Multi-Accounting in Media Buying: How to Keep Ad Accounts Safe
How agencies run dozens of ad accounts without cross-contamination: profile isolation, proxies, warm-up, team roles, and 2FA storage.
Why one browser is a risk, not a convenience
A media buyer rarely runs a single ad account. An agency has dozens of clients, each with its own billing details, its own Business Manager, its own creatives and its own moderation history. Even when working strictly by the rules, the number of accounts adds up fast: test accounts, live accounts, backup accounts, accounts split by geo or by vertical.
Facebook Ads, Google Ads, TikTok Ads and similar platforms explicitly allow managing multiple accounts — through Business Manager, agency structures, partner programs. What they explicitly forbid is creating many accounts to dodge bans and relaunch something that already got shut down for violating the rules. The difference matters: a structure for running a business is normal, a farm for evading enforcement is a violation that gets the whole Business Manager suspended — live client accounts included.
That's the real engineering task here: build an infrastructure where accounts don't "leak" into each other through browser fingerprints, IPs and cookies, and where the team can work without confusion over who logged into which profile and from what device.
What losing an account actually costs
Before getting into tools, it's worth pinning down the numbers, because they explain why isolating profiles is worth the effort in the first place.
- Suspending a Business Manager with 5–10 active client accounts stops every campaign at once, not just one.
- Reinstatement takes anywhere from a few days to several weeks, and a chunk of appeals get denied without explanation.
- While an account is frozen, unspent budget doesn't automatically carry over — the client loses sales momentum, the agency loses trust.
- Reattaching payment methods and domains after a ban adds several more days of downtime even after reinstatement.
When the same browser profile — same canvas fingerprint, same set of fonts, same cookie set — is used to log into several "independent" accounts, the platform reasonably sees the connection between them. Ban one, and the linked ones go down too. Profile isolation isn't about tricking an algorithm — it's about making sure different business units don't technically look like the same user where they aren't.
What a working profile structure looks like
The practice that actually cuts down on incidents rests on a few principles.
One profile — one account or one Business Manager. Don't mix logging into a manager's personal account, a client's BM, and a test account inside the same browser window with shared cookies. Each one gets its own isolated profile with its own fingerprint: OS, browser version, screen, timezone and language pulled from the proxy's exit IP, plus canvas/WebGL/audio noise.
A proxy is tied to a profile, not to a task. If you log into an account today through one IP and tomorrow through another, with no proxy or a different location, that's a sharp jump in the account's behavioral profile — and platforms track that too. A permanent proxy per profile, for the profile's entire lifetime, checked for uptime and for matching the geolocation the client is registered under. The types of proxy that fit different jobs are covered in choosing the right proxy type for multi-accounting — for ad accounts you generally want a static residential or mobile IP, not a cheap datacenter one that platforms flag as suspicious on its own.
Group by client, not by platform type. It's easier to keep all of one client's profiles — Facebook, Google, TikTok, analytics — in a single group with a clear name and color tag than to sort profiles into tabs like "all FB" or "all Google." That saves seconds on every launch, and at the scale of fifty accounts it adds up to hours a week. Structuring this at scale is covered in more detail in organizing profile pools at scale.
Warming up new accounts isn't cosmetic — it's part of the system
A new ad account created today and immediately loaded with a $500 budget on the first login is statistically more likely to get flagged for manual review than one that spent a few days behaving like a regular user first: logging into the interface, checking stats, tweaking settings without sudden spikes in activity. This applies to both personal and Business Manager accounts.
The mechanics are similar to warming up regular social accounts, with the difference that here spend evenness and gradually rising limits matter more than likes and follows. General warm-up principles, including a schedule of actions and common beginner mistakes, are laid out in warming up accounts before launch — it applies to ad accounts too, with platform-specific adjustments.
Team access: who sees what in client accounts
At an agency, a client's account is almost never run by one person. A buyer launches campaigns, an optimizer adjusts bids, a team lead checks budgets, a finance person reconciles spend against invoices. If everyone shares one password to one account saved in Chrome, that's not a team — that's a leak waiting to happen the moment someone quits.
It's more practical to assign roles at the profile level rather than at the level of ad-account passwords:
| Role | Sees | Can do |
|---|---|---|
| Owner | All profiles and accounts | Full control, finance, hiring |
| Admin | Profiles of their teams | Create and hand off profiles, set limits |
| Buyer (member) | Only assigned accounts | Launch campaigns, edit creatives |
| Finance | Spend dashboard | View spend, no account login |
- lev opened Airdrop zkSync 07
- artem closed FB · US · BM-14
- maya is watching artem
- lev transferred TikTok Shop 03
This setup solves the classic agency problem: a buyer who quits on Friday doesn't walk out with access to every client account, because access was granted at the profile level, not via a platform password — and it can be revoked immediately. How to set up roles and limits per profile in more detail is in team roles and profile handoff.
