Organization
How to Organize Client Assets: Logos, Copy, Logins and Files
A practical system for organizing client assets: folder structure, file naming, brand files, copy, and safe handling of logins with a password manager.
By Clientwharf TeamPublished 7 min read
On this page
Why client assets get messy
Every client project starts with a collection of things you didn't make: a logo, some brand colors, product descriptions, photos, a login to the website, access to the analytics account. They arrive over weeks, through email attachments, chat messages, shared drive links and the occasional photo of a sticky note.
Without a system, you lose time in small ways. You search three inboxes for the latest logo. You design with an outdated color because the guidelines were in an old thread. You ask for the website login a second time. Worst of all, credentials end up sitting in email, where they don't belong.
A good asset system does three things: it gives every asset one obvious home, it makes the current version easy to identify, and it keeps sensitive access out of places it shouldn't be. Here's how to build one that works across all your clients.
Start with an inventory
Before thinking about folders, list what you need from the client. Most assets fall into four groups:
| Group | Typical items |
|---|---|
| Brand | Logo files, color values, fonts, brand guidelines, icons, templates |
| Content | Copy, product information, team bios, testimonials the client provides, legal text |
| Access | Website admin, hosting, domain registrar, analytics, social accounts, ad accounts |
| Files and reference | Photos, videos, past work, competitor examples, research, existing documents |
Turn this into a checklist for each new client, with an owner and a due date for each item. That one step prevents most of the chasing later. Our client onboarding checklist includes a full version you can adapt.
A folder structure that holds up
The best folder structure is the one you use for every client, without exception. Here's a simple layout that works for most freelancers and small agencies:
Clients/
acme-co/
01-brand/
logo/
colors-and-fonts/
guidelines/
02-content/
copy/
images/
03-reference/
04-projects/
2026-website-redesign/
working/
delivered/
05-admin/
proposals-and-contracts/
access-log.md
99-archive/
A few principles behind it:
- Number the top-level folders so they always sort in the same order.
- Separate client-supplied assets from your work. Brand and content folders hold what the client gave you; project folders hold what you produce.
- Separate working files from delivered files. When a client asks for "the final version", you look in one place.
- Keep an access log, not passwords. The
access-log.mdfile records what access you have, who granted it and when, without the credentials themselves. More on that below. - Archive instead of deleting. Old material goes to
99-archive, so the active folders stay clean.
Name files so they sort and explain themselves
Good file names save more time than good folders. Harvard Medical School's data management guidance recommends putting the most important information first, using dates in the year-month-day format so files sort chronologically, avoiding spaces and special characters, and adding zero-padded version numbers such as v01 and v02 (Harvard Medical School).
Applied to client work, a pattern like this works well:
client_project_item_v02_2026-10-11.ext
For example:
acme_website_homepage-design_v03_2026-10-11.figacme_brand_logo-primary-dark_2026-09-02.svgacme_website_pricing-copy_v01_2026-10-08.docx
Write the convention down and share it with anyone else who works on the account. The value comes from everyone using the same pattern.
Brand assets: what to collect and how to store it
Brand assets are the ones you'll reuse most, so they deserve the most care. Ask for:
- Logos in vector format (SVG, EPS or PDF) plus high-resolution PNGs with transparent backgrounds. Get every variation: primary, secondary, icon only, light and dark versions.
- Exact color values. HEX and RGB for screen; CMYK or Pantone for print if relevant. Don't sample colors from a JPEG.
- Fonts and licenses. The font names, the files if the client owns them, and confirmation of what the license allows. Don't assume a font the client uses can be installed on your machine or embedded in a website.
- Brand guidelines, if they exist, including spacing rules and logo misuse examples.
Store a short README in the brand folder that lists the primary logo file, the color values and the fonts. When you or a teammate need the basics, it's a ten-second lookup instead of a search.
If the client doesn't have proper logo files, say so early. Recreating a logo from a low-resolution image is a separate piece of work, and it should be scoped as one.
Copy and content: one source of truth
Copy is where version confusion causes real damage. A page goes live with last month's pricing because the "final" text was in an email the designer never saw.
- Pick one place for copy, such as a shared document per page or deliverable, and agree that it's the source of truth.
- Mark status clearly at the top of each document: draft, in review, approved.
- Record approval. Note who approved the copy and when, ideally on the specific version.
- Store images with their credits and rights, especially stock photos and photos supplied by third parties.
When the client sends copy in an email, move it into the source document right away and reply with the link, so the next edit happens in the right place.
Logins and access: handle with care
Access is the most sensitive asset you'll hold, and the one most often handled carelessly. A few rules keep you and your clients safe.
