Facebook Agency Account Access: How to Grant, Audit, and Remove Permissions
Learn how to grant, audit, and remove Facebook agency account access while protecting account ownership, business assets, billing controls, and operational continuity.
Facebook agency account access should be configured as a controlled business permission, not exchanged as a shared login. The correct setup depends on who owns the ad account, which Business Portfolio contains it, what the agency must do, and which brand, data, billing, and administrative actions should remain with the advertiser.
The same applies to facebook ad account access for employees, freelancers, media buyers, analysts, finance users, and external providers. Each person or partner should receive only the assets and permissions required for a defined responsibility.
This guide explains how to plan access, grant it through Meta's business tools, audit permissions, remove access safely, and respond when someone cannot use an account.
The Short Answer: Use People and Partner Permissions
For a professional business setup:
- Keep personal Facebook credentials private.
- Use Meta Business Portfolio to organize business assets.
- Add internal team members as named people.
- Add external businesses through partner access where appropriate.
- Assign only the required ad accounts and connected assets.
- Distinguish full control from partial or task-based access.
- Require two-factor authentication where supported.
- Review access regularly and after every role change.
- Remove former users and partners through a documented process.
- Keep an access register and change history.
Access to an ad account does not automatically provide access to the Page, Instagram account, dataset, domain, catalog, billing information, or Business Portfolio administration. Check every asset separately.
1. Separate Ownership From Access
Ownership answers which business controls the asset inside Meta. Access answers which people or partners can perform specific work.
An advertiser may own the ad account and grant an agency permission to run campaigns. A provider may own the account and grant the advertiser or media buying team permission. Both structures can provide operational access, but they create different dependencies and exit rights.
Before changing permissions, record:
- Business Portfolio that owns the ad account
- Legal business behind the advertising
- Agency or provider involved
- People who need access
- Assets each person or partner needs
- Actions they must perform
- Actions that must remain restricted
- Person authorized to approve changes
For a full comparison of ownership structures, read the account ownership and billing guide.
2. Understand Meta's Permission Layers
Meta's business tools distinguish access to the Business Portfolio from access to individual business assets.
A person may have:
- Full control of the Business Portfolio
- Partial access to the Business Portfolio
- Access to selected Pages, Instagram accounts, ad accounts, datasets, catalogs, or other assets
- Specific task permissions for assigned assets
A partner business may receive access to selected assets without becoming an internal employee of the advertiser's Business Portfolio.
Meta explains the distinction in its documentation on Business Portfolio and business asset permissions.
Do not use “admin,” “full access,” or “agency access” as if each were one universal permission. Ask which business layer and assets are included.
3. Choose People Access or Partner Access
Use People Access for Internal Operators
Named employees and approved individual operators may be added to the Business Portfolio and assigned specific assets.
Meta provides a workflow to add people and assign business assets.
Use this model when the business needs direct accountability for a known person working within the approved operating team.
Use Partner Access for External Businesses
An agency, provider, or other external company can be added as a partner and assigned selected business assets.
Meta provides an official workflow to give a partner access to business assets.
Use this model when the relationship is business-to-business and the external company should manage its own people.
Do not add every freelancer or vendor as a full-control administrator. The access method should match the real relationship and responsibility.
4. Build an Access Requirements Matrix
Define requirements before clicking Invite or Add.
| Role | Assets Needed | Actions Needed | Actions Not Needed |
|---|---|---|---|
| Media buyer | Ad account, Page, dataset | Build and manage campaigns | User administration, business ownership changes |
| Team lead | Ad account, reporting assets | Review budgets and delivery | Unrelated client assets |
| Analyst | Ad account reports | View and export data | Campaign editing, billing changes |
| Finance | Billing records, provider statements | Reconcile spend and balances | Creative or audience changes |
| Creative partner | Approved creative workflow | Supply or review creative | Ad account administration |
| Client stakeholder | Agreed reports | Review results and approvals | Unrestricted business control |
| Business administrator | Business Portfolio and approved assets | Manage authorized access | Campaign work outside role |
| External provider | Agreed account or funding workflow | Perform documented service | Control of unrelated brand assets |
The exact platform permission names may change. The operating principle remains: grant the smallest permission set that allows the role to complete its work.
5. Check Every Connected Asset
Campaign work may require more than the ad account.
