Who Owns the Ad Account? The Access Audit Every Founder Should Run Once a Year

The assets a founder must own outright, how to check who actually controls each one, and the order to run the audit in so nothing locks you out.

Author
Prabhash Jha
Published
Reading time
14 min read

Most founders find out who owns their ad account on the worst possible day. Not during a quarterly review, not while reading a contract — but on the afternoon they decide to change agencies, and discover that the pixel with three years of conversion history sits inside a business portfolio they have never had a login for.

The uncomfortable part is that nobody did anything wrong. No agency set out to hold anything hostage. Someone was in a hurry during onboarding, clicked “create new” instead of “request access”, and the asset was born in the wrong place. Three years later that click is the reason a transition that should take an afternoon takes six weeks.

This is an audit, not an accusation. Run it once a year, on a quiet afternoon, whether or not you are happy with everyone you work with. The point is not to catch anyone. The point is that ownership questions are trivially cheap to fix while the relationship is good and nearly impossible to fix while it is ending.

What “owning” an account actually means

Owning an account means you hold the top-level administrative role on the container that holds the asset, using credentials on an email address at a domain you control.

That sentence has three separate conditions and most founders only satisfy one of them.

The container, not the asset. In almost every ad platform, the thing that matters is not the ad account — it is the organisational shell the ad account lives inside. Meta calls it a business portfolio. Google calls it a manager account. If your agency’s shell owns your ad account, then removing the agency removes the account, because the account was never a separate thing that could be handed back.

The top-level role. Being able to log in and see campaigns is not ownership. Google Ads has five distinct access levels — Email-only, Billing, Read-only, Standard and Admin — and only Admin can grant access, change other people’s access levels, and manage manager-account links. Everything below Admin is a permission someone else can revoke. Google’s own documentation makes the same point in the other direction: an account with only one administrator risks losing tag access entirely if that person becomes unavailable, which is why two admins is the floor, not a nicety.

On an email you control. An admin role attached to founder@gmail.com is better than nothing and worse than it looks. If the person holding that address leaves, disputes the separation, or simply stops answering, you own the account in theory and not in practice. Every administrative role should sit on an address at your own domain, ideally one that survives an individual’s departure.

The assets to check, and who should hold each

Work the list top to bottom. The order is not arbitrary — items near the top can be used to recover items further down, so an audit that starts at the bottom can waste a week proving things you could have taken back directly.

AssetWho should own itThe failure mode
Domain registrationThe company, at its own registrar accountRegistrar account in a developer’s or agency’s name
DNS / nameserversThe companyHosted inside an agency’s account “for convenience”
Business email (Workspace / M365)The company, super-admin held internallySingle super-admin who has left
Meta business portfolioThe company; agency added as a partnerPortfolio created by the agency, assets born inside it
Meta pixel / datasetThe company’s portfolioPixel owned by agency portfolio, history non-transferable
Google Ads accountThe company; agency links via manager accountAccount created under the agency’s manager account
Google Analytics propertyThe companyProperty in an agency-owned account, data not portable
Google Tag Manager containerThe companyContainer in an agency account; site tags depend on it
Search Console propertyCompany holds verified ownershipOnly the agency is a verified owner
Payment methods on ad accountsThe company’s card or billing profileAgency card, so spend history and credit sit with them
Social accountsThe company, with 2FA recovery internal2FA bound to a departed employee’s phone
CRM / marketing automationThe companySeat-based tools where the admin seat is an agency seat

Two rows deserve more than a line each.

The pixel and the analytics property are the ones with real, non-recoverable value. A campaign can be rebuilt in a day. Ad creative can be re-uploaded. Three years of conversion history, audience seeds and learned optimisation signals cannot be exported and re-imported into a fresh pixel — you can move who has access to a dataset, but you cannot move accumulated learning into a new one. This is why the pixel is the asset worth checking first even though it feels like a technical detail.

Search Console has a distinction that catches people out. There is a difference between a verified owner, a delegated owner, and a full user. A delegated owner’s status depends on a verified owner continuing to exist; if the verification token that made the agency an owner is removed and you were never independently verified, you can lose the property. Verify ownership yourself, through your own DNS record, so your verification does not depend on anyone else’s. If you want the wider picture on what that data can and cannot tell you once you hold it, your Search Console numbers are lying to you in five specific ways covers the interpretation side.

