Security & privacy

Review temporary advertising access by task, scope and exit date

Temporary access should begin with a task and end with a verified closure, not simply with a calendar reminder. This suggested access card connects the work a contractor must perform with the clients, capabilities and duration they need. It complements existing team roles rather than teaching the same role setup again or claiming that every account has automatic access expiry.

A task-based access card

An access card contains the contractor's identity reference, sponsor, task, required clients, required capabilities, start time, planned end time, review date and closure owner. Keep authentication secrets out of the card. Describe the deliverable precisely: review stored reporting for Client A and produce a tracking discrepancy list is narrower than help with advertising. The sponsor owns the business need; an authorized administrator decides whether the requested permissions fit that need.

For a teaching example, a contractor must compare one client's saved campaign metrics with a supplied tracking checklist. They need reporting access to that client and no advertising proposals. In AdAce Ads, analysts read assigned clients, while broader administrative roles have broader visibility. The process should choose the least capable role that completes the task and verify the actual client assignment. A contractor helping a second client later requires a reviewed scope change, not an assumption that all agency data is available.

Separate application access from other channels. A person may also hold a direct ad-platform membership, an external AI authorization, a shared report link or copied exports. A team-role adjustment should not be described as withdrawing all of those automatically. The card needs an inventory of the channels actually provided and an owner for each closure. For shared artifacts, record whether access can be withdrawn or whether an already downloaded copy remains outside technical revocation.

Time limits need closure evidence

  • A planned end date is a review trigger unless the actual access mechanism supports and verifies expiry. Do not label a spreadsheet date as a security control. Assign a person to check the resulting state.
  • Review scope after a task changes. New requirements can justify additional permissions, but convenience alone should not turn a short reporting engagement into ongoing administrative access across every client.
  • Use a distinct identity for each person. Shared credentials obscure attribution and make selective revocation difficult. The handoff document should identify which access was supplied without recording the credentials themselves.

Review the full access lifecycle

  1. Write the task and acceptance deliverable before issuing access. Identify the minimum data and tools needed. If the task only requires an aggregate report, consider whether a minimized report is sufficient instead of a full workspace membership.
  2. Have the authorized administrator review the requested role and client assignments. Record the approved boundary in the card. In a controlled setting, confirm that the intended client is available and unrelated clients are outside scope without exposing their data.
  3. At the midpoint or task change, review actual use and unanswered needs. Audit evidence can show recorded actions, but absence of a log entry is not proof that no data was copied through another permitted channel.
  4. At the end, collect the agreed deliverable, transfer open questions and perform the authorized access closure for each inventoried channel. AdAce Ads member deactivation is one control; direct provider memberships and shared materials need their own review.
  5. Record closure evidence: identity, system, completed action, verifier and time. If a channel cannot yet be closed, mark the access card open with an owner and deadline. Check that no unnecessary standing role remains after the contractor's engagement ends.

Revocation has a defined boundary

  • This is an operational review, not legal advice about contractor data obligations. Technical revocation cannot recall information already read or exported. Decide the permitted data boundary before sharing, not only when ending the engagement.
  • A prompt asking an AI to behave carefully does not narrow server-side access. Use actual permissions for the boundary. Any evaluation prompt should require read-only analysis and prohibit propose_change and all other write tools, even if the task is described as a review.

Sources and further reading

Ace, the AdAce Ads mascot

Try it on your own accounts

Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.

Create your workspace