Direct answer
Offboard an agency as a controlled custody transition, not a same-day permission purge. Name legal/contract and platform decision owners, freeze non-essential changes, inventory accounts/dependencies, export evidence, create replacement owner access, test one reversible change/read-back, then remove only scoped agency access. Reconcile platform, bank/card, and agency ledgers separately. Mechanics are mutable: PR-P14 covers country/region TikTok verification documents; PR-P15 covers case-by-case, account-type transaction appeals. Re-verify current routes before live use. Close after owner/finance/operations sign-off; assign each residual an owner/date.
Who this is for
This guide is for advertisers, finance owners, growth leaders, and agency operators moving a high-spend Meta, Google Ads, and/or TikTok program from one operating relationship to another. It fits client-owned accounts, manager-linked arrangements, consolidated billing, and agency-created structures where the parties need a documented exit.
It is not legal advice, a contract interpretation, an insurance opinion, a forensic report, or a promise of platform transfer, review, delivery, reimbursement, or performance. A legitimate agency relationship is not evidence of misconduct. The risk is an unverified owner, billing source, export, permission edge, or exit term. Community reports describe custody anxiety, not prevalence or a finding about any agency. [VOC-F05]
Decision model
Separate three kinds of authority
- Legal/contract owner: interprets notice, return, confidentiality, invoice, and termination terms; counsel decides legal meaning.
- Asset/finance owner: controls platform access, spend approval, billing entity, exports, and restart sign-off; finance reconciles money.
- Platform decision owner: Meta, Google, and TikTok each control their own access, review, billing, verification, enforcement, and UI. Synthesis/inference: a manager/partner link does not by itself establish contract ownership or special support. Google-specific manager mechanics and client unlinking are documented separately. [BC-S09]
Use an asset graph, not an account list
Map legal entity and owner to every portfolio/manager, ad account, Page/Instagram, domain, catalog/feed, pixel/dataset, conversion, payment profile, user/partner, token/app, script/rule, and automation. Record who can add, edit, export, bill, review, unlink, or delete. Synthesis/inference: shared identity, payment, domain, data endpoint, feed, vendor, token, or approver can create common-mode failure. [RS-S17][RS-S18]
Two clocks and four labels
Synthesis/inference: keep legal/contract and operational clocks separate. Label facts controlled, observed, provider-dependent, or unknown; a screenshot or login does not by itself prove ownership, clean persistence, or portability. [RS-S19][DRS-A01]
Diagnostic or control sequence
Run this staged sequence; each step names input, owner, action, and stop/branch. Do not skip ahead for a termination date.
1. Open the transition record and appoint decision owners
- Input: contract/statement of work, notice date, legal entities, platform IDs, current agency contacts, current owner and finance records.
- Owner: client executive or designated asset owner; legal/contract owner confirms the document lane.
- Action: open a UTC record; name transition lead, executor, recorder, finance, asset, and platform liaison. Record the business reason and approval boundaries without alleging misconduct. [RS-S09][DRS-A03]
- Stop/branch: if an authorized owner is unavailable, pause removal and record the gap. If unauthorized spend or compromise is suspected, preserve evidence and branch to security/finance containment. [DRS-A01][PR-P12]
2. Declare a bounded change freeze
- Input: recent-change ledger, campaign calendar, launches, scripts/rules, feeds, domains, payment events, and termination scope.
- Owner: transition lead; asset owner approves exceptions.
- Action: freeze non-essential campaign, budget, billing, tracking, domain, catalog, feed, token, and automation changes. Log safety exceptions and tell both teams who may authorize one.
- Stop/branch: if a contractual/customer obligation conflicts, contract and asset owners define a narrow exception. If the agency refuses, preserve the record; do not retaliate with blanket removal.
3. Build the inventory and custody map
- Input: platform UI/API exports where authorized, user and partner lists, billing documents, domain registrar records, catalog/feed ownership, pixel/dataset IDs, app/token list, automation inventory, and agency handoff materials.
