Meta Business Manager Agency Access: How to Structure Client Assets
A practical guide to client ownership, partner permissions, security, onboarding, API access, and agency offboarding in Meta Business Suite.
The safest way to give an agency access to Meta Business Manager is to keep every critical asset owned by the client’s business portfolio and grant the agency partner access only to the assets and permissions required for its work. This structure protects continuity, makes offboarding easier, and avoids placing business-critical accounts under an employee, freelancer, or agency-owned environment.
Meta now commonly uses the term business portfolio inside Meta Business Suite, although many teams still search for and use the familiar name Meta Business Manager. In this guide, both terms refer to the business-level environment used to organize people, partners, Pages, ad accounts, datasets, catalogs, apps, and related permissions.

What Is Meta Business Manager Agency Access?
Agency access is a permission relationship between two business portfolios. The client’s portfolio owns or controls the relevant business assets, while the agency’s portfolio is authorized to work with selected assets. Meta describes this as giving a partner access to business assets.
This is different from sharing a login, transferring ownership, or inviting every external contractor directly into the client’s portfolio. Partner access creates a cleaner boundary: the client decides what the agency can use, while the agency manages which of its own people work on the assigned assets.
According to Meta’s official guidance, a business can add a partner in Meta Business Suite and assign specific assets. Meta also distinguishes between full control and partial access. That distinction should be treated as an operational decision, not a convenience setting.
The Recommended Client–Agency Ownership Structure
A durable Meta Business Manager agency access structure separates four responsibilities:
- Business ownership: the client owns the portfolio, Page, ad account, dataset, domain, catalog, app, and other core assets whenever the platform supports that ownership model.
- Partner access: the agency is added using its business ID and receives access only to the assets covered by the engagement.
- People management: the client manages its internal people; the agency manages its staff inside the agency portfolio.
- Technical access: apps, system users, tokens, webhooks, and integrations are created for a documented business purpose and monitored separately from human access.
This model reduces dependency on a single person. If an employee leaves the agency, the agency can update its internal assignments without asking the client to rebuild the entire relationship. If the client changes agencies, partner access can be removed while asset ownership remains intact.
Ownership is not the same as visible access
A person may be able to open an ad account or Page without the client having a clean ownership record. During an audit, verify which business portfolio owns or controls each asset, not only whether someone can see it in the interface.
Build an Asset Inventory Before Granting Access
Start onboarding with an inventory. It should be detailed enough that another administrator can understand the environment without relying on memory or chat history.
| Asset | Record | Questions to answer |
|---|---|---|
| Business portfolio | Name, business ID, verified status, full-control users | Who controls the portfolio and who is the recovery contact? |
| Facebook Page and Instagram account | Asset ID, owner, connected account | Who publishes, moderates, and manages messages? |
| Ad account | Account ID, owner, currency, time zone, payment responsibility | Who creates campaigns, approves budgets, and pays invoices? |
| Dataset or Pixel | Dataset ID, connected domains, event sources | Who maintains browser and server events? |
| Catalog | Catalog ID, feed source, commerce connections | Who controls products, feed health, and permissions? |
| Domain | Domain name and verification method | Who controls DNS and can restore verification? |
| App and API integration | App ID, owning business, use case, permissions | Who maintains tokens, webhooks, reviews, and API versions? |
For every row, record the business owner, current administrators, business purpose, agency role, billing owner, technical dependencies, and offboarding action. Review the inventory whenever an asset or integration is added.
How to Add an Agency as a Partner in Meta Business Suite
The interface can change, but the current general path described by Meta is:
- Open Settings for the client’s business portfolio in Meta Business Suite.
- Under Users, open Partners.
- Select the option to add a partner and choose to give a partner access to business assets.
- Enter the agency’s business ID.
- Select only the assets included in the engagement.
- Choose the permissions required for each asset.
- Review the assignment with a second client administrator before confirming.
- Ask the agency to test access without requesting additional permissions unless a specific task fails.
Meta’s official help pages provide the live interface steps for giving a partner access to business assets and explain full control and partial access. Use those pages as the interface reference and use the client’s written access matrix as the approval reference.
A Practical Permission Matrix for Agencies
Permissions should follow responsibilities. The exact labels available can vary by asset and interface version, but the operational principle is stable.
| Agency role | Typical need | Usually unnecessary |
|---|---|---|
| Media buyer | Create and manage campaigns; view performance | Manage people, change business details, control unrelated assets |
| Creative or community team | Publish approved content or manage assigned conversations | Billing, datasets, apps, full portfolio control |
| Measurement specialist | View or configure assigned datasets and events | Page publishing or organization-wide administration |
| Developer | Work with the approved app, system user, webhook, or dataset | Ad account billing and unrelated social assets |
| Reporting analyst | Read performance data for assigned accounts | Publishing, payment methods, people management |
| Agency owner or operations lead | Manage agency-side staffing and escalation | Permanent client-wide full control by default |
Do not use full control as a shortcut. If the work can be completed with task-specific permissions, broader access creates risk without adding operational value.

