Facebook Ad Account Access - Agency Setup and Permissions
The short answer
To work on a client's Facebook ad account, the client keeps ownership and adds your agency's business portfolio as a Partner, then shares the ad account with you at advertiser level. Ask for admin only if you are handling billing. If the ad account does not exist yet, the client creates it inside their own business portfolio, not yours.
That is the whole recommendation. The rest of this page is how to do each part, and what breaks if you get it wrong.
First, get the naming straight
Meta has renamed most of this at least once, which is why guides disagree with each other.
- Business Manager is now the business portfolio, and it lives inside Meta Business Suite.
- The old asset permission labels, Standard access and Admin access, have been replaced by Full control and Partial access.
- Old Facebook Page roles (Admin, Editor, Moderator) have been replaced by a Page Access model.
- The ad account itself is a separate object from the Page and from the portfolio. Access to one is not access to the others.
Menu wording inside Business Suite changes fairly often. Where a click path below does not match what you see, look for the equivalent outcome rather than the exact label.
The portfolio is the container everything else hangs off, so it is worth being precise about what it holds and who owns each item. Our breakdown of the Meta business portfolio walks through that structure before you start granting anything.
Creating a Facebook ad account (and whose portfolio it goes in)
If you are searching how to create an fb ad account, the sequence matters more than the clicks. Whichever business portfolio creates an ad account owns it, and Meta publishes no self-serve way to hand an ad account from one business to another. So the order is:
- The client creates the business portfolio, at business.facebook.com, under their own identity and business details. Logging in with a personal Facebook profile only verifies who they are; it does not put the assets on that profile.
- The client connects their Facebook Page to that portfolio. A connected Page is required before ads can run.
- The client creates the ad account inside their portfolio, from Business Suite settings. Currency and time zone are chosen here. Menu labels on this screen move around more than most, so follow the outcome rather than hunting for an exact button name.
- The client adds the payment method. Their card, their invoices, their spending limits.
- Only then does your agency get added as a partner.
Two things to get right at step 3, because neither is reversible:
- Currency is effectively permanent. Meta's own documentation says changing an ad account's currency closes the account and stops its ads, with a new account created in its place. You lose the account's history along the way.
- Time zone is as permanent as currency. Meta's documentation says changing an ad account's time zone closes the existing account and creates a new one, so ads stop and history stays behind. New accounts default to Pacific time. Set it at creation if the client reports in London or Sydney.
There is also a cap on how many ad accounts a portfolio can hold. Meta does not publish one universal number. Portfolios typically start with a very small allowance, often a single ad account, and it rises as the portfolio builds spend history. Check the current limit on Meta's help pages before planning a multi-account structure.
Getting access to an existing ad account
There are two directions. Pick based on how confident the client is in Business Suite.
Direction A: the client shares assets with you
The client needs full control of their own portfolio. All you send them is your agency's business portfolio ID. That is a number, not a credential, and it is the entire handshake.
- Client opens Meta Business Suite, then Settings.
- Under Users, click Partners.
- Click Add.
- Choose Give a partner access to your assets.
- Enter your agency's business portfolio ID, then Next.
- Select the assets to share, the ad account, the Page, datasets, catalogues, and set the access level on each.
- Click Assign assets.
They can confirm it worked by clicking your agency in the Partners list and opening the Assets you shared tab.
Meta's own copy on that dialog is the best reassurance you will find for a nervous client: the assets remain in their portfolio, and partners can only work on tasks the client assigns. Quote it to them.
Direction B: you request the assets
Use this when the client will not navigate Business settings unaided. You do the work; they only approve.
- In your own portfolio: Settings, then Partners, then Add.
- Choose Ask a partner to assign you their assets.
- Review the information and click Get started.
- Enter the client's email address and their business portfolio ID. Both are required. This catches people out, because Direction A only needs the ID.
- Select the roles for both businesses, then Next.
- Choose the asset types and permission levels, then Next.
- Review, then Send request.
An admin on the client side has to approve it. Nothing is granted unilaterally.
Once the ad account is shared with your portfolio, you assign your own staff to it from inside your own portfolio. That single habit is what makes offboarding a staff member a one-click job on your side, instead of an email to every client.
Which permission level to ask for
Ad account roles are three:
| Role | What it can do | When to ask for it |
|---|---|---|
| Admin | Create, edit and view ads, access reports, edit payment methods, manage permissions | Only when you genuinely own billing or user management on the account |
| Advertiser | See and edit ads, run them on the account's existing payment method | The right default for almost every media buyer |
| Analyst | View ads and reporting | Audits, pitches, reporting-only retainers |
Advertiser is the correct default. It gives full campaign control and no access to the payment method. Clients who push back on admin are pushing back on exactly the right thing, and the honest answer is that you do not need it.
Finance access is a separate option covering transactions, invoices, account spend and payment methods. Leave it with the client unless you are fronting the ad spend yourself.
