Employee Onboarding: Fast Access to Profiles Without Leaks
How to onboard new hires in agencies and buying teams with instant, scoped access to client profiles — no shared passwords, no leftover accounts.
The first week of a new hire's job usually goes not to actual work, but to collecting access. HR issued a company email, but the passwords to ad accounts sit in a team lead's personal Google Doc, CRM access requires a separate IT ticket, and the Facebook Ads Manager login is known only to someone who's been on vacation for a month. The newcomer either sits idle or gets access the wrong way — a screenshot of a password in a chat, or a temporary loan of someone else's laptop.
This isn't a minor annoyance. A team running dozens of client accounts or ad accounts doesn't lose hours to this chaos — it loses days of productivity for every new person. It also creates real risk: passwords circulate through chat history, former interns keep access they should have lost months ago, and if a platform ever asks who logged into an account and when, nobody can answer.
Here's how to structure onboarding so a new employee starts working on day one instead of after a week of approvals — without a single password ending up where it shouldn't.
Why typical access onboarding breaks down
Three scenarios show up again and again.
Scenario 1: a shared spreadsheet of passwords. Convenient until the first departure — after that, every password needs rotating, because nobody knows exactly what the departed person saw. In practice, nobody cleans the spreadsheet for months.
Scenario 2: handing over a personal device. The new hire gets the previous employee's laptop, already logged into a dozen accounts. Fast, but the device fingerprint that's been used for years across those accounts is now tied to a different person — and if the old employee still has a phone on the same Wi-Fi or sync, they sometimes keep receiving notifications by accident.
Scenario 3: a shared master password from a password manager. Better than the first two, but access is still all-or-nothing — a new account manager spends a week seeing every client's budget in the agency, when they should only see one.
All three solve "grant access" but not "grant exactly the access needed, and revoke it just as easily." We covered the reverse side of this process — closing access when someone leaves — in a separate post on employee offboarding: the logic is the same, just running in the opposite direction, and a lot of onboarding problems are really just someone else's unfinished offboarding.
What to decide before the employee's first day
Before the start date, not on it, answer four questions.
- Which exact profiles or accounts need access. Not "the whole department's accounts" — a specific list of clients or ad accounts the person will actually touch in the first week or two.
- What role the employee has. This determines whether they can see passwords, change profile settings, add proxies, or invite other team members.
- Whether there's a limit on simultaneously open profiles. For an intern or junior, a limit isn't distrust — it's protection against mistakes: the person can't accidentally open fifteen client accounts at once or lose track of which tab is which.
- Who supervises the first few days. Does a mentor need to be able to "look over the shoulder" without passwords ever changing hands?
Answer these four up front, and granting access itself takes 10–15 minutes, not several rounds of back-and-forth with IT.
How this works in an antidetect browser with team mode
The difference from a password spreadsheet is that the employee can work inside a profile without ever seeing its credentials. A profile is an isolated environment with its own browser fingerprint, saved cookies, and, where needed, 2FA keys. The person logs into their own GetAntik account, sees the list of profiles assigned to them, and opens one with a click. The password for Facebook Ads or Amazon Seller Central may never be visible at all — it sits in the profile's secure vault and gets filled in automatically.
- lev opened Airdrop zkSync 07
- artem closed FB · US · BM-14
- maya is watching artem
- lev transferred TikTok Shop 03
Roles answer the question of what a person can actually do. A team typically has an owner, admins, regular members, and a finance role. A new media buyer or SMM manager usually needs the member role scoped to one group of profiles — nothing more. Admin rights, which allow changing proxy settings or deleting profiles, should only go to people who've passed a probation period, and not to everyone even then. We covered the logic of roles and profile handoff between teammates in detail in team roles and profile handoff — it pairs well with this onboarding process.
A limit on open profiles is a simple, underrated safeguard. A new hire can be capped at 5–10 simultaneously open profiles, even if they technically have access to 50 client accounts. This cuts the risk of carelessly opening the whole pool at once and mixing up tabs.
Live view and remote control solve the first-day problem without a single password changing hands. A mentor can connect to the newcomer's browser in view mode, show how a profile is filled in, where campaign settings live, what a properly warmed-up account looks like — all without typing a login into a chat window.
