DEV Community

Prabhash Jha
Prabhash Jha

Posted on Originally published at prabhashjha.com

Who Owns the Ad Account? The Access Audit Every Founder Should Run Once a Year

Most founders find out who owns their ad account on the worst possible day. Not during a quarterly review. Not while reading a contract. On the afternoon they decide to change agencies, and discover that the pixel with three years of conversion history sits inside a business portfolio they've never had a login for.

The uncomfortable part? Nobody did anything wrong. No agency set out to hold anything hostage. Someone was in a hurry during onboarding, clicked "create new" instead of "request access", and the asset was born in the wrong place. Three years later that one click is the reason a transition that should take an afternoon takes six weeks.

This is an audit, not an accusation. Run it once a year, on a quiet afternoon, whether or not you're happy with everyone you work with. The point isn't to catch anyone. Ownership questions are trivially cheap to fix while the relationship is good. Nearly impossible to fix while it's ending.

What "owning" an account actually means

Owning an account means you hold the top-level administrative role on the container that holds the asset, using credentials on an email address at a domain you control.

Three separate conditions in one sentence. Most founders only satisfy one.

The container, not the asset. In almost every ad platform, the thing that matters isn't the ad account. It's the organisational shell the ad account lives inside. Meta calls it a business portfolio. Google calls it a manager account. If your agency's shell owns your ad account, then removing the agency removes the account. Because the account was never a separate thing that could be handed back.

The top-level role. Being able to log in and see campaigns isn't ownership. Google Ads has five distinct access levels: Email-only, Billing, Read-only, Standard and Admin. Only Admin can grant access, change other people's access levels, and manage manager-account links. Everything below Admin is a permission someone else can revoke. Google's own documentation makes the same point in reverse. An account with only one administrator risks losing tag access entirely if that person becomes unavailable. Which is why two admins is the floor, not a nicety.

On an email you control. An admin role attached to founder@gmail.com is better than nothing, and worse than it looks. If the person holding that address leaves, disputes the separation, or simply stops answering, you own the account in theory and not in practice. Every administrative role should sit on an address at your own domain. Ideally one that survives an individual's departure.

The assets to check, and who should hold each

Work the list top to bottom. The order isn't arbitrary. Items near the top can be used to recover items further down. So an audit that starts at the bottom can waste a week proving things you could have taken back directly.

Asset Who should own it The failure mode
Domain registration The company, at its own registrar account Registrar account in a developer's or agency's name
DNS / nameservers The company Hosted inside an agency's account "for convenience"
Business email (Workspace / M365) The company, super-admin held internally Single super-admin who has left
Meta business portfolio The company; agency added as a partner Portfolio created by the agency, assets born inside it
Meta pixel / dataset The company's portfolio Pixel owned by agency portfolio, history non-transferable
Google Ads account The company; agency links via manager account Account created under the agency's manager account
Google Analytics property The company Property in an agency-owned account, data not portable
Google Tag Manager container The company Container in an agency account; site tags depend on it
Search Console property Company holds verified ownership Only the agency is a verified owner
Payment methods on ad accounts The company's card or billing profile Agency card, so spend history and credit sit with them
Social accounts The company, with 2FA recovery internal 2FA bound to a departed employee's phone
CRM / marketing automation The company Seat-based tools where the admin seat is an agency seat

Two rows deserve more than a line each.

The pixel and the analytics property are the ones with real, non-recoverable value. A campaign can be rebuilt in a day. Ad creative can be re-uploaded. Three years of conversion history, audience seeds and learned optimisation signals cannot be exported and re-imported into a fresh pixel. You can move who has access to a dataset. You cannot move accumulated learning into a new one. This is why the pixel is the asset worth checking first, even though it feels like a technical detail.

Search Console has a distinction that catches people out. There is a difference between a verified owner, a delegated owner, and a full user. A delegated owner's status depends on a verified owner continuing to exist. If the verification token that made the agency an owner is removed, and you were never independently verified, you can lose the property. Verify ownership yourself, through your own DNS record. So your verification doesn't depend on anyone else's. If you want the wider picture on what that data can and cannot tell you once you hold it, your Search Console numbers are lying to you in five specific ways covers the interpretation side.

How to actually check, platform by platform

Reading a contract tells you what was agreed. Only the platform tells you what is true. Every check below takes under two minutes.

