
A client of mine almost got both of us in trouble a few weeks ago. Her organization had used an image on their website that they didn’t have the rights to use. It was the kind of image that shows up everywhere, easy to find, easy to assume is free, and completely unlicensed for the way they were using it.
As the person who maintains and built her website, I’m partly responsible for that. If I didn’t check every page, that’s on me too.
I caught it before it became a real problem. But it made me sit with a question I don’t think most nonprofits and museums have ever actually asked themselves: if you disappeared tomorrow, would anyone at your organization know what’s on your website, where it came from, or who has the right to change it?
For most of the organizations I work with, the honest answer is no.
I found out how deep this problem runs when it happened to me directly, not a client. I got an email accusing me of using an image without a license. I knew that wasn’t true. I had purchased that image properly, years earlier, through a legitimate stock agency.
What I hadn’t accounted for was that the agency I bought it from had since sold that image, along with its entire library, to a different agency. The new agency had no record of my original purchase, because that transaction happened before they owned the rights. As far as they could tell, I was using their image with no license at all.
I had done everything correctly, and I still had to go digging through years-old records to find my original receipt and license number before I could prove it. If I hadn’t kept that documentation myself, the agency’s own records wouldn’t have been enough, because their records didn’t go back that far.
That’s the part people miss. A license isn’t something you buy once and forget. It’s something you have to be able to produce, on demand, indefinitely, even after the company you bought it from no longer exists in the form it did when you bought it. Stock libraries get sold, agencies merge, platforms shut down. None of that erases the obligation to prove the right to use an image. It just makes proving it harder.
This is exactly why I now build a check into how I maintain client sites: not just “did we license this,” but “do we still have a copy of that license somewhere we can actually find it.”
When people think about “the website,” they think about one thing. In reality, a website is at least four separate things, and they’re rarely owned by the same person or held in the same place.
The domain name is registered somewhere, under an account that belongs to whoever set it up, which might be a former staff member’s personal email, an old board member, or an agency that no longer exists. The hosting is a separate account, with its own login, its own bill, and its own renewal date.
The content, the images, the copy, the design, may have been built by a past employee, a volunteer, or a contractor, and may or may not have ever been formally handed over. And the admin access to actually log in and make changes is its own separate credential, one that gets lost the moment the person who had it leaves.
None of these four pieces are guaranteed to live in the same place, or to be known by more than one person. I’ve walked into projects where the client had no idea who registered their own domain fifteen years ago.
I’ve seen organizations locked out of their own site because the only person with the password left without a handoff. I’ve seen “free” websites built by a board member’s relative that turned out to have no documentation at all, just a live site nobody could touch without breaking it.
This isn’t a failure of the people running these organizations. It’s a structural gap. Nobody trains an executive director to ask these questions, because most of the time, nobody has to, until the one time they do.
It rarely shows up as a dramatic failure. It shows up quietly, the way both of these situations did.
An image gets used because it was easy to find and nobody thought to ask whether the organization had the right to use it. A photo of a program participant, a patient, or a museum visitor gets posted because it seemed harmless, without anyone checking whether a release was signed.
A page gets published years ago and nobody currently on staff remembers writing it, sourcing its images, or reviewing its accuracy. Or, as I learned firsthand, a license gets purchased correctly and then the paper trail for it quietly disappears into a folder nobody thinks to check again.
Each of these is small on its own. Together, they describe an organization that has lost track of what it’s actually responsible for, and what it can actually prove.
Responsibility doesn’t disappear just because nobody’s tracking it. If an image is used without a license, or without the ability to produce one, the organization is exposed regardless of who technically uploaded it, how long ago, or how carefully it was done at the time.
For nonprofits, this exposure carries more weight than it would for a typical small business. Copyright and consent issues touch people who are often already vulnerable: program participants, patients, students, donors. And unlike a private company, a nonprofit’s credibility with funders and the public is part of its actual operating capital.
A dispute over an image or a photo isn’t just a legal headache. It’s a story that undercuts the trust the organization spent years building.
Museums carry an extra layer most organizations don’t. The right to display a physical piece in a gallery is not the same as the right to publish a photograph of it online. That right often belongs to the artist or their estate, and it can be separate from the museum’s own ownership of the physical object. I’ve seen institutions publish beautiful photography of their collections without realizing the image rights and the object rights were never the same thing to begin with.
This is exactly the kind of gap that hides in plain sight, because everything about the museum’s collection feels like it obviously belongs to the museum. Some of it does. Not all of it does.
It’s tempting to respond to stories like these with a checklist: verify your image licenses, get your consent forms in order, audit your old pages. Those are all reasonable steps, but they treat the symptom, not the structure underneath it.
The actual fix is knowing, in writing, who owns your domain, who owns your hosting, who has admin access to your site, and where the proof lives for anything you’ve licensed, in a place more permanent than the seller’s own records.
That’s not a technical project. It’s a governance one, the same category of thing as knowing who has signing authority on your bank accounts or where your bylaws are filed.
Most organizations only discover they’re missing this the same way both of these situations played out: by accident, and after the fact. I’d rather my clients find out on a quiet Tuesday than in the middle of a funder’s due diligence, or worse, a legal notice.
This is the part that connects directly to the work I do. A funder, a major donor, or a foundation program officer researching your organization doesn’t see your internal org chart or your board minutes.
They see your website. If something on it is wrong, outdated, or exposed, they don’t know that’s a governance gap three layers removed from anyone currently on staff. They just see it, and it becomes part of how they judge whether your organization is well run.
The Website Clarity Snapshot is a free twenty-minute look at your site that includes exactly this kind of question: who owns what, what’s currently exposed, and where the gaps are between what you think is true about your website and what’s actually true. It’s the same kind of check I wish every client had, and the same discipline I now hold myself to.
If you lead a nonprofit, museum, or cultural institution and you’re not fully sure who owns your domain, hosting, who has admin access to your site, or what’s actually published on it, I’d rather help you find that out on your own terms. Book a Website Clarity Snapshot.
The organization owns the site itself, including its content and domain, unless a contract says otherwise. But ownership on paper doesn’t mean much if the organization doesn’t actually hold the domain registration, hosting login, and admin access. I recommend every organization confirm they personally control all three, not just the finished website.
The organization can be held liable for copyright infringement even if the image was used unintentionally or in good faith. Nonprofits are not exempt from copyright law, and image rights holders and stock agencies actively monitor for unlicensed use.
Start with your hosting provider and your CMS login history, if available. If nobody currently on staff can produce this information, that’s the gap itself, and it’s worth treating as a priority to resolve rather than something to track down only when there’s a problem.
Often, yes. Owning a physical piece doesn’t automatically include the right to publish photographs of it. That right can belong to the artist or their estate, separately from the museum’s ownership of the object, so it’s worth confirming rather than assuming.
Locate your own original proof of purchase and license number rather than relying on the seller to confirm it. Stock agencies get acquired or shut down, and their records don’t always transfer, so the organization’s own documentation is often the only reliable proof.

Frances Naty Go is the founder of Goldlilys Media, where she helps mission-driven organizations turn their websites into clear, durable systems that support meaningful work over time. She works with museums, nonprofits, health and wellness brands, higher education, life sciences, travel organizations, and expert-led businesses.
With a background in Computer Science from UC San Diego, Frances brings a thoughtful, strategic approach to building digital experiences that educate, orient, and build trust, without unnecessary complexity.
Questions first? Start a conversation

