Direct answer
Multiple ad accounts are not automatically independent. Synthesis/inference: shared identity or legal entity, payment, domain/DNS, catalog/feed, pixel/dataset, credentials/admins, vendors, tokens/automation, policy/category/region, or reporting/backend paths can fail together. Resilience is a tested property of failure paths, not account count. Build a dependency graph, test each material path with an owner and stop condition, preserve evidence, and record residual provider-dependent risk. Never publish or use a portfolio independence score.
Who this is for
Fit: executives, finance/security/measurement owners, and operators of high-spend Meta, Google, TikTok, or mixed-platform programs with multiple accounts, vendors, commerce, or regional campaigns.
Not a fit: account farming, ban evasion, identity/payment rotation, rented accounts, forged records, cloaking, anti-detect tools, credential surrender, indiscriminate chargebacks, or guaranteed restoration.
Governance and evidence guidance only—not legal, tax, insurance, forensic, or platform-support advice. Labels and mechanics change; assign a verifier.
Decision model
Count accounts; test paths
Treat the program as an asset graph, not an account count. Nodes include identity/legal entity; payment profile and issuer; domain/DNS/endpoint; catalog/feed; pixel/dataset/events and consent; admins/recovery contacts; agencies/vendors; OAuth apps/tokens/automation; policy/category/region; and reporting, analytics, CRM, finance, and backend settlement. Draw edges for owns, administers, bills, reads, writes, exports, approves, depends on, or can disable.
Every node/edge gets platform, object ID, legal entity, region, owner, timestamp, and evidence location. Record two mandatory axes: evidence/control state = controlled, observed, provider-dependent, or unknown; and concentration state = critical shared, material shared, tested independent, or unknown. Google documents that manager-account access differs from ownership: a manager account can be given ownership of a client account to manage user access, and client administrators can unlink a manager relationship at any time; a platform role is not, by itself, evidence of legal title or contract rights (editorial boundary, not stated by Google). [BC-S09]
Synthesis/inference: different account IDs can still share a payment profile, domain, event endpoint, token, operator, vendor, or policy-sensitive category. Resilience research supports bottleneck/common-mode review by analogy, not an ad-continuity score. [RS-S17][RS-S18][RS-S23]
Concentration review without a score
For each material edge record common-mode trigger, blast radius, owner, provider dependency, and proof/rollback. Mandatory concentration labels: critical shared = one failure can disable all material paths or essential authority/evidence/settlement; material shared = failure disables a material subset while a controlled path remains; tested independent = named trigger/scope with dated read-back/rollback showing one path can fail without disabling the other and no shared upstream unexamined; unknown = absent, stale, or incomplete evidence. Never probability or portfolio score.
Diagnostic or control sequence
Every step names evidence/input, decision owner, action, and stop/branch. Test one path at a time using read-only or safe staging.
-
Set scope. Input: IDs, entity register, regions, spend authority, incident ID. Owner: risk owner/incident lead. Action: set date range, reviewers, and evidence register. Stop: no authority; record the gap and request no credentials.
-
Build graph. Input: dated exports for payment, DNS, feed, events, users/partners/apps/tokens, automation, vendors, policy, and reporting. Owner: asset owner/ops. Action: row each node/edge with IDs, entity, region, owner, last-good UTC, and evidence. Stop: unfamiliar sharing; copy label, mark it provider-dependent, and block live use pending current official verification.
-
Reconcile identity/payment. Input: authorization, contracts, invoices, verification, profile links, issuer, currency, transactions. Owner: legal/business + finance. Action: separate owner/payer/admin/approver/removal authority; ledger billed, served, bank/card, and agency separately. [BC-S09][PR-P05][PR-P11][BC-S07][BC-S08] Synthesis/inference: ledger separation. Stop: conflict; preserve and route.
-
Trace destination/commerce. Input: registrar/DNS, certificates, endpoints, redirects, feed jobs, destinations, variants, export. Owner: technical/commerce. Action: enumerate consumers; bounded read-back. Stop: unknown consumer/rollback; do not delete, rotate, relink, or clean. Synthesis/inference: shared domain/feed is common-mode exposure. [BC-S19][PR-P18]
-
Trace measurement/backend. Input: pixel/dataset/event IDs, schema, consent, deduplication, analytics, CRM, order/refund, reports. Owner: measurement; finance for settlement. Synthesis/inference: compare status/reporting to a settled cohort; trace event and quarantine report-driven budget decisions as operating controls. [PR-P09][PR-P18] Stop: stale, cross-tenant, or unexplained data.
