NZ small-business systems

Small-business software in New Zealand: where problems start

A New Zealand small business may use a mix of tools for accounting, email, websites, payments and marketing. Each tool may work perfectly well on its own. Problems usually start when nobody is sure who owns an account, which systems share DNS or customer data or what needs to be kept safe before a change.

How to use this guide

Use this as an overview of connected tools

The tools below are common examples that a New Zealand business might choose, inherit or connect. They are examples, not recommendations. Check whether each tool has a clear job, a business-controlled administrator, recorded connections to other services and useful handover notes.

Interfaces and requirements change. Before touching a setting, check the live account, current provider documentation, active integrations and the person responsible for the service.

Business-owned access One purpose per tool Connections recorded Exports tested Handover maintained

What a business needs

What software does a small NZ business usually need?

A small business may only need a modest software stack covering accounting, business email and files, a website or sales channel, payments, customer communication and a secure way to manage it all. A new tool should fix a real problem. If it only copies data or creates another neglected subscription, it probably is not helping.

Domain and DNS

Examples: GoDaddy and Cloudflare.

Purpose: registration, nameservers, DNS records and web traffic controls.

First check: identify the registrar and the authoritative nameservers; they may be different companies.

Email and team files

Examples: Microsoft 365 and Google Workspace.

Purpose: business email, identity, calendars, documents and collaboration.

First check: confirm two business-controlled administrators and working recovery methods.

Website and ecommerce

Examples: WordPress/WooCommerce, Shopify, Wix and Squarespace.

Purpose: publishing, enquiries, bookings, catalogues and online sales.

First check: map the domain, hosting, theme, plugins or apps, forms and checkout separately.

Accounting and payroll

Examples: Xero and MYOB.

Purpose: invoicing, bank reconciliation, GST records, accounts and payroll where configured.

First check: ask the accountant who should have adviser, payroll and business-owner access.

Marketing and customer records

Examples: Mailchimp, HubSpot and Canva.

Purpose: campaigns, contacts, follow-up workflows and reusable brand assets.

First check: confirm list consent, sender identity, integration owners and asset ownership.

Payments

Examples: Stripe, PayPal and Windcave.

Purpose: card acceptance, payouts, refunds and payment records.

First check: confirm the legal account holder, settlement bank account and reconciliation process.

Job and trade workflows

Examples: Tradify and Fergus.

Purpose: quoting, scheduling, job records, invoicing and field-team workflows.

First check: identify which system owns customer, job, invoice and payment status.

Domains and identity

Who should control the domain, DNS and business email?

The business should control the registrar, authoritative DNS and primary email accounts. If the service allows it, keep at least two current administrators. Agencies and technicians can still have delegated access. What you do not want is an account that can only be recovered through a former employee or supplier.

GoDaddy

GoDaddy can be the registrar, DNS host, website host or reseller for another service. Those are separate jobs, even when they appear inside one account.

Common failure: editing a DNS zone that is no longer authoritative.

Escalate to: the registrar for ownership or renewal; the active DNS provider for live records.

Cloudflare

Cloudflare often sits between the registrar and the website, handling authoritative DNS and sometimes proxying web traffic.

Common failure: incomplete imported records, inappropriate proxy status or unresolved DNSSEC state.

Escalate to: an IT or DNS specialist when web, email and verification records overlap.

Microsoft 365

Microsoft 365 connects identity and mailboxes to domain verification, MX, SPF, DKIM, DMARC and sometimes device sign-in.

Common failure: the only global administrator or recovery method is unavailable.

Escalate to: Microsoft or the tenant administrator for licences and identity; DNS support for records.

Google Workspace

Google Workspace can provide Gmail, files, calendars and user accounts, while depending on domain-level email records held elsewhere.

Common failure: consumer Google accounts, Workspace users and domain administration are mistaken for one another.

Escalate to: the Workspace administrator for users and recovery; the DNS provider for domain records.

If a DNS change is planned, use the separate GoDaddy-to-Cloudflare migration checklist to capture records and rollback boundaries before changing nameservers.

Websites and selling

Where does the website platform end and the integration begin?

The website is the part customers see, but it may not control the domain, business email, payment account, accounting records, analytics or customer list. Each connection is a separate service, with its own administrator and recovery method.

WordPress and WooCommerce

WordPress separates hosting, core software, themes, plugins, forms, backups and administrator accounts. WooCommerce adds orders, payments, tax settings, extensions and customer records.

First check: record the host, domain, backup location, payment plugin, update responsibility and working administrator.

Shopify

Shopify can operate the store and sometimes the domain, while email hosting, payment settlements, accounting, marketing and third-party apps remain separate.

First check: list the store owner, domain manager, payment provider, app charges, email records and export options.

Wix

Wix can combine website editing, domains, forms, automations and marketing features, but externally connected DNS, mailboxes, payments or analytics still need their own handover.

First check: confirm whether the domain uses Wix nameservers or pointing and where business email is actually hosted.

Squarespace

Squarespace can cover publishing, domains, commerce, forms and campaigns. Connected email, payment, analytics and fulfilment services may belong to different accounts.

First check: identify the site owner, domain owner, billing owner, form destination and external commerce connections.

Business.govt.nz recommends choosing a website or online-store approach around the business need, payment handling, accounting connections, security and the time required to maintain it, rather than whichever platform has the longest feature list.

Accounting decisions

When should Xero or MYOB questions go to an accountant?

This is a useful line to draw. Your accountant or bookkeeper should decide the chart of accounts, GST treatment, payroll setup, filing process, reconciliation rules and any financial corrections. IT support can sort out access, MFA, browsers, exports, integrations and handover, but it should not make accounting or tax decisions.

