Managing Advertising Permissions Across Multiple Platforms

Managing advertising permissions across multiple platforms is a critical responsibility for any business running paid media campaigns. Whether you are a marketing manager overseeing a team, an agency handling client accounts, or a business owner bringing in external help, understanding how to grant the right level of access-without compromising security-is essential.

This guide covers the major ad platforms-Meta (Facebook/Instagram), Google Ads, LinkedIn, TikTok, Pinterest, X (Twitter), and Snapchat-and explains how to manage users and permissions on each.

TL;DR

  • The principle of least privilege is the foundation of secure ad account management-grant only the permissions each team member needs to perform their role.
  • Each platform uses its own permission model: Meta has Business Suite with employee/partner access; Google Ads uses Admin, Standard, and Read-Only roles; LinkedIn has Billing Admin, Account Manager, Campaign Manager, Creative Manager, and Viewer.
  • Regular permission audits-quarterly reviews of who has access to what-are essential for maintaining security and compliance.
  • Agencies and partners should be added via their Business ID rather than sharing login credentials, which is both more secure and compliant with platform policies.
  • The creator of an ad account is typically the default admin on most platforms-this cannot always be changed without transferring ownership.

General Principles for Managing Ad Account Permissions

Before breaking down each platform, here are principles that apply across all ad platforms.

The Principle of Least Privilege

Grant only the permissions each team member needs to perform their role. A content creator does not need billing access. A campaign manager does not need to add or remove users. Over‑permissioning creates unnecessary security risk.

Use Platform‑Native User Management

Every major ad platform allows you to invite users by email and assign specific roles. Never share login credentials-this violates platform policies and creates security vulnerabilities. Use the platform’s built‑in user management tools instead.

Regular Audits

Schedule quarterly reviews of who has access to your ad accounts. Remove users who no longer need access. This is especially important when team members leave or when agency relationships end.

Distinguish Between Employees and Partners

Most platforms differentiate between internal team members (employees) and external collaborators (partners, agencies). Partners typically require a Business ID or similar identifier rather than an email invitation.

Meta Business Suite (Facebook & Instagram Ads)

Meta’s advertising ecosystem-covering Facebook, Instagram, and Messenger-is managed through Meta Business Suite (formerly Business Manager). This is the central hub for all ad accounts, Pages, Pixels, and other assets.

Understanding the Permission Model

Meta uses a two‑layer permission system:

  • Business‑level roles: Employee Access or Admin Access
  • Asset‑level permissions: For each ad account, Page, or Pixel, you define specific permissions

Business‑level roles:

  • Employee Access: Limited access to assigned assets only
  • Admin Access: Full control over the entire business account

Page permissions:

  • Full Control: The equivalent of the old Admin role-complete management
  • Content Control: Posting, messaging, and commenting

Ad account permissions:

  • Advertiser: Create and manage campaigns
  • Analyst: View‑only reporting

Legacy role mapping:

Legacy RoleNew Equivalent
AdminFull Control
EditorContent Control
ModeratorContent Control (limited)
AdvertiserAssigned at ad account level
AnalystAssigned at ad account level

How to Grant Access

For employees (internal team members) :

  1. Log in to Meta Business Suite and go to SettingsPeople
  2. Click Invite People and enter the person’s email address
  3. Choose their business‑level role: Employee Access or Admin Access
  4. Select the assets (ad accounts, Pages, Pixels) they need access to
  5. Define their permissions for each asset
  6. Click Send Invite

For partners (agencies, external collaborators) :

  1. In Business Settings, go to Partners under the Users tab
  2. Click Add and select Give a partner access to your assets
  3. Enter the partner’s Business ID
  4. Select the assets to share and set permissions
  5. Click Save Changes

Best Practices for Meta

  • Use task‑based permissions-grant only what is needed
  • Ad account owners and admins should have two‑factor authentication enabled
  • When sharing an ad account, provide the Ad Account ID (not the name) to avoid confusion
  • Regularly review the People list and remove former team members

Google Ads uses a straightforward permission model with five access levels. Only users with Admin access can add or remove other users.

Permission Levels

Access LevelWhat the User Can Do
AdminFull control: manage campaigns, add/remove users, access billing, change account settings
StandardModify campaigns, create ads, view reports-but cannot manage users or change account settings
Read‑OnlyView campaigns and performance data-cannot make any edits
Email‑OnlyReceives email notifications but has no direct account access
ExplorerA level for API developers with limited access

How to Grant Access

  1. Sign in to Google Ads with an account that has Admin access
  2. Click the Admin icon (gear symbol) in the top right
  3. Select Access and security
  4. Click the + button to add a new user
  5. Enter the user’s email address
  6. Select the access level (Admin, Standard, Read‑Only, etc.)
  7. Click Send invitation

Best Practices for Google Ads

  • Only the account owner or a designated Admin should manage user access
  • Use Standard access for day‑to‑day campaign managers-they do not need Admin rights
  • Grant Read‑Only access to stakeholders who only need to review performance
  • The Admin level is the “master key”-limit it to as few people as possible

LinkedIn Campaign Manager

LinkedIn’s ad platform uses Campaign Manager for ad account management. If an ad account has been added to LinkedIn Business Manager, user access must be managed through Business Manager instead.