Review access to:
- Facebook Page
- Instagram account
- Dataset or Pixel
- Website domain
- Product catalog
- Custom audiences
- Lead data
- Billing information
- Campaign reports
For each asset, document:
| Asset | Owner | Person or Partner | Permission | Business Purpose | Review Date |
|---|---|---|---|---|---|
| Ad account | |||||
| Facebook Page | |||||
| Instagram account | |||||
| Dataset | |||||
| Domain | |||||
| Catalog |
Do not assume that access to a Business Portfolio automatically provides the correct task permissions for every asset. Do not assume that access to one client should extend to another.
Agencies managing several advertisers should use the multi-client account operating model to keep ownership, assets, funding, and access separated.
6. Grant Access Through a Controlled Workflow
Use an internal approval process before changing Meta settings.
Request
Collect:
- Person or partner name
- Business email
- Partner Business Portfolio ID, where applicable
- Role and manager
- Client or business served
- Assets required
- Tasks required
- Start date
- Expected end or review date
Approval
Confirm:
- The request comes from an authorized owner.
- The business relationship is active.
- The person or partner identity is verified internally.
- The requested permissions match the role.
- Full control is justified separately.
Configuration
Use Meta Business Suite settings to add the person or partner and assign only the approved assets and permissions.
Validation
Ask the user to confirm that the required account and assets appear and that the intended task can be completed.
Record
Update the access register with the date, approver, permissions, and validation result.
Do not send screenshots containing sensitive account details to unrelated people. Do not forward invitations without confirming the intended recipient.
7. Limit Full Control
Meta states that people with full control can perform high-impact actions involving business assets, people, and access shared with partner businesses.
Full control should therefore be limited to properly authorized administrators who need it.
Before granting full control, ask:
- Does the person need to add or remove users?
- Do they need to claim or remove business assets?
- Do they need to change security or business settings?
- Can their work be completed with asset-level permissions instead?
- Who approved the elevated access?
- When will the access be reviewed?
Seniority alone is not a business reason. An executive who only reviews reports may need less platform access than an administrator responsible for permissions.
8. Require Strong Authentication
Meta allows businesses to require two-factor authentication for people in a Business Portfolio. Meta also warns that people without stronger authentication can create security risk and may lose access to certain business functions.
Use Meta's official instructions to require two-factor authentication and review its Business Portfolio security practices.
Operational controls should include:
- Unique personal login for each user
- Two-factor authentication or passkeys where supported
- No shared passwords
- Verified contact information
- Secure administrator devices
- Removal of unknown sessions and users
- Payment instruction verification
- Incident reporting process
Permission design cannot protect a business if administrators share credentials or approve unknown access requests.
9. Audit Access on a Fixed Schedule
Review access monthly for high-change teams and at least on a defined recurring schedule for stable teams. Also review immediately after:
- Employee departure
- Agency or provider change
- Client offboarding
- Role change
- Security incident
- Unexpected ad or payment activity
- Business Portfolio ownership change
- Addition of a new critical asset
For every person and partner, ask:
- Is the relationship still active?
- Does the role still require access?
- Are the assigned assets correct?
- Is the permission level still appropriate?
- Is stronger authentication active?
- Is there any unexplained recent activity?
- Is an end date or review date missing?
Meta provides a business history and permission download that can help businesses review changes. Use Meta's guidance on people permissions and business history.
10. Use a Joiner-Mover-Leaver Process
Joiner
- Confirm identity and role.
- Approve assets and tasks.
- Configure access.
- Require security controls.
- Validate required actions.
- Record the grant.
Mover
- Review all existing permissions.
- Remove access no longer needed.
- Add only new required assets.
- Record the change and approver.
Leaver
- Remove the person from the Business Portfolio where appropriate.
- Remove partner access when the business relationship ends.
- Transfer ownership of work, reports, and approvals.
- Review recent activity.
- Update contact and escalation records.
- Confirm removal is complete.
Meta provides an official process to remove people from a Business Portfolio.
Do not wait until the former employee attempts to access the account. Access removal should be part of offboarding, not an optional cleanup step.
11. Remove Access Without Breaking Operations
Before removing a person or partner, check whether they are the only operator with critical control.
Confirm:
- Another authorized administrator can manage the Business Portfolio.
- Campaign ownership and approvals have been transferred internally.
- Required reports have been exported.
- Payment, funding, and support contacts have been updated.
- Pages, datasets, domains, and catalogs remain controlled by the correct business.
