Meta Business Manager Setup: Roles & Access
Set up your Meta Business Manager portfolio the right way: add ad accounts and Pages, assign roles and permissions, and grant partner access safely.
Updated March 2027 · Likit Sae Lee, CTO

Meta Business Manager (now inside Meta Business Suite) is the parent container that owns your ad accounts, Pages, Instagram, pixels and catalogs, so you manage them as a business rather than from a personal profile. Set it up in the right order: create one business portfolio at business.facebook.com, claim or request the Pages and ad accounts you already own, add people with either full control or partial access, connect payment methods, and grant agencies partner access by their business ID instead of your password. Do this once and you avoid the permission gaps that get accounts restricted, which matters on a platform where Facebook ads can reach about 2.28 billion people (DataReportal, January 2025).
You are ready to run ads, or an agency just asked for access, and suddenly you are staring at a maze of business settings, ad accounts, Pages, roles, and partner requests. Set this container up wrong and you hit permission errors, locked-out teammates, and the restrictions that follow when Meta cannot tell who owns what. Set it up right once, and every ad account, Page, and teammate sits in a tidy structure you actually control. This guide walks the full Meta Business Manager and Business Suite setup: the business portfolio, your assets, roles and permissions, payments, two-factor, and partner access.
What the business portfolio actually is, and why it exists
Before you touch a single setting, get the mental model right, because almost every permission headache traces back to a fuzzy one. Meta's account structure is a set of nested containers. At the top sits the business portfolio, the entity formerly called your Business Manager account. It owns things: ad accounts, Facebook Pages, Instagram accounts, the Meta Pixel or dataset that tracks your site, product catalogs, and the people who work on all of them. Business Suite is the dashboard you see day to day, and Business settings (which opens from the gear inside Business Suite) is where the portfolio and its ownership live. You post, reply, and boost in Business Suite. You assign who can do what in Business settings. Same login at business.facebook.com, two different jobs.
The reason to route everything through a portfolio instead of running ads off your personal profile is separation. Your personal Facebook profile is a person. A business portfolio is a company, and it can hold assets, add and remove staff, carry its own payment methods, and be verified as a real business. When an ad account, a Page, and a payment card all hang off one individual's login, you have a single point of failure: that person leaves, gets locked out, or gets phished, and the business loses everything at once. A portfolio decouples the assets from any one human. That is not bureaucracy, it is the thing that keeps you in control.
This matters more than it used to because the surface is enormous and the stakes are real. Facebook ads could reach about 2.28 billion people in early 2025, per DataReportal, and Meta pulled in $196.18 billion in advertising revenue across full-year 2025, up 22% year over year on its own investor numbers. That scale is why fraud follows the money: Cofense ranked Meta the second most-spoofed brand in credential phishing in early 2024, behind only Microsoft. The setup steps below are equal parts organization and defense. Get the container right, and the rest of your advertising sits on solid ground.
One scoping note. This guide is about the parent container and its permissions, not the mechanics of creating a single new ad account and filling out its currency and time zone form. Where those overlap, the section below points at what to decide, then moves on.
Step 1: Create the business portfolio the right way
Go to business.facebook.com and create a business portfolio. Meta asks for a business name, your name, and a business email. Three small decisions here save you pain later.
First, name the portfolio as the business, not as a campaign or a nickname. This name shows to partners and in access requests, so "Acme Retail" reads better than "my ads test 2." Second, use a business email you actually control long term, ideally on your own domain, not a personal address that might disappear. Third, understand that the portfolio is created and owned by your personal Facebook profile acting as its first admin. You are not creating a separate faceless login; you are attaching a business entity to your existing account and giving it admin rights. That is normal and correct. What you should not do is create a brand-new fake profile to "keep things separate," because Meta treats duplicate or fake profiles as a policy risk and it becomes the exact fragile single point of failure you are trying to avoid.
A personal profile can create only a small number of portfolios, so treat the one you make as the real, permanent home rather than spinning up throwaways. If you manage genuinely separate businesses, a separate portfolio per business is reasonable. If you manage several brands under one company, keep them as separate assets inside one portfolio instead. The dividing line is legal ownership, not convenience.
Once the portfolio exists, do the identity housekeeping early. Add your business details under Business settings, then Business info: legal name, address, and website. This is also where, later, you complete business verification by uploading documents that match your legal entity. You do not need verification to run your first ads, but several higher-trust features and advanced API access require it, and a verified business is a stronger, harder-to-restrict account. Doing the paperwork before you are in a hurry is always easier than doing it while an account sits in review.