User Roles and Permissions

LinkedIn Campaign Manager offers five user roles:

RoleCampaign CreationAd ManagementBilling AccessUser Management
Billing AdminyesyesFull controlyes
Account ManageryesyesView onlyyes
Campaign Manageryesyesnono
Creative Managernoyes (creatives only)nono
Viewernononono

Key restrictions:

  • You can only add 1st, 2nd, or 3rd‑degree connections
  • The person who creates the ad account is automatically the Billing Admin
  • Each ad account must have at least one Billing Admin

How to Grant Access

  1. Go to Campaign Manager and select your ad account
  2. Click Account settings in the left menu
  3. Click Manage access
  4. Click Add user
  5. Enter the person’s name or LinkedIn profile URL
  6. Select their role from the dropdown
  7. Click Send invitation

Best Practices for LinkedIn

  • Assign the Billing Admin role to the person responsible for payments-only one person should hold this for security
  • Use Campaign Manager for day‑to‑day campaign operations
  • Viewer access is ideal for executives who need to monitor performance without making changes
  • If using Business Manager, manage all access through Business Manager, not Campaign Manager

TikTok Business Center

TikTok uses Business Center as its central management hub. Permissions are split into Basic and Advanced roles.

Basic Roles

RolePermissions
AdminFull access to all system functions. Can add/remove members, partners, create ad accounts, and manage all assets
StandardCan work on assigned accounts and assets only. Cannot add/remove users or create new ad accounts

Ad account access levels (assignable by Admin members):

ActionAdminOperatorAnalyst
View ads and performanceYesYesYes
Access reportsYesYesYes
Create and edit adsYesYesNo
Manage AudiencesYesYesNo
Manage financeYesYesNo
Manage ad account settingsYesNoNo

Advanced Roles

Advanced roles are assigned on top of Admin access and provide additional financial permissions:

  • Finance Manager: Can view and manage balances, create/edit billing groups, and pay invoices
  • Finance Analyst: Can view transaction history and download invoices but cannot make changes

How to Grant Access

  1. Log in to TikTok Business Center
  2. Navigate to the Users section
  3. Click Add member and enter their email
  4. Select their role (Admin or Standard)
  5. Assign them to specific ad accounts and assets
  6. Optionally, add an Advanced role (Finance Manager or Analyst) if needed

Best Practices for TikTok

  • Assign Admin roles sparingly-they have full system access
  • Use Standard for most team members, granting access only to the ad accounts they need
  • For finance teams, assign Finance Analyst for view‑only access and Finance Manager for those who need to manage payments

Pinterest Business Manager

Pinterest uses Business Manager to manage ad accounts, profiles, and catalogues. It offers seven ad account permission levels.

Ad Account Permission Levels

Permission LevelCampaign ManagementBillingReportingAudiencesCatalogues
AdminyesFull controlyesyesyes
AnalystyesRead‑onlyyesyesyes
AudiencenononoCreate/editno
Finance (edit)noFull controlyesnono
Finance (read)noRead‑onlyyesnono
CampaignCreate/editnoyesnono
Cataloguesnonononoyes

How to Grant Access

  1. In Pinterest Business Manager, go to Employees or Partners
  2. Click Add and enter the person’s email (they need a Pinterest Business account)
  3. Select the ad accounts to assign
  4. Choose the permission level for each ad account
  5. Click Assign

Best Practices for Pinterest

  • Use Admin for full account management
  • Analyst is ideal for team members who need campaign access without billing permissions
  • Campaign is suitable for those who only create and manage campaigns
  • Audience is a specialist role for audience managers
  • Catalogue permissions are separate-assign Catalogue Admin or Catalogue Ad Creator as needed

X (Twitter) Ads

X (formerly Twitter) – X Ads Manager, offers multi‑user login functionality, allowing you to grant different levels of access without sharing passwords.