Meta. Open Business Settings in your business portfolio. Under Accounts, then Ad Accounts, look at each account and check which portfolio is listed as the owner rather than which people appear in the user list. Do the same under Data Sources for your pixel or dataset. If your portfolio isn't the owner, you have partner access to your own asset. Under Users, then Partners, you should see your agency listed as a partner with specific tasks assigned. That's the correct arrangement.

Google Ads. Go to Admin, then Access and security. Confirm at least two people with Admin access, both on your domain. Then open Account settings, then Managers, to see every manager account linked to yours. A manager account link is how an agency should be connected. It's also something you can unlink yourself, which is exactly the property you want.

Google Analytics. In Admin, check Account access management as well as Property access management. They're separate. Someone can hold power at the account level that's invisible from the property view. Confirm you hold the Administrator role at account level.

Tag Manager. Check both account-level and container-level permissions, and specifically who holds Publish rights. Publish is the one that matters. Whoever holds it can change what runs on every page of your site.

Search Console. Settings, then Users and permissions. Confirm you appear as an Owner. Check Ownership verification to see how that ownership was established.

Write down what you find before you change anything. Honestly, half the value of this audit is having last year's answer to compare against.

The order to fix things in, and the one sequencing trap

Fix in this order: domain, then email, then everything else.

The domain is first because it's the recovery mechanism for almost everything downstream. Control of DNS lets you re-verify Search Console independently, prove ownership to platform support teams, and re-establish email if you have to. If the domain sits in someone else's registrar account, nothing else you fix is durable.

Here is the trap. It's a real one. Under ICANN's Transfer Policy, registrars must apply a 60-day lock preventing transfer to another registrar following a change to the registrant's information. A domain also cannot be transferred during the first 60 days after initial registration, or after a previous registrar transfer. So if you update the registrant details to your company name first, and then try to move the domain to your own registrar account, you can find yourself locked out of the move for two months. By a rule that exists to protect you. ICANN's own guidance is explicit about the sequence. If the goal is to transfer the domain, complete the transfer first, then change the contact information.

Some registrars allow the prior registrant to opt out of that lock. They're not obliged to. And the opt-out has to be exercised before the change request, not after. Assume you won't get it.

Email comes second because password resets for every remaining platform land there. And because a super-admin account nobody at the company controls makes every other fix provisional.

How to move things without breaking a live campaign

The fear that stops most founders from fixing this is reasonable. Pausing a working funnel to satisfy a governance concern is a bad trade. It's also usually an unnecessary one.

Ownership changes and access changes are different operations. Adding your business portfolio as an owner, or adding yourself as an Admin, doesn't remove anyone. You can bring your own control up to the correct level with the agency still fully in place. Nothing stops running. Do that part immediately and independently of any conversation about the relationship.

Do the asset-by-asset transfers while everyone is still cooperating. Meta asset transfers between portfolios need action from both sides. So does unlinking a manager account. Every one of these is a two-minute task for a working relationship, and a support-ticket saga for an ended one.

Never make a tag change and a tracking change in the same week. If you move a container and re-verify a property at once, and conversions drop, you won't know which change caused it. Move one thing. Wait for a clean day of data. Then move the next.

Retire access at separation, don't just intend to. Removing a departing partner's access is a task with a date, not a sentiment. The same discipline applies to employees. If the idea of a written record of who touched what feels excessive, it's the same instinct behind what to log when an AI agent acts on your behalf. The log exists precisely for the situation where memory and goodwill are no longer available.

What to write into the contract so next year's audit is boring

The audit gets easier every year if the paperwork does part of the work. Four clauses cover most of it:

  1. Assets created during the engagement belong to the client. Name the categories explicitly: ad accounts, pixels and datasets, analytics properties, tag containers, creative files, audience lists. Rather than relying on a general "work product" clause that was drafted with documents in mind.
  2. Work happens under client-owned containers via partner or manager access. This is the clause that prevents the wrong-click problem at onboarding. It makes the correct setup the contractual default, rather than a preference someone has to remember.
  3. Access is returned within a fixed number of days of termination, with a named list of what "returned" covers.
  4. Either party can request an access review once per quarter. This is the one people leave out. It's also the one that makes the whole thing routine rather than confrontational. Asking to review access because the contract says you do it every quarter is a very different conversation from asking because you're unhappy.