How to actually check, platform by platform

Reading a contract tells you what was agreed. Only the platform tells you what is true. In every case below, the check takes under two minutes.

Meta. Open Business Settings in your business portfolio. Under Accounts → Ad Accounts, look at each account and check which portfolio is listed as the owner rather than which people appear in the user list. Do the same under Data Sources for your pixel or dataset. If your portfolio is not the owner, you have partner access to your own asset. Under Users → Partners, you should see your agency listed as a partner with specific tasks assigned — that is the correct arrangement.

Google Ads. Go to Admin → Access and security. Confirm at least two people with Admin access, both on your domain. Then open Account settings → Managers to see every manager account linked to yours. A manager account link is how an agency should be connected; it is also something you can unlink yourself, which is exactly the property you want.

Google Analytics. In Admin, check Account access management as well as Property access management — they are separate, and someone can hold power at the account level that is invisible from the property view. Confirm you hold the Administrator role at account level.

Tag Manager. Check both account-level and container-level permissions, and specifically who holds Publish rights. Publish is the one that matters: whoever holds it can change what runs on every page of your site.

Search Console. Settings → Users and permissions. Confirm you appear as an Owner, and check Ownership verification to see how that ownership was established.

Write down what you find before you change anything. Half the value of this audit is having last year’s answer to compare against.

The order to fix things in, and the one sequencing trap

Fix in this order: domain, then email, then everything else.

The domain is first because it is the recovery mechanism for almost everything downstream. Control of DNS lets you re-verify Search Console independently, prove ownership to platform support teams, and re-establish email if you have to. If the domain is in someone else’s registrar account, nothing else you fix is durable.

Here is the trap, and it is a real one. Under ICANN’s Transfer Policy, registrars must apply a 60-day lock preventing transfer to another registrar following a change to the registrant’s information. A domain also cannot be transferred during the first 60 days after initial registration or after a previous registrar transfer. So if you update the registrant details to your company name first, and then try to move the domain to your own registrar account, you can find yourself locked out of the move for two months — by a rule that exists to protect you. ICANN’s own guidance is explicit about the sequence: if the goal is to transfer the domain, complete the transfer first, then change the contact information.

Some registrars allow the prior registrant to opt out of that lock, but they are not obliged to, and the opt-out has to be exercised before the change request, not after. Assume you will not get it.

Email comes second because password resets for every remaining platform land there, and because a super-admin account nobody at the company controls makes every other fix provisional.

How to move things without breaking a live campaign

The fear that stops most founders from fixing this is reasonable: pausing a working funnel to satisfy a governance concern is a bad trade. It is also usually an unnecessary one.

Ownership changes and access changes are different operations. Adding your business portfolio as an owner, or adding yourself as an Admin, does not remove anyone. You can bring your own control up to the correct level with the agency still fully in place, and nothing stops running. Do that part immediately and independently of any conversation about the relationship.

Do the asset-by-asset transfers while everyone is still cooperating. Meta asset transfers between portfolios need action from both sides. So does unlinking a manager account. Every one of these is a two-minute task for a working relationship and a support-ticket saga for an ended one.

Never make a tag change and a tracking change in the same week. If you move a container and re-verify a property at once and conversions drop, you will not know which change caused it. Move one thing, wait for a clean day of data, then move the next.

Retire access at separation, do not just intend to. Removing a departing partner’s access is a task with a date, not a sentiment. The same discipline applies to employees. If the idea of a written record of who touched what feels excessive, it is the same instinct behind what to log when an AI agent acts on your behalf — the log exists precisely for the situation where memory and goodwill are no longer available.

What to write into the contract so next year’s audit is boring

The audit gets easier every year if the paperwork does part of the work. Four clauses cover most of it:

  1. Assets created during the engagement belong to the client. Name the categories explicitly — ad accounts, pixels and datasets, analytics properties, tag containers, creative files, audience lists — rather than relying on a general “work product” clause that was drafted with documents in mind.
  2. Work happens under client-owned containers via partner or manager access. This is the clause that prevents the wrong-click problem at onboarding, because it makes the correct setup the contractual default rather than a preference someone has to remember.
  3. Access is returned within a fixed number of days of termination, with a named list of what “returned” covers.
  4. Either party can request an access review once per quarter. This is the one people leave out, and it is the one that makes the whole thing routine rather than confrontational. Asking to review access because the contract says you do it every quarter is a very different conversation from asking because you are unhappy.

