The record that makes maintenance possible.
WHAT TO RECORD
Application name and version
Where it is installed: domain, subdomain or directory
Database name and user Administrator account Extensions and themes installed, with versions Any licence, and when it renews Any non-default configuration and why Cron jobs and what they do Backup arrangements
WHERE TO KEEP IT
Not only on the server. A document you can reach if the hosting account is unavailable.
WHY
You will not remember in six months, and neither will a colleague. Rebuilding after a disaster requires knowing what was there. Maintenance requires knowing what needs updating. Handing over to someone else requires it.
FOR SEVERAL SITES
A single list covering all of them. Without it, one will be forgotten, and that is the one that gets compromised.
UPDATING IT
When you install, remove or significantly change something. A document describing last year's setup is worse than none, because it misleads.
THE MINIMUM
A page listing what is installed where, and what version. Expand from there.