Digital marketing
Who holds the keys to your page
A business page is an asset, and most are held by the personal account of somebody who is no longer there.
A business page is worth what its audience is worth, and that audience took years to build. It is an asset in the ordinary sense — something you own, that produces value, and that can be lost.
The question of who actually owns it is nearly always asked too late: the day the person who created it can no longer be reached, the day the previous provider stops replying, or the morning the page has gone and nobody knows which account was used to log in.
This article is about that ownership: the personal account behind a business page, the roles and the one to give nobody, a provider leaving, restriction, a compromised account, and what is never recovered. The companion article covers what gets published and how — the formats, the approval circuit, the lead time, measurement — and none of that is repeated here.
It contains no figures. The available statistics on these incidents come from vendors, cover self-selected global samples, and say nothing useful about a ten-person Algerian business.
The page does not belong to whoever runs it
There is a confusion, installed on day one and rarely corrected, between running a page and owning it. Whoever posts every day feels legitimately that the page is theirs; the business feels equally legitimately that it belongs to it. Both can be wrong technically.
Technically, what counts is the list of accounts holding an administrator role, and nothing else. Neither the page name, nor the logo, nor the fact that the business pays for the advertising creates a right of access. A page can carry your brand and be administered exclusively by somebody else.
That situation is more common than people think, and it is nearly always unintentional. It comes from convenience: somebody creates the page one afternoon, on their own account, because you have to start somewhere, and nobody ever revisits that ten-minute decision.
The practical consequence is that a precise question has to be asked, and asked now while everything is fine: which accounts hold an administrator role on this page, and does the business control at least one of them? If the answer is no, or “I don’t know”, that is the only urgent point on this page.
The personal account behind the page
The major platforms do not allow a standalone business page to be created: pages are administered by personal accounts, which belong to individual people. It is a design constraint, it surprises many owners, and it explains most of the situations described here.
It has a consequence that needs stating plainly: an employee’s personal account is an object the business does not control and cannot control. It can be disabled for a reason unrelated to work, lost with a phone, or simply withdrawn by its owner the day they leave.
The answer is not to ask staff for their passwords, which is a bad idea for obvious reasons and generally breaches the terms of use. It is to have several administrators, including at least one account held by somebody who will not be leaving — often the owner, even if they never post.
There is an important nuance: the dormant administrator has to log in from time to time. An account unused for two years can be blocked for inactivity, or ask for a verification its owner no longer knows how to pass. A login each quarter is enough, and it is the only maintenance this precaution requires.
The roles, and the one to give nobody
Platforms offer several access levels, and almost everybody gives the highest one to everybody, because it certainly works and saves understanding the rest. It is the shortcut that produces the irreversible situations.
The administrator role allows, among other things, removing the other administrators. That precise capability is what makes it different from all the others: a person holding it can, in three clicks, become the only one who has it. No other access level allows that.
The rule that follows is simple and rarely applied: the administrator role is reserved for people in the business whose departure would be an event, and nobody else. A provider, an intern, a cousin who helps at weekends gets a publishing role, which allows all the daily work and does not allow closing the door.
The number of administrators also has to be more than one and stay small. One is an outage waiting to happen — illness, a lost phone, a blocked account. Six is an attack surface, and above all a list nobody rereads. Two or three is the order of magnitude that settles both problems.
The provider who leaves
Parting from a provider is when access arrangements reveal themselves, and it is a bad moment to discover they were badly organised. The ordinary case is not conflict: it is the agency that closed, the person who changed career, the number that no longer answers.
What makes that moment difficult is rarely ill will. It is that the provider often created everything — the page, the advertising account, the tool access — under their own credentials, because it was faster on day one and nobody asked otherwise.
Prevention fits in one sentence to put in the contract, or simply in a written message at the start: everything created for the client is created on accounts the client owns, and the provider is invited to them rather than owning them. That sentence costs nothing on day one and is worth several weeks of process later.
The exit is prepared too, and it is three moves on the day the work ends: remove the provider’s access, check no forgotten secondary access remains — a scheduling tool, an advertising permission — and change what needs changing. That last point is often neglected although it is the simplest.
The annual access inventory
Access accumulates and is never withdrawn spontaneously. Every provider, every intern, every connected tool adds an entry to a list nobody rereads, and after three years that list contains names the owner does not recognise.
