every account your business runs on: what is it, who controls it, who's the backup, when does it renew, and whose card pays for it.

It's also the artifact everything else hangs off: offboarding checklists generate from it, cyber-insurance questionnaires are answered from it, due diligence starts from it. Here's how to build one in an afternoon, and keep it alive after.

The eight columns

  • Asset — what it is (domain, Google Workspace, Stripe, Instagram…).
  • Category — domain/DNS, email, cloud, payments, social, marketing, finance. Categories make gaps visible.
  • Provider & account identifier — registrar name, tenant domain, account email. Enough to find the login page and the right account.
  • Owner — which login *holds* the account (the platform's owner/primary-admin/registrant), and whether the business controls it.
  • People with access — everyone with admin or a seat, by name. This column powers offboarding.
  • Backup admin — the second person who can get in. Empty cells in this column are your risk list.
  • Renewal & billing — renewal date, auto-renew status, which card. Cross-check card expiry against renewal dates.
  • Recovery paths — where password resets and 2FA go (email, phone, device). The most-forgotten, most-dangerous column.
What does NOT go in the register: passwords. The register records who and where — credentials live in a password manager. Mixing the two turns your map into a target.

Populate it in three passes

  1. 1
    Pass 1 — public records (30 minutes)
    Start from your domain: registrar and expiry (ICANN's lookup), DNS host (nameservers), mail provider (MX), and the tools visible in your DNS records and website. Stedra's free scan automates exactly this pass and hands you the starting rows.
  2. 2
    Pass 2 — the people interview (an hour)
    Ask everyone who touches operations five questions: what accounts do you own, admin, or use? What renews on your card? Where do your resets go? Which logins have you shared, with whom? What would break if you were unreachable for a month?
  3. 3
    Pass 3 — the money trail (30 minutes)
    Walk three months of card and bank statements. Every recurring charge is an account; every account goes in the register. This pass finds the tools everyone forgot.

Where to keep it, and how to keep it alive

Keep it somewhere access-controlled and versioned — a protected sheet or an internal wiki page beats a file on someone's desktop — readable by leadership, editable by few. It contains your attack surface, so treat it with password-manager-adjacent care even without passwords in it.

Then wire it to events, because a register that isn't maintained is just a snapshot of last year: update it when someone joins or leaves (the people column *is* the offboarding checklist), when a tool is added or cancelled, and on a quarterly review where you re-verify the owner and backup columns. If that cadence sounds like the part that will fail — that's the part Stedra automates: discovery keeps the rows current, monitoring watches the renewal and drift columns, and the departure report reads the people column for you.

ICANN — Registration data lookup (pass 1's primary tool)InsurableIT — the inventory control on cyber-insurance questionnaires
This is one asset. How many others does your business not control?

The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.

Check my business
The employee offboarding checklist for digital accounts
7 min read
The account-ownership questions on your cyber-insurance application, explained
6 min read