When the Social Media Manager Leaves: Revoking Access Across a Marketing Agency's Tool Stack
A practical guide for marketing agency owners on revoking contractor access to Google Ads, Meta Business Manager, Mailchimp, Hootsuite, and Canva when a social media manager or contractor exits.
When the Social Media Manager Leaves: Revoking Access Across a Marketing Agency's Tool Stack
When a marketing contractor or social media manager ends their engagement, their access to your ad accounts, email lists, and brand assets doesn't end automatically. Google Ads Manager seats, Meta Business Manager roles, Mailchimp audience access, and Canva Brand Kit permissions all require manual revocation — and each platform has its own process. This guide walks through the specific steps for every tool in a typical marketing agency stack, so nothing gets missed.
Why This Matters for Agencies
Most employee offboarding guides focus on IT: shut down the email, deactivate the laptop, disable SSO. Marketing agencies have a different problem. A departing social media manager might hold admin-level access to ad accounts with active budgets, pixel data tracking thousands of site visitors, email subscriber lists that took years to build, and brand assets you paid contractors to create.
The 68% figure from Ponemon Institute — organizations that can't reliably confirm they've removed a departed person's access — is probably even higher for agencies, where contractor relationships "fade out" rather than formally end.
Why Marketing Agency Access Is Harder to Revoke
Marketing contractor relationships rarely end with a clear termination date. The campaign wraps up. Communication tapers off. The retainer gets paused. And then three months later you realize your former social media manager still has Standard User access to your Meta Business Manager account.
This is the fading-relationship problem. With a full-time employee, there's a last day, an IT offboarding checklist, and an HR trigger. With a contractor, there's often none of that — and marketing tools don't send you a reminder that someone who hasn't logged in since February still has access to your Meta Pixel data.
The tools themselves make this harder. Unlike SSO-connected apps that deactivate automatically when you remove a user from Google Workspace, marketing platforms — Google Ads, Meta Business Manager, Mailchimp, Hootsuite — have their own permission systems that operate independently. Removing someone from your Google Workspace doesn't remove them from your Google Ads Manager. These are separate access grants that require separate revocation.
The other risk factor: some marketing tools give contractors access to assets that can be exported or transferred. A departing contractor with Mailchimp access can export your full subscriber list before you think to revoke their permissions.
Google Ads Manager — The Money Risk
Google Ads is the highest-stakes item on this list because a contractor with Standard Access or Admin access can make changes to live campaigns, adjust bids, pause ads, or redirect budgets — even after their engagement ends.
Access levels to know:
- Admin access — can add and remove other users, link accounts, and make all campaign changes.
- Standard access — can create, edit, and view campaigns. Cannot manage users.
- Read-only — cannot make changes.
How to revoke: In your Google Ads account → Tools & Settings → Access and Security → Users. Find the user and remove them. This is account-level access — if they were added through a Google Ads Manager Account (MCC), you'll need to revoke their access at the MCC level too, not just the individual account.
What doesn't revoke automatically: If your contractor was using Google Ads via a Manager Account they control, the MCC link itself may remain even after you remove the user. Check Linked Accounts to confirm the manager account is fully unlinked.
The timing risk: If there's an active campaign, remove access before informing the contractor. A contractor who knows they're being let go and still has Google Ads Admin can pause your campaigns, change your budget, or edit your creatives in the window between the conversation and when you remember to revoke access.
Meta Business Manager — Pixel Data and Audience Lists
Meta Business Manager is more complex than Google Ads because it has multiple permission layers: Business Portfolio level, ad account level, Facebook Page level, Instagram account level, and asset-specific permissions (pixels, catalogs, apps).
A contractor added as an Employee or Admin to your Business Portfolio can see your custom audiences, retargeting pixels, and historical ad data — even if their actual campaign access is limited.
What to revoke and where:
- Business Portfolio people — Settings → People → find the contractor → Remove from Business. This removes their access to the entire portfolio.
- Partners (agency access) — If the contractor used their own Business Manager account linked as a Partner, go to Settings → Partners and remove the partner connection. This is separate from removing individual people.
- Facebook Page roles — People added as Page admins, editors, or analysts at the Page level are separate from Business Manager. Check Pages → Settings → New Pages Experience → Roles.
- Instagram account access — Instagram connected accounts have their own collaborator list. Check Instagram → Settings → Creator/Business → Connected Tools.
The data risk: Custom Audiences are visible to anyone with ad account access. They can't export the list itself, but a malicious actor could use your audience for targeting during the window before you revoke.
Email Marketing Tools — The Subscriber List Risk
Email platforms are where the data export risk is real. A Mailchimp user with Manager access or higher can export your entire subscriber list as a CSV. This is your most valuable marketing asset — a list that took years to build, fully downloadable by anyone with the right role.
Mailchimp:
- Account Owner → Settings → Users → find the user → Manage → Remove.
- Roles to watch: Owner and Manager both have export permissions. Viewer-only cannot export.
- Connected apps: if they set up any Mailchimp API integrations (Zapier, their own tools), check Settings → Connected Sites and Integrations → Connected Apps and revoke separately.
Klaviyo:
- Settings → Account → Account Users. Remove the user here.
- API keys they created under their account persist separately — go to Settings → API Keys and audit for keys created by their user. Revoke any keys you don't recognize.
HubSpot Marketing Hub:
- Settings → Users & Teams → find the user → Actions → Remove from Account.
- HubSpot contacts and lists remain in your account; you're removing their login access, not the data.
