
Stack Planning
Part of Marketing stack security and permissions
Removing access when an agency engagement ends
Coordinate an agency handover, remove direct and indirect access, verify business control and record remaining data obligations.
undefined
Agree a cut-off with the business and system owners, then sequence the work handover and access removal around it. Record the cut-off, the owner responsible for each change and the checks that will confirm it.
The business needs to retain control of its accounts and required records while closing the former agency’s access routes. Keep campaign operations and required records with business owners as access is removed.
Reconcile agency access routes
List individual logins, agency-organisation invitations and identity-provider groups. Content First’s access guide names Google Ads, a Google Ads manager account, Facebook Business Manager, a Facebook Page and Ad Account, and Google Search Console (Content First). Also list CMS roles, shared drives, connected applications, service accounts, API credentials and automations the agency created or operates. Reconcile the agency’s list with internal system owners; neither list alone proves completeness.
For each entry, mark whether the underlying account and working space are controlled by the business or the agency. Arrange an approved replacement for any needed agency-controlled connection before cutting it off.
Assign owners for pending posts, live advertisements, reports and creative files. Treat moving a full social publishing queue as a separate migration task, with an owner and completion point.
Set the handover order
Use an access register with columns for platform or account, access holder, role, business owner, action, agreed cut-off, due date and verification evidence. For each entry, record the required handover before cut-off, the removal or credential change at cut-off, and the post-cut-off check; assign an owner to exceptions. Start by confirming account control and replacement operators, then retrieve agreed deliverables and remove unneeded users, groups, agency-organisation access, app grants and credentials.
Removing a user from Microsoft Entra ID does not necessarily end every application session: Microsoft says an app can, where its authentication protocol allows, silently reauthenticate with a refresh token, and Entra ID cannot directly revoke an app-issued session token (Microsoft Learn). Inspect each connected application’s owner, permissions, separate grants and dependent workflow; where needed, move the workflow to a business-controlled connection before revocation.
Verify access removal and business continuity
Have each system owner confirm the changes they control, and review active sessions and tokens where exposed. Microsoft recommends deprovisioning users in applications, especially those with app-issued sessions or direct sign-in, and ensuring applications revoke their own session tokens and stop accepting still-valid Microsoft Entra access tokens (Microsoft Learn). Change shared passwords or API secrets known to the agency if still in use, updating dependent integrations through an approved process.
Keep a dated before-and-after role record where available. For each critical route, record the check and result against the register, including direct roles, agency-organisation access and material app grants; a removed-user screen alone cannot prove every alternate route is closed.
Record what could not be checked, why, and the owner and due date for resolving it. Keep the task open until critical routes are verified or an authorised business owner accepts the documented exception.
Finish the information handover
Confirm who received the agreed campaign files, reports and customer records. Check the agreement for retained copies, subcontractors, return and deletion terms, and request any evidence it requires. Revoking system access does not delete exported information, and a confirmation may not prove immediate removal from every backup.
If the business is an APP entity, the Privacy Act 1988 (Cth) includes the Australian Privacy Principles. The OAIC says its Guide to Securing Personal Information covers reasonable steps to protect personal information under the Act. APP 11 guidance addresses reasonable steps to destroy or de-identify it, except where it is contained in a Commonwealth record or must be retained under Australian law or a court or tribunal order (OAIC).
Close the task when an internal owner can identify current administrators, confirm the next campaign can operate and account for remaining access or data-retention exceptions. Record the cut-off, changes, verification limits and owners of unfinished work. The OAIC’s guide directs entities to its guidance on data breach notification, which includes detailed information about the mandatory requirements for reporting serious data breaches under the Privacy Act (OAIC).



