Operations

Never give your agency your password. Do this instead.

Why you should never give your agency your password, what delegated access looks like on Meta, YouTube, LinkedIn and TikTok, and how to revoke it in one click.

Short answer

Never give your agency your password. Every platform has delegated access: Meta Business Suite roles, YouTube channel permissions, LinkedIn page admin roles, TikTok business roles. It works alongside two-factor authentication and can be revoked in one click. VALORAE Media asks for delegated access on every platform and never for a login, whatever the tier.

Do not hand over the password. Every platform you post to has a way of letting someone else post without knowing your login: Meta Business Suite roles for Facebook and Instagram, channel permissions on YouTube, page admin roles on LinkedIn, business roles on TikTok. You grant a named person or partner a specific role, your two-factor stays on, and when you stop working together you remove them in one click. The rest of this post is why it matters and how to do it on each platform.

Why you should never give your agency your password

A password is all-or-nothing. It cannot be scoped to posting or tied to a named person, and it cannot be partly revoked. The only way to take it back is to change it, which logs out every device including yours, and tells you nothing about what was done while it was shared.

The practical problems arrive sooner than that.

Two-factor authentication breaks first. Either the codes go to your phone and someone at the agency messages you late in the evening asking for one, or you switch it off to make things easier. Both are bad. The first makes you a bottleneck. The second removes the one control that stops a leaked password becoming a lost account.

Then the platforms notice. A login from a new device in a different city looks like a takeover, because that is exactly what a takeover looks like. Accounts get locked, verification gets demanded, and the person who has to sort it out is you.

Finally, there is no record. Delegated roles show who did what under their own name. A shared login shows one user doing everything, so when a post goes out that nobody approved, you cannot tell who pressed the button.

It is a red flag on the agency side as well

Most writing on this subject treats the client as the only party with something to lose. The agency has as much.

An agency that holds passwords is a suspect the moment anything goes wrong on a client account. A post goes out at the wrong time, or an account is locked after a login from an unfamiliar location. With delegated access the agency can point to the audit trail. With a password it can only ask to be believed.

There is also a contagion problem. Threads on r/smallbusiness describe managers losing access to several client accounts at once because everything was interconnected. One compromised inbox or one lost phone, and every client is exposed together. An agency that collects passwords is building that outcome into its own operation.

So treat a request for your login as a process signal as well as a security problem. It says the agency has not set up the standard way of working, and it is fair to wonder what else it skipped. The same logic applies to the accountability question: the shape of the answer tells you more than the words.

What agency FAQ pages say about it

We read through a set of competitor FAQ pages on social media management. One agency answered the password and two-factor question, and its answer was that it requires your credentials. Not one of the pages we read said who owns the accounts, or what happens to access when the relationship ends.

Those are the two questions that decide whether an ending is a clean handover or a scramble. If an agency's public material does not address them, ask before you sign anything, and keep the written answer.

Delegated access, platform by platform

The setup differs slightly on each platform but the shape is the same. You stay the owner, you add a person or a business, you choose what they can do, and you can remove them from the same screen.

PlatformWhere you grant itWhat to give an agency
Facebook and InstagramMeta Business Suite, under people or partnersTask-based access to the Page and the Instagram account. Not full control.
YouTubeYouTube Studio, Settings, PermissionsEditor for whoever posts. Viewer for reporting. Keep Manager and ownership.
LinkedInPage admin tools, Manage adminsContent admin. Super admin stays with you.
TikTokTikTok Business Center, members and assetsA member role scoped to the account. The login stays yours.

Facebook and Instagram

Add the agency as a partner in your business portfolio, or add the individual as a person, then assign the Page and the Instagram account with the tasks they need. Posting and scheduling is one task. Replying to comments and messages is another. Insights is a third. Ads is a fourth you should not need to grant. Full control is a separate switch, and an agency does not need it.

YouTube

YouTube Studio has a permissions page where you invite by email and choose a role. Editor covers the day-to-day work of uploading and publishing. Manager can change channel settings and add other people, which is more than a posting arrangement needs. Ownership stays with the Google account that created the channel.

LinkedIn

Company pages have admin roles. Content admin can create, edit and publish posts. Super admin can add or remove other admins and edit the page itself. Give the first, keep the second.

TikTok

TikTok Business Center lets you add members and share your TikTok account as an asset with a role attached. It keeps the account login, the recovery details and the two-factor on your phone, where they belong.

Keep two-factor on throughout

Delegated access and two-factor authentication are designed to work together. Agency staff log in to their own accounts with their own second factor. Your account keeps yours.

If a vendor tells you two-factor is in the way, the honest translation is that the vendor wants a shared login. Decline, and ask for the delegated-access route instead.

What happens when you part ways

On r/smallbusiness there is a familiar thread shape: someone paid an agency, ended it after two months, and is now asking whether to demand a refund. What those threads rarely mention is the access question, and that is the one that can hurt for longer.

With delegated access, ending is short.

  1. Remove the partner or person from each platform.
  2. Disconnect any scheduling tool they connected.
  3. Check for anyone else who was added while they were there.
  4. Look through the activity log for anything you did not approve.

Your scheduled posts, if they were set up in a tool you own, are still yours. That is one reason to decide early what you hand over and what you keep.

With a shared password, the list is longer.

  • Change it on every platform.
  • Check the recovery email and phone number on each account, because those are what an attacker changes first.
  • Review connected apps and third-party tools.
  • Check for admins you did not add.
  • Confirm two-factor is on and pointing at your device.

Then hope you did not miss one. That difference is the strongest argument for delegated access, and it applies before you know whether the relationship will work out.

How we handle it

We ask for delegated access on every platform and we do not take passwords, whatever the tier.

On Edit, we need nothing. You post, so there is no access to grant. On Manage, from $899 per month, we need a posting role on each platform we post to. On Full Page, $2,000 to $3,500 per month, we also need a community role where we handle comments. The tiers are laid out here.

There is no contract and you can move between tiers at any time, which only works if the access arrangement is as easy to end as the billing. Removing us should be one click on your side, and with delegated access it is.

If an agency's onboarding form has a field for your password, ask where its delegated-access instructions are. If it has none, you have learned something about the agency before paying it anything.

Frequently asked questions

What if the agency says it needs the password to post?

It does not. Posting is a delegated role on every major platform: a task-based role on Meta, an Editor on YouTube, a Content admin on LinkedIn, a member role on TikTok. If an agency cannot post through those, it has not set up the standard way of working. That is a process problem on its side, not a reason to hand over your login.

Do I have to turn off two-factor authentication for an agency?

No, and you should not. Delegated access means agency staff log in as themselves, with their own two-factor, and your account keeps its own. The only reason to disable it is to share a single login, which is the thing to avoid. If a vendor asks you to switch it off, ask why the platform's own access tools are not enough.

What happens to my accounts if I stop working with the agency?

With delegated access, you remove the person or partner from each platform and disconnect any scheduler they connected. Scheduled posts in a tool you own stay yours. If you gave out a password instead, change it, check the recovery email and phone number, review connected apps and other admins, and confirm two-factor is still on and still tied to you.

Does VALORAE Media ever need my password?

No. On the Edit tier we need no access at all, because you post. On Manage and Full Page we ask for a posting role on each platform, plus a community role where we handle comments. Everything is granted to a named person or partner on your side and can be removed by you in one click, which fits an arrangement with no contract.

Want us to run the page, not just edit the videos?

We edit short form, long form and thumbnails, then title, caption, schedule and post them. Send one video and we will show you what we would do with it.

Book a free call

Keep reading