- Owner: operations executor collects; asset owner validates; agency supplies records it controls under the contract.
- Action: record each object’s ID, legal entity, full-control owner, agency role, billing owner, export, dependencies, last-good time, removal authority, and unknowns. Include DNS/hosting, catalogs/feeds, pixels/datasets/events, conversions, creatives, portable audiences, scripts, apps, tokens, webhooks, and reports. Access is not ownership.
- Stop/branch: unknown ownership, portability, or deletion authority means no delete/transfer/relink. Ask contract owner for interpretation and platform owner for current mechanics. Synthesis/inference. [BC-S09][RS-S17][RS-S18]
4. Preserve evidence and exports before changing custody
- Input: current permissions, partner links, campaign/ad/group state, budgets, billing history, invoices, payment transactions, notices, case IDs, audit/activity logs, automation code/configuration, feed snapshots, event samples, and communications.
- Owner: recorder/evidence owner; security or counsel decides retention/hold questions when applicable.
- Action: export last-good/current state where authorized; preserve errors, UTC/time zone, IDs, headers, case chronology, transactions, and collector/location. Keep a read-only copy and log unavailable data; screenshots supplement exports. Preserve before revocation, deletion, relinking, rotation, or rebuild. [DRS-A01][RS-S03]
- Stop/branch: minimize personal/payment/customer data and never send secrets. Route retention/hold questions to the appropriate professional.
5. Establish replacement access before removals
- Input: custody map, least-privilege matrix, owner identities, recovery contacts, clean endpoints, MFA/SSO policy, replacement team names, and platform-specific role options.
- Owner: asset owner approves; security owner provisions; operations executor tests.
- Action: confirm advertiser full-control access and recovery contact; invite named replacement users at minimum roles. Keep agency access until tested. Least privilege is supported for account security. Do not provide passwords, MFA codes, cookies, browser data, remote control, or full payment credentials to an inbound/unverified contact. Synthesis/inference: use a known-clean endpoint; MFA is layered, not proof persistence is clean. [PR-P12][DRS-A15][BC-S18][RS-S04][BC-S10]
- Stop/branch: if the agency is sole administrator, unreachable, or compromise is suspected, do not remove the last path. Preserve evidence and use the current platform recovery route; Meta’s route does not prove every asset is restored. [BC-S11]
6. Test one change and read it back
- Input: approved test object, before-state export, expected permission/billing/measurement state, rollback value, and independent observer.
- Owner: operations executor performs; asset owner approves; recorder captures read-back.
- Action: make one low-risk reversible change; record actor, UTC, object, expected/observed state, and independent confirmation. Bound scripts/rules and read back platform state; Google says Ads Scripts are best-effort. [BC-S06]
- Stop/branch: mismatch, scope expansion, or warning means stop, preserve read-back, and roll back where authorized. Do not stack fixes.
7. Reconcile billing, entity, and contract lanes separately
- Input: platform invoices/balances and transaction IDs; bank/card statements; agency invoices and credits; contract entity/period; served-delivery export; authorized-user list.
- Owner: finance owner leads; contract owner handles rights/notice questions; platform liaison uses the official billing route.
- Action: keep separate ledgers for platform billed, served delivery, bank/card, agency invoice, and platform/analytics/backend outcomes. Match entity, period, currency, time zone, account, transaction, and authorization. Google warns legitimate-balance chargebacks can create suspension risk. [BC-S07][BC-S08][PR-P11]
- Stop/branch: unauthorized activity → preserve and use platform plus issuer/bank fraud routes; legitimate balance → reconcile before disputing; agency invoice mismatch → finance/contract owner. No indiscriminate chargeback or unsupported fraud label.
8. Transfer measurement and dependency continuity
- Input: event schema/version, pixel/dataset and server-event ownership, domain verification, catalog/feed schedules, conversion definitions, report queries, API clients, token scopes, automation schedules, and backend/CRM cohort.
- Owner: measurement/data owner; domain/catalog owner; operations executor records tests.
