As a Meta ad account grows past a single media buyer, access control stops being an afterthought and becomes an operational risk surface. Who can edit budgets, who can see billing, who can publish creative, and who can be removed cleanly when a contractor's engagement ends -- these decisions determine whether a $100k/month account runs smoothly or becomes a liability. This guide covers how Business Manager permissions actually work and how to structure roles for agency and in-house teams operating at scale.
How Business Manager access actually works
Meta Business Manager (now often referred to under the Meta Business Suite/Business Portfolio umbrella) separates access into a few distinct layers: Business Portfolio-level roles (Admin, Employee), asset-level access (which specific ad accounts, Pages, pixels, or catalogs a person or partner can touch), and task-level permissions within each asset (manage campaigns, view performance, manage billing, moderate comments, etc.).
This layered model exists so an agency can be granted access to run ads on a specific ad account without ever seeing the client's other assets, and so a single employee can have campaign-editing rights on one account and only reporting-view rights on another. Agencies working with multiple ad accounts, as with shared agency accounts used to reach $100k+/month thresholds, should treat this granularity as a control mechanism, not a bureaucratic hurdle.
Core roles and what they should map to
There is no single official role name for every function, but in practice most agency teams converge on the same functional tiers regardless of exact Meta terminology, because the underlying task permissions are the same set of checkboxes.
- Admin / Owner -- full control including adding/removing people, billing, and asset settings; reserved for account leads and agency ops, never junior media buyers
- Media Buyer / Campaign Manager -- can create, edit, and publish campaigns, ad sets, and ads; cannot alter billing or remove team members
- Analyst / Reporting -- read-only access to Ads Manager and Events Manager; used for finance, clients who want visibility without edit risk, and QA reviewers
- Creative / Community Manager -- Page-level access to publish organic content and respond to comments/messages, often without any ads-manager campaign access at all
- Developer / Pixel Manager -- access scoped to Events Manager, CAPI settings, and the pixel/dataset only, without campaign-editing rights
Partner access vs. employee access
A critical distinction for agencies: assigning a person directly to an ad account (employee access) is different from assigning an entire partner Business Portfolio to an asset (partner access, via Business Manager ID sharing). Partner access is how most agency-shared-ad-account arrangements work -- the agency's Business Portfolio is granted access to run within the client's Business Manager, and the agency then manages its own internal team roster without the client needing to individually approve each media buyer.
This is the model used when unlimited agency ad accounts are shared into a client's own Business Manager: the client sees one partner relationship rather than a rotating list of individual names, while the agency retains full internal flexibility to staff accounts as needed.
Offboarding: the part everyone forgets
The most common access failure in agency setups isn't over-permissioning on day one -- it's under-cleaning on exit. A media buyer who leaves the agency, a freelancer whose contract ends, or a client-side employee who changes roles should be removed from every asset the same week, not discovered six months later during a security review.
Maintain a simple access log (a shared sheet is sufficient at most scales) listing every person or partner with access to each ad account, the date granted, the role, and the reason. Review it monthly for any account spending above $20k/month, and immediately upon any personnel change. This single habit prevents the two most common incidents: a departed employee with lingering billing visibility, and an ad account with five 'temporary' admins nobody remembers granting.
Two-factor authentication and account security hygiene
Every person with Admin-level access to a Business Portfolio should have two-factor authentication enforced, not just recommended. Meta allows Business Portfolio-level 2FA requirements to be turned on for all people with access, which is worth enabling on any account managing significant spend. Compromised admin credentials on a high-spend account are a fast path to unauthorized campaign creation, budget changes, or asset theft.
Beyond 2FA, avoid shared logins entirely. Every login being tied to an individual, verified person is what makes an access log meaningful -- shared credentials make audit trails useless and violate the principle that access should be traceable to a specific accountable person.
Structuring access as accounts scale
As spend and account count grow, the temptation is to keep granting Admin access because it's the path of least resistance when someone asks for 'just a quick fix.' Resist this. A team running $100k+/month across multiple ad accounts should have a documented default: new media buyers start at Campaign Manager level, Admin is granted only to leads, and any access change requires a one-line written reason logged somewhere durable.
Power Ads structures partner-level access on every agency ad account it shares into a client's Business Manager, so clients retain full visibility and control over their own Business Manager while the agency manages internal team access on its side.
Key takeaways
- Business Manager separates portfolio-level, asset-level, and task-level permissions -- use all three layers rather than defaulting everyone to Admin
- Map real functional roles (media buyer, analyst, creative, developer) to the specific task permissions each actually needs
- Partner access (Business Portfolio to Business Portfolio) is how agency-shared ad accounts typically work, keeping client-side administration simple
- Offboarding departed staff and expired contractors is the most commonly neglected part of access control -- review monthly
- Enforce two-factor authentication for all Admin-level users and avoid shared logins entirely
FAQ
Can a client revoke agency access at any time?
Yes. Whoever controls the client's Business Portfolio can remove a partner's access at any time, which is one reason clients should always confirm they retain Admin-level control of their own Business Manager in any agency arrangement.
Should freelancers get direct ad account access or should everything route through a partner Business Portfolio?
For anything beyond a one-off task, route freelancers through a partner Business Portfolio or a dedicated agency-side Business Manager rather than granting direct personal access to a client asset -- it makes offboarding a single click instead of a manual hunt.
How many Admins should a single ad account realistically have?
Most well-run accounts, even large ones, keep Admin count in the low single digits. Everyone else should be scoped to the narrowest role that lets them do their job.