Step 2: Add and organize your assets (Pages, ad accounts, pixels, catalogs)
With the container in place, bring your assets into it. In Business settings you will see a left rail listing asset types. The common ones for an advertiser look like this.
| Asset type | What it holds | How you usually add it |
|---|---|---|
| Facebook Page | Your brand's public presence and organic posts | Claim (if you own it) or request access (if a client owns it) |
| Instagram account | The linked Instagram profile ads can run from | Connect it to the portfolio and the Page |
| Ad account | Campaigns, billing, and spend | Create new, claim an existing one, or request access |
| Meta Pixel / dataset | Website and conversion tracking | Create in Events Manager, then assign to people and ad accounts |
| Product catalog | The product feed for shopping and dynamic ads | Create in Commerce or Catalog Manager, then assign |
The decision that trips people up most is claim versus request. Claiming an asset pulls ownership into your portfolio: use it for Pages and ad accounts your business genuinely owns and should keep. Requesting access grants you a working role on an asset that stays owned by someone else: use it when you help manage a client's Page or a partner's ad account. Get this backwards and you create ownership disputes that are slow and painful to unwind, because moving a claimed asset back out requires the current owner to release it. Rule of thumb: claim what is yours, request what belongs to someone else.
On ad accounts specifically, know the creation limit before you plan your structure. A brand-new portfolio can create exactly one ad account until Meta confirms your first payment, according to Meta's Business Help Center. Only after that first confirmed payment, and with a clean track record, does the cap rise. You can check your current limit under Business settings in the business info area. The practical consequence: do not architect a plan that assumes five fresh ad accounts on day one. Start with the one, get a payment through it, and let the limit grow. If you already run ad accounts elsewhere, claiming or requesting them is the faster path than trying to spin up new ones you are not yet allowed to create.
Two settings on an ad account are locked at creation and cannot be changed afterward: its currency and its time zone. Every bill, budget, and report reads in that currency and aligns to that time zone forever, so choose the currency you actually sell and pay in, and the time zone your team works in, before you spend a cent. That single choice is the one piece of the individual-account setup worth flagging here even though the container is the focus.
Step 3: Roles and permissions, the part that prevents most errors
This is the heart of a clean setup, and the source of most "I can't access anything" tickets. Meta's model works on two layers, and you have to think about both.
The first layer is portfolio-level access. When you add a person to the portfolio, you give them one of two levels: full control or partial access. Full control (the admin level) can manage everything, including settings, billing, adding and removing other people, and claiming or deleting assets. Partial access can only see and work on the specific assets you explicitly assign them, and nothing about the business settings themselves. The second layer is asset-level permissions. For each asset you share with a partial-access person, you toggle exactly which tasks they can perform. Portfolio access always caps asset access: someone on partial access cannot do more than the tasks you granted, no matter what an asset toggle says.
Here is how the two access levels compare at a glance.
| Capability | Full control (admin) | Partial access |
|---|---|---|
| Work on assigned assets (create ads, post, reply, view reports) | Yes | Yes, only where assigned |
| See the full list of business assets and settings | Yes | No, only assigned assets |
| Add, remove, or change other people's access | Yes | No |
| Manage payment methods and billing | Yes | Only if granted the finance task |
| Claim, add, or delete assets | Yes | No |
| Turn on the two-factor requirement | Yes | No |
The principle is least privilege. Give full control to the one or two people who genuinely own the account, usually a founder and a trusted operations lead. Everyone else gets partial access, scoped to only the assets and tasks their job needs. A media buyer needs Manage ads on the ad account and Create content on the Page, not the ability to add and remove people. A community manager needs Messages and Community activity, not billing. A finance person needs the finance task on the ad account, not campaign controls.
Within a Page, the task toggles you will assign include managing the Page, creating content, moderating messages and comments, running ads, and viewing insights. Within an ad account, the tasks split roughly into managing campaigns, viewing performance, and managing account finances (the billing and payment side). Older Business Manager setups exposed these as named business roles such as finance analyst and finance editor; the current interface leans on task toggles instead, but the intent is identical: separate who can spend from who can see, and separate both from who can restructure the account. When someone leaves, you remove them from the portfolio once and their access to every asset ends with it. That single off-switch is the entire reason to route people through the portfolio rather than adding them Page by Page.
Step 4: Add people and partners without handing over the keys
There are two distinct ways to give access, and confusing them is a classic mistake. You add people (individuals who log in with their own Facebook accounts and belong to your business), and you add partners (whole other business portfolios, typically an agency or a freelancer's own business).
To add a person, go to Business settings, then People, invite them by email, choose full control or partial access, then select the assets and tasks. They accept from their own account. Simple, and right for employees.
To add an agency, do not add the individual employees of that agency one by one, and never, ever share your login. Use partner access. Ask the agency for their business portfolio ID, a numeric ID they can read off their own Business settings. In your portfolio, go to Partners, choose to add a partner, paste that ID, and assign scoped access to the specific ad account, Page, or pixel they will manage. The agency's own portfolio now has a defined role on your asset, and their staff work through their own credentials under their own two-factor. You remain the owner. When the engagement ends, you revoke the partner in one click and every one of their people loses access at once, with no orphaned logins left behind.
