Why permissions fail before ads do
Many Meta advertising failures that look like “account problems” start as people problems: too many admins, departed freelancers still holding roles, partners with wider access than the scope requires, or a single admin who is unavailable when a restriction notice appears. Business Manager permissions decide who can act when something breaks.
Safe agency access means using Meta’s role and partner invitation flows — never personal Facebook passwords — with a written map of which assets the partner needs and for how long. That discipline applies whether you use self-serve accounts or agency-provisioned spend nodes.
People roles vs partner business access
Inside a Business Manager, people are assigned roles (such as admin or employee-level access patterns Meta currently exposes) and then given permission on specific assets: ad accounts, Pages, catalogs, datasets. Admins can typically manage people and assets; narrower roles should be preferred for day-to-day media buyers when your process allows it.
Partner business access connects another Business Manager to yours so their people can work on shared assets without becoming employees of your BM. This is usually the cleaner model for agencies and freelancers: access is scoped, revocable, and auditable at the business level. Confirm whether you are partnering into their BM, they are partnering into yours, or both — blast radius differs.
Page-level roles can also sit outside the BM story. Inventory Page access separately so advertising is not blocked by a personal profile that “owns” the Page while the BM looks healthy.
- Prefer partner BM access for external agencies over adding many personal profiles as full admins
- Scope asset permissions to what the engagement needs — not “admin on everything” by default
- Keep at least two trusted internal admins so one vacation or departure does not strand the BM
- Review finance and payment permissions separately from creative/media roles
What agencies actually need
A media partner typically needs access to the ad accounts they will operate, the Pages or Instagram accounts used in ads, and the Dataset/Pixel required for optimization — plus enough Business Manager visibility to troubleshoot delivery. They rarely need your personal profile password, unrestricted admin on unrelated brands, or ownership transfer of your primary domain by default.
Ask for a permission request in writing: assets, role level, duration, and whether they need finance access. Decline password sharing every time. If a vendor cannot work through Business Manager invites, that is a process failure on their side, not a reason to weaken security.
When the agency provisions the spend node on their BM, you still need clarity: your role on that account, whether you can export history, who owns creatives and audiences, and how access ends. Permissions are bidirectional risk — they can see your performance data; you may depend on their admins during an incident.
Least-privilege workflow for onboarding and offboarding
Onboard in order: define scope → send partner or user invite → grant asset-level permissions → confirm two-factor practices for critical admins → launch. Do not grant broad admin “temporarily” and forget it. Temporary access without a calendar reminder becomes permanent risk.
Offboard the same week a contract ends: remove partner access, revoke people roles, rotate CAPI tokens if the partner held them, and confirm Dataset and Page ownership remain with your team. Document what they can still see in email or shared drives — Meta permissions are only one surface.
Quarterly access reviews catch drift: old contractors, unused partners, and duplicate personal logins mixed into business assets. Messy permissions make Business Manager restrictions harder to diagnose and recover from because nobody is sure who can still act.
Permissions during restrictions and audits
When an ad account, Page, or Business Manager is limited, your first operational question is whether someone with real control can still open Business Settings and act. If the only admin is a former contractor, recovery options shrink before any appeal is drafted.
A Meta account health audit often starts with a permissions map for that reason. Fixing access hygiene does not guarantee restoration under Meta’s systems — but it preserves the ability to appeal, remediate, or migrate measurement deliberately instead of in a panic.
Red flags
Walk away from access patterns that increase long-term risk even if they feel faster at kickoff.
- Requests for personal Facebook passwords or authenticator codes
- Pressure to add the partner as sole admin on your only Business Manager
- Unclear ownership of Pages, domains, or Datasets after “setup”
- Refusal to use partner invites or to document what access is needed
- Claims that special permissions create policy immunity or unofficial Meta partnership status