Access Levels

There are five access levels:

LevelPermissions
Account AdministratorFull access to ads.x.com. Can create new admins/managers, edit access, modify campaigns, view performance data, and access billing information
Ad ManagerAccess ads.x.com. Can modify campaigns and view performance data. Cannot manage other users
Creative ManagerAccess ads.x.com. Can modify creatives and view previews. Cannot create or modify campaigns
Campaign AnalystAccess ads.x.com. Can view performance data. Cannot create or modify campaigns
Organic AnalystView‑only access to organic content data

How to Grant Access

  1. Log in to X with an Account Administrator account-this is required to manage users
  2. Go to SettingsUsers
  3. Enter the person’s X username (@name)
  4. Select the access level
  5. Click Save changes

Best Practices for X

  • The creator of the ad account is automatically the Account Administrator
  • Use Ad Manager for most team members who run campaigns
  • Creative Manager is suitable for designers who only need to manage ad creatives
  • Campaign Analyst is ideal for reporting and analytics roles

Snapchat Ads Manager

Snapchat Ads Manager offers several member roles that can be assigned at the organization or ad account level.

User Roles and Permissions

RoleManage Ad Account DetailsManage Advertising CollateralUpload/Manage AudiencesView PerformanceCreate/View Creatives
Account Adminyesyesyesyesyes
Agency Memberyes (limited)yesyesyesyes
Campaign Managernoyesyesyesyes
Data Managernonoyesnono
Data Analystnononoyesno
Creative Managernoyesnonoyes

How to Grant Access

  1. Log in to Snapchat Ads Manager with an Organization Admin account
  2. Navigate to BusinessMembers and select the user
  3. Assign the appropriate role
  4. Optionally, grant access to all ad accounts and catalogues

Best Practices for Snapchat

  • Assign Account Admin only to those who need full control of the ad account
  • Campaign Manager is the primary role for day‑to‑day campaign management
  • Use Data Manager and Data Analyst for audience and reporting specialists
  • Creative Manager is ideal for design team members

Summary: Permission Models at a Glance

PlatformCentral HubKey RolesPartner Access Method
MetaBusiness SuiteAdmin, EmployeeBusiness ID
Google AdsGoogle Ads interfaceAdmin, Standard, Read‑OnlyEmail invitation
LinkedInCampaign Manager / Business ManagerBilling Admin, Account Manager, Campaign Manager, Creative Manager, Viewer1st–3rd degree connection + role
TikTokBusiness CenterAdmin, Standard, Finance Manager, Finance AnalystEmail invitation
PinterestBusiness ManagerAdmin, Analyst, Audience, Finance, Campaign, CataloguesEmail invitation (requires Pinterest Business account)
X (Twitter)Ads ManagerAccount Administrator, Ad Manager, Creative Manager, Campaign AnalystX username
SnapchatAds ManagerAccount Admin, Agency Member, Campaign Manager, Data Manager, Data Analyst, Creative ManagerEmail invitation

Key Takeaways

  • Never share passwords. Every major ad platform supports individual user accounts with role‑based permissions. Use these features.
  • Apply the principle of least privilege. Grant only the permissions each person needs. Over‑permissioning creates unnecessary security risk.
  • Conduct regular audits. Review who has access to your ad accounts at least once a quarter. Remove former employees and inactive partners.
  • Separate internal and partner access. Most platforms have specific workflows for adding employees versus agencies or external partners. Use the correct method.
  • Understand the default admin. On most platforms, the person who creates the ad account is automatically the primary admin. Ensure this is the right person.
  • Document your permission structure. Maintain a clear record of who has what access across all platforms. This is essential for security audits and onboarding/offboarding.
  • Use Business Manager / Business Center where available. Centralized management tools (Meta Business Suite, TikTok Business Center, LinkedIn Business Manager) provide better control than per‑account management.

Conclusion

Managing ad account permissions across multiple platforms is a core operational responsibility for any business running paid media. Each platform has its own permission model, but the underlying principles are consistent: grant the minimum access required, use platform‑native user management rather than shared credentials, and audit permissions regularly.

The cost of a permission mistake-whether a data breach, unauthorised spend, or a campaign accidentally paused-can be significant. Investing time in setting up permissions correctly is far cheaper than dealing with the consequences of getting it wrong.

Start by auditing your current permissions on each platform. Remove users who no longer need access. Then, document your permission structure and establish a regular review cadence. Your ad accounts-and your budget-will thank you.

Need help managing your ad accounts? Playful Sparkle has been engineering digital products since 2004, offering SEO & Digital Marketing, Web Development, and App Development services. Our team can help you set up and manage advertising permissions across all major platforms. Contact us to discuss how we can help you secure and streamline your ad operations.

Was this helpful - Post
Zsolt Oroszlány

Zsolt Oroszlány

Founder & Chief Creative Officer of Playful Sparkle since 2004, combining business leadership, digital strategy, design, and software engineering to help organizations build effective digital solutions. Regularly publishes insights on web development, SEO, design, and emerging technologies.