Partner access is a setting in a Meta business portfolio that lets another business, usually an agency or consultant, work on assets you own, such as an ad account, Facebook Page, Instagram account, dataset or catalogue, without transferring ownership. You decide which assets they see and what they can do with each one, and you can withdraw access at any time.
How partner access works
Every business that uses Meta’s tools seriously should have a business portfolio (formerly Business Manager). Assets sit inside the portfolio that owns them. To work with an outside business, you open Business settings, go to Partners, choose to give a partner access to your assets, and enter their business portfolio ID. You then select each asset and the level of access: full control, or partial permissions such as managing campaigns or viewing performance only.
Access can be granted asset by asset. An agency running your ads may need the ad account, the dataset for conversion tracking and the Page the ads run from, but not your catalogue or your Instagram inbox. A web developer fixing your tracking may need the dataset alone.
The partner’s administrator then assigns their own staff to your assets from inside their portfolio. You never see or manage their individual people, and they never need your login. The process also works the other way: a partner can request access to an asset by its ID, and you approve or decline the request.
Why it matters
The most expensive mistake I see in UK accounts is an agency that created the client’s ad account or pixel inside its own portfolio. When the relationship ends, the client can lose years of campaign history, audiences and conversion data, and has to start again. With partner access, everything stays in your portfolio and the supplier simply loses the key when they leave.
It also matters for security. Sharing a personal login is against Meta’s terms and a common route to account takeovers and disabled ad accounts. Partner access, combined with two-factor authentication for everyone involved, limits the damage any single compromised account can do.
There is a UK GDPR angle. A partner working in your ad account and dataset can see audience and lead information that includes personal data. Giving them only the assets they need is data minimisation in practice, and your contract with them should cover how they handle that data.
Common mistakes
- Letting a supplier set up the ad account, Page or dataset in their portfolio “to save time”.
- Adding the agency’s staff as individual people with admin rights, instead of granting access to their business.
- Giving full control of every asset when the partner only runs ads.
- Forgetting to remove a former agency, which then keeps access to live ad spend and customer data.
- Having only one admin in your own portfolio, so losing that person’s account locks the business out.
How to act on it
Check that your business portfolio owns your ad accounts, Pages, Instagram account, dataset and any catalogue. If a supplier owns any of them, ask for a transfer or recreate them in your portfolio before the next contract renewal. Make sure at least two trusted people in your business have admin rights, both with two-factor authentication.
When you hire help, ask for their business portfolio ID and grant access only to what they need. That is how I work on every account in my Facebook ads management service: the assets, history and data stay in your name.
