Security baseline
- Give every teammate an individual Marketer identity.
- Use Selected workspaces when account-wide reach is unnecessary.
- Use Viewer for read-only review.
- Connect only the provider resources that belong to the active workspace.
- Keep passwords, OAuth codes, reset links, API keys, and MCP credentials out of chat, Slack, tickets, recordings, and screenshots.
- Keep Review everything until real paused launches are verified.
- Route warning and critical notifications to someone who owns the response.
- Remove former teammates, stale invites, unused MCP seats, and unrecognized connected agents promptly.
Diagnose access by layer
Check these layers in order:- Personal authentication — can the person sign in through a listed identity?
- Account membership — does the person still belong to the account?
- Workspace reach — is the workspace under All workspaces or explicitly selected?
- Workspace role — Owner, Admin, Member, or Viewer?
- Provider authorization — is the connected identity or key healthy?
- Provider resource selection — is the exact account, store, property, Page, pixel, or catalog selected?
- Policy — do guardrails, approvals, autonomy, and billing state allow the action?
- External session — for MCP or Slack, is the personal link, seat, scope, or workspace grant valid?
Access symptom matrix
Contain a possibly compromised account
1
Save evidence without secrets
Record timestamps, page names, exact messages, and sanitized screenshots.
2
Sign out every session
Go to Settings → Authentication and select Sign out everywhere.
3
Secure sign-in
Secure the email and listed identity providers, then use Send reset link where appropriate.
4
Review account access
Ask the account Owner or Admin to inspect members, roles, selected-workspace grants, and pending invites.
5
Revoke external access
Disconnect unknown MCP agents, review MCP seats, and rotate rejected or exposed provider credentials in the provider and Marketer.
6
Contain material activity
Return autonomy to Review everything, pause affected workflows through their supported controls, and inspect approvals and provider activity.
Protect credentials by type
Handle uncertain reads safely
When a page reports unavailable status or a refresh failure:- preserve the last-known connection or cached data;
- refresh once before mutating state;
- mark cached figures as stale;
- capture the exact error;
- avoid disconnecting or creating duplicates; and
- escalate with scope and timestamp.
Prepare an escalation
Include only what another operator needs:- account and workspace name;
- your effective role and access mode;
- page and exact visible error;
- provider resource ID when relevant;
- expected and actual behavior;
- last successful action or sync time;
- reporting date range, currency, and attribution source; and
- sanitized screenshot.
Recurring review
Review quarterly and after every team change:- members, roles, and pending invites;
- workspace switcher reach;
- provider identities and selected resources;
- MCP seats and connected sessions;
- Slack routing and notification recipients;
- guardrails, autonomy, audiences, and protected campaigns;
- account-versus-workspace billing ownership; and
- recovery owners and contact paths.