Business Portfolio Access: Who Holds It, and What Happens When They Go
A Business Manager is only as durable as the number of people who can still get into it. Here is what Meta actually publishes about admin structure and verification status, why a second admin has to have accepted to count, and what the listings on this shelf do and do not tell you about access.
Avery BennettThe failure everyone describes is the same one. A single admin's personal profile gets restricted, and the container holding every ad account and Page for the business goes with it. What makes it worse than it sounds is a sentence in Meta's own documentation on adding an ad account: once an ad account is inside a business portfolio, access to it can only be assigned through that portfolio. There is no side door back to the ad account. Lose the portfolio, lose everything filed under it.
So the useful version of this topic is not a setup walkthrough. It is a short list of who can hold access, what Meta writes down about it, and what a listing has to say before you can believe its access claims.
The names changed, and one of them matters
Meta's current product is Meta Business Suite, and the thing people still call a Business Manager is now a business portfolio. Almost nobody in the resale market has updated their vocabulary, so listings and forum threads will keep saying BM for years. That is harmless. What is not harmless is looking for business verification where the old guides put it.
Verification status now lives in Security Center, inside Business Suite settings, reachable directly at the settings security path on business.facebook.com. Meta describes Security Center as where you access the features that safeguard the business and the people who manage it, and checking business verification status is one of the things it lists. Worth knowing: verification can be started from other surfaces, Commerce Manager included, so Security Center is where you check where you stand, not necessarily where you or a previous owner began.
Redundancy has a published ceiling, and it is generous
People treat a second admin as an imposition on a scarce resource. It is not. Meta documents that a single ad account can be assigned to as many as twenty-five people, so nothing about the platform is pushing you toward a single point of failure. That is a choice teams make by not deciding, rather than a constraint they are working under.
What Meta does not publish anywhere is a verification turnaround time. An earlier version of this page gave a range of a few days to a few weeks, presented as typical. That range was not Meta's and it is gone. If you need to know where a portfolio stands, the answer is to read its status rather than to estimate from a timeline that does not exist.
A backup admin only counts once it has been accepted
This page previously suggested inviting a spare admin on an address nobody uses and keeping the acceptance link somewhere safe as a way back in. Do not do that, and it has been removed. An unaccepted invitation link is a stored credential to your entire business container, sitting outside any account you control, waiting for whoever finds it. It is also not a recovery route Meta documents.
The structure that actually holds is duller. A second person, on an account that is genuinely theirs and genuinely in use, who has accepted the invitation and appears as an admin today. The test is not whether an invitation was sent. It is whether a second name is listed as admin right now, and whether that person could log in this afternoon without asking you for anything.
Two practical consequences. First, do it during setup rather than after an incident, because after an incident the account that would have sent the invitation is the one that is locked. Second, if you are handing a portfolio over or taking one on, confirm your own admin status before the previous holder's access is removed, not after. The order of those two operations is the whole handover.
Checking where you are logged in, where Meta contradicts itself
This is worth flagging because both routes are live in Meta's English help today and they do not agree.
One page tells you to open Accounts Center, then Password and security, then Where you're logged in. That page is also the one carrying Meta's migration notice, which says you may see either Accounts Center or Meta Account settings depending on where your account sits in the rollout. Another page, on reviewing recent logins, tells you to go to Settings and Privacy, then Activity Log, then Where you're logged in, and does not mention Accounts Center at all.
Try the Accounts Center route first, since it is the page Meta has kept current with the migration. If your account still shows the older layout, the Activity Log route is not wrong, it is just the other half of a documentation set mid-migration. Either way the destination is the same list of sessions, and reviewing it before a handover is how you find out that someone else is still signed in on a device you have never seen.
What the listings on this shelf say about access, and what they leave out
Measured today under the storefront's own visibility rule, the ad and Business Manager shelf holds 161 live listings across eight suppliers, of which twenty are TikTok Business Center products rather than Facebook. Reading the Facebook rows for access language rather than for price produces a clearer picture than any comparison table.
Seven titles state how many admin links come with the account. Four go further and say what happens to the seller's own access: that the previous admin can leave, that admin deletion is enabled, that other admins can be removed. Those wordings are the ones you want, and they are the dearer listings on the shelf rather than the cheaper ones.
The number that matters more is the one on the other side. The great majority of listings here say nothing at all about admin structure. Not that access is exclusive, not that it is shared, not how many people currently hold it. Silence is not a claim of exclusivity, and a portfolio can hold up to twenty-five assigned people without any of them being visible from the outside. If a listing does not name what happens to the seller's access, treat that as an open question rather than as an answered one.
One uniformity worth knowing so you stop comparing it: warranty on this shelf is almost entirely a single value, twelve hours, on 158 of the 161 listings. It is not a differentiator here, and twelve hours from delivery is not long enough to discover an access problem by waiting. Whatever you are going to check, check it the same day.
The order that works on a handover
- Get yourself listed as admin, and confirm it in the interface, before anything is removed from the other side.
- Open Security Center and read the actual verification status rather than the listing's description of it.
- Review active sessions and end any you do not recognise.
- Add a second admin who is a real person on a real account, and confirm the invitation has been accepted.
- Check your ad account creation limit under Business info, so you know whether the structure you planned is possible yet.
- Do all of this on day one, because the window in which a problem is still someone else's problem is measured in hours.
If you are sourcing a portfolio rather than building one, the ad and Business Manager shelf is where that stock sits, and pairing it with a stable login environment from the proxy shelf is the other half of the setup. Access claims are exactly the kind of thing that only gets tested after money changes hands, which is what makes buyer reviews more informative here than product descriptions. Meta's Business Help Center holds the current version of every limit quoted above, and those limits do move, so read them there before you build a structure on one.