- Action: transfer only what the map/contract permits. Test domains, catalog/feed ownership/freshness, pixel/dataset events, deduplication, reports, CRM/backend access; freeze cohort definition. Keep platform, analytics, and settled outcomes as separate ledgers. Synthesis/inference. [RS-S07][RS-S08]
- Stop/branch: shared token, agency endpoint, non-entity domain, or unclear event ownership means stop relinking; name an owner/date and obtain verification.
9. Remove agency access in scoped stages, with rollback
- Input: signed or recorded handoff approval, replacement-access test, export index, finance reconciliation status, agency role list, and removal authority.
- Owner: asset owner authorizes; operations executor removes one specified user/partner/session at a time; recorder verifies.
- Action: remove only authorized agency users, partners, apps, tokens, rules, or billing permissions, one at a time. Preserve before-state, read back each material change, and retain rollback. Do not delete shared domains, catalogs, datasets, payments, or automations.
- Stop/branch: lost recovery path, inaccessible child, unexpected delivery/measurement change, or contract issue means stop; restore last safe state where authorized and escalate.
10. Validate, sign acceptance, and assign residuals
- Input: post-removal access diff, dependency checks, billing worksheet, event test, campaign/automation diff, official case IDs, monitoring view, and unresolved-unknown register.
- Owner: asset owner, finance owner, and transition lead jointly sign; each residual gets a named owner and date.
- Action: require owner access, no unreviewed persistence, dependency validation, finance reconciliation/residuals, evidence, limited event/conversion test, monitoring, and joint asset/finance/transition sign-off. Read back the first approved post-transition change. [RS-S09][RS-S10]
- Stop/branch: any critical unknown keeps the transition open or requires a signed exception with owner/date. Login/green dashboard alone is insufficient. Synthesis/inference.
Platform mechanics refresh note
Platform mechanics are mutable. PR-P14 covers TikTok verification documents by country/region; PR-P15 covers case-by-case, account-type transaction appeals. Sources were checked 2026-07-19. Before acting, open the current first-party route for the affected account and region and verify displayed mechanics. [PR-P03][PR-P10][PR-P11][PR-P13][PR-P14][PR-P15][PR-P16]
Evidence to preserve
- Contract/SOW, termination notice, amendments, data-return terms, and invoice correspondence.
- Legal entity, account/portfolio/manager, campaign/ad, domain, catalog/feed, pixel/dataset, token/app, and automation IDs.
- Full-control, recovery-contact, user, partner, manager, billing, and removal-authority records.
- Last-good/current campaign, budget, permission, billing, catalog/feed, domain, event, and report exports.
- UTC/time-zone timeline, raw errors, status URLs, case IDs, headers, actor, expected/observed state, and rollback result.
- Platform balances, bank/card references, agency invoices, credits, and authorization records; redact unnecessary payment details.
- Test-event metadata and cohort definition; record unavailable evidence and its owner/date. [DRS-A01][RS-S03]
What not to do
- Do not remove agency users/partners at once before replacement access and exports are tested.
- Do not share passwords, codes, cookies, browser data, remote control, IDs, or payment numbers.
- Do not delete shared domains, catalogs, feeds, datasets, tokens, scripts, or invoices.
- Agency involvement is not proof of abuse; platform mechanics are not legal ownership.
- Do not create replacement accounts, rotate identities/payments, cloak destinations, forge records, spam appeals, or buy “un-ban” services. Meta describes enforcement against rented accounts and fake restoration services. [PR-P07]
- No blanket chargeback, legal/insurance conclusion, guarantee, timeline, or outcome claim.
- Do not relaunch broad spend before custody, dependencies, billing, evidence, measurement, test, monitoring, and sign-off.
When to escalate
Self-service or routine transition: one platform, clear owner, documented contract, healthy replacement access, no active compromise, exportable records, and a reversible low-risk handoff test. Use current first-party documentation and keep the transition record.