A worked example shows why the structure pays off. Say you run one company with three brand Pages, and you bring on an agency plus two in-house staff. The clean setup: one portfolio owns all three Pages and two ad accounts (one created now, the second added after your first payment lifts the creation limit). Your operations lead gets full control. Your two staff get partial access, one scoped to Manage ads on both ad accounts, the other scoped to Create content and Messages on all three Pages. The agency is added as a partner with access to just the ad accounts, not the Pages or the payment methods. Six months later the agency contract ends: you revoke the partner, and nothing else in your account so much as flickers. No password changes, no hunting for stray permissions, no locked-out staff. That is the whole payoff of doing it in this order.
Step 5: Payment methods, two-factor, and business verification
Now lock the account down. Three settings do most of the security work.
Payment methods live at the portfolio and ad-account level, not on a person. Add your card or other payment method under Billing and payments in Business settings, and assign it to the ad account that will use it. Centralizing payment here, rather than on one buyer's personal card, means spend does not stop when a person changes. Ad accounts on automatic billing carry a billing threshold that rises as you build history: Meta charges you when you hit the threshold or on your monthly bill date, whichever comes first. Watch that first bill clear cleanly, because that confirmed payment is also what unlocks your ability to create additional ad accounts and starts building the account history that keeps costs and trust healthy. With the average price per ad up 9% across full-year 2025 on Meta's own numbers, a stable, trusted billing relationship is not a nice-to-have.
Two-factor authentication is the single highest-value defensive step, and Meta lets a portfolio admin require it. Under Security Center in Business settings, set the two-factor requirement to either admins only or everyone. Admins only covers the people who can touch billing and settings; everyone is the stronger posture and the right default for any account with real spend, because it forces every person who can log in to secure their own account first. This directly counters the threat pattern in the wild: the phishing campaigns Cofense documented in early 2024 impersonated Meta's own policy and support notices to harvest logins and hijack ad accounts, and an enforced second factor is what stops a stolen password from becoming a stolen account. It costs you nothing and takes minutes.
Business verification is the third layer. Under Business info or the Security Center, you can verify your business by submitting documents that match your legal entity: a registration document, a utility bill, or similar proof of name and address. Verification is not required to run your first campaigns, but it unlocks higher-trust features, is a prerequisite for advanced API access and for some partner arrangements, and generally makes your account more resilient to restriction because Meta can confirm a real business stands behind it. Do it early, while you are not under time pressure, and keep the documents consistent with the name you entered in Step 1.
Step 6: The permission errors that trigger restrictions, and how setup prevents them
Most account restrictions are not random. They are trust signals firing, and a clean setup removes the avoidable triggers. Here are the common ones and the setup step that defuses each.
The first is running everything off a single personal profile. If that profile gets phished, disabled, or simply belongs to someone who leaves, every asset attached to it is at risk in one stroke. The fix is the portfolio itself: assets owned by the business, not the person, with more than one admin so no single lockout is fatal. The second is a brand-new account with no history trying to spend big or create many ad accounts at once. Meta reads that as risk. The fix is patience: one ad account, a clean first payment, then scale as the creation limit and billing threshold rise. Remember Facebook counted about 10 million active advertisers as far back as 2020 (Statista via Search Engine Land), and the platform has automated its trust checks accordingly, so a slow, legitimate ramp reads far better than an aggressive cold start.
The third trigger is unclear ownership: claiming an asset you should have requested, or a tug-of-war where two portfolios both think they own a Page. The fix is the claim-versus-request discipline from Step 2, claim what is yours and request what is not. The fourth is over-granting access, where too many people hold full control or an agency is handed admin over the whole portfolio. If any one of those accounts is compromised, the attacker inherits everything. The fix is least privilege plus partner access: full control for owners only, partial access scoped to the task, and agencies added as partners you can revoke instantly. The fifth is the security gap, an admin without two-factor, which is precisely what the phishing campaigns target. The fix is the enforced two-factor requirement from Step 5.
If an account does get restricted, the same clean structure is what lets you recover fast. A verified business, a real payment history, an enforced two-factor policy, and clear ownership give Meta everything it needs to confirm you are legitimate when you request a review through Account Quality. A messy account gives the review nothing to go on. You cannot make restrictions impossible, but you can make your account the boring, obviously-real kind that rarely triggers them and clears quickly when it does.
Getting the most out of a clean setup
A well-built portfolio is not a one-time chore, it is the thing you maintain lightly and forever. Set a reminder to review your People and Partners lists on a schedule, and remove anyone who no longer needs access, because stale permissions are a slow leak. Keep full control to the smallest possible group. Re-check that two-factor stays enforced after any staff change. Keep your business verification documents current so a name or address change never leaves you scrambling mid-review. And keep payment methods on the business, not on an individual, so a departing employee never takes your billing with them.
