DAS 100 · Module 2

Accounts & Setup

Facts verified: July 2026Last updated: July 2026Curriculum v2026.1

What you'll be able to do

  • Set up a Business Manager that survives contact with reality (bans, breakups, staff turnover)
  • Run ads on pages you don't own without anyone having to share a password like it's 2014
  • Never lose an ad account to a preventable mistake

The short version: Business Manager is the advance sheet of your ad operation - nobody enjoys doing it, everyone enjoys having done it. Set up a Business Manager, create your ad account inside it (timezone and currency are permanent, so breathe before clicking), verify your domain, add a backup payment method, turn on two-factor for everyone, and add a second admin. Then learn Partner access, because in this industry you will spend your whole career running ads on other people's pages.

The boring module that saves your business

Here's a fun industry fact: the most common way music and nightlife operators lose their entire ad operation isn't a policy violation. It's structural. One person set everything up on their personal profile, that profile got restricted (or that person quit, or the co-promoter situation went the way co-promoter situations go), and everything attached to it went down with the ship.

This module exists so that never happens to you. It's the load-in of this course. Do it right and every show after this gets easier.

Business Manager: your venue, not your apartment

A Business Manager (business.facebook.com) is a container that owns your business assets - pages, ad accounts, pixels/datasets, catalogs - separately from any one person's Facebook profile. People get ACCESS to the container; no person IS the container.

Why this matters (the because): personal profiles are fragile. They get hacked, flagged, and restricted for reasons that have nothing to do with your ads. When assets live in a Business Manager with multiple admins, one person's bad day doesn't become the whole operation's bad month.

First rodeo

If this is your first rodeo: you might currently be boosting posts from your personal account. That works until it doesn't, and when it doesn't, there's no undo. Spend the 30 minutes. Future-you, standing at the door on a Friday with a dead ad account, is begging you.

Go deeper: how restrictions cascade

Meta's enforcement links entities: a restricted personal profile can restrict the Business Managers it admins, which can restrict the ad accounts inside, which pauses every ad. This cascade is why admin redundancy isn't paranoia - it's structural engineering. It's also why you should never buy or borrow ad accounts (a common gray-market "fix") - inherited accounts carry inherited risk history.

The permanent decisions

When you create an ad account, two settings are forever: timezone and currency. Choose wrong and your only fix is a new ad account, which means abandoning your account history - and account history is part of what delivery optimizes on. Set the timezone to where your shows actually happen. Your reporting days should end when your business days end (fine, 4am, we know who we're talking to - midnight is still the setting).

Domain verification and payment hygiene

Verify your domain (Business settings → Brand safety) - it proves you own the site your ads point to and unlocks full control over link presentation. Takes ten minutes with a DNS record or meta tag.

Payment: add a primary AND a backup method. Ads stop the moment a card declines, and cards love to decline at 11pm on the Thursday before your biggest show, because the universe has a sense of humor. If your card has a low limit, know your account spending limit settings too - useful guardrail when multiple people can touch the account.

Two-factor and the two-admin rule

Every person with access: two-factor authentication, mandatory, non-negotiable. Business Managers get hijacked through the weakest personal account attached to them, and hijacked ad accounts get drained running someone else's scam ads on your card.

And the two-admin rule: your Business Manager needs at least two trusted admins. One admin is a single point of failure. This is the ad-ops version of never giving one person the only key to the cash drawer.

Partner access: the section this industry actually needs

Here's where generic courses wave goodbye and we keep going. In events and music, you almost never run ads only on assets you own. The promoter runs ads for the venue's page. The manager runs ads for the artist's page. The label runs ads through the roster's pages. Welcome to the whole job.

There are three ways to get access to someone else's page, in ascending order of correctness:

  1. They share their password. No. Never. This is the marketing equivalent of leaving the safe open because counting the drop is annoying. It's also how accounts get flagged for suspicious logins.
  2. They add you as an individual with a page role. Fine for tiny situations, fragile at scale - access is tied to your personal profile, and offboarding is manual and usually forgotten.
  3. Partner access (the professional standard). Their Business Manager grants YOUR Business Manager access to specific assets with specific permissions. Clean grant, clean audit trail, clean removal when the relationship ends. Both sides stay owners of what's theirs.

The because: partnerships in this industry end - residencies move, managers change, labels and artists part ways. Partner access means offboarding is one click instead of a password-changing panic and a group chat that ends three friendships.

Go deeper: who requests what (the etiquette)

The operator (you) should send the request specifying exactly which assets and permission levels you need - and ask for the minimum. Requesting admin-everything from a venue you just met reads like asking for the master keys on your first shift. Standard ask for running ads: advertise permission on the page, access to (or creation of) the pixel/dataset, and your own ad account funding the spend. Walk the client through approval on a call; the approval UI confuses civilians.

