Ad account sharing and access risk: security
Old agency access or shared passwords put accounts at risk.

Former agency still admin, intern shared password, no 2FA — account takeover or accidental campaign delete risk. Google MCC and Meta Business Manager role discipline is mandatory. Account security is critical on agency transition.
Role hierarchy
Google: Admin only business owner. Agency Standard or Read-only + Editor at campaign level. Billing admin separate.
Meta: Business Admin with client; agency Partner access at campaign level.
- Admin = owner
- Agency Standard max
- Billing separate
- 2FA mandatory
2FA and SSO
Two-factor on all admin accounts. Agency staff personal 2FA, no shared accounts.
Google Workspace or Microsoft SSO on corporate accounts.
Agency transition
Exit checklist: remove old agency users, revoke tokens, delete API keys. Ownership to client email.
Report trust starts with access model.
Shared password risk
Password sharing breaks audit log — unknown who deleted. Each user separate email.
Kass Agency uses partner access; never asks for password.
Suspension link
Suspicious activity can trigger Google suspension. Clean access after account suspension.
User causing policy violations risks account.
Regular audit
Quarterly user list review. Delete 90-day inactive users.
Export users from Meta Business Settings and Google Admin.
Account security matters as much as ad performance.
Secure account setup in ADS onboarding. Contact us.