Qualified specialist coordination: multiple platforms or entities; agency-owned or consolidated billing; sole-admin or unknown-owner risk; shared domains/catalogs/datasets/feeds/tokens; active unauthorized spend; evidence/finance/measurement reconciliation; or a transition crossing security and contract boundaries. The specialist can organize evidence and decisions, not control a platform review.
Route outside this guide: suspected fraud to the platform and issuer/bank; endpoint compromise to qualified security responders; contract interpretation to the contract owner/counsel; insurance questions to broker/insurer/counsel; domain/registrar disputes to the registrar and appropriate professional. No route guarantees an outcome or response time.
FAQ
Should the agency be removed immediately on the termination date?
No. First preserve evidence, confirm authority, establish replacement access, test one reversible change, and document the handoff. Remove only scoped access the asset owner is authorized to remove; keep a rollback path.
Is an agency-owned account automatically unsafe or unlawful?
No. Managed and client-owned arrangements can both be legitimate. Verify owner flags, billing entity, portability, exports, contract terms, and who can add or remove access. Legal interpretation belongs to the contract owner and counsel. Synthesis/inference: platform access evidence does not adjudicate contract ownership. [BC-S09][VOC-F05]
Can I just change the password and remove the agency?
Synthesis/inference: a password change alone does not verify removal of partner links, sessions, tokens, OAuth apps, scripts, feeds, or billing permissions. Review persistence and dependencies from a known-clean endpoint, preserve evidence, and follow the platform’s current recovery/security route. [BC-S09][BC-S06][BC-S10][BC-S11][PR-P12]
Should the agency invoice be disputed with the platform charge?
No. Keep the platform ledger, bank/card record, and agency invoice separate. Finance should match entity, period, account, transaction, and authorization; contract questions go to the contract owner/counsel. A legitimate platform-balance chargeback can create suspension risk. [BC-S07][BC-S08]
What proves the handoff is complete?
Acceptance requires owner-controlled access, no unreviewed agency persistence, dependency and measurement tests, billing reconciliation or named residuals, preserved evidence, a limited authorized test, monitoring, and sign-off. A login or green dashboard alone does not prove completion.
Which platform instructions can be copied into a live runbook?
Use only current first-party instructions. PR-P14 covers country/region TikTok verification documents; PR-P15 covers case-by-case, account-type transaction appeals. Recheck the affected account/region before live use. [PR-P03][PR-P10][PR-P13][PR-P14][PR-P15]
Source appendix
All sources were accessed 2026-07-19. Mutable platform sources should be rechecked against the affected account and region immediately before live use.
| Key | Title — author/publisher; publication date | URL |
|---|---|---|
| RS-S03 | Cybersecurity Incident & Vulnerability Response Playbooks — CISA; 2021 | https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf |
| RS-S04 | Multi-Factor Authentication (MFA) — CISA; Revision Date January 05, 2022 | https://www.cisa.gov/resources-tools/resources/multi-factor-authentication-mfa |
| RS-S07 | Monitoring Distributed Systems — Rob Ewaschuk, Google SRE; 2017 | https://sre.google/sre-book/monitoring-distributed-systems/ |
| RS-S08 | Service Level Objectives — Google SRE authors; 2017 | https://sre.google/sre-book/service-level-objectives/ |
| RS-S09 | Managing Incidents — Andrew Stribblehill, Google SRE; 2017 | https://sre.google/sre-book/managing-incidents/ |
| RS-S10 | Postmortem Culture: Learning from Failure — John Lunney and Sue Lueder, Google SRE; 2017 | https://sre.google/sre-book/postmortem-culture/ |
| RS-S17 | Mapping Disruption Sources in the Power Grid and Implications for Resilience — Maureen S. Golan and Javad Mohammadi; arXiv; 2022-07-17 | https://arxiv.org/abs/2207.08146 |
| RS-S18 | Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks — John Matta, Jeffrey Borwey, Gunes Ercal; arXiv; 2014-04-01 | https://arxiv.org/abs/1404.0103 |
