Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. When Someone Leaves Our Agency, How Do We Know Which Client Accounts, Logins and 2FA Codes They Still Control?
Problems We Solve

When Someone Leaves Our Agency, How Do We Know Which Client Accounts, Logins and 2FA Codes They Still Control?

When staff leave a marketing agency, client logins and 2FA codes often go with them. We build an access register so leavers are removed and nothing is lost.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Marketing agency staff collect access to client ad accounts, social pages, websites and tools, often with two-factor codes tied to their personal phone. When they leave, nobody has a list of what to remove or transfer. We build an access register that records who holds what for each client, runs a leaver checklist from it, and moves shared logins into a password manager with codes the agency controls.

The Monday after a leaving do

A senior paid social manager leaves on good terms. Two weeks later a client's Facebook page needs a change, and the page admin turns out to be his personal profile. The client's LinkedIn ads account needs a two-factor code that goes to his mobile. The login for a client's email marketing tool is in his browser's saved passwords. He is helpful when contacted, but he is now working at another agency, and everyone is uncomfortable.

Meanwhile the IT side of offboarding went fine: laptop returned, Google Workspace account suspended. None of that touched the client accounts, because those were never on the agency's own systems in the first place.

Why client access is invisible

  • Access is granted client by client over years, to whoever needed it at the time.
  • Many platforms tie access to a personal profile or phone number rather than to the agency.
  • Shared logins for smaller tools live in a spreadsheet, a Slack message or someone's browser.
  • Two-factor codes go to whichever phone number was entered first.
  • The agency's offboarding checklist covers its own tools, not the client's.

No one person has the full picture. Each specialist knows what they personally hold, and nobody knows what everyone holds.

Why it matters beyond the inconvenience

A former employee with admin access to a client's page or ad account is a security risk even if they mean no harm, because their own account could be compromised. Clients are rightly unhappy to learn that someone who left still has access to their spend. Work stalls while access is recovered, and for some platforms recovery is slow and out of your hands.

The access register we build

  1. A register of every client platform, listing who at the agency holds access, at what level, and whether it is through an agency business account or a personal profile.
  2. Where a platform has an API that lists users, such as Google Ads manager accounts or Meta Business Manager, the register is filled and refreshed automatically.
  3. Shared logins for tools without proper user management are moved into a team password manager such as 1Password or Bitwarden, with folders per client and access per role.
  4. Two-factor codes for shared logins are held in the password manager or on an agency-owned device, so they do not depend on one person's phone.
  5. When someone is marked as leaving in your HR tool or a simple form, a leaver checklist is generated from the register: every client access they hold, what to remove and what to transfer first.
  6. The checklist is worked through before the last day, and anything that cannot be removed yet is flagged with an owner.
Type of accessRisk when someone leavesWhat the register does
Ad accounts via manager accountLow if removed centrallyLists users, flags leavers
Social pages via personal profilePage stuck with a personal accountFlags personal ownership early
Shared tool loginsPassword in someone's browserMoves it into the password manager
Two-factor on a personal phoneCodes leave with the personMoves codes to agency control
Client website adminNamed or shared admin userRecords it and removes on leaving

The register also works the other way. When a client leaves, the same list shows every access your staff hold to that client's accounts, so everything is removed together.

What the next leaver looks like

Someone hands in notice. The ops lead generates the leaver checklist from the register and sees every client account involved. Personal-profile page roles are transferred to the agency business account in the notice period. Shared logins are already in the password manager, so the password is changed and nothing is lost. On the last day, the checklist is complete and the client accounts no longer depend on someone who has left.

Signs this could happen to you

  • Some client pages or ad accounts are held through staff members' personal profiles.
  • Two-factor codes for client tools go to employees' own phones.
  • Shared passwords sit in spreadsheets, chat messages or browsers.
  • Offboarding covers your own systems but not client accounts.
  • Nobody can list who holds access to a given client's accounts.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do we need a password manager?

For shared logins, a team password manager is the safest home. If you already use one, we organise it by client and connect it to the register.

Can the register find everyone with access automatically?

Only for platforms whose APIs list users. The rest are recorded when access is granted and checked in a periodic review.

Does this make us compliant with data protection rules?

It gives you a clear record of who can reach client data, which helps. What your obligations are is a question for your own adviser.

Will it lock people out by mistake?

No. It produces a checklist for a person to work through. Removals are done by your team, not by the system on its own.

What does the cost depend on?

How many platforms and clients you manage, and how many of those platforms can be read through an API.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin leaks out of your agency

Describe how a normal month runs at your agency: how retainers are sold, how time is logged, where client work is tracked and which tools you already pay for, such as Harvest, Float, Asana, Xero or HubSpot. We will tell you what we would build, what we would leave alone, and if a setting in a tool you already own would fix it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →