The situation this addresses is common and rarely malicious. A previous provider set things up efficiently, which meant using their own accounts, and nobody discussed ownership because the relationship was working. The problem surfaces only at the point of separation, when the thing you assumed was yours turns out to be registered to somebody else.
Start with the items that are painful to lose. Your domain, which controls your address and your email. Your hosting. Your business profile. Your advertising accounts and your analytics property. Each of those should be registered to you or to the business, with the provider granted access, and the correction is straightforward while everybody is on good terms.
Ask directly rather than assuming, and ask in writing. A short message requesting confirmation of which accounts exist, whose name each is in, and administrative access to each is a reasonable request that a competent provider will handle without objection. Reluctance to answer is itself the finding.
Check what is being paid for, since inherited stacks reliably contain subscriptions nobody uses. Tools bought for a project that ended, duplicates doing the same job because the second was added without checking, and free tiers that quietly became paid. Ninety days of bank and card statements plus a search of your email for renewals produces the list, and the annual ones will not appear in a ninety day window.
Look for the accounts registered to a personal email address, which is the most common failure and the one that causes trouble at the worst moment. An advertising account tied to a former contractor's personal address is an account you cannot recover if that person becomes unreachable, and the recovery process assumes you can prove ownership you may not be able to demonstrate.
Do not cancel anything before establishing what depends on it. Tools connect to each other in ways that are not obvious, and removing an account that appeared unused can break a form, an integration, or a tracking setup that was working silently. Check what breaks in a test rather than discovering it live.
Change the credentials and review the access list once transfers are complete, because a former provider retaining access to your analytics or your advertising account is an exposure regardless of intent. This is procedure rather than suspicion, and treating it as routine from the start is what makes it unremarkable.
Then write down what you now have, what each thing does, what it costs, and who has access. Inherited stacks are undocumented by definition, and that page is what converts a set of accounts somebody else assembled into infrastructure you actually control.
Ask for a handover document rather than only for access, since credentials without context leave you with a set of accounts you cannot operate. What each tool does, why it was chosen, and how it connects to the others is knowledge that exists only in somebody's head and disappears when the relationship ends.
Set a date to review what you keep once you understand the stack, because the instinct on inheriting something is to preserve it entirely. Several months of running the business yourself is enough to know which tools you actually use, and that is the point to remove the rest.
Check the billing dates as well as the amounts, because annual renewals on inherited subscriptions arrive without warning and frequently for tools nobody has opened. Knowing what renews and when is what turns a surprise charge into a decision.