Security Controls for Meta Business Partner Access
A correct asset structure still depends on account security. At minimum:
- Maintain at least two trusted client administrators with full control, where appropriate.
- Require strong, unique passwords and multi-factor authentication for people with access.
- Use named accounts instead of shared logins.
- Review people, partners, and asset assignments on a recurring schedule.
- Remove former employees and contractors promptly.
- Keep business verification and recovery information current.
- Document who can change payment methods, domains, apps, and system users.
- Export or record permission reviews when the platform provides that capability.
Meta publishes additional recommendations in its guide to business portfolio security best practices.
A Documented Agency Onboarding Workflow
A reliable onboarding process should be repeatable. Use the following sequence:
- Confirm identity and scope. Record the client portfolio ID, agency portfolio ID, legal or trading names, responsible contacts, and statement of work.
- Complete the asset inventory. Identify the assets that already exist, who owns them, and any missing dependencies.
- Create the permission matrix. Map each task to the minimum asset permission required.
- Approve access. Require approval from a client administrator before assignment.
- Test one asset at a time. Confirm that publishing, campaign, reporting, or technical tasks work as intended.
- Document the result. Record the access granted, date, approver, agency owner, and next review date.
- Monitor changes. Review new assets, staff changes, errors, and unexpected permission requests.
Plan offboarding during onboarding
Do not wait until a contract ends to decide what must be removed. Define the offboarding owner, notice process, handoff documents, token rotation, data export, campaign transition, and final access review in advance.

Agency offboarding checklist
- Remove the agency partner from assets that no longer require access.
- Review agency-linked individuals and confirm no direct access remains.
- Revoke or rotate tokens, system-user credentials, and webhook secrets where applicable.
- Transfer campaign documentation, naming conventions, audiences, creative records, and reporting notes.
- Confirm active campaigns, automated rules, billing, and scheduled reports have an owner.
- Remove obsolete CRM, lead, analytics, and file-sharing connections.
- Record the completion date and the client administrator who verified the final state.
Apps, System Users, and API Access
Human partner access and programmatic access are related but not identical. A developer working with the Marketing API, Graph API, Conversions API, or webhooks may also need an app, a system user, an access token, and specific asset assignments.
Meta defines a system user as a server or software entity that makes API calls to assets owned or managed by a business. System users should be created for a documented integration, assigned only the required assets, and monitored by someone who understands token lifecycle and API version changes. See Meta’s official system user documentation.
For each integration, document the app ID, app owner, business owner, system user, token custodian, requested permissions, data fields, webhook subscriptions, API version, error monitoring, and shutdown procedure. Do not place production secrets in public code, shared spreadsheets, or ordinary chat messages.
If measurement is part of the engagement, our guide to Pixel and Conversions API measurement explains event design, deduplication, privacy, testing, and monitoring.
Common Meta Business Manager Agency Access Mistakes
- The agency creates and owns the client’s ad account. This can complicate billing continuity, reporting history, and a future agency change.
- Business assets live under an individual’s personal setup. Personal accounts may be required to authenticate, but the business should still maintain documented organizational control.
- Everyone receives full control. Broad access increases the impact of mistakes and compromised accounts.
- External staff are added directly without a partner structure. The client then becomes responsible for managing every agency staffing change.
- System users and tokens are undocumented. An integration may continue operating after its owner leaves, with no clear way to rotate or revoke access.
- Billing responsibility is assumed rather than recorded. Campaign ownership and payment responsibility should be explicit before launch.
- Offboarding removes people but not integrations. Apps, tokens, CRM connections, shared files, and automated reports also require review.
Meta Business Access Audit Checklist
- Can the client identify its business portfolio ID and trusted full-control administrators?
- Does the client own or control each critical Page, ad account, dataset, domain, catalog, and app?
- Is the agency connected as a partner using the correct business ID?
- Does every assigned permission have a current business reason?
- Are billing, security, recovery, and technical responsibilities documented?
- Are people, partners, system users, and tokens reviewed regularly?
- Could the client remove the agency without losing ownership or access to historical assets?
- Is there a written handoff and offboarding procedure?
Frequently Asked Questions
Should an agency own a client’s Meta ad account?
For a long-term client-owned setup, the client should generally own or control its core ad account and grant the agency appropriate partner access. An agency-owned account can create dependencies when billing, data access, or the relationship changes.
What is the difference between partner access and adding a person?
Partner access connects one business portfolio to another. The agency can then manage its own team assignments. Adding a person directly makes the client responsible for that individual’s access and future removal.
Does an agency need full control?
Usually not. Full control should be limited to responsibilities that genuinely require portfolio-level administration. Campaign management, reporting, publishing, and technical implementation often work with narrower asset permissions.
Can one agency receive access to several client assets?
Yes. The client can assign multiple supported assets to the agency partner, but each assignment should follow the written scope and least-privilege principle.
What should be removed when an agency contract ends?
Review partner assignments, directly added people, system users, tokens, apps, webhooks, CRM connections, shared files, automated rules, reports, and billing responsibilities. Removing one visible partner entry may not remove every technical dependency.
How often should Meta business permissions be reviewed?
Review them whenever staff, agencies, integrations, or responsibilities change, and also on a recurring schedule. High-impact assets such as ad accounts, apps, datasets, domains, and payment settings deserve more frequent review.
Final Recommendation
A strong Meta Business Manager agency access structure is simple to explain: the client owns, the agency receives scoped partner access, people are managed by their own organizations, and technical credentials have named owners. If that model is documented before campaigns and integrations depend on it, the business can grow or change partners without losing control of its digital infrastructure.
Need help auditing a current setup? Contact Franklin OKOLI LLC with the business portfolio, asset types, and access problem you want to solve.