Once you decide to work with an agency, the first practical question is: "How will they access my account?" Too often the answer is a bad habit: the username and password are sent over WhatsApp. This article explains how to grant access for both Google Ads and Meta without sharing a password and while keeping ownership of the account.
Why passwords are never shared
- Risk of losing ownership: whoever knows the password can change the recovery email, two-step verification and the payment method.
- No trail: every action done with the same user shows up as "you"; nobody can tell who did what.
- Not revocable: when the work ends, the only way to cut access is to change the password, and copied sessions may stay open in the meantime.
- Against the rules: Google and Meta prohibit account sharing in their terms and provide official partner methods for agencies.
The right method: the platform's own permission system
Both platforms have an official path designed for agencies. The logic is the same: the account stays yours, the agency connects with its own identity and a limited permission, and you remove that permission with one click.
Google Ads: manager account (MCC) link
- Ask the agency for its manager account customer ID (10 digits, formatted 123-456-7890).
- In Google Ads go to Admin → Access and security → Managers.
- Accept the link request the agency sent, or enter the ID and send a link request yourself.
- Choose the access level: Standard is enough for day-to-day management; it does not require billing or user management rights.
- When the work ends, click Remove link on the same screen.
Details: What is a Google Ads MCC (manager account) link?
Meta: partner in Business Manager
- Ask the agency for its Business Manager (business portfolio) ID.
- Go to Business settings → Users → Partners → Add → Give a partner access to your assets.
- Select which ad accounts, pages and pixels to share and set the permission level per asset ("Manage campaigns" is enough for an ad account).
- Remove the partner at any time with the Remove button.
Details: Adding an agency partner in Meta Business Manager
A third way: app connection via OAuth
Some agencies, YUEN among them, ask you to connect through their own platform using OAuth. You click "Connect", Google's or Meta's own consent screen opens, the requested permissions are listed one by one and you approve. The agency never sees your password at any step; the platform receives only a limited, encrypted access key. You revoke it from Google Account → Security → Third-party apps, or from the agency's portal, with one click.
Checklist before granting access
- Is access set up with the agency's identity, not your own username?
- Is the permission limited? (Payment method, adding users and account ownership are not opened to the agency.)
- Is there a who-did-what log, visible in the agency's portal or the platform's change history?
- Can you remove access yourself with one click?
- Does the agency explain in writing where and how it stores access keys?
Short answer
Agency access to an ad account is granted not with a password but through the platform's partner / manager account permission or via OAuth. The account stays yours, the permission is limited and revocable, and every action is logged. Do not work with an agency that does not use these methods.
At YUEN the connection is made only via OAuth; no step ever asks for a password. Details: Trust & access.

