TikTok Ads

TikTok Ad Account Access & Permissions

Least privilege, named owners, and clean offboarding beat shared logins every time.

Why permissions are a spend-risk issue

Most TikTok account chaos is not mysterious. It is over-permissioned partners, forgotten members, unclear admin ownership, and media buyers who inherited access through a personal login someone shared years ago. When something is limited or a vendor relationship ends, nobody can tell who still has control.

Good permission design does not make non-eligible offers compliant. It keeps operations auditable, reduces lockouts, and limits blast radius when a contractor or agency leaves.

Business Center roles vs advertiser access

Business Center roles govern organization-level capabilities: managing members, partners, and asset assignment. Advertiser / ad account permissions govern who can create campaigns, edit ads, or view performance inside a specific spend node.

People often conflate “I can open Ads Manager” with “I am an org admin.” Separate those needs. A media buyer may need campaign access without the ability to invite new partners. Finance may need billing visibility without creative edit rights. Match roles to jobs.

  • BC admin/owner capabilities are broader than campaign editing
  • Advertiser access should be scoped to the accounts someone actually runs
  • Reporting-only access is often enough for stakeholders who do not buy media

Partner access done correctly

When an agency needs to operate, invite them through Business Center partner or member flows that TikTok provides. Define which advertiser accounts they can use, what they can edit, and how long access should last.

Avoid building critical structure only inside a partner’s Business Center unless the contract and exit plan are explicit. If the agency owns the only BC that holds your pixel and ad account, offboarding becomes a commercial and technical project — not a toggle.

Security basics that prevent expensive mistakes

Never share personal TikTok, email, or device passwords with agencies, freelancers, or “account specialists.” Shared passwords destroy accountability, complicate recovery, and are unnecessary when Business Center invitations exist.

Use unique user identities for each person. Disable access when people leave. Prefer SSO or strong authentication practices where your organization supports them. Treat ad accounts like payment systems — because they spend money.

Revoking access cleanly

Revocation should be a checklist, not a memory exercise. When a campaign sprint ends or a vendor is replaced, remove their member or partner access, confirm they cannot open advertiser accounts, rotate any tokens or shared assets they touched, and record who remains admin.

If you cannot name the remaining Business Center admins in one sentence, fix that before you scale spend. Orphaned admin access is how teams lose accounts after staff turnover.

  • Remove partners and members the same week the engagement ends
  • Confirm advertiser-account roles after BC-level changes
  • Document remaining admins and finance owners
  • Re-check pixel/event permissions after partner removal

Permissions checklist for agencies and in-house teams

Use this before launch and again at quarterly review.

  • Named internal owner for Business Center admin
  • Agency access via official partner/member invites — never personal passwords
  • Least-privilege roles for buyers, creatives, and finance
  • Written offboarding steps in the SOW or internal runbook
  • Inventory of advertiser accounts each partner can still open
  • Tracking assets owned under a BC your team can still access after vendor changes