| RS-S19 | Characterizing User and Provider Reported Cloud Failures — Cetin, Talluri, Iosup; arXiv; 2021-10-23 | https://arxiv.org/abs/2110.12237 |
| PR-P03 | Request a review if you are restricted from advertising on Meta platforms — Meta; undated | https://www.facebook.com/business/help/530209463124901 |
| PR-P07 | Meta Takes Legal Action Against Scam Advertisers — Meta Newsroom; 2026-02-26 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ |
| PR-P10 | Google Ads account suspensions overview — Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/9841640?hl=en |
| PR-P11 | Billing and payment suspensions — Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/13704200?hl=en |
| PR-P12 | Secure your Google Ads account: Introduction — Google Ads Help; current/undated | https://support.google.com/google-ads/answer/2375456 |
| PR-P13 | About suspended ad accounts on TikTok — TikTok for Business; June 2026 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 |
| PR-P14 | How to verify your business on TikTok — TikTok for Business; May 2026 | https://ads.tiktok.com/help/article/about-business-verification?aadvid=72391499277 |
| PR-P15 | About transaction-related appeals — TikTok for Business; July 2026 | https://ads.tiktok.com/help/article/about-transaction-related-appeals |
| PR-P16 | TikTok Advertising Policies — TikTok for Business; August 2025 | https://ads.tiktok.com/help/article/tiktok-advertising-policies?lang=en&redirected=2 |
| BC-S06 | Errors and Warnings — Google Ads Scripts team; 2026-06-24 | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors |
| BC-S07 | Billing and payment suspensions — Google Ads Help; current | https://support.google.com/google-ads/answer/13704200 |
| BC-S08 | How to dispute a Google Ads charge — Google Ads Help; current | https://support.google.com/google-ads/answer/10560092 |
| BC-S09 | Manager Accounts (MCC): About Google Ads manager accounts — Google Ads Help; current | https://support.google.com/google-ads/answer/6139186 |
| BC-S10 | If your account was hacked or someone is using it without your permission — Meta; current | https://www.meta.com/help/policies/539039418231124/ |
| BC-S11 | Recover a hacked or compromised business portfolio — Meta; current | https://www.facebook.com/business/help/25302697499431030 |
| VOC-F05 | Sole Business Portfolio admin permanently disabled — u/Exact_Kiwi3437, Reddit; 2026-07-16 | https://old.reddit.com/r/FacebookAds/comments/1uxske3/ |
| DRS-A01 | Digital Evidence Preservation: Considerations for Evidence Handlers — Barbara Guttman, Douglas R. White, Tracy Walraven, NIST; 2022-09 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf |
| DRS-A03 | Incident Response Plan Basics — CISA; undated | https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf |
| BC-S18 | Scammers pose as Meta support in Facebook — Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ |
| DRS-A15 | Scammers pose as Meta support in Facebook — Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ |
Related resources
- Managed vs Direct Ad Accounts — Ownership and Risk ComparisonCompare managed and direct ad account structures using ownership, billing, permissions, support, portability, policy exposure, and exit terms.
- Ad Account Redundancy — The $50k+/mo PlaybookHow to build ad account redundancy so a single ban never takes your business offline. The playbook for advertisers spending $50k+ per month.
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- Ad Account Ownership & Access Audit for High-Spend OperationsMap legal ownership, platform roles, admin access, custody, dependencies, tokens, partners, and safe offboarding before an ad incident.
- Ad Incident Evidence Capture Guide: Preserve the Record Before You Change the SystemPreserve ad evidence before changing access, billing, campaigns, tracking, domains, catalogs, integrations, or appeals.
- Ad Account Billing Interruption Reconciliation: Balance, Authorization, and RevenueReconcile ad balances, payment rails, agencies, credits, disputes, attribution, and revenue without premature chargebacks.
- Ads Not Delivering: A Zero-Spend Diagnosis Across Meta, Google, and TikTokZero reports, impressions, conversions, and delivery failure for a frozen scope: an evidence-first decision tree.
Contact AdsInfra
Send a message about this resource before making a high-impact change.