Inventory access across every route
Review direct ad-account roles, business portfolio assignments, partners, system users and connected applications. A clean people list can still hide broad partner or integration access granted through another business asset.
Map each permission to a current responsibility
Record who owns billing, campaign edits, reporting, asset administration and incident response. Meta distinguishes admin, advertiser and analyst capabilities; select the lowest role that supports the documented task.
- Named internal asset owner
- Role justified by current work
- Partner scope limited to required assets
- Connected tool owner and review date
Remove access without creating an ownership gap
Before removing an agency, employee or system user, verify billing, Page, dataset, domain and integration ownership. Transfer operational knowledge and recovery details so least privilege does not become accidental lockout.
Set event-driven and recurring reviews
Trigger reviews at onboarding, role change, offboarding, partner change and suspected incident, then add a recurring control. Store the reviewer, date, decision and exceptions rather than relying on a screenshot with no accountable follow-up.
Worked example
A former agency still has admin access although it no longer operates the account. The owner verifies current responsibilities, removes the obsolete role, confirms recovery ownership and records the review date without changing access needed by active operators.
Common mistakes
- Removing access before confirming who owns recovery and billing duties.
- Leaving broad admin roles in place because no incident has occurred yet.
Editorial next decisions
Use these guides only when their decision becomes the next unresolved constraint in your evidence trail.
- Meta Ads activity history: turn changes into an audit trail — use it to investigate and govern changes made in a meta ad account.
- Meta Ads automation levels: choose how much authority to delegate — use it to choose an appropriate level of automation for meta ads operations.
- Meta Ads automated rules: make the safe action explicit — use it to design safe automated rules for meta ads account operations.
Limitations
Meta interfaces and role models can change, and this operational checklist does not replace an organization’s identity, device, legal or incident-response security program.
Questions readers ask next
Should agencies receive ad account admin access?
Only when their responsibility requires administrative capabilities and the grant is documented. Many delivery tasks can use narrower permissions and partner asset scope.
Can team members share one Facebook login?
Meta states that account sharing and inauthentic profiles violate its rules. Assign individual access with the role required for each person’s work.
Sources checked
Primary documentation was checked on the date shown. Product interfaces and eligibility can change, so verify the current account state before acting.
- Add people to an ad accountMeta · verified August 12, 2026
- How to view activity history for adsMeta · verified August 12, 2026