Here is a scene from my litigation years that I never managed to forget. A CEO, three years into her startup, locked out of everything in one afternoon. The domain, the code, the cloud console, the company's own email. Her cofounder held the credentials, and the credentials were the argument. The dispute was legally about equity. Practically, it was about passwords.
On paper, ownership is a set of rights. In the first years of a startup, ownership is mostly a set of logins.
The asset map nobody draws
A young startup runs on a surprisingly short list of assets, and almost all of them live in somebody's personal account. The domain name, registered one evening on a personal card. The GitHub org, created under one founder's handle. The cloud account, the Stripe account, the social handles, the API keys, the shared drive, the mailing list. Each one has a single owner in the registrar's or provider's records, and that owner is a person, not the company. The company does not exist yet.
None of this matters while everyone is aligned. All of it matters the day someone leaves, slows down, or falls out with the team. The person holding an asset does not need to be right to have leverage. They just need to be the one who can turn it off. Can you remove a cofounder before incorporation shows how that leverage plays out when a split turns hostile.
Whoever holds the keys holds the company, until paper says otherwise.
What careful teams do
Draw the map. One page, every asset, three columns: what it is, whose account holds it, what it would cost to lose. Most teams discover the entire company sits under one person's personal email. That discovery is the point.
Spread the keys. Registrars, GitHub orgs and cloud providers all support multiple owners or admins. Two owners on everything critical is a reasonable default. This is not about distrust. It is about no single person being a single point of failure, in either direction: a hostile departure, or simply a lost phone and a locked account.
Then write the destination down. Your founder agreement should list the key assets, name their current holders, and record the promise that matters: these assets are held for the future company, and will be transferred to it at incorporation. It should also say what happens on departure. A founder who leaves returns access and cooperates with transfers. One signed sentence, and the afternoon lockout scene becomes a breach instead of a stalemate.
Before and after incorporation
Before incorporation, personal ownership is unavoidable. Somebody's card pays for the domain. The founder agreement is what turns that accident of logistics into a recorded, temporary arrangement instead of a silent claim.
After incorporation, migrate for real. Company email addresses, company billing, org-level ownership, credentials in a shared vault. Due diligence will look for exactly this. "The domain is still on the CTO's personal account" is a small sentence that makes investors ask big questions.
List your assets, name their holders, and put the transfer promise in writing. The builder walks you through it.