How-to

How to give a colleague access to your Meta ad accounts (without sharing your Facebook login)

The growth team just hired a second person who has to launch ads, and every ad account hangs off the founder's Facebook login. Here are the two routes that work without sharing it, with Meta's own rules quoted.

Adlio team7 min read

The short answer

Don't share the login. Give the colleague their own access: add them to your business portfolio (basic access is the default) and assign only the ad accounts they work on, with "Manage campaigns" if they build and launch ads. Or keep them out of Meta and let them launch through a tool with its own team access, working through one owner's connection. Our default: Meta access for whoever switches ads on and reads results, a launch tool for people who only need to get batches of ads into the right account.

Meta quotes below come from Meta's help centre, checked on 28 September 2026. Our own recommendations are labelled as our default.

Why sharing the founder's login is the wrong fix

  • It breaks Meta's rules. "Sharing your Facebook account or creating inauthentic profiles managed by multiple people is against our Terms of Service and Community Standards."
  • It hands over everything. The login carries every Page, payment method and portfolio setting the founder can reach. With full control, that is "everything in the business portfolio, including business portfolio settings, people, tools and business assets".
  • Two-factor gets weaker. Meta recommends it "to help protect your business portfolio and assets from unauthorized access". A shared login means shared codes, or two-factor switched off (our reading).
  • The history loses its names. Activity history shows "who made changes, what changes were made and when those changes were made". With one login, every change carries the founder's name. See who changed an ad.

Offboarding then means changing the founder's password. Own access avoids all of it: per Meta, granting people permissions to your ad account "doesn't give them permission to log in as you or see things on your profile that you haven't shared with them."

Route 1: their own access in Meta

Someone with full control of the business portfolio does this. From Meta's article on adding people:

  1. "Go to Settings in Meta Business Suite for your business portfolio", then "Click People in the left menu."
  2. "Click Invite people in the top right" and enter their email address. It "must match the one used for their Facebook account".
  3. Leave the portfolio permission at basic, the default. People with basic access "can work only on the business assets they're assigned."
  4. "Select business assets and permissions for the person you're adding, then click Invite." Pick only the ad accounts for the apps, brands or markets they run.

They then accept the invitation. For someone already in the portfolio: click their name under People, then "Assign assets".

The permission per ad account, from Meta's task-based access table:

Access on the ad accountView adsCreate and edit adsAccess reportsSettings, finances and permissions
Manage campaigns (partial)yesyesyesno
View performance (partial)yesnoyesno
Manage ad accounts (full)yesyesyesyes

Ads Manager calls these levels Advertiser, Analyst and Admin; the permission rows match (the pairing is our reading). Meta suggests Advertiser for "people who need to build and manage ad campaigns but should not control billing or account membership", for example "a marketing team member". That is "Manage campaigns", the right level for most growth marketers.

  • Freelancers. Temporary access "provides only basic access for a minimum of 3 days and a maximum of 75 days", then removes the person automatically. It is a toggle under Advanced options.
  • Limits. "An ad account can be assigned to up to 25 people" and "One person can manage up to 25 ad accounts." Watch the second if you run an account per app and per market.

An agency working in a client's account is a different case, a partner share between portfolios: see how an agency gets access to a client's ad account.

The catch: whoever can build can also publish

"Create and edit ads" is one permission; there is no publish row. In the Meta documentation we read, no role builds ads without being able to switch them on, and an Advertiser can "set up ads using the payment method associated with the ad account". Whoever builds the batch can make it spend. Details in Meta ad account roles.

Meta's one native publish gate is peer approval. Its "Extra protection" level "requires that every ad needs approval before it can run", by a trusted user. But:

  • "To set up or edit peer approval, you must have full control of the business portfolio."
  • "The business portfolio must own the ad account you want to add peer approval to."
  • "Ads published by people with full control of the business portfolio do not require a second review."
  • Whether ads created through the Marketing API, which launch tools use, are held the same way: not stated.

The money-side net is a spending limit, set by an ad account admin: "When you reach this limit, your ads pause, and your ad account stops spending money." For a sign-off routine, see approval before launch.

Route 2: launch without a Meta role

We are Adlio, so weigh this accordingly: it is the model we built. The owner connects Facebook once. On the Team plan, a colleague logs in with their own email and works through that connection, with no role in your business portfolio. They see only the ad accounts you share, and per account you decide whether they may launch. Without launch rights they can edit an account's copy, naming and UTM defaults, but not upload or create ads. The Page, Instagram account and EU DSA details stay with the owner.

