Client update reports: keeping a changelog for agency and freelance work

Agency and freelance work has a visibility problem that product work doesn’t. When you ship a feature in your own product, users see it. When you spend a retainer month keeping a client’s site fast, patched, backed up, and online, the client sees nothing — which is the point of maintenance, and also the reason retainers die. The question that kills them — “what am I actually paying for?” — is rarely asked out loud. It accumulates silently and gets answered at renewal time, by whichever party has the better records.

Most agencies answer it with a maintenance report assembled the night before the renewal call: a scramble through commit logs, ticket queues, and invoices, compressed into a PDF the client skims once. This guide argues for the alternative that product teams already use on themselves: a changelog per client, written as the work happens. The monthly report stops being a writing task and becomes a reading of what’s already there — and at renewal, the whole history is one link.

A changelog per client, not a report per deadline

The failure mode of the end-of-month report is archaeology. Reconstructing three weeks of work from git messages and time-tracker entries produces exactly the vague lines clients learn to skim past: “site maintenance,” “various fixes, ” “updates applied.” The details that would have earned trust — which form was silently failing, what the speed number was before and after — are gone by then, because the person who knew them has moved on to other clients’ emergencies.

Writing the entry at ship time fixes this the same way it fixes internal changelogs: two minutes while the context is loaded beats twenty minutes of reconstruction when it isn’t. Finish the work, post one dated entry to that client’s log, move on. The discipline is per event, not per month — and the monthly rhythm survives as a digest: assembled from entries that already exist, per the skip-nothing-write-nothing rule for digests. If a month’s report takes more than fifteen minutes to produce, you’re not keeping a changelog; you’re writing history from memory.

Write for the person paying

The reader of a client changelog is almost never a developer. They’re a marketing manager, a practice owner, a founder — someone who knows their own website as a set of pages and outcomes, not as a stack. Everything in the non-technical release notes guide applies, with the volume turned up, because this reader is also deciding whether to keep paying you:

  • Name things as the client sees them. “The Contact page form” and “your online booking calendar,” not the plugin, module, or template that implements them.
  • Symptoms, not stack traces. “Your enquiry form had been silently failing for visitors using Safari — fixed, and we added a check that alerts us if it ever stops sending again” beats “patched mail handler deprecation” in every way that affects renewal.
  • Numbers the client can feel. Page-load seconds before and after, uptime for the month, how many spam signups the new filter blocked. Skip the numbers only you can feel (bundle sizes, Lighthouse subscores) — or translate them.
  • Screenshots for anything visual. A before/after pair of the redesigned banner does more than a paragraph; the screenshots guide covers the craft.

The invisible work is the point

Here’s the tension every agency changelog has to resolve: the work that justifies a retainer is mostly work the client should never notice. Plugin and dependency updates, security patches, backups, uptime monitoring, renewing certificates. Leave it out and the log looks like you did nothing; itemize it and the log reads like a printer toner receipt.

The resolution: batch the routine, spotlight the notable. One line — “Applied 14 plugin and platform updates (all tested on a staging copy first)” — covers the routine. Then pull out anything with a story: “One of this month’s updates fixed a security hole being actively exploited on other sites — yours was patched within a day of the fix being available.” That single sentence does more for renewal than fifty itemized version bumps, because it converts maintenance from a list into evidence of vigilance. For WordPress work — a huge share of agency retainers — the plugin changelog guide explains what those upstream entries mean and which ones deserve translating for your client.

And a changelog is not a timesheet. Hours belong on the invoice; the changelog records outcomes. The moment entries start reading “0.5h — misc admin,” the document stops building trust and starts inviting an audit.

For the quiet months — no launches, nothing broke — write the entry anyway, and make it a verification report: uptime this month, updates applied, backup restore tested (a backup you’ve never restored is a hope, not a backup), forms checked end-to-end. “Nothing needed fixing, and here’s how we know” is a genuinely reassuring thing to read from someone you pay monthly.

The monthly report, assembled not written

The dated log is the source of truth; the monthly email is its digest. Send it the same day each month — cadence is a promise, and a report that arrives like clockwork is itself evidence of an agency that runs like clockwork. The email stays short: three to six lines, each linking to the full entry on the client’s changelog page, so the log — not your email thread — is where history lives.