-
Review access/partners/tokens/automation. Input: owners, recovery, admins, sessions, MFA/SSO, partners, OAuth, token scope/expiry, scripts, logs, contracts. Owner: security/asset; vendor supplies records. Synthesis/inference: verify owner recovery, least privilege, approval split, offboarding, clean endpoint, bounded read-back; MFA is not clean-account proof. [RS-S04][RS-S05][PR-P12] Scripts are best-effort; read back. [BC-S06] Stop: revocation could erase evidence.
-
Review policy/region/reporting. Input: policy/detail IDs, category/entity/market, verification, notices, status URL, API export, finance ledger. Owner: legal/business + data; provider decides eligibility. Action: compare paths, preserve labels. Stop: mutable mechanics uncertain; block live use pending current official verification.
-
Test, accept, and register residuals. Input: graph, results, unknowns, rollback, routes, sign-offs. Owner: executive risk owner; providers retain decisions. Action: record both axes and choose a control. A control pass does not prove independence. Stop: no “tested independent” without the named-trigger predicate; freeze risky change, preserve evidence, and use the official route.
Every test record includes trigger, paths, upstreams, boundary, date, evidence, rollback, residual, owner/sign-off. Control tests set control state only; tested independent requires the scoped predicate; otherwise concentration is critical shared, material shared, or unknown.
| Failure path | Dependency/control test (not an independence verdict) | Control pass / stop condition | Owner |
|---|---|---|---|
| Identity/legal entity | Compare entity, verification, owner identity, region, authorization. | Control pass only with documented operating model; stop on mismatch. | Legal/business |
| Payment | Map profile, issuer, currency, balance, invoice, approver. | Control pass with documented funding/reconciliation; stop on shared unresolved balance. | Finance |
| Domain/DNS | Enumerate registrar, DNS, certificates, redirects, consumers. | Control pass with rollback and lawful destination test; stop on unknown consumer. | Technical |
| Catalog/feed | Trace source, job, credential, destination, last-good export. | Control pass when sync is bounded; stop on unbounded overwrite. | Commerce |
| Pixel/dataset/events | Trace schema, consent, event ID, platform, analytics, backend. | Control pass with bounded event test; stop on ambiguity. | Measurement |
| Admins/credentials | Review owner recovery, sessions, apps, tokens, partners, clean endpoint. | Control pass with revocation/read-back; stop if evidence would be destroyed. | Security |
| Vendor/agency | Compare contract, billing, exports, links, termination, handoff. | Control pass with owner access and handoff; stop on disputed custody. | Commercial |
| Tokens/apps/automation | Compare scope, expiry, schedule, ceiling, alert, read-back. | Control pass after bounded mutation verification; stop on failed read-back. | Automation |
| Policy/category/region | Compare current detail, category, entity, audience, market. | Control pass only as a local condition; stop on mutable-label uncertainty. | Legal/business |
| Reporting/backend | Compare billed, served, attributed, analytics, CRM, settled ledgers. | Control pass on defined cohort reconciliation; stop on stale/cross-tenant data. | Data/finance |
Evidence to preserve
- Asset graph: platform/product, object IDs, entity, region, owner/role/partner/consumer, edge type, last-good UTC, evidence location.
- Identity/change: admins, recovery, sessions, MFA/SSO, apps/OAuth, token scope/expiry, extensions, offboarding, actor/approver, expected/observed state, read-back, rollback. Never store secrets.
- Finance: profile/account links, invoice, transaction ID, currency/time zone, authorization, bank/card, agency invoice, served period.
- Domain/commerce/data: registrar/DNS, certificates/endpoints/redirects, feed jobs/exports, destination IDs, pixel/dataset/event IDs, schema, consent, deduplication, analytics, CRM, order/refund, settlement, freshness.
- Provider/security: exact label/error, policy/detail ID, status URL, request/case ID, notice, access history, unavailable-data note, collector/source, capture time, retention/redaction, immutable-copy reference where appropriate.
- NIST treats accounts and cloud objects as digital-evidence preservation problems. [DRS-A01] Synthesis/inference: screenshots supplement exports; preserve before cleanup and apply privacy, retention, and access controls.