A good agency will agree to all four without friction. From their side, this is simply the correct way to run an account. The sequencing that a well-run onboarding follows anyway is set out in the first 90 days of an agency account. Reluctance to put any of it in writing is itself information.

Where this connects to the harder conversations

Access is the quiet infrastructure underneath every difficult decision a founder eventually has to make.

If you're weighing whether a relationship has run its course, the honest version of that decision is much easier when you already know that leaving costs you an afternoon rather than a quarter. The signals worth acting on are covered in when to fire a client, the four signals, and why revenue is never one. The mirror image applies to vendors you're thinking of leaving.

And if the relationship is ending badly over money, the access question becomes charged in both directions. The principle I hold to when I'm the one owed money is to withhold labour, not assets. The reasoning is in the client has stopped paying: here is the sequence, in order. The reason to run this audit while everything is calm is so that you never have to find out whether the other party holds the same principle.

The annual version, compressed

Once a year, block ninety minutes and do exactly this:

  1. Open each platform's settings page and record the owning entity for every asset in the table above.
  2. Confirm at least two administrators per platform, both on company email addresses.
  3. Remove every person who no longer works with you, and every partner whose engagement has ended.
  4. Check that 2FA recovery for social accounts points at something the company controls, not an individual's personal phone.
  5. Confirm the payment method on each ad account is the company's.
  6. Diff this year's list against last year's, and ask about anything that moved.

Step six is the one that turns an audit into a system. A single snapshot tells you the state of things. Two snapshots tell you the direction they're drifting in. Which is the thing you actually want to know.

FAQs

Who legally owns an ad account created by an agency?

Whoever controls the container it was created in, unless a contract says otherwise. And platform terms generally govern the operational reality regardless of what a contract says. This is why the contract clause and the platform setup both matter. The contract gives you a claim. The platform setup gives you the account. A claim without control means negotiating for something you already own on paper.

Can I transfer a Meta pixel to a different business portfolio?

You can transfer ownership of a dataset between portfolios, and both sides need to act for it to complete. What you cannot do is move accumulated learning into a brand-new pixel. That history is tied to the dataset itself. This is the practical reason to fix pixel ownership early, rather than accepting a fresh pixel as a workable substitute later.

What is the difference between a Google Ads manager account and account ownership?

A manager account links to your account to administer it. It doesn't have to own it. The correct arrangement is that your company holds the ad account with Admin access on your own emails, and the agency's manager account is linked. You can unlink a manager account yourself. Which is precisely why that structure is safer than an account created inside the agency's manager hierarchy.

How many people should have admin access to an ad account?

At least two, both on company email addresses. One is a single point of failure. Google's documentation warns specifically that a sole administrator becoming unavailable can cost you tag access. More than three or four dilutes accountability without adding resilience.

What happens to my domain if I change the registrant details before transferring it?

You trigger a 60-day lock that prevents transferring the domain to another registrar. ICANN's Transfer Policy requires registrars to apply that lock after a change to registrant information. If your goal is to move the domain into your own registrar account, do the transfer first and update the contact details afterwards.

Should I run this audit if I trust my agency completely?

Yes. Trust is the reason it's easy, not a reason to skip it. Almost every ownership problem I've seen came from a rushed onboarding click rather than bad intent. It stays cheap to fix for exactly as long as both parties are willing to spend two minutes in a settings screen. The audit is insurance against accident, not against malice.

What if the agency refuses to transfer an asset?

Escalate through the platform's support process with your contract and your domain control as evidence. Take the loss on anything genuinely non-recoverable rather than letting the dispute stall the business. Then rebuild what you must under containers you own. It's a bad outcome, and it's survivable. Which is why the sequencing advice above puts domain and email first. Those are the two that make everything else recoverable.

Key takeaways

  • Ownership is the container plus the top-level role plus an email you control. Two out of three isn't ownership.
  • Check the platform, not the contract. Settings screens tell you what is true.
  • Fix in order: domain, email, then everything else. The top of the list recovers the rest.
  • Transfer a domain before changing registrant details, or eat a 60-day lock.
  • Raise your own access to Admin today. It removes nobody and breaks nothing.
  • Two admins per platform, both on company addresses. One is a single point of failure.
  • Put the quarterly access review in the contract, so asking is routine, not adversarial.
  • Diff this year against last year. The drift is the finding.

Top comments (0)