Step-by-step guide
Last updated: August 2026
Have these ready — it's what onboarding stalls on:
Grant the minimum the work needs. On Amazon Ads, the levels are:
| Access level / role | What it can do |
|---|---|
| Admin | Full control including users. |
| Editor | Create and manage campaigns. Usual agency level. |
| Viewer | View campaigns and reports. |
A few minutes to invite; the agency accepts the invitation.
Open Account settings → Manage users and grant the access — a few minutes.
Accept and confirm from their side, then start work.
Access is granted when:
The most common problems and how to fix them:
Amazon separates advertising accounts, brands and entities. Grant access to the specific advertising account the agency needs.
The agency must accept the emailed invite.
The agency is invited as a user by email with a role — no password shared, removable anytime.
Everything above is why agencies switch to a single link. HandItSafe requests exactly this Amazon Ads access for you — the client approves through Amazon Ads's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.
FAQ
No. The agency is invited as a user by email with a role.
Editor to manage campaigns; Admin only if they must manage users.
Yes, from Manage users. HandItSafe adds one-tap client removal.
Editor to manage campaigns; Admin only if they manage users.
DSP access is managed separately; grant it in the DSP console if the agency runs programmatic.
Keep reading
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.