Live browser view and remote control of a teammate's session is also useful here: a team lead can open a buyer's active profile, see exactly what's happening in the account right now, and take over control if needed — no screenshots forwarded back and forth, no password requests.
Mistakes that most often cost an account
Mixing personal and work accounts in one window. A buyer logs into their personal Facebook, then in the same tab logs into a client's Business Manager "to save time." The platform now sees a link between a personal profile and a work account where neither the buyer nor the client wanted one.
One proxy for a batch of accounts. Saving money on proxies means a dozen different accounts log in from the same IP at the same time — a textbook pattern for an automated block that hits several accounts at once.
Sudden changes to profile configuration. Manually updating the browser version, changing the system timezone, rebuilding the environment — and an account that ran smoothly for six months suddenly gets flagged for review. A profile's fingerprint needs to stay stable between sessions, and change only alongside a proxy change, as part of a deliberate plan. How to track these mismatches is covered in fingerprint consistency in an antidetect browser.
Storing passwords and 2FA codes in a shared text file. A Google Sheet with passwords and secret two-factor keys, forwarded around in a messaging app, is a source of both leaks and plain confusion, like two people logging in with the same code at the same time.
No activity log. When something goes wrong with an account, it helps to quickly see who logged into the profile, when, and what settings they changed. Without a log, that turns into polling the whole team from memory.
Technical details that rarely get discussed but matter a lot
Cookies and history aren't just about convenient logins. Importing and exporting cookies in JSON or Netscape format comes in handy when handing an account off to another buyer or transferring a client between agencies by agreement — no need to log in again and trigger a review from a "new" device if the session moves with the profile. Scheduled cookie warm-up keeps accounts that aren't actively used right now looking "alive" to the platform.
https://www.youtube.com/
https://www.wikipedia.org/
https://www.reddit.com/
https://www.amazon.com/
The app opens the profile, browses the sites and closes it. Profiles in use are skipped.
Syncing across devices. A buyer works from a laptop at the office and from a home computer in the evening — the profile and its state should be identical in both places, without a manual export-import step every time.
Handing a profile to another account. When a client moves from one manager to another, or an agency transfers management of an account to a partner, the profile with its full history and settings can be handed off without rebuilding it from scratch.
Encryption of profile data on the device. For an agency storing access to dozens of client ad accounts, this isn't an abstract protection measure — it's a direct client requirement, often written into contracts, that access be stored so that not even the tool's provider can read it. More on the encryption model and access recovery is in encryption and the 2FA key vault for profiles; a general overview of security mechanisms is on the security page.
Automating routine checks. A daily sweep of twenty accounts to check moderation status and spend can be partly offloaded to a script through the local API, if the team is already working with Puppeteer or Playwright — a scenario described in automating profiles with Puppeteer and Playwright.
What a team lead's day on the dashboard looks like
A team lead at an agency running 40 active accounts usually doesn't start the morning by opening each account one by one — instead, they check the overall picture: who on the team is already online, how many browsers are open right now, total spend across all clients yesterday. This saves time on the first pass and immediately surfaces anomalies — an account that's been open for three hours with no activity, or spend running twice the usual daily pace.
Spend, 30 days
Where to start if everything currently lives in one browser
If every account currently lives inside one Chrome profile with saved passwords, the migration is better done in stages rather than in one day.
- Pull the list of all active accounts and Business Managers by client, and note which proxies and IPs were used on the last successful login.
- Set up a separate isolated profile for each Business Manager, and attach a permanent proxy with the same geolocation as before.
- Transfer the cookies of the current active session into the new profile, so there's no fresh login and no review triggered by the platform.
- Grant team access through roles instead of a shared password, and set profile limits per person.
- Don't change the account's working schedule during the first week — log in at the same rhythm as before, to avoid sudden shifts in account behavior.
It's easiest to start on the free plan, which includes 3 profiles — enough to test the structure on a single client before migrating the full account list. The full list of plans and profile limits is on the pricing page, and installers for macOS and Windows are on the download page.
FAQ
Will Facebook or Google penalize an agency for running many accounts? No, as long as the structure is transparent: agency Business Managers, partner access, real clients behind each account. Platforms penalize creating fictitious accounts to bypass restrictions already imposed, not legitimate scaling.
Does every account need its own proxy, or can one be shared per client? If a client has several accounts across different platforms, one stable proxy with the right geolocation can serve all of that client's profiles — the important part is not crossing proxies between different clients.
What happens if a buyer quits and they were the only one with account access? If access was granted through a profile role rather than a personal platform password, the account and all its settings stay with the agency — that person's access is simply revoked.
How do you quickly tell something's off with a profile's fingerprint? A sudden spike in security checks or identity verification requests during routine actions is a signal to check whether the profile's configuration changed, or the proxy shifted to a different geolocation without warning.