Meta ad account roles for agencies: who can build ads, who can publish them, and who can spend
Every agency wants a junior to build the client batch and a senior to decide what goes live. Meta's permission model does not have that role. Here is what it does have, per Meta's own documentation, and three ways to get the split anyway.
The short answer
Meta gives an ad account three roles, Admin, Advertiser and Analyst, and none of them lets a person build ads without also being able to publish them. Whoever can create and edit ads can switch them on, on the client's funding source. So if you want a junior or a freelancer to build a client's batch while someone senior decides what goes live, Meta offers one narrow native route (Creative Hub mockups), and otherwise the split has to come from your process or your launch tool.
Everything Meta-specific below is quoted from Meta's help centre and Marketing API reference, checked on 23 September 2026. What we recommend on top of that is labelled as our default.
The roles Meta actually has
In Ads Manager, "ad accounts have 3 permission roles". In a business portfolio (Business Manager) the same access is handed out as tasks: three kinds of partial access and one kind of full access. Side by side, from Meta's two help pages:
| Ads Manager role | Business portfolio access | View ads | Create and edit ads | Reports | Payment, settings and permissions |
|---|---|---|---|---|---|
| Admin | Manage ad accounts (full) | yes | yes | yes | yes |
| Advertiser | Manage campaigns (partial) | yes | yes | yes | no |
| Analyst | View performance (partial) | yes | no | yes | no |
| none | Manage Creative Hub mockups (partial) | no | no | no | no (mockups only) |
The quotes that matter:
- Advertiser: "can create, edit, and manage ads, as well as view all ads and access performance reports. Advertisers cannot change the payment method on the ad account and cannot add or remove other people's access."
- Analyst: "has view-only access. Analysts can view existing ads and access performance reports, but cannot create ads, edit ads, change payment methods, or manage other people's permissions."
- In the Marketing API, the same Advertiser access is described as: "Create ads using the funding source associated with the ad account."
Notice what is missing. "Create and edit ads" is one permission, and there is no row called "publish". In the documentation we read, there is no role that may build an ad but not switch it on. That absence is the whole problem for an agency: the person who can build the batch can also make it spend.
Why paused is the line that actually protects the budget
Ads can be created in two statuses, active or paused. Meta's Marketing API reference: "When an ad is created, it will first go through ad review, and will have the ad status PENDING_REVIEW before it finishes review and reverts back to your selected status of ACTIVE or PAUSED. During testing, it is recommended to set ads to a PAUSED status so as to not incur accidental spend." And: "New ads are in pending state and do not run until Facebook approves or rejects them. After we approve an ad it runs."
Two consequences for an agency:
- A batch created active goes live on its own the moment review clears, with no human in between. A batch created paused is reviewed straight away and then waits. More on that timing in Facebook ad review in bulk.
- Meta charges on delivery ("usually, you're charged based on the number of impressions your ad receives"), so a paused ad that never delivers costs nothing. That is our reading of Meta's billing pages; Meta does not say it in one sentence.
Paused protects the budget only until someone with Advertiser access switches the ads on. Which brings us back to who holds that access.
Three ways agencies split building from publishing
1. Creative Hub mockups (Meta-native)
The one place Meta separates the two. Per its Creative Hub permissions page, "Create, view and edit mockups" and "Share mockups via link" are open to Admin, Advertiser and "Manage Creative Hub mockups", while "Create ads from mockups" is limited to "Admin, Advertiser". So a junior with only mockup access builds and shares, and a senior turns approved mockups into ads.
The limits are real. Meta lists unsupported objectives ("Engagement (with the conversion location Facebook Page) and App promotion (Meta Advantage+ app campaigns)") and "dynamic creative ads are also not supported". And a mockup still has to become an ad one by one in Ads Manager, which is fine for three concepts and slow for a forty-creative batch (our view).
2. Drafts and one named publisher (a convention)
Everyone who builds gets "Manage campaigns", everyone works in drafts ("before you publish your ad it's considered a draft"), and one senior uses "Review and publish". Jon Loomer describes the client-approval version of this: share the draft preview link, with the catch that "you'll need to keep your ad in draft while your client reviews it" (secondary source).
Be honest about what this is: a rule people follow, not a control. Every person with "Manage campaigns" can still publish. It works in a disciplined team of three and erodes the week someone is in a hurry.
3. A launch tool that only creates paused ads, with its own permissions
We are Adlio, so weigh this section accordingly. This is the split we built for: on the Team plan, a team member logs in with their own email and works through the agency owner's Facebook connection, so they need no role in the client's business portfolio at all. They see only the client ad accounts you share with them, and per account you decide whether they may launch. Every ad Adlio creates is paused, with no setting that changes that, so the most a member can do is put a paused batch in the client's account. Switching it on happens in Ads Manager, by someone who has access there.
Without launch rights a member can see the account and edit its copy, naming and UTM defaults, but cannot upload or create ads. The Page, Instagram account and EU DSA details stay with the owner either way. How the per-account settings keep clients apart is in managing multiple Facebook ad accounts; the agency view is on the agency page.
The client's side: partner access and a spending limit
The client stays in charge of what the agency may do. From Meta's partner pages:
- The client shares the ad account with the agency's business portfolio as a partner and chooses "full control of the business asset, or partial access".
