Skip to main content
Back

You onboard social media clients without collecting passwords by using permission-based access, which in practice means one of two things: the client grants your business partner access inside the platform's own settings, or you send them a connection link from your scheduler and they authorize each account themselves on the platform's own login screen.

No password changes hands in either version. That matters beyond tidiness. Meta says people should not share passwords, give other people access to their Facebook accounts, or transfer accounts, and a stored client-password list creates a security and offboarding liability of its own.

Why Collecting Passwords Fails, Even When Clients Offer

Plenty of clients will happily text you their Instagram password, which is exactly why you need a firm access policy. A sign-in from an unfamiliar device or location can prompt a security check or a two-factor code, and the person holding the account's recovery method has to resolve it. More importantly, Meta's published terms say not to share passwords or give another person access to a Facebook account. Permission-based access avoids both the policy problem and the credential store.

Creating a separate personal Facebook profile for work does not solve that problem. Meta requires accurate account information and prohibits shared or inauthentic accounts. Use your own authentic profile with two-factor authentication, then keep client access inside the permission systems below. Work-only managed Meta accounts are a separate organization-managed identity option, but Meta does not publish an on-demand route for beginning a business-tools migration. The current position is covered in getting access to Meta managed accounts faster.

Maeve for Agencies

One workspace per client, a connection link for onboarding, roles for your account managers, and approvals that run by link too.

See the agency workflow

Plan, preview, and publish in one workflow

Path One: The Platform's Own Role System

The major business platforms provide permission-based access for at least part of the work. On Meta, a client can give a business portfolio partner access to assets or assign Page access to an individual. LinkedIn Pages have admin roles, TikTok Business Center supports member and partner access, Google Business Profile has owner and manager roles, and Pinterest business accounts can add employees or partners. The exact roles and available actions differ by platform.

This is the right answer for ads, because ad accounts only move through Meta's partner system, and it is fine at a handful of clients. The problem is what it asks of the client. Partner access on Meta means knowing what a Business Portfolio is, finding a portfolio ID or accepting a request in the right place, and clicking through screens designed for marketers rather than for a cafe owner doing this once. In practice that is a call per client, or a screenshots-by-email exchange that runs for days. At fifty clients, an access path with a call in it is not a path.

The version that scales is a connection link, and the mechanics are what make it safe. Your scheduler generates a link tied to one client's workspace. You send it by email or text. The client opens it, sees the platforms you have asked them to connect, and taps each one. Each tap bounces them to that platform's own login page, on the platform's own domain, where they sign in as themselves and approve a specific list of permissions. The platform then issues the tool a scoped token, the same mechanism behind every Sign in with Google button. The client's password goes to the platform it belongs to and nowhere else.

Run onboarding this way and the client's whole job is one link and a couple of logins they already know. They never join your team, never see your other clients, and never touch a portfolio ID. Revocation stays in their hands the entire time, from the platform's connected-apps settings, which is a better security position than any password arrangement, and the comparison is laid out in how OAuth compares to handing over a password. What separates one implementation from another: whether the link covers the platforms your clients actually use, whether each client lands in a separate workspace, and whether you can resend it when the client swears it never arrived. In Maeve the link is per workspace and covers Instagram, Facebook Pages, LinkedIn, TikTok, YouTube, X, Threads, and Pinterest, and the same pattern handles client review and approval without a client login.

The Limits No Vendor Leads With

Maeve's connection link does not grant access to Meta ad accounts. If the engagement includes ads, use Meta's business-asset access flow for that work. Google Business Profile is also outside Maeve's current client-connection link, so the client needs to add the appropriate owner or manager through Google Business Profile.

A few Instagram features remain native-only. Third-party publishing requires an eligible professional account, and interactive Story stickers and Instagram's licensed audio catalog are not carried through Maeve's scheduled Story publishing. Plain image and video Stories can publish automatically, while a Story that needs a poll, question, or native music track needs an in-app handoff. Platform authorizations can also be revoked or invalidated, including after some password or security changes, so document who can reconnect an account instead of promising a fixed token lifetime.

The Onboarding Flow, Start to Finish

This holds up whether you are onboarding your third client or your hundredth. It assumes a scheduler with per-client workspaces and a connection link, with the platform-roles path slotting into step four for ads and Google Business Profile.

Create the client's workspace before you send anything One workspace per client, named for the client, with the account managers who will run it already invited. Accounts should land somewhere your other clients can never see.
Generate the connection link, scoped to the platforms this client uses A cafe with Instagram and Facebook should see two buttons, a B2B client maybe LinkedIn and X. Fewer choices means fewer places for the client to stall.
Send it with one line of instruction Text or email: tap this link, sign in to each platform as you normally would, and you are done. No portal, no signup, no call. Resend a fresh copy if it goes missing.
Handle ads and Google Business Profile the platform-native way If the engagement includes ads, request partner access to the ad account through your Meta Business Portfolio. For GBP, have the client add you as a manager from their profile settings.
Verify what landed and note what is missing Check the workspace shows every expected account. A client who connected Instagram but skipped TikTok is normal; chase it now, not the night a TikTok post is due.
Document access and expect reconnections One shared note per client: which accounts are connected, who holds platform roles, who can reauthorize a connection, and who picks up the rare app-only post.

So the shape of the answer is a connection link for publishing and the analytics side of the work, platform partner access for ads and Google Business Profile, your own real profile with two-factor on as the only Meta login you ever use, and a written note per client covering the gaps. Password collection is the thing to eliminate, the link flow genuinely exists, and no single link does all of it. All three are true at once. What matters at scale is that the flow asks nothing of the client beyond logins they already know, and everything after it, the first-week setup and the approval rounds, can run over links too.