Residual risk register
Record unresolved exposure after each test; a residual is accepted only by the named owner and remains visible until re-tested.
| Residual risk | Why it remains | Safe control now | Owner / next validation |
|---|---|---|---|
| Identity/legal entity and payment | Provider identity, entity, balance, issuer, and mechanics remain external or mutable. | Preserve matching records; separate ledgers; reconcile before dispute; no rotation. | Legal/finance / first-party and transaction tests |
| Domain/DNS/feed and data/reporting | One endpoint, feed, sync, dataset, or stale report can affect many assets. | Export; alert; bounded change/rollback; settled cohort; quarantine decisions. | Technical/commerce/data / consumer and event tests |
| Admin/vendor/token and policy/region | Access, partner, automation, category, and regional decisions may remain provider-dependent. | Least privilege; clean endpoint; scoped read-back; record route; block live use pending verification. | Security/legal / access and current-route checks |
| Evidence or staffing gap | Missing exports, owner, or handoff weakens recovery. | Preserve unavailable-data note; assign authority; do not promise coverage. | Incident lead / tabletop or handoff test |
What not to do
- Do not infer independence from account/card/channel count or publish a portfolio-independence score.
- Do not create replacement accounts, rotate identity/payment, rent trusted accounts, cloak destinations, use anti-detect tools, forge records, spam appeals, or delete shared assets/evidence. Meta has described enforcement against rented trusted accounts and fake “un-ban” services. [PR-P07]
- Never send passwords, MFA codes, cookies, government IDs, full payment details, browser data, scripts, or remote-control access to an inbound recovery contact. Fake support campaigns have targeted credentials and sessions. [BC-S18][DRS-A15]
- Synthesis/inference: do not diagnose or relaunch from a green dashboard, login, support reply, or script completion; branch billing disputes [BC-S07][BC-S08], preserve evidence, and validate ownership, persistence, dependencies, finance, events, monitoring, and sign-off.
When to escalate
Self-service: one platform, clear owner, no suspected unauthorized activity, few dependencies, preserved evidence, reversible action, and a specific current first-party step.
Escalate: cross-entity finance/security/domain/data/vendor/policy/reporting/region scope, sole-owner or partner continuity, threatened evidence, or unsafe testing. Route to platform, bank/issuer, registrar/DNS operator, vendor/agency owner, counsel, or finance according to the decision. No route guarantees reinstatement, reimbursement, review timing, delivery, or performance. If authority or safe access is missing, preserve and refer rather than improvise.
FAQ
Do separate ad-account IDs prove independence?
No. Synthesis/inference: shared identity, entity, payment, domain, data, admin, vendor, token, policy, region, or reporting edges can still fail together; test the path. [RS-S17][RS-S18]
Should different cards count as redundancy?
Not alone. [PR-P05][PR-P11] Synthesis/inference: different cards do not establish independence; map profile, issuer, currency, authorization, invoice, account links, and provider risk. Finance owns the decision and current mechanics should be checked against current official documentation.
Is a separate domain independent?
Not necessarily: registrar, DNS, certificate, redirect, hosting, analytics, catalog, and operator edges may still be shared. Synthesis/inference: test the whole path and preserve rollback. [BC-S19]
Does a separate pixel or dataset remove measurement concentration?
No. [PR-P09][PR-P18] Synthesis/inference: a separate pixel or dataset does not remove measurement concentration; trace schema, consent, deduplication, server endpoint, analytics, CRM, backend settlement, and reporting, then reconcile a defined cohort before instrumentation changes.
What can we call an account after one test?
Only the tested predicate, such as “owner access observed.” Synthesis/inference: do not call a portfolio independent or recovered until material paths, finance, evidence, monitoring, and sign-off pass.
Source appendix
All sources below were accessed 2026-07-19. Source classes are preserved. Check mutable platform mechanics against current official documentation before acting.
