Most serious problems with business assets are access problems, not marketing ones. A clear meta business workflow keeps ownership, roles and documentation in order so a departure or a lost login is an inconvenience rather than a crisis.
Assets belong to the business
The recurring failure is a page or ad account effectively owned by an individual's personal profile. When that person leaves, changes roles, or loses access to their account, recovery is slow and sometimes impossible.
Assets should sit under the business structure with at least two current people holding full access. This costs nothing to set up and is very expensive to retrofit once contact with the original owner has been lost.
What to keep in order
- Every page, ad account and catalogue owned at business level.
- At least two current people with full administrative access.
- Agency and contractor access granted as partners, not personal logins.
- Access reviewed quarterly and removed promptly when people leave.
- Roles assigned by need rather than by seniority.
- Two-factor authentication on all administrative accounts.
- A written record of which assets exist and who is responsible.
Sharing a login is the one practice worth eliminating entirely. It defeats access logging, survives departures invisibly, and makes any later investigation impossible.
Separate roles deliberately
Not everyone who posts needs billing access, and not everyone who analyses results needs to be able to publish. Assigning the narrowest role that allows the work reduces both accidental damage and the impact of any single compromised account.
Keep a plain written record outside the platform of what exists and who is responsible. When something goes wrong, the useful question is usually "who can fix this", and that answer should not require a search through settings. Page-level review sits in the page audit checklist, and campaign structure in the campaign organization guide.
Common questions
How often should access be reviewed?
Quarterly, and immediately whenever someone leaves. Dormant access is the most common route to a compromised asset.
Should agencies own assets?
No. Grant partner access to assets the business owns, so the relationship can end without losing anything.
What if the original owner is unreachable?
Recovery is possible but slow. That difficulty is exactly why ownership should be arranged correctly beforehand.
Is two-factor authentication necessary?
On any account with administrative access, yes. It is the single most effective control available.
Who should hold billing access?
A small, named set, separate from the people publishing day to day. See contact.
What should be documented about assets?
What exists, who owns it, who has access and what it is used for. One page is enough, and it saves hours during any handover.
Should personal profiles be used for administration?
Access is always tied to a personal profile, which is precisely why the assets themselves must sit at business level rather than being owned by that profile.