---
title: "People and access: who sees what, who may do what, and who did it"
description: "Roles, two-factor sign-in, active sessions, keys for outside systems and an action log. Data from different organisations is kept apart on every request."
canonical: https://adsbeast.pro/features/en/team-security
language: en
section: features
product_route: https://adsbeast.pro/users
translations:
  - ru: https://adsbeast.pro/features/ru/team-security
  - uk: https://adsbeast.pro/features/uk/team-security
  - sk: https://adsbeast.pro/features/sk/team-security
  - es: https://adsbeast.pro/features/es/team-security
  - he: https://adsbeast.pro/features/he/team-security
  - ar: https://adsbeast.pro/features/ar/team-security
---
# People and access: who sees what, who may do what, and who did it

An agency works with other people's money and other people's ad accounts, so access here is not a detail. Roles decide who sees the finances, who confirms the actions that move money, and who only reads. Sign-in is protected by a second factor, every action is recorded, and the data of one organisation is out of reach of another on every single request.

## What you set up

- **Roles**: What a person sees and what they may confirm
- **Sign-in**: A second factor with backup codes, and a list of active sessions
- **Keys**: Keys for outside systems, kept apart from the accounts of people
- **Log**: Who changed what and when, across the whole system
- **Separation**: Organisations see nothing of each other on any endpoint
- **Retention**: How long data is kept and the rules for deleting it

Access to ad accounts lives in the tokens of the organisation and is revoked on the platform side. The system neither stores nor asks for ad account passwords.

## What the section does

### Roles built around what a person actually does

An ads specialist does not need the agency finances, and a bookkeeper does not need bid controls. Roles split access to the money, to the settings, and to confirming the actions that move a budget.

- Roles with different access to finance and settings
- The right to confirm money actions, separate from the right to propose them
- Access to one client rather than the whole portfolio where that is what you want

### A sign-in that a stolen password does not open

A second factor with backup codes, and a list of active sessions with the option to close somebody else's. These are dull things that matter exactly once - and on that occasion they are either there or they are not.

- A second factor and backup codes
- A list of active sign-ins with their devices
- A session closed remotely

### Organisation data is kept apart on every request

The separation is not checked once at the door but on every endpoint that accepts a client identifier. A request carrying somebody else's identifier is refused, even when it comes from a fully authenticated user of another organisation.

- A client ownership check on every request
- Public endpoints attribute a lead by a signed token, not by a field in the body
- Secrets come back as a present or absent flag, never as a value

### A log you can reconstruct events from

Who confirmed a budget change, who switched a placement on, who granted access and who revoked it. The log is not there to punish anyone but to rebuild the picture when something has gone wrong.

- An action log across the whole system
- Who confirmed each money action
- A history of access granted and revoked

## How to set access up

Setting this up takes one evening, and then it needs no attention until the team changes.

1. **Add the people** - Invite the team and give roles that match what each person does.
2. **Switch on the second factor** - Above all for the people who confirm money actions.
3. **Issue keys to systems** - Outside systems get keys of their own, not the account of a person.
4. **Set the retention** - How long data is kept and the rules for deleting it under agency policy.

## Figures from the code

- 7 - interface languages for the team
- 8 - channels under one access model
- 4 - notification channels with personal settings

## What the section does not do

- It does not store ad account passwords - only access tokens, revoked on the platform side.
- It does not show the values of keys and secrets in responses: what comes back is a present or absent flag.
- It does not let anyone past the separation of organisations, however fully authenticated they are.
- It does not delete the action log at the request of somebody whose actions are in it.

## Questions and answers

### Can a specialist see the agency finances?

Only if their role carries that access. Finances, contractor payouts and profit by client are closed off separately from the day-to-day advertising screens.

### What happens if a user of another organisation supplies a client identifier that is not theirs?

The request is refused. Client ownership is checked on every endpoint that accepts it, not once at sign-in.

### Does the system store ad account passwords?

No. The connection runs on access tokens issued and revoked on the platform side. The lifetime and scope of each token show in the Connection health section.

### How do I give access to an outside system?

With a key of its own in the keys section, rather than a shared human account. The key is revoked independently, and its use shows in the log.

## Invite the team and hand out access that matches what each person does

The first 14 days are free on any plan and you do not need a card to start. The second factor, the action log and the separation of organisations work on every plan.

- Start free: https://adsbeast.pro/signup?lang=en
- Pricing: https://adsbeast.pro/pricing?lang=en

## See also

- [Approvals: automation proposes, a person decides, the system applies](https://adsbeast.pro/features/en/approvals): Automation proposes changes to budgets, bids and statuses, a person confirms them, and the system applies them and reads the result back from the account.
- [Client portal: the client sees their figures and signs off their own decisions](https://adsbeast.pro/features/en/client-portal): The client sees their own figures and signs off what is theirs to decide, on a personal link with no password. The portal is closed to search engines.
- [Agency finance: how much you actually earn on each client](https://adsbeast.pro/features/en/agency-finance): Your own revenue, costs and profit: what each client earns you, who has not paid, cohorts by month of joining, and payouts to contractors.
- [Today: what is happening right now and what needs a decision](https://adsbeast.pro/features/en/dashboard): One screen for every agency account: spend by platform in one currency, refreshed every 15 minutes, what is on fire and what needs a decision.

