AdKit

Team members and access levels

Invite teammates to AdKit, limit each one to specific projects, and control who can add logins, assign ad accounts, and publish.

Admins decide who sees what. Your workspace is your team's shared space in AdKit. Inside it, each client or brand is a project with its own ad accounts, and those accounts come from a platform login, the Meta or Google sign-in an admin added once.

Every teammate gets an access level and a list of projects, and works only inside those.

This matters most for agencies: a teammate assigned to two clients can't open the other twenty, or see their ads.

Roles

Every member of a workspace has one of four levels, set under Settings → Members.

LevelWhat they can do
OwnerEverything an Admin can, plus remove admins. The person who created the workspace.
AdminAdd platform logins, assign ad accounts to projects, invite and remove members, set anyone's access level and projects. Sees every project.
WriteCreate, edit, and publish campaigns and drafts inside their assigned projects. Can't add logins or assign ad accounts.
Read onlyView campaigns, results, and drafts inside their assigned projects. Can't change anything or publish.

Pick Write for anyone who runs campaigns, and Read only for clients or reviewers who only check results.

Two guardrails. Admins can't lower their own access, so nobody locks themselves out of Settings by accident. And only the owner can remove an admin, so one admin can't lock the others out. The owner's role can't be changed or transferred yet. If the owner leaves your company, reach out and we'll move it.

With the levels clear, here is the order to set the team up.

Set up your team

Logins first, then accounts, then people. A member invited before their project has ad accounts lands in an empty project.

  1. Add the platform logins. Under Settings → Integrations, sign in to Meta, Google, and the other platforms once. Only admins can do this, because one login opens every ad account behind it. See Connect your ad accounts.
  2. Assign ad accounts to projects. Under Settings → Ad accounts, give each project the accounts it should manage. One project per client keeps campaigns and reporting apart.
  3. Invite the member. Under Settings → Members, enter their email, pick Write or Read only, and pick their projects. New invites start on All projects, which also includes any project created later, so change it for anyone who should only work on certain clients. You can also give someone no projects at all, for example while their client is still being set up.

When they sign in, they see only the projects you picked, with the accounts you assigned. Nothing else in the workspace is open to them.

Change or remove access

To change someone's level or projects, open Settings → Members and edit their row.

Changes apply immediately. Remove someone from a project, or switch them from Write to Read only, and their next click gets refused. If they had a tab open, it may keep showing the old screen until they reload, but nothing they do in it goes through.

The same goes for their AI agents. An agent connects with an AdKit key tied to the member's own account, so it gets that member's level and projects, whatever the member asks it to do. If Jade can only open the KPMG project, her Claude can only manage KPMG's campaigns.

Removing Jade from the workspace ends her access to every project, and her agents' access with it. How keys work is in Control what an AI agent can do.

Let a Write member add a platform loginMake them an admin for a few minutes. Sometimes the right login belongs to a Write member, for example a teammate who manages a client's Microsoft Advertising account under their own email. Change their level under Settings → Members, let them add the login under Integrations, then switch them back to Write.While they're admin they can open every client and change any member, so do it while you're with them. The login stays connected after the switch. Assign its accounts to projects under Settings → Ad accounts like any other.
Personal and company workspacesThey're the same thing. AdKit creates a workspace for you when you sign up, named after you. Rename it under Settings, invite your team, and that's your company workspace.A second workspace is only useful when two teams must not see each other's logins at all. It runs on the same plan if you own both, but it needs its own logins, so you sign in to each platform again.

Questions? Reach out and we'll help.

Related docs