top of page

Credential management for marketing accounts you must own

  • Aug 22
  • 4 min read

Updated: 3 days ago

Introduction


The most expensive marketing problem a small business can have is not a failed campaign. It is discovering that the advertising account, the domain or the review profile belongs to somebody who has left.

Recovering an account you do not administer ranges from tedious to impossible, and it tends to be discovered at the worst moment.


1. Credential management for marketing starts with an inventory


You cannot secure or transfer what nobody has listed.

Write down every account: domain registrar, hosting, website admin, email sending tool, each advertising platform, each social profile, the business listing, review platforms, analytics, the design tool, the scheduling tool, the phone system.

For each, record who administers it, which email address it is registered to, and who has access. Most businesses find at least two accounts nobody could confidently log into.


2. Register everything to a business address, not a personal one


The single most important rule, and the one most often broken at the beginning.

Every account should be tied to an email address the business controls, such as a generic administrative address, not to an individual's personal account or a departed employee's work address.

This matters because account recovery runs through the registered email. If that address is outside your control, so is the account, regardless of who pays for it.


3. Understand the difference between access and ownership


Being able to log in is not the same as being the owner, and the distinction is where agencies and freelancers cause accidental damage.

On most advertising platforms, ownership sits with whoever holds the administrator or manager account. If an agency created your ad account inside their own structure, you may have full working access and no ability to take it with you.

Check, before an engagement rather than at the end: is this account owned by us, with the supplier granted access, or owned by them?


4. Grant individual access, never shared logins


Shared credentials cause three problems: you cannot tell who did what, you cannot revoke one person's access without changing it for everyone, and the password gets circulated far beyond the intended group.

Every significant platform supports adding users with their own logins and defined permission levels. Use it, even for a team of two.

Where a platform genuinely has no multi-user support, that account belongs in a password manager with access controlled there.


5. Use a password manager, and stop sending credentials in messages


Passwords sent by email or chat persist in searchable archives indefinitely, including archives you do not control.

A shared password manager with a business-owned account solves this properly: credentials are shared by reference rather than by copy, access can be withdrawn, and the record of who has what is centralised.

The cost is trivial relative to the exposure. This is also where any account without multi-user support should live.


6. Turn on two-factor authentication, and think about the second factor


Two-factor protection is now standard and it creates a specific transfer problem: the codes go to somebody's phone.

Prefer an authenticator whose codes can be shared through the password manager, or a business phone number rather than a personal one. Store recovery codes in the password manager as well.

The failure to plan for is not an attacker. It is an employee leaving with the only device that can approve a login.


7. Offboard access the same day


When anyone leaves — employee, freelancer, agency — access removal should be a same-day checklist, not an intention.

Work through the inventory: remove their user account, change any shared credentials they knew, remove them from the password manager, revoke any connected app authorisations, and confirm the registered email on each account is still yours.

Connected authorisations are the item most often missed. A tool someone linked years ago may retain access long after their login is gone.


8. Review access quarterly


Permissions accumulate. People gain access for one project and keep it for years; suppliers you no longer use remain listed as administrators.

Once a quarter, open each significant platform's user list and remove anyone who should not be there. Confirm the administrator is still an appropriate person, and confirm the registered email address.

Fifteen minutes per quarter. It is also the point at which you discover the account nobody has looked at since the person who set it up moved on.


Conclusion


Inventory every account with its administrator and registered address, tie everything to a business-controlled email, and confirm you own rather than merely access the important platforms.

Grant individual logins instead of sharing passwords, keep credentials and recovery codes in a shared password manager, plan for two-factor devices leaving with people, offboard access the same day, and audit every user list quarterly.


Related reading


 
 
 

Comments


bottom of page