Anna runs a hair salon in Poznań. Four people on the team, a calendar booked two weeks ahead. Social media went to the receptionist, because she talked to clients the most.
Handing over the job took one sentence: "Just log in, the password is salonName2024".
A year later the receptionist left for a salon two streets away. The password stayed in her phone. The Instagram app stayed logged into the company account. Anna only noticed when someone replied to a client's message at 11:40 pm.
That is how most small businesses hand over their social accounts: one shared password, on a handshake, with no way to take it back. Facebook, Instagram and Google Business Profile have had a proper answer to this for years. It takes about fifteen minutes and no technical knowledge at all.
A password is not a permission. A password opens the entire account: settings, payment methods, message history, the delete-page button. A permission can be trimmed down to a single task and revoked with one click, without disrupting anyone else.
If you read our piece on phishing attacks targeting Facebook page admins, you know the other half of this problem: attackers hunt precisely for the people who hold full control of a company page. Every extra device with your company password saved in it is another open door for them.
What a shared password actually costs
Short answer: it costs you control at the moment you did not plan for. An employee leaving, an argument over the final invoice, a lost phone, one click on a message from "Facebook support".
The numbers back this up. In a Beyond Identity survey of laid-off employees, 30% admitted they still had access to their former employer's social media accounts, 32% to company email, and 91% could still reach company files (Beyond Identity, offboarding research). In an earlier survey by the same company, 83% of respondents kept using a previous employer's accounts after leaving, and 24% deliberately held on to a password (Beyond Identity, 2022). Those are US and UK samples, but the mechanism is universal: nobody revokes the access they forgot about.
There is a purely technical risk on top of that. Poland's national CERT team logged 260,783 security incidents in 2025, of which 97% were online fraud, phishing included (CERT Polska annual report for 2025, NASK). Its moje.cert.pl monitoring service alone recorded leaks involving nearly 5.5 million passwords in a single year of operation (NASK). A password that lives on three phones and one sticky note under a keyboard will eventually land in a dataset like that.
There is a third cost almost nobody counts: no accountability. When everyone logs in with the same password, you cannot establish who deleted a client's comment, who promised a discount in a private message, or who changed the opening hours. There is no culprit because there is no trail. With individual access, every action has a name attached.
The extreme version looks like plenty of long-running restaurants: the Facebook page was created by a waiter who left three years ago, and the Google Business Profile was set up by an agency that stopped answering emails. The owner holds full control of neither asset. Recovering an orphaned page means weeks of correspondence with the platform and proving the business is yours, not fifteen minutes of clicking.
Access to social accounts without sharing a password: how it works
One rule covers all three platforms: your company page is an asset, and people are granted named access to it from their own personal account. Your employee logs into their own Facebook or their own Google account and sees your page in the panel. They never learn your password.
| Shared password | Named permission |
|---|
| One password, several phones | Everyone logs in with their own account |
| All or nothing | You switch on only the tasks needed |
| Revoking means changing the password and disrupting everyone | Revoking means one click on one person |
| You cannot tell who did what | Action history with a name attached |
| The employee can delete the page | Without full control, they cannot |
One trap catches a surprising number of salons and restaurants: do not create a separate personal profile "for the business". Facebook allows one personal account per person, and accounts like that get blocked during verification. A company page is meant to be an asset attached to the real people who manage it, not to a fictional character named after your salon.
This is not only a small-business problem. According to Zoho Vault's report on workforce password security, 74% of organizations lack a complete picture of who has access to which systems and at what permission level (Zoho Vault, State of Workforce Password Security 2026). The difference is that in a four-person business you can sort this out once and be done with it for years.
Facebook Page access levels: who can do what
Start with one fact: the classic Page roles no longer exist. Admin, Editor, Moderator, Advertiser and Analyst are names from a previous era. Meta now works with Page access, and the equivalent of the old admin is full control.
You have two types of access to choose from, and this is the most important decision in the whole process:
Facebook access means the person manages the Page directly from Facebook and can act "as the Page". It comes in full control (everything, including adding and removing other people) and partial access, where you switch on selected items from seven separate tasks: content, messages, ads, insights, events, moderation, and linked accounts.
Task access is the narrower option. The person works only through business tools such as Meta Business Suite or Ads Manager, and never appears on Facebook in the Page's name. That is the natural choice for an external contractor.
A beauty studio in Wrocław handles it like this: the new person handling communication gets partial access with three tasks, namely content, messages and insights. Ads, settings and payment methods stay with the owner. Three months later the collaboration ends and revoking access takes two clicks. The Instagram account was never logged in on anyone else's phone.
