Gabriel Espinheira
A marketing manager recently admitted that client passwords were scattered across email, Teams and a shared Google Doc. One former freelancer still had Meta access six months after finishing the work. The manager called the setup "genuinely embarrassing". The owner would probably use a different word: exposed.
Marketing agency access should be business-owned, tied to a named person, limited to the smallest useful role and reviewed before its reason expires. This is basic delivery administration. If you cannot tell who changed a campaign, tag, domain record or form integration, you cannot tell who did the work or caused the breakage.
TL;DR: Good marketing agency access is business-owned, assigned to named people, limited to the work and reviewed by a set date. Keep six fields for every permission: asset, person, role, reason, reviewer and review-by date. Treat admin as a temporary elevation, then confirm the change and downgrade it.
What should marketing agency access look like?
The business should control the account, billing relationship and recovery path. Each agency user should then receive a named role with enough permission to complete a defined job, plus a date when somebody will check whether that permission still makes sense.
That last part is usually missing. An agency asks for admin during onboarding. The request feels urgent, so the owner approves it. The work changes; the permission does not. Months later, nobody remembers why it was granted or whether removing it will break something.
This is access debt: old permissions whose purpose is no longer clear. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses had identified a cyber breach or attack in the previous 12 months. It also found that 73% restricted admin or access rights to specific users and 47% required two-factor authentication for networks or applications. The figures are not causal proof. They show that controlled access is normal business hygiene, not enterprise theatre.
The practical rule is simple: the business owns the asset. The agency earns the permission.
Why shared passwords break more than security
Send one CMS login to five people and the audit trail stops meaning what you think it means. The platform may record a change by admin@company.com, but it cannot tell you which person changed the tracking code at 16:42 on Friday.
A password manager improves how a secret travels. It does not turn one shared identity into five attributable identities. When the platform supports separate users, use them. The UK National Cyber Security Centre recommends individual accounts, multi-factor authentication and least privilege. Its social-media guidance says to avoid sharing passwords and revoke access when no longer required.
Imagine a campaign starts counting every page view as a lead. The ad platform reacts, spend moves and the weekly report suddenly looks excellent. Named identities let you trace and fix the change. A shared login leaves a room full of suspects.
For Gabriel Espinheira, founder of SharpHaw, this is part of proof of work: if nobody can name who changed the tag, the change log proves nothing. Access and delivery belong in the same operating record.
The six fields in an agency access register
One living table, owned inside the business, is enough to expose most access problems.
| Field | What to record | The question it answers |
|---|---|---|
| Asset | Google Ads account, Analytics property, CMS, domain or social profile | What can this permission change? |
| Person | The external user’s name and work email | Who will act through it? |
| Role | The exact role or permission set | What can that person do? |
| Reason | A current task or responsibility | Why is the access necessary? |
| Reviewer | A named person inside the business | Who decides whether it continues? |
| Review-by date | A date or trigger, such as "after launch" | When must the decision be made again? |
"Agency team" is not a person. "Ongoing support" is not a useful reason. "Permanent" is not a review date.
The review-by field is the hinge. If the platform cannot expire access automatically, keep the date with the work. It is not necessarily a removal deadline. It is the point when somebody must choose to renew, reduce or remove the permission.
An agency running campaigns every week may keep an editor role for months. A developer changing DNS for a migration may need privileged access for two hours. Both can be sensible when the reason and review trigger are explicit.
How much access does each marketing system need?
Role names vary by platform. Start with the change the agency must make, then choose the lowest role that permits it.
| System | Normal working access | When higher access may be justified | Business control to retain |
|---|---|---|---|
| Google Ads | Linked manager account with the required client permissions | Billing, user management or a setup task that genuinely needs ownership privileges | Client account, billing visibility and an internal administrator |
| Google Analytics | Viewer, Analyst, Marketer or Editor at the relevant property | Adding users, changing property-level administration or restructuring the account | An internal Administrator and recovery access |
| Website CMS | Editor or a custom content role | Plugins, themes, integrations, user management or a deployment | Hosting, domain, backups and an internal administrator |
| Domain and DNS | No standing access for ordinary content or campaign work | A named record change, migration or verification task | Registrar account, recovery email, MFA and a verified record of the change |
| Social accounts | Platform partner access or a named role | Adding users, changing ownership settings or handling a platform restriction | Primary owner, recovery path and billing |
| CRM and finance | Reports or fields needed for attribution | A defined integration or data repair with documented scope | Customer records, exports, user administration and financial data outside the agreed measurement need |
Official platform documentation supports this approach. A Google Ads manager account can link to a client account, and Google says ownership should be granted only when those privileges are required. Google Analytics roles can apply at account or property level. WordPress roles separate administration from editing and publishing.
