Close-up of a smartphone showing Instagram login on a wooden table.
Photo by freestocks.org on Pexels

Stack Planning

Part of Marketing stack security and permissions

Reviewing administrative access across marketing tools

Review effective administrator rights across marketing tools, groups, native accounts and connected apps, then verify each approved change.

Repeat the review at an interval set for the organisation’s risk and whenever duties change. Compare each identity’s effective rights with its current work. Start with systems that can publish, change permissions, spend money or export customer information.

SimplyBook.me’s Marketing Suite is accessed from its admin interface and includes functions for managing booking links to Facebook, Instagram, Google, Booking.page Marketplace and a booking website or widget. Bookings can be tracked by channel, so treat linked destinations as separate access routes. Do not assume the suite’s user list shows every underlying permission.

A user list is a starting point, but may miss group assignments, underlying native accounts and connected applications.

Identify every relevant access route

For each tool, obtain users and roles from its owner. Add identity-provider groups, agency users, service accounts, API credentials and applications with broad permissions. Where a management tool controls a website, social or advertising account, inspect the underlying account too.

Record the identity, business sponsor, effective privilege, purpose and the person authorised to approve a change. Mark unexplained access for investigation. Establish an unfamiliar service account’s purpose before removing it, because it may run a critical integration.

Check whether an identity can change users or security settings, publish, export or connect another app. Compare effective roles, group membership and direct assignments against product permissions and connected-account settings. Confirm the current task, business-owner approval, sign-in method and multi-factor authentication.

If Microsoft Entra supplies identity roles, record them alongside product access. Its Application Administrator role can create and manage all aspects of app registrations and enterprise apps. Assess whether the person’s current task requires the assigned role.

Compare each privilege with a task

Ask the sponsor which action requires administrator access. Someone who schedules a campaign may not need to invite users. Someone who reads a report may not need to export customer records.

Where a narrower role supports the work, assign an owner to make and verify the change. Keep individual accounts where the service permits. If a shared credential is unavoidable, record its custodian, authorised users and change procedure.

Check connected applications separately. In some systems, an application’s authorisation token can keep working after the human user’s password is reset. Confirm the grant’s owner, permissions and purpose. Coordinate removal of an unused grant with the owner of any dependent workflow.

Close findings with evidence

For each change, record the previous and new right, approver, date and verification result. Confirm the person can still complete the intended task. Confirm the removed privilege is no longer available through another known route.

If the service cannot expose or test a route, record that limit rather than treating a settings screen as complete proof. The review should leave an explained set of effective administrators and assigned actions for unknown or excessive rights.

More from Stack Planning