Who should own your marketing accounts and data?
Your company should own its domain, website, advertising accounts, analytics properties, CRM, and source files. An agency should receive named, role-based access that can be reviewed or removed without losing the business history.
Websites, tracking, automation, and technical search
10 min read · Published August 30, 2026

Should your agency own your marketing accounts?
No. Your company should be the verified owner or primary administrator of every critical marketing asset. The agency should work through its own named users or manager account. That arrangement protects history, makes permissions auditable, and lets either side end the engagement without holding the business hostage.
This is not about distrusting agencies. It is basic operational hygiene. Good agencies also benefit because their work is easier to audit, staff changes are cleaner, and nobody has to share passwords in a spreadsheet.
A recent small-business discussion on Reddit described a company spending heavily on advertising and agency fees while lacking direct access to its own accounts. The numbers in that post are one person's account, not market evidence. The anxiety is still instructive: access becomes painfully visible when a relationship starts to fail.
What should the client own?
Ownership should sit with a company-controlled identity wherever the platform allows it. Agency staff receive the minimum access needed to do the agreed work, ideally through an agency manager account or named business email.
| Asset | Primary owner | Agency access |
|---|---|---|
| Domain registrar and DNS | Client company | Limited role only when changes are in scope |
| Website hosting and CDN | Client company | Named developer or administrator role |
| CMS and source repository | Client company | Named editor or contributor access |
| Google Ads | Client company | Linked agency manager account |
| Meta and LinkedIn advertising | Client business portfolio | Partner or named user access |
| Google Analytics and Tag Manager | Client company | Role-based property or container access |
| Google Search Console | Client verified owner | Full or restricted user as needed |
| CRM and marketing automation | Client company | Named role with scoped permissions |
| Creative source files | Client company under the contract | Agency working access |
| Call tracking and reporting dashboards | Client company | Named administrator or analyst access |
Why does ownership matter if the relationship is good?
Because business history has value. Campaign learning, conversion settings, audiences, domain reputation, analytics annotations, and source files become more useful over time. Rebuilding them after a dispute costs money and creates measurement gaps.
Google's own products are built around role-based access. Google Ads lets an agency link an existing client account to a manager account. Google Analytics supports users at account or property level. Search Console separates verified owners, delegated owners, full users, and restricted users. Shared passwords are not required for normal agency work.
- Continuity. A staff or agency change does not erase historical data or interrupt billing.
- Security. Each person has a named identity, appropriate permissions, and an access trail.
- Accountability. The client can inspect spend, changes, results, and who made them.
- Recovery. The business can remove access without recreating its entire marketing stack.
- Compliance. Consent settings, customer data, and vendor permissions stay under company oversight.
Should you ever share a password with an agency?
Avoid shared passwords when the platform supports separate users. A shared login hides who made a change, complicates offboarding, and often spreads multi-factor authentication codes through insecure channels.
If a legacy platform has no user roles, use a company-controlled credential vault, require multi-factor authentication, document who has access, and rotate the credential when the engagement ends. Do not send production passwords through chat or email.
What should you check before hiring an agency?
Ask the ownership question before work begins, then put the answer in the contract. A verbal promise is difficult to enforce during a rushed handoff.
The contract should also separate ownership from licensing. A stock image, font, software subscription, or proprietary agency tool may have limits even when the finished deliverable belongs to the client. List those exceptions while everyone is still friendly.
- Who creates each new account, and under which company identity?
- Which roles will agency staff receive?
- Will subcontractors receive access, and how will the client know?
- Who controls platform billing and recovery methods?
- Where will source files, copy, research, and campaign documentation live?
- What does the agency export or transfer when the engagement ends?
- How quickly will agency access be removed after termination?
- Which intellectual property belongs to the client after payment?
Run this account ownership audit
Create one register of critical assets. For each asset, record the login URL, verified owner, administrators, billing owner, recovery email, multi-factor authentication method, agency access, and last review date.
- Confirm that at least two trusted people inside the company can recover the domain and primary email system.
- Check that the agency uses named access rather than a former employee's login.
- Export current user lists from advertising, analytics, CRM, CMS, hosting, and reporting platforms.
- Remove dormant users and reduce permissions that are broader than the work requires.
- Store contracts, scopes, brand files, campaign notes, and tracking documentation in a client-controlled location.
- Schedule a quarterly permission review and an immediate review after any staffing change.
What should you do if the agency controls everything?
Do not start by threatening to cancel. First, build an inventory, preserve available evidence, and request a written transition plan with dates. Sudden access changes can interrupt campaigns, DNS, forms, or reporting.
Ask for administrator access, account IDs, billing records, tracking maps, audiences, creative files, source files, platform support history, and a list of active automations. Confirm what will happen to campaigns during the handoff. If the agency refuses, review the contract and contact the platform or a qualified lawyer for the assets that carry legal or financial risk.
Do not create duplicate advertising accounts as a first reaction. Platforms may treat the duplicates as suspicious, and the business can lose valuable history. Recover or transfer the existing asset when the platform supports it.
How Branddirr handles client access
Branddirr's operating position is simple: the client should be able to leave without losing its business history. Scope documents name the owner, access required, systems affected, and handoff obligations before paid work begins.
A practical setup may differ by platform, but the principle does not. Branddirr should not need ownership of a client's domain or primary business accounts to do legitimate work. Where a platform requires a particular arrangement, the reason and recovery path should be written down.
Questions buyers ask
Direct answers for the questions that usually appear before a buying decision.
Can an agency create a Google Ads account for us?+
It can, but the safer structure is a client-controlled account linked to the agency's manager account. Confirm billing, administrator access, and recovery details before campaigns launch.
Should an agency be an owner in Google Search Console?+
Usually the client remains the verified owner and grants the agency the user level required for its work. Search Console documents owner, full user, and restricted user roles, so permanent verified ownership is rarely necessary for routine SEO delivery.
Who should own website code and design files?+
The contract should say. For a custom client-funded build, Branddirr's default expectation is that the client receives the agreed source files and administrative access after payment, subject to clearly listed third-party licenses.
How often should access be reviewed?+
Review critical platforms at least quarterly and whenever an employee, contractor, or agency relationship changes. Domain, email, billing, and recovery access deserve the strictest review.
Need help applying this to your business? See Growth Audit.