Do not ask which role agencies normally get. Ask which action fails if this person has one level less.
When does an agency really need admin access?
Sometimes the honest answer is now. A launch, analytics migration, DNS change, billing repair or new-user setup can require a privileged role. Refusing every admin request would turn sensible control into theatre and slow down the work.
The answer is temporary elevation:
- Name the person and the exact change.
- Record the current configuration or take a backup.
- Grant the role for a defined window.
- Make the change through the named identity.
- Read back what changed and test the result.
- Downgrade or remove the role, then record that action.
US cyber-security guidance recommends time-based privileged access and periodic entitlement reviews. The principle is plain: admin is a tool for a privileged task, not a medal for becoming the agency.
Somebody must approve an elevation, so the agency may occasionally wait. Agree the fast path in advance: who approves, where the request appears, the response time and who confirms the downgrade. Speed comes from a clear route, not open doors.
Agency access should end with the decision that justified it, not with the relationship.
How much business data should an agency see?
A roofing business owner recently asked whether a marketing supplier needed access to payroll, overhead and the full profit-and-loss account to judge ad performance. One reply cut through the argument: the agency should measure the channel it owns, not audit the whole company.
That is the right starting point. A paid-media partner may need revenue by qualified lead source, gross margin bands or closed-sale values to stop optimising for cheap enquiries that never buy. It rarely needs employee salaries or unrelated supplier costs.
Ask three questions before sharing a field or report:
- Which marketing decision will this data change?
- Can an aggregate, band or filtered report answer it?
- Who inside the agency can see or export it?
If the first answer is vague, stop. If an aggregate will do, share the narrower view. If the answer is "the team", ask for names. Measurement needs enough context to judge commercial quality, not a tour of the company.
Run this 15-minute marketing agency access audit
Open the systems where marketing can spend money, publish content, change tracking or redirect traffic: usually ads, analytics, website, domain and social accounts. Then run this sequence:
- Confirm ownership. The business controls the primary account, recovery email, billing and at least one internal administrator.
- List external users. Export or inspect every agency, freelancer, app and partner connection. Translate generic labels into named people where possible.
- Test the role. Ask what current task requires each permission and what would fail one role lower.
- Find the ghosts. Remove former staff, finished freelancers, unused integrations and duplicate manager relationships after checking dependencies.
- Set review dates. Give every remaining permission a reviewer and a date or event that forces a fresh decision.
- Protect recovery. Turn on MFA where supported and store recovery methods somewhere the business controls.
Do not begin by deleting unfamiliar users. Resolve the identity and dependency first. An unexplained service account may power a form, reporting connector or deployment. The goal is controlled access, not a dramatic lockout followed by a broken Monday.
Repeat the audit when someone leaves, scope changes, a launch finishes, an integration goes live or an invoice stops. For stable roles, a quarterly check is a sensible default. Privileged access deserves a shorter trigger.
What a good agency should show you
A good partner should answer four questions quickly: who changed it, what authorised the work, how it was tested and whether elevated access was removed.
If a tracking tag changed at 16:42 on Friday, the record should connect a named login, task, test result and current role. It turns "we worked on tracking" into inspectable delivery.
SharpHaw puts that operating record in SharpOS. Every subscription includes one shared workspace for the work, assets, reporting and client context. The client owns the code and content, sees the work in motion and can move up, down or out month to month. You can check the current scope on the SharpHaw plans page.
Frequently asked questions
Should a marketing agency have admin access?
Only when a specific task requires admin privileges. Grant the role to a named person for a defined window, record the change, test the result and downgrade it afterwards. Routine campaign, content or reporting work should use a lower role whenever the platform supports one.
Is it safe to share a password with a marketing agency?
Use the platform’s named-user or partner access instead of sharing a password whenever possible. If a shared credential is unavoidable, transfer it through a password manager, enable MFA, limit who can retrieve it and replace it after the task. A vault protects transfer; it does not create individual accountability.
Who should own a Google Ads account, the client or the agency?
The client business should retain the account, its data and a working administrator. The agency can manage campaigns through a linked manager account. Google allows clients to unlink that relationship and recommends granting manager ownership only when those additional privileges are genuinely required.
How often should agency access be reviewed?
Review access whenever a person leaves, the scope changes, a privileged task ends or an integration is replaced. A quarterly review is a practical fallback for stable working roles. Temporary admin should be checked as soon as the named task has been tested, not at the end of the contract.
Permanent admin feels fast because the cost arrives later: an account nobody wants to touch, a change nobody can attribute and an exit that begins with a scavenger hunt. Keep the six access fields together, then let good partners work quickly inside a boundary everyone can see.
Want a senior operator to review how your website, ads, content and access fit together? Ask SharpHaw to review your operating model. You will speak directly with the engineer running the work and see what should stay, change or expire.