For the Page, ask for partial access, business tools only. That works through Business Suite and Ads Manager, which covers media buying. Be aware of the limit before you promise organic work on the same grant: Page partial access (business tools only) works through Business Suite and Ads Manager but cannot switch into the Page on Facebook, so it is not enough if you also do organic posting. The step-up for that is partial access (business tools and Facebook), which can switch into the Page and is still not full control. Full control of a Page should stay with the client, because an agency with full control of a Page can lock the client out of it. That is not a hypothetical you want on your side of the table.
If part of the brief involves running ads on content posted from a creator's or the client's own handle, that sits on a separate permission track from everything above. Our guide to setting up Meta partnership ads permissions covers how those approvals work.
At the portfolio level, nobody from your agency needs full control of the client's portfolio. Ever.
What goes wrong
The client has a personal ad account, not a business one. A personal ad account sitting outside any business portfolio has no partner-sharing mechanism at all. The fix is not shared credentials, and it is not starting from zero either. An individually-owned ad account can be claimed into the client's own new portfolio, which keeps the same account rather than starting a new one. Confirm what carries over with Meta before you promise a client their history is safe. Claiming is one-way, so it must be claimed into the client's portfolio, never yours.
Someone tries to add you directly to the ad account. Meta requires that the person being added has an active Facebook account and is a Facebook friend of the person adding them. Your senior buyer is not going to be Facebook friends with the client's finance director. This is on its own a good reason to use partner access.
Two-factor enforcement lands overnight. Enforcement is set at portfolio level, only people with full control can change it, and it applies immediately. Turn 2FA on for every agency account before a client enforces it, and before you connect any integration, or your API calls start failing with errors nobody can trace.
Old access nobody remembers. People who could manage a Page before it was added to a portfolio can still manage it afterwards. The portfolio is not the full list. Audit Page Access during onboarding and clear out the former employee and the cousin who set the Page up in 2014.
Access is granted but not live. Granting Facebook access requires the granter to enter their own password, and the recipient to accept an emailed invitation. Until they accept, nothing works. Check, do not assume.
If the account is restricted or disabled rather than just inaccessible, that is a different problem with its own appeals process. No amount of permission work will fix it, and the client has to run the appeal from the account that owns the asset.
The traps that only appear at the end
Partner access is permission, not ownership, and you keep none of it. The moment a client revokes, you lose the Page, the ad account and its entire campaign history, pixel and dataset access, catalogues, the Instagram inbox, and every custom audience that was shared. All at once.
Two habits make that survivable:
- Export reporting on a schedule into your own storage rather than relying on Ads Manager still being there.
- Keep creative, copy and campaign structure in your own systems, not only inside the client's account.
And the mirror image, which is worse: if you created the client's ad account inside your portfolio, they cannot cleanly take it with them. There is no transfer flow. They either abandon their own ad history or stay dependent on an agency they have already left. That conversation costs you referrals for years.
There is also a tool almost nobody uses. Meta Business Suite can grant temporary basic access for a minimum of three days and a maximum of 75, after which access is revoked automatically and the person is removed. For audits, pitches and freelance cover, that is exactly the right instrument.
Where this fits in the wider onboarding
Ad account access is one row in a much longer list. Most agencies also need the Page, the Instagram account, the dataset or pixel, GA4, Google Ads and Search Console, and the same ownership logic applies to all of them. Our full client account access guide for agencies covers thirteen platforms in both directions.
Once the access is in place, the day-to-day problem changes shape: several clients, several inboxes, several logins. Inflowave is an agency CRM built for that, with one inbox across Instagram, Facebook, WhatsApp, SMS, email and voice, an isolated workspace per client, role-based permissions for your team, pipelines and white-label dashboards. Plans start at $27 a month, with the agency plan at $149.
FAQ
Do I need a Facebook Page to create an ad account?
Not to create one, but yes to use it. You can create the ad account inside the portfolio first; a Page connected to that portfolio is required before ads can actually run, because ads run from a Page identity. In practice, connect the Page first so nothing blocks launch.
Can I transfer an ad account from my agency's portfolio to my client's?
Meta publishes no self-serve ownership transfer for ad accounts or Pages. Create assets in the client's portfolio from the start and share access outward. That is the only reliable answer.
What is the difference between admin and advertiser on a Facebook ad account?
Admin adds payment-method editing and permission management on top of everything an advertiser can do. Advertiser gives full campaign control with no billing rights, which is what most agency work needs.
Can I change my ad account's currency or time zone later?
Not in place, and this applies to both. Meta's documentation says changing either one closes the existing account and creates a new one, and the ads stop. Choose both carefully at creation.
Why can't I add my colleague to a client's ad account?
The direct add path requires the person to have an active Facebook account and to be a Facebook friend of the person adding them. Use partner access at the portfolio level instead, which has no such requirement.
How many ad accounts can one business portfolio have?
There is a limit, but Meta assigns it per portfolio rather than publishing one number. Portfolios typically start with a very small allowance, often a single ad account, and it rises as the portfolio builds spend history. Check the current limit on Meta's help pages before planning a multi-account structure.
What happens to my access if the client fires us?
It all disappears at once, and irreversibly: ad account, campaign history, Page, datasets, audiences. Export reporting on a schedule and keep your creative in your own systems.

