Intelligence
BusinessPlaybookIllustrative

Business Suite permissions: the quiet cause of loud incidents

Most platform emergencies trace back to how access was structured years earlier. A permission audit is the least exciting, highest-return hour in the calendar.

By Researcheo11 June 20266 min read

Illustrative: examples in this piece are constructed to demonstrate a pattern. They do not describe any specific client or engagement.

Access is granted in a hurry — a freelancer for one campaign, an agency for one quarter, a colleague covering leave — and almost never revoked. Years later, the business portfolio holds a list of people and partners nobody can fully account for.

The structural rules that prevent most incidents

  • The business owns the assets. Pages, ad accounts, pixels and catalogues should never sit under an individual's personal profile alone.
  • At least two internal admins, both with two-factor authentication, both employees.
  • Agencies and freelancers get partner access to specific assets, never full admin on the portfolio.
  • Offboarding removes platform access on the same day it removes email access.
  • A quarterly review of every user, partner and asset, with the result written down.

Illustrative: a company changes agencies, loses the only remaining admin, and cannot regain control of its own pixel — with campaigns still running against it.

None of this is technical work. It is administrative discipline, and it is the difference between a ten-minute correction and a multi-week recovery.

Sources & references

  • Business Suite / business portfolio roles and partner access documentation

Researcheo Intelligence

Analysis on growth, AI, platforms and digital risk. Sent when there is something worth saying — not on a schedule.

We use your email only to send Researcheo Intelligence. Unsubscribe any time. See our privacy notice.