| Key | Source title; author/publisher; publication date | URL | Supports and boundary |
|---|---|---|---|
| RS-S17 | Mapping Disruption Sources in the Power Grid and Implications for Resilience; Golan & Mohammadi; arXiv; 2022-07-17 | https://arxiv.org/abs/2207.08146 | Analogy: common-mode mapping. |
| RS-S18 | Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks; Matta, Borwey & Ercal; arXiv; 2014-04-01 | https://arxiv.org/abs/1404.0103 | Analogy: bottlenecks, no score. |
| RS-S23 | Resilience Analysis for Competing Populations; Fassoni & Braga; arXiv; 2019-03-14 | https://arxiv.org/abs/1903.06291 | Analogy: context dependence. |
| RS-S04 | Multi-Factor Authentication (MFA); CISA; Revision Date January 05, 2022 | https://www.cisa.gov/resources-tools/resources/multi-factor-authentication-mfa | Layered authentication. |
| RS-S05 | Digital Identity Guidelines: Authentication and Authenticator Management (SP 800-63B); NIST; 2025-08-26 | https://pages.nist.gov/800-63-4/sp800-63b.html | Session/recovery controls. |
| RS-S19 | Characterizing User and Provider Reported Cloud Failures; Cetin, Talluri & Iosup; arXiv; 2021-10-23 | https://arxiv.org/abs/2110.12237 | Visibility divergence. |
| PR-P05 | Fix a failed payment issue on Meta; Meta; undated | https://www.facebook.com/business/help/268196136699959/ | Payment state. |
| PR-P09 | History | Google Ads Status Dashboard; Google; live/undated | https://ads.google.com/status/publisher/summary | Product-scoped status. |
| PR-P11 / BC-S07 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/13704200?hl=en | Payment/verification states. |
| PR-P12 | Secure your Google Ads account: Introduction; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/2375456 | Access security. |
| PR-P13 | About suspended ad accounts on TikTok; TikTok for Business; June 2026 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 | Account Health vocabulary. |
| PR-P14 | How to verify your business on TikTok; TikTok for Business; May 2026 | https://ads.tiktok.com/help/article/about-business-verification?aadvid=72391499277 | Regional documents. |
| PR-P16 | TikTok Advertising Policies; TikTok for Business; August 2025 | https://ads.tiktok.com/help/article/tiktok-advertising-policies?lang=en&redirected=2 | Category/market index. |
| PR-P18 | Google Ads Experiencing Outage Impacting Key Features; Matt G. Southern, Search Engine Journal; 2024-08-01/09-19 | https://www.searchenginejournal.com/google-ads-experiencing-outage-impacting-key-features/523624/ | Reported data isolation. |
| BC-S06 | Errors and Warnings; Google Ads Scripts team; current/undated | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors | Best-effort execution. |
| BC-S08 | How to dispute a Google Ads charge; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/10560092 | Reconcile before dispute. |
| BC-S09 | Manager Accounts (MCC): About Google Ads manager accounts; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/6139186 | Access/unlink mechanics. |
| BC-S18 / DRS-A15 | Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Hlal & Chatra, Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ | Inbound impersonation threat. |
| BC-S19 | The Dangers of DNS Hijacking; Cartron with Shelley, F5 Labs; 2025-01-09 | https://www.f5.com/labs/articles/the-dangers-of-dns-hijacking | DNS dependencies. |
| PR-P07 | Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ | No-evasion posture. |
| DRS-A01 | Digital Evidence Preservation: Considerations for Evidence Handlers; Guttman, White & Walraven, NIST; 2022-09 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf | Evidence preservation. |
| DRS-A03 | Incident Response Plan Basics; CISA; undated | https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf | Roles/exercises. |
Related resources
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- Google Ads Suspension Recovery — The Full RoadmapA step-by-step roadmap for recovering from a Google Ads suspension: how to triage the suspension type, which appeal channel to use, realistic timelines, and what to do if the appeal fails.
- TikTok Ads Not Delivering? Diagnose Zero ImpressionsTikTok ads approved but not delivering or spending? Check delivery status, billing, schedule, audience, bid, budget, and creative before making changes.
- Meta Pixel Not Firing — Troubleshooting GuideYour Meta Pixel is not firing or firing inconsistently. Here's how to diagnose the issue, fix broken tracking, and restore your conversion data and retargeting audiences.
- Ad Account Ownership & Access Audit for High-Spend OperationsMap legal ownership, platform roles, admin access, custody, dependencies, tokens, partners, and safe offboarding before an ad incident.
- Ad Account Suspended: Incident Response ChecklistA platform-neutral suspension runbook: classify the state, preserve evidence, contain safely, reconcile billing, verify recovery, and restart with monitoring.
- Ad Incident Evidence Capture Guide: Preserve the Record Before You Change the SystemPreserve ad evidence before changing access, billing, campaigns, tracking, domains, catalogs, integrations, or appeals.
- Ad Account Billing Interruption Reconciliation: Balance, Authorization, and RevenueReconcile ad balances, payment rails, agencies, credits, disputes, attribution, and revenue without premature chargebacks.
- Ads Not Delivering: A Zero-Spend Diagnosis Across Meta, Google, and TikTokZero reports, impressions, conversions, and delivery failure for a frozen scope: an evidence-first decision tree.
Contact AdsInfra
Send a message about this resource before making a high-impact change.