top of page

Marketing account access management: own what you pay for

  • Aug 22
  • 3 min read

Updated: 2 days ago

Introduction


Access management sounds like an IT concern. It is actually the single thing that determines whether your marketing is an asset you own or an arrangement you rent.

The distinction is invisible while everyone gets along, and total when they do not.


1. Marketing account access management: access is not ownership


Being able to log in is not the same as owning the thing.

If your ad account sits inside an agency's business manager, they can remove your access. If the analytics property was created under a contractor's login, the history goes with them. If the domain is registered to whoever built the site, renewal is not in your hands.

The test is administrative, not emotional: could you remove everyone else's access and retain your own? If not, you have access.


2. Create accounts in your name first, then grant access


The correct order matters and is almost always reversed.

Create the account under a business email you control, verify you are the owner or admin, then invite whoever needs to work in it at the level they need. Someone else creating it and adding you later leaves ownership where it started.

This costs nothing at the outset and is difficult to unwind afterwards, which is why it should be settled before work begins rather than at handover.


3. Use a business email nobody personally owns


Accounts tied to an individual's address leave when that individual does — and recovery emails go somewhere you cannot read.

Use a role address, controlled by the business and accessible to more than one person. The same applies to phone-based two-factor: a code going to a departed employee's phone locks you out of your own account, and platforms are unsympathetic.


4. Grant the least access that works


Not everyone needs admin. Most tools distinguish between viewing, editing and managing users, and the last one is what actually matters.

Keep the number of people who can change ownership or remove others to the smallest possible set — ideally the owner and one other, so nobody is a single point of failure. Everyone else gets whatever level lets them do their job.


5. Keep one record of what exists


A short sheet, one row per account: what it is, whose name it is in, which email recovers it, who currently has access, and at what level.

That record is the difference between a ten-minute offboarding and a week of archaeology. It also answers the question that reliably arrives at the worst moment — "who has access to the ad account?" — without anyone guessing.

Store it somewhere more than one person can reach.


6. Offboard deliberately


When a contractor, agency or employee leaves, work through the sheet rather than relying on memory.

Remove their access, change any shared passwords they knew, confirm nothing was left registered to their personal address, and export anything that lives only in a tool you might stop using.

Do it while the relationship is still cordial. Requests made after a bad ending are answered slowly or not at all.


7. Check before you need to


The audit takes an afternoon and is worth doing now rather than in a crisis. Eight things: domain, website and hosting, Business Profile, ad accounts, analytics, customer list, creative files, social accounts.

For each, establish whose name it is in and who can remove whom. Fix the domain first — losing it takes your email and website together — then the customer list, which is the one thing that cannot be rebuilt.


8. Put it in writing with suppliers


Any engagement should say, in the agreement, that accounts are created in your name, that access is granted rather than ownership transferred, and that everything produced becomes yours at final payment.

A capable supplier will be entirely comfortable with that. Reluctance is informative, and it is much cheaper to learn at the proposal stage than at the end.


Conclusion


Access is not ownership: the test is whether you could remove everyone else and keep yourself.

Create accounts in your own name under a role email nobody personally owns, grant the least access that works, keep one sheet recording every account and who holds what, offboard deliberately while relationships are good, audit the eight critical assets now, and put the arrangement in writing before work starts.


Related reading


 
 
 

Comments


bottom of page