Step-by-step checklist: day one, week one, month one
| Stage | What to do | Owner |
|---|---|---|
| 1–2 days before start | Create a team-space account, assign a role, pick 3–5 starter profiles | Team lead / admin |
| Day one | Grant access to profiles, set a concurrent-session limit, walk through a live view of a working profile | Mentor |
| Week one | Expand the list of accessible profiles as training progresses, check the activity log | Team lead |
| Probation period | Withhold rights to change proxies, delete profiles, or invite new members | Admin |
| After probation | Re-evaluate the role, raise limits and access level if warranted | Owner / admin |
| If the role touches money | Keep a separate finance role — access to billing, not necessarily to the profiles themselves | Owner |
This doesn't require a ten-page document — it fits on a single checklist applied identically to every new hire.
What to hand over right away, and what to hold back
Splitting access into "safe from day one" and "only after a review" keeps you from granting more than necessary just to be polite.
Safe from day one:
- access to specific client/account profiles assigned at the start;
- viewing the activity history of their own profiles, for self-checking;
- basic interface instructions — doesn't matter whether the person ever sees a password.
Only after probation or a team lead's sign-off:
- admin rights (managing proxies, limits, other members);
- access to the finance side — billing, team-wide spend stats;
- the ability to export cookies or profile credentials;
- access to 2FA keys in the profile's vault — usually not required for everyone who works with an account.
That last point gets missed often: someone can run a full ad campaign without ever manually entering a two-factor code, because the account is already authenticated inside the profile. Access to the keys themselves is only needed by people responsible for recovery or issuing backup codes — a separate role, unrelated to day-to-day work. The mechanics of that vault are covered in encryption and the profile's 2FA vault.
Common mistakes when granting access to a new hire
Giving access to the entire profile pool "just in case." It's simpler to scope access to 5 clients up front than to later figure out who logged into an account nobody assigned to the newcomer.
Not recording when and to whom access was granted. If you have to untangle, three months later, who was authorized to log in at the moment of an incident, a team activity log saves hours of guesswork.
Handing out admin rights for convenience rather than necessity. An admin can change proxy settings and fingerprint configuration on other people's profiles — convenient for a team lead, excessive for a rank-and-file buyer, even an experienced one.
Forgetting the profile limit. Without one, a new person could technically open the entire pool at once if they were accidentally granted access to it. The limit isn't about distrust — everyone makes mistakes, and a system-level safeguard is cheaper than cleaning up after one.
Passing along a personal device with browsing history and saved logins. Even as a "temporary fix while we sort out access," it leaves a device fingerprint tied to two different people and complicates diagnosis if something goes wrong with an account later.
Not planning the process in advance, deciding on the fly. If the profile list, role, and limit get decided on the first working day, onboarding inevitably stretches out — while the team lead digs up passwords, figures out exactly what access is needed, and checks with a client before handing over their account.
Scale matters
For a three-person team with a dozen profiles, manual onboarding through a shared document is still tolerable — the risk is low if there's discipline. But once you're past 50–100 profiles and the team has turnover (interns, project-based contractors), the manual process stops working: the number of profiles you're responsible for when someone joins or leaves grows faster than anyone can track in their head. Organizing a large profile pool is its own topic, covered in detail in organizing hundreds of profiles without chaos. If you're already counting profiles in the hundreds, it's worth sorting that structure out first, then building onboarding on top of groups and tags.
In practice, teams pick a plan based on team size and the number of client accounts: a small agency of 3–5 people usually fits comfortably into 20–100 profiles, while larger teams with contractor turnover find it easier to work with a 300-profile plan and up, where member roles and limits configure flexibly. Current limits and pricing are on the pricing page.
FAQ
Do I need to change an account's password after every new hire? No, not if access is granted through a profile assignment and a role rather than a raw password. The employee works inside an already-authenticated environment and may never know the credentials. Change the password only if it was shown to the person directly — say, during an email-verification step the newcomer completed themselves.
How quickly can access be revoked if someone doesn't pass probation? If access was granted through profile assignment and a role, removing the assignment and taking the person out of the team is enough — account credentials were never exposed, so there's no need to rotate them unless you suspect a leak.
Can a contractor get two-week access without risking it becoming permanent? Yes, as long as you note a review date on the checklist — for example, a monthly calendar reminder for the team lead to audit the list of active members. The technical controls (role, profile limit) don't replace the organizational habit of regularly checking who should still have access.
What if a new hire needs access to a client's account, but the client won't share the password with a third party? This comes up constantly in agencies — and it's a strong argument for working through profiles rather than passwords from the start: you can honestly tell the client that agency staff never see their password directly, only a working environment the client can revoke at any time.
Should a new hire get live-view access before getting their own credentials? That's a reasonable intermediate step for the first few days: a mentor walks through the real workflow live, the newcomer watches and asks questions, and full independent access follows once the core processes are clear.