Every account we may ask you to open up, on one page.
You keep ownership of everything. We get a partner seat or a named user, you can take it away in two clicks, and we never hold a password. Find your platform in the table, follow the link, and reply "Done" to your onboarding email when it is granted.
What we need, platform by platform
Only the rows that match your engagement apply. Your onboarding email lists the ones we need from you. Times are for the person granting it, once they are logged in as an admin.
| Platform | What we need | Who grants it | Time it takes | Link |
|---|---|---|---|---|
| Meta Business Manager | Partner access for Business ID 570563043895208. For a brand-new advertiser, Admin for stephen@thegrowthbully.com so we can build the ad account inside your portfolio. | An Admin on your Business Manager | 5 minutes | Meta |
| Facebook Page | Assigned to the partner with Ads and Content. Page must sit in your Business Manager, not on a personal profile. | Page admin | 2 minutes | Meta |
| Meta ad account | Assigned to the partner with Manage campaigns. Your card stays on it; ad spend goes from you to Meta. | Ad account admin | 2 minutes | Meta |
| Instagram account | Added to your Business Manager, assigned to the partner with Create ads, and connected to the ad account. | Business Manager admin | 5 minutes | Meta |
| Meta pixel / dataset | Assigned to the partner with View and manage. Owned by you, never by us. | Business Manager admin | 2 minutes | Meta |
| Meta Leads Access | Partner listed under Leads Access so instant-form leads can reach your CRM. | Business Manager admin | 2 minutes | Meta |
| Google Ads | Accept our manager link request, or add stephen@thegrowthbully.com as Admin. Billing stays on your card. | Google Ads admin | 3 minutes | |
| Google Analytics (GA4) | Editor on the property for stephen@thegrowthbully.com. | Property Administrator | 2 minutes | |
| Google Tag Manager | Publish permission on the container, or we create a container in your account. | Container Admin | 2 minutes | |
| Search Console | Full permission on the property. | Verified owner | 2 minutes | |
| Google Business Profile | Manager on the profile. | Primary owner | 2 minutes | |
| Webflow | A workspace seat, or site access as a collaborator. You buy the site plan. | Workspace owner | 3 minutes | Website |
| WordPress | A user with the Administrator role for stephen@thegrowthbully.com. | Existing Administrator | 2 minutes | Website |
| Shopify | Collaborator access (request code from you, request from us, approval by you). | Store owner | 5 minutes across two replies | Website |
| Domain and DNS | A handful of records on new subdomains, pasted by whoever holds your DNS. No change to your main domain or your corporate email. | Your IT team or web partner | 15 minutes to paste, up to a day to verify | Website |
| Content admin on the company page; Campaign Manager access for ads. | Super admin of the page | 2 minutes | Social | |
| TikTok | Partner in your Business Center and the ad account assigned to us. | Business Center admin | 5 minutes | Social |
| Your CRM | Nothing to grant. We build it and send you the login. If no invite arrived, reply BLOCKED. | Us | Same day | CRM |
| Stripe, bank, card | No access, ever. You pay our invoices through our billing link or by transfer; you pay ad platforms on your own card inside your own accounts. | Nobody | None | Billing |
Rules we follow with your accounts
We never take ownership
Your Business Manager, ad accounts, pixel, Google properties, Tag Manager container, domain and creative files belong to you. We are added as a partner business or a named user. If a previous agency created an asset inside their own portfolio, we help you claim it into yours rather than repeating the mistake. The one exception is a brand-new advertiser with nothing set up yet: even then you create the Business Manager, and we build the ad account inside it. The full sequence is in the Meta ad account setup guide.
You can revoke access in two clicks
Every grant on this site is reversible from your side without asking us. On Meta it is Business Settings → Partners → The Growth Bully → Remove, which removes all of our people at once. On Google it is removing the user or the manager link. On WordPress it is deleting the user. Access ends the moment you click, and nothing of yours goes with it.
