The Monday after a leaving do
A senior paid social manager leaves on good terms. Two weeks later a client's Facebook page needs a change, and the page admin turns out to be his personal profile. The client's LinkedIn ads account needs a two-factor code that goes to his mobile. The login for a client's email marketing tool is in his browser's saved passwords. He is helpful when contacted, but he is now working at another agency, and everyone is uncomfortable.
Meanwhile the IT side of offboarding went fine: laptop returned, Google Workspace account suspended. None of that touched the client accounts, because those were never on the agency's own systems in the first place.
Why client access is invisible
- Access is granted client by client over years, to whoever needed it at the time.
- Many platforms tie access to a personal profile or phone number rather than to the agency.
- Shared logins for smaller tools live in a spreadsheet, a Slack message or someone's browser.
- Two-factor codes go to whichever phone number was entered first.
- The agency's offboarding checklist covers its own tools, not the client's.
No one person has the full picture. Each specialist knows what they personally hold, and nobody knows what everyone holds.
Why it matters beyond the inconvenience
A former employee with admin access to a client's page or ad account is a security risk even if they mean no harm, because their own account could be compromised. Clients are rightly unhappy to learn that someone who left still has access to their spend. Work stalls while access is recovered, and for some platforms recovery is slow and out of your hands.
The access register we build
- A register of every client platform, listing who at the agency holds access, at what level, and whether it is through an agency business account or a personal profile.
- Where a platform has an API that lists users, such as Google Ads manager accounts or Meta Business Manager, the register is filled and refreshed automatically.
- Shared logins for tools without proper user management are moved into a team password manager such as 1Password or Bitwarden, with folders per client and access per role.
- Two-factor codes for shared logins are held in the password manager or on an agency-owned device, so they do not depend on one person's phone.
- When someone is marked as leaving in your HR tool or a simple form, a leaver checklist is generated from the register: every client access they hold, what to remove and what to transfer first.
- The checklist is worked through before the last day, and anything that cannot be removed yet is flagged with an owner.
| Type of access | Risk when someone leaves | What the register does |
|---|---|---|
| Ad accounts via manager account | Low if removed centrally | Lists users, flags leavers |
| Social pages via personal profile | Page stuck with a personal account | Flags personal ownership early |
| Shared tool logins | Password in someone's browser | Moves it into the password manager |
| Two-factor on a personal phone | Codes leave with the person | Moves codes to agency control |
| Client website admin | Named or shared admin user | Records it and removes on leaving |
The register also works the other way. When a client leaves, the same list shows every access your staff hold to that client's accounts, so everything is removed together.
What the next leaver looks like
Someone hands in notice. The ops lead generates the leaver checklist from the register and sees every client account involved. Personal-profile page roles are transferred to the agency business account in the notice period. Shared logins are already in the password manager, so the password is changed and nothing is lost. On the last day, the checklist is complete and the client accounts no longer depend on someone who has left.
Signs this could happen to you
- Some client pages or ad accounts are held through staff members' personal profiles.
- Two-factor codes for client tools go to employees' own phones.
- Shared passwords sit in spreadsheets, chat messages or browsers.
- Offboarding covers your own systems but not client accounts.
- Nobody can list who holds access to a given client's accounts.