Prefer your own account over shared credentials
The safest password is the one nobody shares. Most modern platforms, including website builders, analytics tools, hosting providers and social media managers, let an owner invite another person as a user with their own login. Ask the client to invite you rather than hand over their password. This follows the principle of least privilege, which NIST describes as limiting access to the minimum necessary to accomplish the task (NIST CSRC Glossary). Ask for the lowest role that lets you do the job, such as editor rather than owner.
Your own account also creates a cleaner record, and it can be removed at the end of the project without anyone changing a password.
When a credential must be shared, use a password manager
Sometimes there's no way around a shared login. In that case, never send passwords by email, text message or plain chat. Those messages are stored in many places and are easy to forward.
Use a password manager instead. CISA recommends a different strong password for each account and suggests a password manager as the practical way to manage them (CISA). The UK's NCSC gives similar guidance and also recommends turning on two-step verification for the password manager account itself (NCSC).
Most password managers have sharing features built for this. For example, 1Password can share an item through a link that expires and can be limited to specific email addresses (1Password Support). Bitwarden Send creates end-to-end encrypted links with deletion dates, optional expiration, access limits and password protection (Bitwarden Help). Shared vaults are another option for longer engagements.
Keep an access log
For each client, record what access you have, without the passwords:
| System | Access type | Granted by | Date | Remove at end? |
|---|---|---|---|---|
| Website admin | Own user, editor role | Dana | 2026-09-02 | Yes |
| Google Analytics | Own user, viewer | Dana | 2026-09-02 | Yes |
| Domain registrar | Shared login, stored in password manager | Sam | 2026-09-10 | Client to rotate password |
At the end of the project, work through the list. Remove your user accounts, and remind the client to change any credentials that were shared.
A note on tools
Be cautious about storing credentials in project tools that weren't designed for them. Clientwharf, for example, is a client portal, not a password vault, and doesn't offer a credential storage feature. You can use a request item such as "Invite us to your website admin" to track that access was granted, but the credentials themselves belong in a password manager.
Collect assets from clients without chasing
The easiest way to get assets on time is to ask for them in one clear list instead of scattered messages:
- Be specific. "Primary logo in SVG or EPS" instead of "your logo".
- Explain why. "We need the analytics access to set up conversion tracking before launch."
- Give a date for each item, tied to the project schedule.
- Make it easy to respond. Let clients upload files or mark items done in one place.
In Clientwharf, this is what the requests checklist in each client's private portal is for. You list what you need, the client uploads files or marks items as done, and you both see what's still outstanding.
Keep it maintained
An asset system decays unless it's maintained. Build a few habits:
- File as you go. When an asset arrives, save it to the right folder with the right name that day.
- Review at milestones. At each project milestone, move old versions to the archive and update the brand README.
- Close out properly. At the end of a project, deliver final files, remove access you no longer need and archive the working folders. Our project handoff checklist walks through it.
- Follow your contract on retention. Keep what you're required to keep, and delete what you've agreed to delete.
Client asset checklist
- Asset inventory sent to the client with owners and dates
- Standard folder structure created for the client
- File naming convention written down and shared
- Logos collected in vector and PNG formats, all variations
- Color values and fonts recorded, licenses confirmed
- One source of truth agreed for copy, with status and approvals
- Access granted through your own user accounts where possible
- Shared credentials only through a password manager
- Access log kept, without passwords
- Access removed and files archived at project end
Organizing client assets isn't glamorous work, but it pays for itself on every project. Clients notice when you never have to ask for the logo twice.
Frequently asked questions
What's the best folder structure for client assets?
One top-level folder per client, then a consistent set of subfolders such as brand, content, reference, projects and archive. The exact names matter less than using the same structure for every client.
How should clients share passwords with me?
Ideally they don't share passwords at all; they invite you as a user with your own login. When a shared credential is unavoidable, use a password manager's sharing feature, never email or plain chat.
Can I store client logins in a project management or client portal tool?
Only if the tool is built as a credential vault. Most project tools, including Clientwharf, are not password managers. Use them to track that access was granted, and keep the credentials themselves in a password manager.
How should I name client files?
Put the most useful information first and keep the pattern consistent: client, project, item, version and an ISO-style date such as 2026-10-11. Avoid spaces and special characters.
Sources
- Harvard Medical School Data Management: File Naming Conventions(datamanagement.hms.harvard.edu)
- CISA: Use Strong Passwords(cisa.gov)
- NCSC: Managing your passwords(ncsc.gov.uk)
- 1Password Support: Share items with anyone(support.1password.com)
- Bitwarden Help: About Send(bitwarden.com)
- NIST CSRC Glossary: Least privilege(csrc.nist.gov)