Naming conventions (yes, really)

Decide a naming scheme now: pages, ad accounts, datasets, campaigns. Something like [CLIENT] - [ASSET] and [CLIENT] - [SHOW/RELEASE] - [PHASE] - [DATE]. The because: in six months you'll have dozens of assets, and "Untitled Campaign (Copy) (Copy)" is how spend ends up on the wrong show. Ask us how we know.

From the field

A promoter we know ran everything through the personal profile of one team member - pages, boosts, payment. That team member's profile caught a restriction over something unrelated to ads entirely. Every page went admin-less overnight, mid on-sale, and recovery took weeks of appeals. The rebuilt setup: Business Manager, two admins, partner access, 2FA. Total setup time: under an hour. The outage cost more than every hour of setup they'll ever do, combined, for life.

Common mistakes

  • Running the whole operation from one personal profile (see: everything above)
  • Wrong timezone/currency at ad account creation - permanent, no appeal, straight to jail
  • Sharing passwords instead of Partner access
  • One admin, no backup payment method
  • Skipping 2FA because "we're small" - hijackers love small; less monitoring, same stealable card

Take-home

Account Setup Checklist - BM → ad account → domain → payment + backup → 2FA → second admin → partner access flow → naming conventions. Print it, do it once, keep it for every client onboarding forever.

Learn more

Optional extra credit. Nothing below is required for the quiz, the certificate, or the job - the full lesson is above. This is for the sickos who want more.

  • Meta Business Help Center: Business Manager setup, Partner access, domain verification (business.facebook.com/help) - the primary docs, dry but authoritative
  • Our Module 9 covers what happens when accounts DO get restricted and how appeals actually work

Sources & dates: Meta Business Help Center (accessed July 2026) · Restriction-cascade behavior per practitioner consensus and Meta policy docs (July 2026)

Interface recreations

The screens this module describes, rebuilt in our own palette and type. Layout and information architecture only - no logos, no screenshots.

Contact Sheet Recordsbm_44120193 · USD · America/New_York
M2-A · Business Manager creationBusiness Settings · schematic

Business details

Tell us about your business. This information appears on invoices and to your partners.

1The Business Manager name is the top-level container - every ad account, Page, and person lives underneath it.
2Use a role-based email, not a personal one. This is what recovers the business account if a person leaves.
3The website field is later reused as the domain you verify under Brand Safety - keep them matching.
4One person creates the Business Manager. Everyone else gets added afterward with a scoped role, not a login share.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Contact Sheet Recordsbm_44120193 · USD · America/New_York
M2-B · Ad account creationBusiness Settings · schematic

Time zone & currency

Choose carefully - these settings are permanent for this ad account.

!

Time zone and currency cannot be changed after this account is created. Getting either wrong means abandoning the ad account and starting over with a new one - and losing its delivery history. 2

1These two fields are the entire reason this step gets its own screen - everything else here is editable later.
2Match the timezone to where the team actually works, not where the venue is, if they differ - it governs every report's day boundary.
3Read the warning before clicking. There is no confirmation dialog after this that saves you from a wrong currency.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Contact Sheet Recordsbm_44120193 · USD · America/New_York
M2-C · Domain verificationBusiness Settings · schematic
Verified domains
  • contactsheet.coVerified 3
  • archie.contactsheet.coPending

Verify archie.contactsheet.co

Choose one verification method. 1

TXT record value
meta-domain-verification=8f2c1a9e4b7d0f3c6a1e8b5d2c9f4a7e

Add this TXT record at your DNS provider for contactsheet.co, then click Verify. 2

1Three equivalent paths to the same result - pick whichever your DNS or hosting access allows without waiting on someone else.
2DNS propagation can take up to 72 hours. Start this step long before an on-sale, not the week of.
3Verifying the domain lets the business control link previews and Page ownership for URLs on that domain across the platform.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Safelight Presentsact_20260728 · USD · America/New_York
M2-D · Payment methodsBusiness Settings · schematic
Payment methods
  • CARD
    Visa ending in 4471Primary · added Jan 2026
    Primary
  • CARD
    Mastercard ending in 0092Backup 1
    Backup
Payment threshold 2
$250.00

Billed automatically once spend since last charge reaches this amount.

Billing country / currency
United States · USD
Next scheduled bill date
August 1, 2026
1A backup card matters because a declined primary card mid on-sale pauses every campaign silently - delivery just stops, no alert loud enough to notice in time.
2High-spend days can hit the threshold and trigger an extra charge before the monthly bill - expect more than one billing event during an on-sale week.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Safelight Presentsact_20260728 · USD · America/New_York
M2-E · Two-factor authenticationBusiness Settings · schematic
Enforcement scope 1

"Everyone" requires 2FA for anyone with any role on this Business Manager before they can perform actions.