The inventory that settles this takes twenty minutes a year. Open the list of people holding a role on the page, the list of connected applications, and the list of accounts with access to the advertising account. Three lists, read once, with one question per line: does this person or tool still work for us?
The most surprising part is nearly always the connected applications list. A scheduling tool tried for a fortnight two years ago generally keeps its authorisation, and that authorisation lets it publish. This is not theoretical: unexpected posts regularly appear on pages whose owner has forgotten a connection.
When you do it matters, as with any periodic check: attach it to something that already exists, the annual close or a contract renewal. An inventory with no date gets done once, in the year somebody read an article about it.
Two-factor authentication, and the device that carries it
Two-factor authentication is the only measure that genuinely changes the probability of an account being taken, and platforms now require it for accounts administering pages. It is no longer a choice, it is a precondition.
It does introduce a dependency few people anticipate: the second factor lives on a device. A phone lost, stolen, or simply changed without precaution turns a protection into a lock you are on the wrong side of, and recovery takes considerably longer than losing a password.
Two precautions settle most of it and take five minutes at activation. Keep the backup codes provided at that moment, printed or written down, somewhere other than the phone concerned. And register a second factor — a second device, or another method — rather than only one.
This deserves particular attention in a context where phones change often and a SIM can be replaced. Authentication resting solely on a message sent to a number is the most fragile option available, precisely because the number is not as personal as people assume.
The day the page is restricted
A page can be restricted or suspended by the platform without prior warning, for a supposed breach of the publishing rules. It is an incident distinct from a compromise, and it is handled completely differently.
The frequent causes are rarely spectacular: an advert containing a prohibited claim, an image reported by several people, an administrator account itself reported for a reason unrelated to the business. The decision is often automatic, and it is often reversible.
The only thing to do at the first moment is to read precisely what is alleged, in the space provided for it — not to guess. Appeal procedures exist, they work in a notable share of cases, and they require answering the exact reason rather than the assumed one.
What must not be done is creating a second page in the meantime. It is the natural reflex, it is understandable, and it makes things worse in two ways: it can be read as circumvention, and it splits the audience if the first page comes back — which happens more often than the anxiety of the moment suggests.
The compromised account
The takeover of an administrator account is the most serious incident on this page, because it combines a loss of access with active use of your name. The usual scenario is not a technical intrusion: it is a message that led somebody to enter their credentials on a page that looked like the right one.
The most common motive is commercial. A page with a real audience serves to run adverts paid for with the registered payment method, or to sell the audience itself. That means time matters: most of the damage happens in the first few hours.
The useful sequence is short and has to be read before it is needed. The compromised account is recovered first, not the page — while the account is in somebody else’s hands, removing its access achieves nothing. Then remove unknown administrators, check the registered payment methods, and stop any running campaigns.
The real prevention is elsewhere and it is human. Nobody enters their credentials from a link they received, ever, including when the message appears to come from the platform and announces a violation. That sentence, said once to the team, is more effective than the rest of this section.
What is never recovered
You have to know what is reversible and what is not, because it changes what to protect first. A restricted page often comes back; a compromised account is frequently recovered; the audience does not rebuild.
What disappears permanently when a page is deleted is the followers and the history of posts with their comments. No procedure restores them, and that is the real value of the asset this page’s first section describes.
What is always recoverable, by contrast, is what you hold elsewhere: your images, your text, your customer list, your website. It is the strongest argument for a simple rule — what matters must exist somewhere you control, and a page on a platform is not that place.
That does not mean doing without these platforms: they are where the customers are. It means not keeping the only copy of anything there. A customer list existing only as conversations in a messaging app disappears with the account, and it is the most expensive error we see.
The business manager
Platforms offer a space intended for businesses, distinct from personal accounts, in which pages, advertising accounts and payment methods are held as assets. It is the structural answer to everything above, and it is very widely ignored by small outfits.
What that space changes fits in one sentence: assets belong to the organisation and people hold roles in it, instead of assets belonging to people. An employee leaving then becomes a role removal rather than a negotiation.
It has a reputation for being complicated and it is moderately so — an hour for a small business, once. The real difficulty is not technical, it is that nobody does it before needing it, and that by the time it is needed you first have to resolve the access problem it would have prevented.
There is an order to respect and it avoids the most common trap: the page has to be added to that space by an administrator who controls it. If the page still belongs to a former provider’s account, that step is precisely the one that will not go through, and the next section applies.
