Playbook, marketing agency

Who has access to what, when the accounts belong to the client

In most trades this is a customer locked out of a supplier's portal. Here it is the reverse: the agency holds a seat on accounts the client owns, and the questions are about who at the agency can see what, how a leaver is removed, and what happens when somebody tidying up a user list takes the agency out of an account mid campaign.

Why this is not the general answer

The handling pattern for account access problems holds across every trade. What follows is the part that does not.

  • The accounts belong to the client, so the agency's access is granted rather than owned, and it can be withdrawn at any moment without warning or explanation.
  • Access is usually removed by accident rather than by decision, when an administrator on the client side reviews a user list, and the first anybody knows is that a scheduled change cannot be made.
  • Freelancers and subcontractors in the delivery chain need access too, which makes who holds a seat a data protection question and not only an operational one.
  • Asking for access is the moment a prospect is most suspicious of an agency, so the published request has to name which level is needed and why each one, rather than asking for administrative rights everywhere and hoping.

How it arrives

  • how do we remove your team from our accounts
  • what level of access do you actually need
  • someone at our end removed you by mistake
  • who at your agency can see our data
  • does your freelancer have access to our accounts
  • we are changing agency how do we get you off the accounts

What has to be indexed for this to work

Material behind this answer
The access levels you request, with a reason for eachWhich seat on which kind of account, at what level, and what it is needed for. A request that asks for the highest level everywhere is the one clients refuse, and the reason attached is what gets it granted.
How a client removes the agency, in their own handsThe plain statement that it is theirs to withdraw, and roughly how. Publishing it is a trust move: an agency that explains how to remove itself reads as one that does not rely on being hard to leave.
Internal access control, described honestlyWho inside the agency has access, whether anybody outside it does, how a leaver is removed and how quickly. Larger clients ask this, and it belongs next to the data position rather than buried in it.
What is lost when access endsHistory, saved audiences, reporting configurations, anything built inside an account. Clients changing agency assume it all transfers, and finding out afterwards is the worst version of this conversation.

The reply

A reply worth copying
Those accounts are yours, so access to them is yours to grant and to withdraw whenever you want, and our published position explains which levels we ask for and what each one is needed for [1]. If access came off and something is scheduled to run, that needs the account team today rather than a page, because I cannot see any account or request a seat. On who inside the agency can see what, and anybody outside it involved in delivery, our data position covers it [2].

The opening sentence gives the client the answer they were braced to argue for, which is the fastest way to make the rest credible. It flags the live consequence of removed access without pretending to know whether there is one. And it points at the internal position rather than reassuring, because reassurance is exactly what a suspicious question does not want.

Where it stops

The trigger. The visitor asks for access to be granted or removed, says something has stopped working, or offers a login.

The handover, worded
Access is changed by people with the account open, never in a chat, and no login should be typed here. Leave your name and an email with what needs changing and the account team will pick it up.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never ask for or accept a username, a password, an invite code or a one time code.
  • Never confirm that a named person at the agency does or does not have access to an account.
  • Never say access has been granted, removed or restored, because nothing here touches an account.
  • Never suggest a client grant a higher level of access than the published request describes.

Questions

Should we publish how a client removes us?
Yes, and it is one of the few pages that earns goodwill simply by existing. Clients who feel locked in behave like clients who are looking. An agency documenting its own removal is making a claim about the work rather than about the lock.
Can it grant or revoke anything?
No. It reads what you publish and writes nowhere, so every access change ends with a person. What it removes is the round of emails asking which level is needed and why.
Somebody typed a password into the chat. What now?
Treat it as exposed and have it changed. The assistant should refuse credentials in its wording and the fallback should repeat that, but the real fix is never asking for them anywhere in your material, because people copy the pattern they are shown.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.