Subject: March on yoursite.com — what changed

Hi Dana — here’s March in two minutes:

WHAT CHANGED ON YOUR SITE
- New testimonials section on the homepage (you approved the design Mar 12; live Mar 14)
- Checkout page now loads in 1.9s, down from 4.1s — slow-loading images fixed

BEHIND THE SCENES
- 14 plugin and platform updates applied, tested on staging first
- Uptime: 100%. Backups: daily, and this month’s restore test passed
- Blocked 2,140 spam form submissions (new filter from February holding up)

NEEDS YOUR DECISION
- Your homepage hero video is 40MB and costing you mobile visitors —
  we’d like to replace it with a compressed version (no visible difference).
  OK to proceed?

Full history, anytime: https://updates.youragency.com/p/yoursite

Two details in that template earn their place. “Needs your decision” turns the report from a broadcast into a conversation and quietly documents that the ball is in the client’s court — useful when “why wasn’t this done?” comes up later. And the permanent link at the bottom is the renewal packet: when the contract conversation happens, you send one URL showing eighteen months of dated, specific work — or print the page to PDF and bring it. An unbroken history is the same buying signal for an agency as it is for a product.

When something broke

Sites go down. Plugins conflict. A deploy breaks the checkout for an hour. The instinct to keep incidents out of the client’s changelog is exactly backwards: if they noticed, an unexplained outage plus a silent changelog reads as either ignorance or cover-up — and if they didn’t notice, the honest entry is free trust. “Your site was down for 22 minutes on Tuesday night; the host had a hardware failure, we moved you to a new server, and here’s the monitoring alert-to-restore timeline” shows the client precisely what they’re paying to have handled. The craft is the same as hotfix communication — symptom first, impact honestly bounded, what changed so it won’t recur — and anything still broken belongs in a known-issues line, not in silence.

Boundaries: one client, one log

One project per client, never shared. Client A must never appear in client B’s log — not as a name, not as “another client’s incident taught us,” nothing. Cross-client leakage is the fastest way to make every client wonder what their log teaches your other customers.

Some things stay internal even for the client’s own log: which subcontractor did the work, what it cost you, the three approaches that failed before the fix, upstream vendors’ sins editorialized. Keep an internal log for your team’s archaeology; the client’s log is the professional surface of it. The two-streams pattern — one pipeline, different audiences — is the same one product teams use.

Mind the privacy of the page itself. An unlisted changelog URL is obscurity, not authentication — fine for “we redesigned the homepage,” wrong for anything confidential. Traffic numbers, security details worth attacking, contract terms: those go in email or the client’s portal, with the changelog entry saying only that the work happened.

Anti-patterns

  • The invoice dump. Thirty line items with hour fractions. That’s billing data cosplaying as communication; it invites auditing, not confidence.
  • Silence until renewal. Eleven quiet months, then a heroic PDF. By then the client has already formed the opinion the report was meant to prevent.
  • The jargon wall. “Upgraded PHP 8.1→8.3, migrated to Gutenberg blocks, resolved CLS regressions.” The reader can’t tell whether that’s a week’s work or an afternoon — so it counts as neither.
  • The “all good!” empty report. A report with no content teaches the client that reports carry no information. Quiet months get the verification treatment, not a shrug.
  • Hidden incidents. The client’s analytics, customers, or own eyes will eventually surface the outage your log omitted. One discovered omission poisons every past and future entry.
  • Promise creep. “Coming next” lines that quietly become commitments. Date only what’s scheduled; frame the rest as options awaiting the client’s go-ahead — which doubles as an upsell surface that doesn’t feel like one.

Doing this on Wakelog

Wakelog’s shape happens to fit agency work well: projects are free and unlimited, so “one project per client” costs nothing. Each client gets a clean public page at its own URL with dated entries, tag filters (new / improved / fix / announcement), and permalinks you can cite in emails and renewal decks; unlisted mode keeps the page out of the directory and search engines for clients who’d rather not advertise. Entries post from the web, from a single curl in your deploy script, or from the CLI at the end of a maintenance session; the monthly email is then a ten-minute skim-and-summarize, and the print stylesheet means “export the renewal packet” is just printing the page to PDF. Honest caveats: unlisted is not authentication (see above — nothing confidential), and Wakelog won’t send the monthly email for you — the email guide covers wiring the RSS feed into your mail tool if you want that automated. If a client already has a pile of past reports, start-a-changelog rules apply: begin today, backfill the greatest hits with their real dates. Free, no email required, two-minute setup — and /try shows what a client’s page would look like before you commit to anything.

Related guides

Last updated 2026-08-01 · All guides