People
PersonRoleMethod 2Status
Admin, Contact Sheet RecordsAdminAuthentication appEnabled
Manager, Safelight PresentsEmployeeSMSEnabled
Booker, Contact Sheet RecordsEmployeeNot set upNot enrolled
Recovery codes 3

10 single-use codes generated. Store them outside the Business Manager they protect - a password manager, not a Page description.

1"Admins only" is the workable default for a small operation - "Everyone" is stronger but blocks employees until they enroll.
2Authentication app beats SMS - SIM-swap fraud targets phone numbers specifically, and admin access is the actual prize.
3Recovery codes are the only way back in if the authentication app's device is lost - treat them like the master key they are.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Contact Sheet Recordsbm_44120193 · USD · America/New_York
M2-F · Add peopleBusiness Settings · schematic
Email invite
booker@contactsheet.co
Role 1
Assign assets 3
  • Safelight PresentsAd account · act_20260728
    Manage campaignsView performanceManage billing
  • @safelightbostonPage
    ModerateCreate contentManage Page
1Role is chosen before assets, on purpose - it sets the ceiling of what any per-asset toggle below can grant.
2Admin access should be rare. Every additional admin is another account that, if compromised, controls the whole business.
3Employee access still needs explicit task toggles per asset - inviting someone grants nothing by itself.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Contact Sheet Recordsbm_44120193 · USD · America/New_York
M2-G · Partner access · senderBusiness Settings · schematic

Request access to a partner's asset

Contact Sheet Records is requesting access from another business. 1

Pending approvalSent to partner business · awaiting response
1Partner access is the correct way to share an asset across businesses - no shared logins, no adding a person from another company as an employee.
2Ad account, Page, and dataset can each be requested independently - request only what the collaboration actually needs.
3Ask for the narrowest permission that does the job. Full control can always be escalated to later; it's harder to walk back.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Safelight Presentsact_20260728 · USD · America/New_York
M2-H · Partner access · receiverBusiness Settings · schematic

Incoming partner request

Contact Sheet Records is requesting access to an asset owned by Safelight Presents. 1

Safelight PresentsAd account · act_20260728
Awaiting your decision
Requested permission 2
Manage campaigns

Requested by Contact Sheet Records · label handles the on-sale co-promotion campaigns from this account.

Audit note: every partner grant and revoke is logged in Business Settings → Activity Log, with the approving admin's identity, permanently. 4

1The receiver always keeps control - a request never grants access on its own; an admin on this side must act.
2Review the exact permission requested, not just who is asking - the same partner can validly request different levels for different assets.
3Approving does not transfer ownership - the venue's ad account stays the venue's; the partner just gains scoped access to it.
4The activity log is the paper trail that answers "who could touch this account" months later, during any dispute.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.
Safelight Presentsact_20260728 · USD · America/New_York
M2-I · Naming conventionAds Manager · schematic
All assets
TypeName
Campaign
SAFELIGHT - ARCHIE - ONSALE - 2026-071
Campaign
SAFELIGHT - DEVELOP - EVERGREEN - GA
Campaign
CSR - ARCHIE - KEYSTONE - RELEASE - 2026-07
Ad set
UCTOUR26 - BOS - WARM2
Ad set
UCTOUR26 - PHL - WARM
Audience
SFL - VENUE - ENG - 180d3
Audience
CSR - ARCHIE - BUY - 365d
Audience
LBL - SCENE - ENG - 180d
Dataset
Safelight Dataset4
Dataset
CSR Dataset
Pattern legend
SAFELIGHT / CSR / SFL / LBL
owning entity or business shorthand
ARCHIE / DEVELOP / VENUE / SCENE / GENRE
artist, night, or targeting theme
ONSALE / EVERGREEN / RELEASE / ENG / BUY
campaign phase or audience behavior
2026-07 / 180d / 365d
month or lookback window

Segments join with " - " (spaced hyphen), always in the same order, so every asset list sorts and skims the same way.

1Campaign names read as full sentences: who, what, phase, when - answerable without opening the campaign.
2Ad set names drop the entity because the campaign above already carries it - each level adds only what's new.
3Audience names encode the source and the window - "ENG - 180d" means engagement, last 180 days, not lifetime.
4Datasets stay plain-language on purpose - they're shared across every campaign and don't need the phase segments.
Interface recreation for instruction - accurate as of July 2026. Not a screenshot.