The reward for all of this is that the interesting work gets easier. Once the container, roles, and access are right, you spend your time on what actually moves results: the research into which angles are working, the creative you make and test, the campaigns you launch, and the numbers you read afterward. A platform like AdPlay.ai keeps that create-and-launch loop in one place, but the point stands with any workflow. The Business Manager setup is the foundation, quiet and unglamorous, that lets everything built on top of it stay standing. Do it once, do it in order, and you will not think about it again until it saves you.
By the numbers
Frequently asked questions
What is the difference between Meta Business Manager and Meta Business Suite?
They are two views of the same thing. Meta Business Suite is the day-to-day dashboard for posting, messages, insights and boosting across your Facebook Page and Instagram. Business Manager (now surfaced as Business settings inside Business Suite) is the control panel underneath it, where the business portfolio, ad accounts, people, roles, payment methods and partner access live. You post and reply in Business Suite; you set up ownership and permissions in Business settings. Both open from business.facebook.com.
Do I need a business portfolio to run Facebook ads, or can I just boost from my Page?
You can boost a post straight from a Page without a portfolio, but you should not run real ads that way. A business portfolio separates business assets from your personal profile, lets you add teammates and agencies with scoped roles, holds payment methods centrally, and keeps ownership clear if someone leaves. Without it, everything is tied to one person's login, which is exactly the fragile setup that leads to lost access and restrictions.
What is the difference between full control and partial access?
Full control (the admin level) lets a person manage everything: settings, billing, other people, and the ability to add or remove assets. Partial access lets a person work only on the specific assets you assign them, with task toggles such as create content, manage ads, respond to messages, or view insights, and nothing else. Give full control to the one or two people who own the account, and partial access to everyone else. Portfolio-level access always caps what an asset-level permission can do.
How many ad accounts can I have in one business portfolio?
A brand-new business portfolio can create exactly one ad account until Meta confirms your first payment, per Meta's Business Help Center. After that first confirmed payment and a clean track record, the creation limit rises over time. You can see your current cap under Business settings, then Business info. If you already own ad accounts elsewhere, you can also claim or request access to them rather than creating new ones, which does not count against the creation limit the same way.
How do I give my agency access without sharing my Facebook password?
Use partner access, never a shared login. In Business settings under Partners, choose to add a partner, enter the agency's business portfolio ID (a numeric ID they give you), and assign them scoped access to the specific ad account, Page or pixel they need. They log in with their own credentials through their own portfolio. You stay the owner, you can revoke access in one click, and nobody is passing passwords around.
Should I claim a Page or request access to it?
Claim a Page or ad account when your business owns it and it should live inside your portfolio permanently. Request access when someone else owns the asset (a client, or another business) and you only need to work on it. Claiming moves ownership into your portfolio; requesting grants you a role on an asset that stays owned by someone else. Choosing wrong is a common cause of ownership disputes, so claim what is yours and request what is not.
Is two-factor authentication required for Meta Business Manager?
Meta lets a portfolio admin require two-factor authentication for the people who access it, and turning it on is strongly recommended. In Business settings under Security Center you can set the requirement to admins only or to everyone in the portfolio. Given that Meta was the second most-spoofed brand in credential phishing in early 2024 (Cofense), enforcing two-factor across everyone who can touch billing or ads is one of the highest-value setup steps you can take.
Why does my ad account keep getting restricted, and how does setup help?
Restrictions usually trace back to trust and ownership signals: a brand-new account with no payment history, assets tied to a single personal profile, unverified business identity, or an admin account that gets phished. A clean portfolio setup addresses most of these: verify your business, enforce two-factor, keep full control limited to owners, use partner access instead of shared logins, and build a payment history before scaling. It does not guarantee you never see a review, but it removes the avoidable triggers.
Sources
- 1.DataReportal, Essential Facebook Statistics and Trends (2025)
- 2.Meta, Fourth Quarter and Full Year 2025 Results (Investor Relations) (2025)
- 3.Cofense, Unmasking a Cyber Attack that Targets Meta Business Accounts (2024)
- 4.Meta Business Help Center, About Business Portfolio and Asset Permissions (2026)
- 5.Meta Business Help Center, Find Your Business Portfolio's Ad Account Limit (2026)
- 6.Meta Business Help Center, Turn On the Two-Factor Authentication Requirement (2026)
- 7.Search Engine Land, Facebook Statistics for Marketers (cites Statista active advertisers) (2025)
Keep exploring
Turn ad research into winning ads
Research the ads that work, generate the creative on-brand, and launch to Meta, all in one tool.
7-day free trial · No credit card required
