02: BM Nolimit Access Governance and Client Isolation
Grant only the access required to deliver the contracted service, with a tested revocation path.
1. Objective and Ownership
An agency can lose operational control through excessive permissions, forgotten contractors, or one unavailable administrator. Access governance must survive employee departure and client offboarding.
The Security Lead owns the permission standard. The client owner approves asset access. Ad Operations implements the approved configuration. Portfolio access, billing authority, and campaign execution require separate decisions.
2. Prerequisites and Role Design

Confirm the client organization, business identifiers, authorized approver, required assets, and work scope. Use supported partner access where applicable, rather than sharing a personal login.
| Role | Intended access | Approval boundary |
|---|---|---|
| Client asset owner | Ownership and partner authorization | Client-controlled |
| Agency access administrator | Approved partner and staff assignments | Security approval |
| Media buyer | Assigned campaigns and necessary reporting | Client scope and budget |
| Measurement engineer | Relevant event-source configuration | Data-access approval |
| Finance operator | Necessary billing and reconciliation | Finance approval |
| Auditor | Read-only evidence where supported | No execution authority |
These are organizational roles. Map them to permissions actually supported by each platform; do not assume identical role granularity across interfaces.
3. Execution Procedure
- **Build an asset register.** Map client, portfolio, ad accounts, pages, datasets, domains, and authorized operators.
- **Confirm the invitation destination.** Validate the business identifier through an established client contact before granting access.
- **Apply least privilege.** Grant named people and approved partner organizations only the assets and tasks they need.
- **Require MFA.** Each human operator uses their own identity and authentication factors. Identity-Verified KYC Profiles do not replace authentication controls.
- **Separate client access.** Enforce client-specific groups and scope checks. An operator serving two clients must receive two explicit approvals.
- **Protect automation credentials.** Where supported, use scoped service identities, documented token ownership, expiry tracking, and controlled rotation.
- **Prepare emergency access.** Maintain independently recoverable access for authorized administrators, with controlled emergency use and immediate review.
- **Record changes.** The proposed NoLimit Shopping Proprietary Ledger should retain before-and-after permission states, approver, implementer, reason, and expiry.
4. Validation and Release Gates

Test positive and negative cases. The assigned buyer must reach the approved client account; an unassigned operator must not. Verify that a reporting-only role cannot publish or alter billing where the platform supports that separation.
Run an offboarding rehearsal using a test operator. Remove the relevant business access, revoke associated automation credentials where necessary, and verify loss of access through supported controls.
Release requires approved permissions, working recovery, and a completed revocation test. A roster export alone does not establish that access boundaries work.
5. Incident Response and Rollback
For an unexpected administrator or invitation, freeze permission changes and investigate the affected business assets. Preserve evidence, revoke unauthorized access, and rotate exposed credentials without disturbing unrelated clients.
Restore only the last reviewed permission set. Do not restore a compromised token from backup. If the platform restricts an account, follow its review process; additional profiles are not a substitute for resolving the restriction.
6. KPIs and Operating Cadence

Track privileged-user count, MFA coverage, orphaned grants, overdue access reviews, and time to revoke a departed operator's access.
Review privileged access weekly and client scope at onboarding, contract change, and offboarding. The required output is an approved access matrix plus evidence that unauthorized operations are denied.
---