What we never touch
- Your corporate email. No change to the main domain's MX, SPF or DMARC records, and no access to any staff mailbox. Anything we send is from a subdomain or a mailbox you connect yourself.
- Your main website. For campaign builds, pages are hosted by us on a subdomain such as
go.yourdomain.com. Where we do need the site itself (pixel, Tag Manager, a booking widget), we ask for a named user and tell you what will be installed before it goes in. - Your billing. We ask for Manage campaigns on ad accounts, not Manage ad account. We cannot add or remove payment methods, and we never see card details.
- Your passwords. Partner and user access replaces password sharing on every platform that supports it. Where a platform has no roles (a personal LinkedIn profile, an older CMS), the password comes to us through a one-time link and you change it when the work is done.
- Your data subjects. Forms collect name, contact details and stated interest. No health, medical or financial-status fields. Requests from individuals about their data are forwarded to you and never answered by us.
Passwords only through a one-time link
If a password has to travel at all, it travels once and then destroys itself. Use onetimesecret.com or the share feature in your password manager (1Password, NordPass, Bitwarden and LastPass all have one). Paste the password, generate the link, send the link. Never put a password in an email body or a chat message, even to us. We will ask you to reset it if you do.
- Open onetimesecret.com. Paste the password into the box. Leave the passphrase empty unless you will send it separately.
- Click Create a secret link. Copy the link.
- Send the link to
stephen@thegrowthbully.com. The username can go in the same email; the link cannot be read twice. - When the work is finished, change the password. We do not need it after that.
For your IT team
Larger organisations route access through IT or a data-protection officer, and we would rather hand them a ticket than a chase. Forward this section as it stands. Every row has a rollback that takes effect immediately and needs no action from us.
| System | Permission requested | Scope | Rollback |
|---|---|---|---|
| Meta Business Manager | Partner link to Business ID 570563043895208 | Only the assets you assign. No ownership, no billing rights, no named personal accounts. | Business Settings → Partners → Remove. Immediate. |
| Meta ad account | Manage campaigns | Build, run and report on ads. Not Manage ad account: no payment methods, no account settings. | Remove the asset from the partner. |
| Facebook Page | Ads and Content | Run ads as the Page, publish approved organic posts. No Page ownership, no removing admins. | Remove the asset from the partner. |
| Instagram account | Create ads | Instagram placements on ads. Full Instagram control only if organic posting is in scope, and then Content is added. | Remove the asset from the partner. |
| Meta pixel / dataset | View and manage | Read events, configure standard events. Dataset stays in your portfolio. | Remove the asset from the partner. |
| Google Ads | Manager account link, or Admin user | Campaign management and conversion setup. Payment profile stays yours. | Admin → Access and security → Managers → Unlink, or remove the user. |
| GA4 | Editor on the property | Events, conversions, audiences. Not Administrator: cannot add users or delete the property. | Property access management → remove user. |
| Google Tag Manager | Publish on the container | Add and publish tags. Not account Administrator. | User Management → remove user. |
| DNS | Records pasted by your team on two new subdomains | No change to apex records, MX, root SPF or corporate mail. Exact rows are on the DNS page. | Delete the records. Sending stops within one TTL. |
| Website CMS | Administrator user (WordPress) or collaborator (Shopify) | Tracking tags, consent banner, landing pages. Declared in writing before anything is installed. | Delete the user or revoke the collaborator. |
What to whitelist
If your organisation filters outbound email or blocks unknown senders, add these so our messages and the platform invites reach the right people:
- Sender domain
thegrowthbully.com(all of our staff mail). - Invites from Meta arrive from
facebookmail.com; from Google,google.com; from your CRM,leadconnectorhq.comandmsgsndr.com. - If we host campaign pages, the subdomain
go.yourdomain.compoints atsites.ludicrous.cloud. Nothing on your network needs to change; this is a public DNS record only.