Xero

Common failure: bank feeds, payment feeds, payroll access or ecommerce integrations are interrupted or duplicated.

Owner: the business should retain subscriber control while the accountant receives the access appropriate to their work.

First check: identify the organisation subscriber, connected banks, payment feeds, payroll users and adviser access.

MYOB

Common failure: product editions, company files, online access, bank feeds, payroll and adviser permissions are confused during support or migration.

Owner: the business should control the subscription and recovery method, with accountant access agreed explicitly.

First check: record the exact product, organisation or file, owner, bank-feed status, payroll boundary and backup and export process.

Inland Revenue notes that more than half of surveyed small businesses manage accounts or wages online, and that payroll software can file employment information. The convenience is real, but it makes clear permissions and integration ownership even more important.

Marketing and deliverability

Why do marketing or ecommerce emails reach spam folders?

Spam problems rarely come down to one setting. They usually appear when the visible sender, sending platform, DNS authentication, consent records and mailing list no longer line up. Before changing DNS or blaming the mailbox provider, verify the sending domain and the current SPF, DKIM and DMARC instructions for every active sender.

Mailchimp

Mailchimp holds audiences, campaigns, automations, templates and sender settings.

Common failure: domain verification is mistaken for full authentication, or DNS records are lost during a provider change.

First check: confirm the account owner, audience source, consent basis, sending domain and Mailchimp's current authentication status.

HubSpot

HubSpot can combine contacts, forms, CRM activity, email, automation and website tracking.

Common failure: multiple portals, duplicated contacts, hidden workflow owners or an integration that writes unexpected data.

First check: map the portal owner, data source, form destinations, connected inboxes, workflows and export permissions.

Canva

Canva often contains brand kits, social graphics, presentations, templates and shared design assets.

Common failure: the team's only editable assets live in a personal account or are shared without clear ownership.

First check: confirm the team owner, billing, brand-kit access, folders, export formats and offboarding process.

NZ consent requirements

New Zealand commercial electronic messages generally require recipient consent, accurate sender identification and a working unsubscribe method.

Common failure: a technically deliverable list is treated as legally or ethically permissioned without evidence.

Escalate to: the business owner or legal adviser for consent decisions; the email platform or deliverability support for technical sending issues.

For more technical detail, use the email deliverability support guide and confirm each sender's current provider instructions before editing DNS.

Money and job records

How do payments and job systems stay reconcilable?

A checkout can say "paid" while the money trail is still a mess. Keep the payment account, settlement bank account, accounting feed, order or invoice, refund process and job record linked by identifiers that staff can follow later.

Stripe, PayPal and Windcave

Common failure: the website integration works, but ownership verification, settlement details, refunds, disputes or accounting feeds belong to an inaccessible account.

First check: confirm the legal owner, administrators, bank account, website connection, payout schedule, refund process and accounting feed.

Tradify and Fergus

Common failure: customer, job, quote, time, invoice and payment states drift between the job system and accounting platform.

First check: decide which system is authoritative for each record and who reviews failed or duplicated synchronisation.

Handover checklist

How should a business software stack be handed over?

A proper handover is more than a list of passwords. It should cover account ownership, recovery methods, billing, data exports, connected services and day-to-day responsibilities. Test recovery and exports while the outgoing administrator is still available. Remove old access only after the new administrators have shown that they can run the stack.

1

Inventory every service

  • Service name, purpose, URL, plan, renewal and billing owner.
  • Primary and backup administrators.
  • Recovery email, phone, security keys and stored recovery codes.
2

Map the connections

  • DNS records and verified domains.
  • Forms, APIs, webhooks, plugins, apps and automation owners.
  • Customer, payment, invoice and accounting data flows.
3

Test continuity

  • Administrator sign-in and account recovery.
  • Current exports, backups and restoration instructions.
  • Website enquiry, email, payment, invoicing and reporting processes.
4

Close the old access safely

  • Replace personal ownership with business-controlled accounts.
  • Rotate shared credentials and review API tokens or app access.
  • Remove former users only after the new owners verify continuity.

Choose who should handle it

Who should handle a software problem?

When something breaks, start with whoever controls that part of the stack. A small account problem should not turn into unnecessary changes to the domain, website or accounting system.

Vendor support

Use the vendor for platform outages, billing disputes, identity verification, service-specific errors or functions only the provider can inspect.

Accountant or bookkeeper

Use them for GST, payroll, chart-of-accounts, reconciliation, filing, financial corrections and decisions about accounting configuration.

Web provider

Use the web provider for themes, plugins, forms, checkout presentation, hosting, website backups, analytics implementation and release testing.

IT or systems support

Use IT support for access and MFA, domain/DNS dependencies, email authentication, integration mapping, device/browser faults, collecting diagnostic details and handover documentation.

The broader NZ SME tech checklist helps inventory the core systems. When the issue crosses providers, remote IT support can help identify what is failing in the setup before live settings are changed.

Sources

Official guidance behind the practical checks

These sources explain the New Zealand requirements and which provider is responsible for each part of this guide. Product screens and requirements change, so check the current official documentation before making a live change.

About this guide

What the examples cover

The examples group recognisable services by the job they do for a New Zealand small business. The examples focus on recurring account, DNS, data and handover problems that a business can check. The right provider depends on the business's needs. For more about the author, see About John Finnerty. Check current provider documentation before changing live settings.

Related reading

Use the page that matches the problem before changing several connected systems at the same time.