The path if you do not use Business Manager: go to your Page, click Manage, then Professional dashboard and Page access. With Business Manager: Business settings, then Users, People, Add, enter the email address, pick the permission level, select the Page and click Invite. Changing or revoking access is the three dots next to the person's name and either Edit access permissions or Remove from Page.
Three details that will save you a headache:
- The person you invite must have their own Facebook account. The invitation goes to an email address or profile name. You do not create an account for them and you never hand over your password.
- Instagram needs a one-time exception. To attach a business Instagram account to your business portfolio, its password has to be entered once during linking. You do that yourself, once. After that you grant people access without the password.
- Turn on two-factor authentication on your personal account and require it from everyone with access. Meta blocks some permission-related operations when it is missing, and without it a stolen password is all an attacker needs.
Always keep two people with full control: yourself and one absolutely trusted person, such as a co-owner or a family member. One construction company added a second family member in that role. If one account gets hijacked or locked, the Page is not left without a fully privileged caretaker.
Google Business Profile access: make the employee a manager
The rule is simple: give an employee or agency the manager role, never owner. A manager does almost everything day-to-day work requires: edits information and hours, adds photos, publishes posts, replies to reviews, pulls insights. What a manager cannot do is add or remove users and delete the business profile (Google Business Profile Help).
Google's own documentation puts it in one sentence:
"Managers (formerly 'location managers') have nearly identical access to the profile as owners" - with a list of two exceptions: adding and removing users, and deleting the business profile.
The hierarchy is worth knowing, because this is where the most common mistake hides. A profile can have many owners but only one primary owner, and only owners can remove other owners and managers. Give someone the owner role and you hand them the right to remove you.
There is also a time-based safeguard few people know about: a new owner or manager has to wait 7 days before they can delete the profile, remove other users or transfer primary ownership. That is your window to undo a mistake.
The path: open your Business Profile, go to Business Profile settings, then Users and access, click Add, enter the email and pick Manager. Revoking works in the same place: select the person and click Remove user.
Social media permissions in SyncBooster: you invite a person, not a password
In SyncBooster you never hand over a password: you invite someone by email to a specific brand, and from that point they work from their own account. Same logic as Meta and Google, but in one place for every channel at once.
- You connect the accounts once, yourself. Channels are linked to a brand on your side, so your Facebook, Instagram and Google Business Profile passwords never leave your computer. We covered the step-by-step in our guide to connecting social media accounts.
- You invite the employee by email to one brand. They see only the brand you added them to, create and publish posts, and work with an assistant that already knows your business. They cannot invite anyone else or touch the connected accounts. The full feature description is in our article on adding team members to a brand.
- Revoking access takes effect immediately. Remove the person from the brand and their session stops meaning anything. An invitation that was never accepted expires automatically and you can withdraw it at any time.
The result for you as the owner: your employee works independently, and you hand nobody the keys to your company's online identity.
When an employee leaves: the access revocation checklist
Revoke access on the day the person finishes, and do it in this order. The first three items close the doors that actually matter; the rest tidy up everything else.
Do not put this off until "the next chance you get". Access nobody revoked stays open for years regardless of the departing employee's intentions, and your client inbox stays open right along with it.
Frequently asked questions
Can I give an employee access to my Facebook Page without sharing a password?
Yes, and it is the only correct way. You invite them from their own Facebook account, choose the scope of permissions, and revoke it whenever you want. Your password never leaves your head.
Which access level should a social media person get?
Partial access with content, messages and insights. Keep full control for yourself and one trusted person. Add ads only when the employee genuinely manages the budget.
What happens to the posts after I remove an employee from the Page?
They stay. Content published in the Page's name belongs to the Page, not to the person who sent it. Revoking access deletes neither posts, nor insights, nor message history.
Will the employee see my personal Facebook profile?
No. Permissions cover the business Page only. Your personal profile, friends and private messages stay invisible, just as their profile stays invisible to you.
Why shouldn't I make an employee an owner of my Google Business Profile?
You can, but you should not. An owner may remove other users and the entire business profile. A manager does all the day-to-day work without that risk.
Fifteen minutes today, years of calm
Sorting out access is one of the few business tasks you do once and that then protects you for as long as the business exists. Open your Page and profile settings today, look at who is on those lists, and remove any name that no longer means anything to you.
And if you want to take most of the publishing work off your plate and off your employee's, try SyncBooster. You connect the accounts once, invite your person to a brand by email, and an assistant learns your business and writes posts for Facebook, Instagram and Google Business Profile. You keep the part that matters: the keys stay with you.