Taking over a page nobody has access to
The case comes up regularly and it is not hopeless. The page exists, it carries your name, it has an audience, and no company account holds a role on it. The first reflex — create a new page — is the wrong one, for the reason developed above: the audience does not transfer.
The first route is always human and it succeeds more often than people imagine. Find the person, explain, ask for an administrator to be added. A former provider generally has no interest in keeping a page they no longer use, and refusal comes from silence more often than from hostility.
The second route is the claim procedure the platforms provide, which exists for exactly this situation. It requires proving you represent the business — registration documents, official correspondence — and it takes weeks rather than days. It does work, provided the page name genuinely matches the business name.
That last point is what decides it, and it is worth anticipating well in advance: a page named exactly as the registered business is recoverable, a page carrying an invented trading name much less so. It is one argument among others for making the two match.
What we do, and what we refuse
What we take on is bounded: the access inventory, setting up the business space, checking the company holds at least one administrator who will not leave, and the written list of what to do on the day of a restriction or a takeover.
We do not accept an administrator role where a publishing role does the job, and it almost always does. That refusal looks excessive and it is the only one that guarantees the client anything: an administrator provider can remove the other administrators, and no contract makes that act impossible — only the absence of the right does.
We do not work from a client’s personal account, even when it is faster and even when they offer. It breaches the terms of use, it exposes their private conversations, and it makes it impossible to distinguish afterwards what was done by whom — which is precisely the question asked on the day of an incident.
Finally, we do not promise to recover a page. Claim procedures exist, they often work, and their outcome depends on matches between names and documents we do not control. What we can do is assemble the file properly and say honestly, before starting, whether the page name makes the attempt plausible or not.
Frequently asked questions
Who actually owns our page?
The accounts holding an administrator role, and nothing else. Neither the name, nor the logo, nor the fact that you pay for the advertising creates a right of access: a page can carry your brand and be administered exclusively by somebody else. Ask the question now, while everything is fine — if the answer is “I don’t know”, that is the only urgent point in this subject.
Should we give our provider the administrator role?
No. That role allows removing the other administrators — the precise capability that distinguishes it from all others, and no contract neutralises it. A provider, an intern or a relative who helps gets a publishing role, which allows all the daily work and does not allow closing the door. Keep two or three administrators, all internal.
Our former provider has stopped replying and holds the access.
Start with the human route: finding the person and asking for an administrator to be added succeeds more often than people imagine, refusal coming from silence more often than hostility. Otherwise, the claim procedure exists for this situation: it requires proof that you represent the business and takes weeks. It works above all if the page name genuinely matches the registered business name.
Our page has been restricted. What first?
Read precisely what is alleged in the space provided, and answer that exact reason rather than the assumed one. Appeal procedures work in a notable share of cases. Above all do not create a second page in the meantime: it can be read as circumvention, and it splits the audience if the first comes back — which happens more often than the anxiety of the moment suggests.
An administrator account was compromised. In what order?
The account first, the page second: while the account is in somebody else’s hands, removing its access achieves nothing. Then remove unknown administrators, check the registered payment methods and stop any running campaigns — most of the damage happens in the first few hours, because the motive is nearly always commercial.
What is never recovered?
The followers and the history of posts with their comments. A restricted page often comes back, a compromised account is frequently recovered, but the audience does not rebuild. Hence a simple rule: what matters must exist somewhere you control. A customer list existing only as conversations in a messaging app disappears with the account, and it is the most expensive error we see.
Where we come in
Twenty minutes is enough to learn who owns the page. The day that owner stops answering, those twenty minutes are worth nothing.
- We open the business space and attach the page to it, in your name.
- We bring every role down to what it strictly needs, ours included.
- We check each quarter that the owner is still signing in.
If the page already belongs to a business account and you have a second administrator, we have nothing to sell you.
Read next
Social content: a post is an announcement, not a document
What gets published in a feed disappears, including for you. The document has to exist elsewhere, at an address that belongs to you.Filming without closing: shooting inside a business that is open
The equipment is not the problem. The problem is filming while you serve, with customers in shot and one pair of hands.Trialling Snapchat: the stopping rule is written before the first dinar
On a platform whose figures will settle nothing, the only honest method is to decide in advance what would make you stop.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.