Denha NexusFeature · People and access

People and access: who sees what, who may do what, and who did it

An agency works with other people's money and other people's ad accounts, so access here is not a detail. Roles decide who sees the finances, who confirms the actions that move money, and who only reads. Sign-in is protected by a second factor, every action is recorded, and the data of one organisation is out of reach of another on every single request.

14 days on any plan, no card needed to start. After the click: a three-field form and the workspace.

What you set up

Roles
What a person sees and what they may confirm
Sign-in
A second factor with backup codes, and a list of active sessions
Keys
Keys for outside systems, kept apart from the accounts of people
Log
Who changed what and when, across the whole system
Separation
Organisations see nothing of each other on any endpoint
Retention
How long data is kept and the rules for deleting it

Access to ad accounts lives in the tokens of the organisation and is revoked on the platform side. The system neither stores nor asks for ad account passwords.

01What it looks like

People and access in ADS Beast

Screen recording: team roles, the second factor and active sessions, keys for outside systems, and the action log across the whole system.

A screen recording of the product in the ADS Beast demo workspace. The clients and campaigns on screen exist for the demonstration; no real advertiser stands behind them.
02What it does

What the section does

01

Roles built around what a person actually does

An ads specialist does not need the agency finances, and a bookkeeper does not need bid controls. Roles split access to the money, to the settings, and to confirming the actions that move a budget.

  • Roles with different access to finance and settings
  • The right to confirm money actions, separate from the right to propose them
  • Access to one client rather than the whole portfolio where that is what you want
02

A sign-in that a stolen password does not open

A second factor with backup codes, and a list of active sessions with the option to close somebody else's. These are dull things that matter exactly once - and on that occasion they are either there or they are not.

  • A second factor and backup codes
  • A list of active sign-ins with their devices
  • A session closed remotely
03

Organisation data is kept apart on every request

The separation is not checked once at the door but on every endpoint that accepts a client identifier. A request carrying somebody else's identifier is refused, even when it comes from a fully authenticated user of another organisation.

  • A client ownership check on every request
  • Public endpoints attribute a lead by a signed token, not by a field in the body
  • Secrets come back as a present or absent flag, never as a value
04

A log you can reconstruct events from

Who confirmed a budget change, who switched a placement on, who granted access and who revoked it. The log is not there to punish anyone but to rebuild the picture when something has gone wrong.

  • An action log across the whole system
  • Who confirmed each money action
  • A history of access granted and revoked
03How it works

How to set access up

Setting this up takes one evening, and then it needs no attention until the team changes.

  1. 01

    Add the people

    Invite the team and give roles that match what each person does.

  2. 02

    Switch on the second factor

    Above all for the people who confirm money actions.

  3. 03

    Issue keys to systems

    Outside systems get keys of their own, not the account of a person.

  4. 04

    Set the retention

    How long data is kept and the rules for deleting it under agency policy.

04How it fits together

Where the data comes from and what you get out of it.

Ad accounts hand over their statistics through your own OAuth apps. The system puts them into one picture, agents look for what to change, and only what you approve gets changed.

Platforms
  • Google AdsOAuth
  • MetaOAuth
  • TikTokOAuth
  • LinkedInOAuth
  • Microsoft AdvertisingOAuth
  • Windsor.aiAPI key
ADS Beast
Combines and checks
  • sync every 15 minutes
  • conversion to USD at the day rate
  • reconciliation with the native account
  • 90 days of history
What you get
  1. One spend summaryEvery account in one currency and one date window.
  2. Tasks from agentsWhat to change, where and why, linked to the row in the account.
  3. A person decidesBudgets, bids and statuses change only after approval.

Early access

See your own ad accounts the way the diagram shows them.

We are opening access to agencies in turn. Leave a work email and we will write when your turn comes, then help you connect the first account.

We use the email only to reply about access. Privacy policy

05Figures from the code
7
interface languages for the team
8
channels under one access model
4
notification channels with personal settings
06What it does not do

What the section does not do

  • It does not store ad account passwords - only access tokens, revoked on the platform side.
  • It does not show the values of keys and secrets in responses: what comes back is a present or absent flag.
  • It does not let anyone past the separation of organisations, however fully authenticated they are.
  • It does not delete the action log at the request of somebody whose actions are in it.
07Questions and answers

Questions and answers

Can a specialist see the agency finances?

Only if their role carries that access. Finances, contractor payouts and profit by client are closed off separately from the day-to-day advertising screens.

What happens if a user of another organisation supplies a client identifier that is not theirs?

The request is refused. Client ownership is checked on every endpoint that accepts it, not once at sign-in.

Does the system store ad account passwords?

No. The connection runs on access tokens issued and revoked on the platform side. The lifetime and scope of each token show in the Connection health section.

How do I give access to an outside system?

With a key of its own in the keys section, rather than a shared human account. The key is revoked independently, and its use shows in the log.

Invite the team and hand out access that matches what each person does

The first 14 days are free on any plan and you do not need a card to start. The second factor, the action log and the separation of organisations work on every plan.

14 days on any plan, no card needed to start. After the click: a three-field form and the workspace.