- Open account or verification cases have an active owner.
Removal should reduce risk without creating an avoidable operational lockout.
For agencies and clients, exit terms should be defined before onboarding. Use the provider buyer's checklist to review asset, data, funding, and access treatment at termination.
12. Diagnose Missing Access Correctly
When a user says “I cannot access the account,” identify the exact failure.
The Ad Account Does Not Appear
Check:
- Correct Meta profile is being used.
- Invitation was sent to the intended person.
- Invitation was accepted.
- Correct Business Portfolio is selected.
- The ad account was assigned to the person or partner.
- The account still exists in the owner's Business Portfolio.
The Account Appears but Campaigns Cannot Be Edited
Check the task permission assigned to the ad account. View-only or reporting access may not allow campaign changes.
The Account Works but the Page or Dataset Does Not
Check asset-level assignment. Ad account access does not automatically grant access to every connected asset.
Billing Is Not Visible
Billing visibility and payment actions may require separate permissions or owner involvement depending on the structure.
One User Is Restricted
Determine whether the restriction applies to the person's advertising access rather than the ad account. Reassigning the same account may not solve a user-level restriction.
The Business Portfolio Is Restricted
Identify the affected business and use the official status and review path available in Meta. Do not create new businesses or accounts to bypass enforcement.
13. Respond to Suspicious Access
If you see unknown users, partners, campaigns, payment methods, or permission changes:
- Record the affected assets and activity.
- Notify the authorized business administrator.
- Review people, partners, sessions, and permissions.
- Secure administrator accounts.
- Remove confirmed unauthorized access without removing the only legitimate controller.
- Review payment and advertising activity.
- Preserve evidence and change history.
- Use Meta's available security and support process.
Treat security remediation separately from policy remediation. If unauthorized ads were created, the business may need to address both the compromise and the advertising issue.
If advertising is restricted, follow the recovery and continuity guide.
14. Evaluate Provider-Granted Access
When an external provider owns the account, confirm:
- Owner inside Meta
- Access granted to the advertiser's Business Portfolio, named users, or both
- Exact campaign and reporting permissions
- Assets that can be connected
- Actions requiring provider support
- Process for adding or removing users
- Security requirements
- Treatment of access during a restriction
- Exit date and data access
- Provider's ability to remove access
Do not accept “you will get full access” without a permission list and ownership explanation.
Access Audit Checklist
| Control | Verified? |
|---|---|
| Account owner identified | |
| Business purpose documented | |
| People use unique logins | |
| Partners use formal business access | |
| Full control is limited | |
| Asset-level permissions reviewed | |
| Two-factor authentication required | |
| Former users removed | |
| Unused partner access removed | |
| Access register current | |
| Change history reviewed | |
| Offboarding process documented | |
| Emergency administrator identified |
An account is not well governed merely because the correct people can access it today. The business also needs a repeatable method for approving, reviewing, and removing that access.
Build Access Around Responsibility
AdAccRun helps eligible advertisers, agencies, and media buying teams evaluate currently available account arrangements, including ownership, Business Portfolio connection, permissions, funding, and support requirements. Availability, configuration, pricing, timing, limits, and replacement terms depend on review and the option offered at the time.
Talk to AdAccRun on Telegram and share your business model, target markets, expected spend, Business Portfolio details, and required access structure.
Frequently Asked Questions
Should I Give an Agency Full Control?
Only if the documented service genuinely requires it and the business approves the risk. Many campaign-management tasks can be completed with selected asset permissions. Ask the agency to list the exact actions it needs.
Can I Share My Personal Facebook Login With a Media Buyer?
No professional workflow should depend on shared personal credentials. Add authorized people or partner businesses through Meta's business permission tools.
Why Can a User See the Ad Account but Not the Page or Dataset?
Business assets can have separate permissions. Check whether the Page, Instagram account, dataset, domain, or catalog was assigned to the person or partner.
How Often Should Permissions Be Reviewed?
Use a defined recurring schedule based on team change and risk. Review immediately after staff, agency, provider, client, or security changes.
What Should Happen When an Agency Relationship Ends?
Stop new access, export agreed reports, reconcile funding, transfer responsibilities, remove people and partner permissions, confirm asset ownership, and document completion.
Does Access Mean I Own the Ad Account?
No. A user may be able to manage campaigns without owning the account. Confirm which Business Portfolio owns the account and what happens when the relationship ends.