We can also supply a change-request pack (one page per change with risk rating, blast radius, rollback and verification test) if your IT process needs one. Ask in your reply.
Who owns what, and what transfers when we stop
This comes up when a data-protection officer asks whose privacy policy applies, and again when an engagement ends. The short version: you own the asset, we hold a seat on it, and the seat is the only thing that changes.
| Asset | Owner | Our role | When we stop |
|---|---|---|---|
| Business Manager | You | Partner (or Admin person for a first-time build, downgraded to partner afterwards) | You remove the partner. Everything stays. |
| Ad account | You | Manage campaigns | Campaigns, history, audiences and billing stay in your account. We hand over a written learnings document. |
| Pixel / dataset | You | View and manage | Event history stays with you. If we placed the tag on pages we host, we remove it when the pages come down. |
| Tag Manager container | You (created in your Google account) | Publish | Nothing to transfer. If a container was created in our account before this rule, we transfer it on request. |
| GA4 property | You | Editor | Nothing to transfer. Data stays. |
| Domain and DNS | You | None. We tell you what to paste. | You delete the subdomain records. Your main domain was never touched. |
| Campaign pages we host | The design is yours; the hosting is ours | Builder and host | Pages come down at the end of the notice period. We supply exports of copy and images on request. |
| Creative files | You | Producer | Every final ad, video and document is in a shared folder from day one. Download and keep a master copy on your own storage; we do not keep folders open indefinitely. |
| CRM contacts and conversations | You | Builder and administrator | Export from Contacts at any time. See exporting your contacts. |
Common questions on this page
Why do you need Admin or full permissions rather than a limited role?
Because a limited role bounces back a week later asking for more. Editor on WordPress cannot install a pixel. Employee on a Business Manager cannot create an ad account. Viewer on GA4 cannot mark a conversion. We ask once for the level that lets us finish the job, we tell you exactly what that level can and cannot do, and you can take it away at any time.
A colleague is leaving or joining. How do we add or remove people?
If the asset lives in your own account (the normal case), you add or remove them yourself: on Meta under Business Settings → Users → People, on Google under the property's access management. If we built something inside our own account for you (an older setup), email us the person's name, email address and what they need to do, and we grant it the same day. Tell us about leavers too, so alerts and reports stop going to a dead mailbox.
You asked me for access months ago. Why are you asking again?
A new CRM account, a new ad account or a new Business Manager does not inherit earlier connections. Once a partner link is in place it persists, so if we are asking again, something on one side was rebuilt. Check Business Settings → Partners: if The Growth Bully is listed with the right assets, reply with a screenshot and we will look on our side.
Can we run it as "you direct, our team implements" instead of giving you access?
Yes, on some engagements. We write the tracking brief, the campaign setup guide and the audience plan; your team executes inside your accounts. It is slower, and the delivery clock starts when the work actually begins on your side. Stephen will confirm whether it suits your scope.
Does your access let you see our customers' personal data?
Only what the platforms already expose to a campaign manager: aggregated performance, and the lead details that arrive through forms we build. Nothing from your corporate mail, your CRM outside the campaign sub-account, or your accounting. We act as a processor, you remain the controller, and any request from an individual about their data is forwarded to you.
Who on our side should do the granting?
Whoever is Admin on the account today, which is often not the person we are speaking to. Before you start, check the People or Users page on the platform and find your own name. If it says Employee, Standard or Viewer, ask the Admin to do the grant or to promote you first. Sending the page link to that person is faster than trying to work around the role.
Do you need access to our Stripe or bank?
No, and we will never ask. Our invoices are paid through our own billing link or by bank transfer. Ad spend is paid by you to Meta and Google on your own card inside your own accounts, and we charge no percentage of it. If anyone claiming to be from The Growth Bully asks for card or banking logins, stop and phone Stephen.
Stuck? Email stephen@thegrowthbully.com with a screenshot of the whole window.