Why ad account access security matters
Every person, partner, and login connected to your ad accounts is a path to your budgets, billing, and customer data. Meta warns that bad actors often target inactive accounts in an effort to gain access to a business portfolio, and Google's security guidance starts from the same premise: anyone with access to your Google Account can access your Google Ads account and look up your advertising data. Meta has also reported that increases in time spent online have come with an increase in cybercrime and fraudulent activity.
The operational risks are concrete:
- **Spend and billing exposure.** Google's best-practices guide tells advertisers to watch for unexpected changes to ads or budgets, and to check bank or credit card statements if they suspect billing information was accessed. - **Compromised credentials.** Practitioner security guidance citing the IBM Cost of a Data Breach Report identifies compromised credentials as the most common initial attack vector — which is why shared logins and orphaned permissions are liabilities, not conveniences. - **Silent drift.** Access granted months ago to a freelancer, a former employee, or a past agency rarely revokes itself. No platform sends you a reminder that a permission has gone stale.
It also helps to separate what can go wrong by layer. A person's login can be phished. An ad account can carry unauthorized users. A Page or dataset can be assigned to the wrong partner. A Business Portfolio — Meta's container for business assets — can be over-provisioned with admins. Each layer has its own controls, and this guide walks through them in order: roles, partner access, login security, offboarding, and monitoring.
Admin roles and permissions
The working principle is least privilege: grant each person the minimum access their job requires, and nothing more. Google's own best practices say to grant the minimum access needed for each user, and its access levels make that practical — Admin users can invite new users and change the account, Standard users cannot, and Read only or Email only access covers people who never need to touch campaigns.
Platform by platform:
- **Google Ads.** Access levels run from Admin down to Read only and Email only. Two structural safeguards matter. First, keep at least two admins: Google warns that if your account has only one administrator, you may lose access to your tags if that user becomes unavailable. Second, consider multi-party approval, which requires a second administrator to approve sensitive actions like adding users, removing users, or changing roles. - **Meta.** People are added to an ad account with roles based on the permissions you want them to have, and assets inside a business portfolio are assigned to people or to partners. Practitioner guidance recommends keeping portfolio admins to two or three people, because a portfolio admin can remove every other admin — over-provisioned portfolios are a known escalation path in account compromises. - **TikTok.** Only Business Center Admins can grant member access to TikTok accounts. Practitioner documentation describes tiered ad account roles (Admin, Operator, Analyst) plus separate finance roles, so campaign staff never need billing permissions by default.
Before sending any invite, do a fifteen-minute mapping exercise: write down each person's name, their job, and the minimum role that job requires. Treat Admin access as needing explicit justification. Revisit the map whenever someone's role changes — permission drift is how a read-only analyst ends up able to edit live campaigns.
Partner and agency access
The structural rule that survives every platform redesign: ownership stays with the business the asset describes, and access flows through partnership. In practice, the client's Business Portfolio owns the ad account, the Page, and the dataset (pixel); the agency's portfolio is added as a partner and receives assigned assets; and the agency assigns its own people internally. Agency staff should never be added as individuals directly on client assets.
Why the model matters:
- **Portability.** If an agency creates the ad account or dataset inside its own portfolio 'for convenience,' the client's spend history and the dataset's learning are trapped when the relationship ends. Practitioner guidance is blunt: get the ownership direction wrong and offboarding means the client loses account history. - **Billing hygiene.** Keep payment methods client-owned unless explicitly agreed otherwise — agency onboarding checklists flag verifying client-owned payment methods as a standard step. - **Revocability.** Partner access is one grant to one business. Ending the relationship is one partner removal, not an archaeology dig through person-level permissions.
Platform mechanics:
- **Meta.** Partners are other Business Portfolios. Meta's developer documentation is explicit that storing customer passwords is not an approved model — access should be granted through the platform, never handed over as credentials. - **Google Ads.** Agencies typically connect through a manager account (MCC). Each Google Account can have direct access to up to 20 Google Ads accounts, so a manager account is the better option at scale. Use the Related managers tab to check whether accounts are linked to managers outside your hierarchy. - **TikTok.** Clients add your Business Center as a partner and choose which ad accounts to share. TikTok allows ad accounts to be linked to multiple Business Centers, so a client can work with more than one partner without transferring ownership.
Two-factor and login security
Two-factor authentication (2FA, or 2-Step Verification) is the highest-leverage login control available: Google's documentation states it can help keep bad actors out even if your password has been compromised.
Enforce it — don't merely suggest it:
- **Meta.** Business portfolio admins can require two-factor authentication for everyone who accesses the portfolio; everyone the requirement applies to must set it up on their personal Facebook account before they can get in. - **Google Ads.** Turn on 2-Step Verification under Access and security, Security tab. If you run a manager account, security mandates let you require 2-Step Verification across all current and future sub-accounts you own, with an effective date you choose. Google also describes its Authenticator app as a more secure verification method than SMS. - **TikTok.** Enable Two-Step Verification for both Ads Manager and Business Center, and enforce it for all members.
Then layer on domain and phishing controls:
- **Allowed email domains.** Google Ads (including at the manager-account level) and TikTok Business Center both let you restrict invitations to approved email domains, so people outside your organization can't be invited in. - **Credential hygiene.** Never share logins between people. Google explicitly advises granting each person access with their own Google Account instead of sharing a username and password, and recommends unique passwords per site. - **Phishing verification.** Google states it will only contact you from an @google.com email domain and will never send an unsolicited message asking for your password. TikTok advises verifying that outreach claiming to be from TikTok for Business is genuine before responding. - **Extra verification for sensitive data.** TikTok's Data Security Verification requires an identity check with a verification code before anyone can access advertising data.
Ready to upgrade your ad account infrastructure?
AdsInfra provides certified agency accounts for Meta, TikTok, and Google. Setup in 2-5 business days.
Talk to a SpecialistOffboarding and revoking access
Offboarding is where access security usually fails, because nothing breaks on day one when you skip it. Practitioner research describes the six-month problem: months after a client relationship ends, many agencies still have access to that client's accounts — not out of malice, but because revocation is invisible and nothing reminds you to do it.
Build a same-day revocation checklist:
- **Google Ads.** Go to Access and security in the Admin menu, find the user, and select Remove access. If an agency manager account is linked, unlink it from the Managers tab. Google's warning is direct: unless you remove inactive users, they can still sign in and make changes. - **Meta.** Remove both layers — the partner connection under Business Settings, Partners, and any individuals added directly under People. Meta's Security Center specifically recommends removing inactive users because bad actors target them. - **TikTok.** Remove members who no longer require access, revoke partner access to ad accounts, and confirm that pending invitations are valid. TikTok's own best practices list removing inactive users as a core hygiene step. - **Your own systems.** Delete stored OAuth tokens and revoke API access — not just the visible platform connection. Practitioner offboarding guidance stresses that a stored token can keep accessing a client's data until it expires, even after the connection appears removed.
Two discipline points:
1. **Don't rely on the other party to remove you.** If you're the departing agency, request written confirmation; if you're the account owner, verify each removal yourself in the platform's access settings. 2. **Document every revocation** — date, platform, who performed it, and a screenshot or confirmation email. Meta does not document a guaranteed timeline for every access change to propagate, so treat a removal as complete only after you verify it in Business Settings.