- Even with full control, a partner "cannot share the business asset with another business"; only the owner can.
- With partial access, the agency "can only assign people in their business portfolio permission to complete the specific tasks that you have assigned the partner". The client's choice caps what the agency can hand down to its own people.
- The client can remove the partner at any time, provided they have full control of their own portfolio.
A second safety net that only the client's admin can set is the account spending limit: "When you reach this limit, your ads pause, and your ad account stops spending money." And: "You have to be an admin of an ad account to create an account spending limit."
For freelancers there is temporary access: it "provides only basic access for a minimum of 3 days and a maximum of 75 days", after which the person is removed automatically.
A setup that holds up (our default)
- Client to agency: partner access with "Manage campaigns" on the ad account. Full control only if you really manage the client's billing or permissions.
- Inside the agency: "Manage campaigns" on a client account only for the people who decide what goes live there. Everyone else gets "View performance", or no Meta role at all if they build through a tool.
- Every batch lands paused. Run the pre-launch QA checklist on it, then one named person switches it on.
- A spending limit on every client account, set by the client's admin, sized to a bad week rather than a normal one.
- Freelancers on temporary access with an end date, so access does not outlive the job.
- In the EU: check that the DSA beneficiary and payer are right for this client before anything goes live; see DSA beneficiary and payer fields.
If you want steps 2 and 3 enforced rather than agreed, that is what a paused-only launcher with per-account launch rights gives you; see how bulk upload works. The first 15 ads are free, without a card.
Frequently asked questions
Can I give someone access to create Meta ads but not publish them?+
Not with an ad account role. Meta's partial-access permission "Manage campaigns" covers viewing, creating and editing ads, and there is no separate publish permission; the Advertiser role "can create, edit, and manage ads". The closest native split is Creative Hub: someone with only "Manage Creative Hub mockups" can build and share mockups, and only an Admin or Advertiser can turn them into ads. Otherwise the split has to come from your process or your launch tool.
What is the difference between Advertiser and Analyst on a Meta ad account?+
Per Meta, the Advertiser role "can create, edit, and manage ads, as well as view all ads and access performance reports" but "cannot change the payment method on the ad account and cannot add or remove other people's access". The Analyst role "has view-only access": existing ads and reports, no creating or editing. Only an Admin manages payment and permissions.
Do paused ads cost money or go through review?+
They are reviewed at creation: Meta's Marketing API documentation says a new ad first has the status PENDING_REVIEW and then "reverts back to your selected status of ACTIVE or PAUSED", and recommends PAUSED during testing "so as to not incur accidental spend". Meta charges on delivery (usually impressions), so an ad that stays paused and never delivers is not charged. That last step is our reading of Meta's billing pages, not one Meta sentence.
Should an agency ask for full control of a client's ad account?+
Usually not. Creating and running ads needs "Manage campaigns" (partial access); only full control ("Manage ad accounts") adds the ad account's settings, finances and permissions. Leaving payment and access with the client is cleaner for both sides, and the client keeps the power to remove the partnership. This is our default, not a Meta rule.
Sources
- Meta Business Help: What are the ad account permission roles in Meta Ads Manager?
- Meta Business Help: Business portfolio assets and their task-based access settings
- Meta Business Help: About access levels in business portfolios
- Meta Business Help: About mockup permissions in Creative Hub
- Meta Business Help: Create ads from Creative Hub mockups
- Meta Business Help: Drafts in Ads Manager
- Meta Business Help: Publish drafts in Ads Manager
- Meta Business Help: How you are charged for ads
- Meta Business Help: Share business assets with a partner
- Meta Business Help: Account spending limits
- Meta Marketing API reference: Ad (status, review)
- Meta Marketing API reference: Ad account assigned users (tasks)
- Jon Loomer: Creative Hub and drafts for ad mockups
Adlio team
Built by media buyers who launch Meta ads in volume. Questions or corrections: support@adlio.ai.
Topic cluster
Launch hygiene and QA
Naming, UTMs, identity, DSA and the paused review that makes a bulk batch safe to set live.
- Meta ads naming convention: a template you can copy, and how to apply it to every ad
- UTM parameters for Meta ads: set them once per account, apply them to every ad
- The pixel and conversion event per ad account: set once, verify on every launch
- Instagram account not showing in Ads Manager: the causes, and when you do not actually need it
- Adding ads to an existing ad set: what it does to the learning phase, budget and delivery
- Facebook ad review when you publish in bulk: timing, re-review triggers, and the paused-ads advantage
- Rolling back a bulk launch: pause many ads at once without resetting learning
- Managing multiple Facebook ad accounts: how to keep client A's settings out of client B's ads
- Meta ad account roles for agencies: who can build ads, who can publish them, and who can spend
- Meta ads in the EU: the DSA beneficiary and payer fields, and how to stop them blocking your launches
Related guides
- How-toManaging multiple Facebook ad accounts: how to keep client A's settings out of client B's ads
- ChecklistLaunch every Meta ad paused: the pre-flight QA checklist for bulk batches
- How-toFacebook ad review when you publish in bulk: timing, re-review triggers, and the paused-ads advantage
- How-toMeta ads in the EU: the DSA beneficiary and payer fields, and how to stop them blocking your launches