- Check connected integrations — if they set up any workflows or external triggers using their own credentials, those may break when their account is removed. Document what breaks before revoking.
Scheduling Tools and Canva Brand Kit
Hootsuite:
- Organization → Members → find the member → Remove from Organization.
- If they were the only person who connected a social account (via their personal login), that social connection may drop when you remove them. Reconnect the social account yourself before removing them.
- Scheduled posts queue under their profile may stop publishing. Export the queue or reassign posts before removal.
Buffer:
- Settings → Team Members → Remove. Similar caveat: social account reconnection may be needed if their personal credentials were used to authorize the connection.
Canva Brand Kit: This is one of the most overlooked access points for marketing agencies. A departing contractor with Editor access to your Canva Team can access your Brand Kit (logos, color palettes, fonts, brand voice docs), download your brand templates, and see any private designs shared with the team.
- Canva → Settings → People → find the member → Change Role to No Access or Remove.
- Brand templates they created and shared with the team remain in your team's shared folders — they stay, but the person loses access.
- Check if they were using a personal Canva Pro account linked to your team. In that case, their personal account access to your brand assets revokes when you remove them.
Later, Sprout Social, and others: The pattern is the same — look for Team Settings or Users section, remove the member, and check whether any social account authorizations were done with their personal credentials.
The 30-Minute Access Revocation Checklist
Run this checklist in order when a marketing contractor's engagement ends. Do it before telling them, if the relationship is contentious.
Advertising platforms (do first — highest risk):
- Google Ads → Tools & Settings → Access and Security → Users → Remove
- Google Ads → Tools & Settings → Linked Accounts → check Manager Accounts and remove any MCC links
- Meta Business Manager → Settings → People → Remove from Business
- Meta Business Manager → Settings → Partners → remove partner Business Manager links
- Facebook Pages → Settings → Roles → remove the person
- Instagram → Settings → Connected Tools → remove access
Email and CRM (do second — export risk): 7. Mailchimp → Settings → Users → Remove; audit Connected Apps 8. Klaviyo → Settings → Account Users → Remove; audit API Keys 9. HubSpot → Settings → Users & Teams → Remove from Account
Scheduling and creative (do third): 10. Hootsuite → Team → Remove (reconnect social accounts first if needed) 11. Buffer → Settings → Team Members → Remove 12. Canva → Settings → People → Remove or change to No Access 13. Any other scheduling tool (Later, Sprout, Planoly) → Users/Team settings
Final check: 14. Document what social account connections broke and reconnect them under your own credentials 15. Check your email platform for API integrations the contractor may have set up 16. Log the removal date for each tool in your contractor records
This takes 20–30 minutes done carefully. It's worth the time — the alternative is discovering months later that a former contractor still has access to your ad spend.
See also: The Agency Contractor Access Audit Checklist for a periodic review process, and IP Protection for Design Agencies if the contractor also handled design assets.
Platform Comparison: Revocation Method and Risk Level
| Platform | Where to Revoke | Data Export Risk | Social Account Reconnect Needed? |
|---|---|---|---|
| Google Ads | Access and Security → Users | Low (no export) | No |
| Google Ads MCC | Linked Accounts → Manager Accounts | Medium (budget control) | No |
| Meta Business Manager | Settings → People | Medium (audience visibility) | No |
| Facebook Page | Page Settings → Roles | Low | No |
| Mailchimp | Settings → Users | High (subscriber export) | No |
| Klaviyo | Settings → Account Users + API Keys | High (list export + API) | No |
| HubSpot Marketing | Settings → Users & Teams | Low (data stays) | No |
| Hootsuite | Organization → Members | Low | Yes — check first |
| Buffer | Settings → Team Members | Low | Yes — check first |
| Canva | Settings → People | Medium (brand asset download) | No |
Frequently Asked Questions
Does removing someone from Google Ads also remove them from Google Analytics? No. Google Ads and Google Analytics 4 have separate permission systems. Removing a user from Ads leaves them in GA4. Go to GA4 → Admin → Account Access Management (or Property Access Management) to remove them separately.
What happens to scheduled social posts if I remove someone from Hootsuite? Posts they scheduled may stop publishing after their account is removed — depends on how the social account connection was set up. Before removing them, export or screenshot the content calendar and reconnect any social accounts they originally authorized. Then remove the user.
Can I revoke Meta Business Manager access without the contractor knowing? Yes. Removing someone from Meta Business Manager is silent — they don't receive a notification. Their access ends immediately. This is worth knowing for situations where you want to act before having the offboarding conversation.
Stop Doing This Manually
Marketing tool access is one part of the broader problem: when a contractor leaves, access across every tool they touched needs to be revoked — not just the marketing stack. Optserv tracks which tools each contractor has access to across their entire engagement and generates a revocation checklist on exit. When the next social media manager leaves, you run one offboarding flow instead of a 16-step manual hunt across ten dashboards. Start free at app.optserv.ai/signup.
Sources
- Ponemon Institute: "2026 State of Identity Security" — 68% of organizations can't confirm access removal on departure
- Cerby: "I Hired an Agency. I Have No Idea If They Still Have Access to Our Accounts" — cerby.com/blog
- Meta Business Manager help documentation — business.facebook.com
- Google Ads access and security documentation — ads.google.com/help
Run your entire team from one place.
Optserv handles hiring, onboarding, access management, and offboarding — built for startups that want to operate like grown-ups without the enterprise overhead.
Try Optserv free