Every ad Adlio creates is paused; no setting changes that. Switching on happens in Ads Manager, by someone with access there, so route 2 sits next to route 1 for one or two people (our default). The history shows who launched each batch ("Launched by"). More on the page for growth teams and in how bulk upload works.

We are not the only tool with this model, and not the cheapest. The Teams add-ons of Rapid Ads and Volume Creatives both list "Members launch on your behalf", "Never share your Facebook login" and "Every seat gets their own login". Ads Uploader works the other way: "Each user needs their own login through Facebook authentication", so each colleague still needs route 1 (our reading).

Per person, USD, monthly billing, excluding tax, checked on 28 September 2026:

PeopleAdlio TeamRapid AdsVolume CreativesAds Uploader Team
3$349 = $116.33 each$39 + 2 x $29 = $97 = $32.33 each$49 + 2 x $29 = $107 = $35.67 each3 x $49 = $147 = $49.00 each
5$349 + 2 x $59 = $467 = $93.40 each$39 + 4 x $29 = $155 = $31.00 each$49 + 4 x $29 = $165 = $33.00 each5 x $44 = $220 = $44.00 each

Assumptions: at Rapid Ads and Volume Creatives the owner holds the base plan and the rest are $29 seats (neither says whether the owner also needs a seat); Ads Uploader's team prices come from its pricing page's script, not its visible text. So Adlio costs about 2 to 3.6 times as much per person. Our case is not price: launch rights per account, ads that can only be created paused (Volume Creatives creates them "in the state you choose (PAUSED by default)"), all 69 Advantage+ enhancements opted out, and settings per ad account. Rapid Ads' app also sets ad account access per member (seen in its publicly served app code on 28 September 2026), but in neither tool did we find a member who can prepare an account without launching in it. Full comparisons: Rapid Ads alternative and Ads Uploader alternative.

A setup that holds up for a growth team (our default)

  1. One company-owned business portfolio, with two people on full control so one lost login does not lock you out, and nobody else, since full control skips peer approval.
  2. One ad account per app, brand or market, so access follows the account; see managing multiple Facebook ad accounts.
  3. Everyone else on basic access: "Manage campaigns" on the accounts they run, "View performance" where they only read.
  4. A spending limit on every account, sized to a bad week, not a normal one.
  5. Everything lands paused, goes through the pre-launch QA checklist, and one named person per account switches it on.
  6. Freelancers on temporary access, with an end date.

Frequently asked questions

Can I give someone access to one ad account but not the others?+

Yes. Add them to your business portfolio with basic access, which Meta describes as working "only on the business assets they're assigned", and assign just that ad account with the permission they need, usually "Manage campaigns". Your other ad accounts stay invisible to them. On Adlio Team it works the same way: a colleague sees only the ad accounts you share with them.

Can someone create ads but not publish them?+

Not with a Meta role. "Create and edit ads" is one permission, and an Advertiser can "set up ads using the payment method associated with the ad account". The closest native gate is peer approval with "Extra protection", which holds every ad for a trusted user, but setting it up needs full control of the portfolio, it only works on ad accounts your portfolio owns, and ads published by people with full control skip it. The other route is a launch tool that only creates paused ads, used by someone who has no Meta role.

Does a colleague need their own Facebook account?+

For access in Meta, yes: the invitation email "must match the one used for their Facebook account", unless your organisation uses managed Meta accounts. For an ad account outside a business portfolio, Meta also requires that you are Facebook friends. To launch through Adlio Team, no: they log in with an email address. Someone on the team still needs Meta access to switch the paused ads on.

How many people can one Meta ad account have?+

Per Meta's limits page, "An ad account can be assigned to up to 25 people" and "One person can manage up to 25 ad accounts." Hit either limit and access to unused ad accounts has to go: the person removes themselves, or someone with full control of the portfolio removes them.

How do I give a freelancer access that ends by itself?+

Use temporary access when you add them: under Advanced options, switch on the Temporary access toggle and set an end date. Meta allows "a minimum of 3 days and a maximum of 75 days", limited to basic access, and removes the person from the portfolio and its assets when it expires.

Sources

Adlio team

Built by media buyers who launch Meta ads in volume. Questions or corrections: support@adlio.ai.

Topic cluster

Teams and client accounts

Running Meta ads across many ad accounts with more than one person: access, roles, approval, and keeping accounts apart.