A good agency will agree to all four without friction — from their side, this is simply the correct way to run an account, and the sequencing that a well-run onboarding follows anyway is set out in the first 90 days of an agency account. Reluctance to put any of it in writing is itself information.

Where this connects to the harder conversations

Access is the quiet infrastructure underneath every difficult decision a founder eventually has to make.

If you are weighing whether a relationship has run its course, the honest version of that decision is much easier when you already know that leaving costs you an afternoon rather than a quarter. The signals worth acting on are covered in when to fire a client — the four signals, and why revenue is never one; the mirror image applies to vendors you are thinking of leaving.

And if the relationship is ending badly over money, the access question becomes charged in both directions. The principle I hold to when I am the one owed money is to withhold labour, not assets — the reasoning is in the client has stopped paying: here is the sequence, in order. The reason to run this audit while everything is calm is so that you never have to find out whether the other party holds the same principle.

The annual version, compressed

Once a year, block ninety minutes and do exactly this:

  1. Open each platform’s settings page and record the owning entity for every asset in the table above.
  2. Confirm at least two administrators per platform, both on company email addresses.
  3. Remove every person who no longer works with you, and every partner whose engagement has ended.
  4. Check that 2FA recovery for social accounts points at something the company controls, not an individual’s personal phone.
  5. Confirm the payment method on each ad account is the company’s.
  6. Diff this year’s list against last year’s and ask about anything that moved.

Step six is the one that turns an audit into a system. A single snapshot tells you the state of things. Two snapshots tell you the direction they are drifting in, which is the thing you actually want to know.

FAQs

Who legally owns an ad account created by an agency?

Whoever controls the container it was created in, unless a contract says otherwise — and platform terms generally govern the operational reality regardless of what a contract says. This is why the contract clause and the platform setup both matter: the contract gives you a claim, and the platform setup gives you the account. A claim without control means negotiating for something you already own on paper.

Can I transfer a Meta pixel to a different business portfolio?

You can transfer ownership of a dataset between portfolios, and both sides need to act for it to complete. What you cannot do is move accumulated learning into a brand-new pixel — that history is tied to the dataset itself. This is the practical reason to fix pixel ownership early rather than accepting a fresh pixel as a workable substitute later.

What is the difference between a Google Ads manager account and account ownership?

A manager account links to your account to administer it; it does not have to own it. The correct arrangement is that your company holds the ad account with Admin access on your own emails, and the agency’s manager account is linked. You can unlink a manager account yourself, which is precisely why that structure is safer than an account created inside the agency’s manager hierarchy.

How many people should have admin access to an ad account?

At least two, both on company email addresses. One is a single point of failure — Google’s documentation warns specifically that a sole administrator becoming unavailable can cost you tag access. More than three or four dilutes accountability without adding resilience.

What happens to my domain if I change the registrant details before transferring it?

You trigger a 60-day lock that prevents transferring the domain to another registrar. ICANN’s Transfer Policy requires registrars to apply that lock after a change to registrant information. If your goal is to move the domain into your own registrar account, do the transfer first and update the contact details afterwards.

Should I run this audit if I trust my agency completely?

Yes, and trust is the reason it is easy rather than a reason to skip it. Almost every ownership problem I have seen came from a rushed onboarding click rather than bad intent, and it stays cheap to fix for exactly as long as both parties are willing to spend two minutes in a settings screen. The audit is insurance against accident, not against malice.

What if the agency refuses to transfer an asset?

Escalate through the platform’s support process with your contract and your domain control as evidence, and take the loss on anything genuinely non-recoverable rather than letting the dispute stall the business. Then rebuild what you must under containers you own. It is a bad outcome, and it is survivable — which is why the sequencing advice above puts domain and email first, since those are the two that make everything else recoverable.

Key takeaways

  • Ownership is the container plus the top-level role plus an email you control. Two out of three is not ownership.
  • Check the platform, not the contract. Settings screens tell you what is true.
  • Fix in order: domain, email, then everything else — the top of the list recovers the rest.
  • Transfer a domain before changing registrant details, or eat a 60-day lock.
  • Raise your own access to Admin today; it removes nobody and breaks nothing.
  • Two admins per platform, both on company addresses. One is a single point of failure.
  • Put the quarterly access review in the contract so asking is routine, not adversarial.
  • Diff this year against last year. The drift is the finding.

Keep reading