media-buying · account-linking · meta-ads · google-ads · isolation

How ad accounts get linked, and how to contain a ban

What actually joins two ad accounts on Meta, Google Ads and TikTok, what each platform documents about multiple accounts, and how to contain a ban.

Argus · · 13 min read

The hour after

The first email is survivable. One ad account disabled, one appeal, one afternoon lost. What breaks the week is the next forty minutes, when two accounts that had nothing to do with the flagged campaign go down as well, and then the Page that was attached to one of them.

That cascade is not folklore, and it is not a mystery. It is written into the policies. Meta's Community Standard on Account Integrity says the company may restrict or disable accounts, entities and business assets, including Business Managers and ad accounts, that are "owned by the same person or entity as an account that has been disabled". Google's suspension overview says plainly that "accounts related to the suspended account may be suspended", and that new accounts an advertiser creates afterwards may be suspended too. TikTok's suspension documentation notes that for agency accounts, a suspended account cannot be used to create new ad accounts or add money to them.

So the useful question is not whether platforms join accounts together. They say they do. The useful question is which joins you have created without meaning to, and which ones you have created on purpose because your business genuinely needs them.

One boundary before anything else, because it decides whether the rest of this is worth reading. This post is about running accounts you are entitled to run: separate brands, separate legal entities, separate clients, separate markets. It is not about getting back onto a platform that has already shown you the door. Creating accounts to work around a suspension is the specific thing every platform in this post prohibits by name, and it is outside what Argus is for.

What the platforms actually publish about multiple accounts

It is worth reading the primary documents rather than the forum lore, because the picture they paint is not "one account per human".

Meta builds the concept in. A business portfolio is the container that holds Pages, Instagram accounts, ad accounts, catalogues and datasets, and the ad account limits page describes a world of many: one person can manage up to 25 ad accounts, an ad account can be assigned to up to 25 people, and a business starts with a creation limit of one ad account until it makes a confirmed payment. A closed ad account still counts against the limit, which is a detail worth knowing before you open the twenty-fifth.

The constraint Meta does apply is about ownership, not count. The account sharing limitation is explicit: unless you are a verified agency, your portfolio can only manage ad accounts owned by the same company that owns the portfolio. Meta goes as far as to say that if your organisation is arranged into business units run by different companies in one corporate group, a portfolio belonging to one of those companies can only manage that company's ad accounts. Agencies handling several clients pass agency verification first.

Google Ads ships a product for exactly this. A manager account, still widely called an MCC, is described as an account that lets you view and manage multiple Google Ads accounts from one place, including other manager accounts. That is the sanctioned shape for an agency or an in-house team with several books of business.

What Google prohibits is narrower and sharper. The circumventing systems policy forbids creating multiple accounts after being suspended in order to get around policy, and its own best-practice list tells advertisers to avoid opening a lot of accounts in a short period using different email addresses, to make sure each account is connected to a real business, and to use a safe payment method. Separately, the unfair advantage policy forbids trying to show more than one ad for your business, app or site in a single ad location, and says each destination you promote should offer distinct value. Note what that second rule keys on: the similarity of the ads and the destinations, not the device that submitted them.

TikTok puts ad accounts inside a Business Center and treats several as normal. Its guide to creating ad accounts in Business Center frames separate accounts as the way to keep separate budgets, campaigns and performance data for each brand, product line or region you manage. Only a Business Center admin can create them, and the default limit varies by the type of Business Center.

Read together: several accounts are ordinary. What each platform polices is whether the accounts represent real, distinct businesses, and whether one of them is a workaround for another one's enforcement.

What actually links two accounts

Account linking is a conclusion, not a technique. A platform decides two accounts are one operation and acts on both. The evidence falls into six buckets, and they are not equally addressable.

An honest caveat that applies to the first three: Meta, Google and TikTok do not publish the signals they correlate on, and nobody outside those companies knows the weights. What follows is what is observable from the outside and what the platforms' own product surfaces make obvious. Where a claim is inference rather than documentation, it is marked as such.

1. The device and the browser

Every browser leaks a description of the machine it runs on. The W3C's guidance for specification authors splits this into passive fingerprinting, which reads characteristics already present in the contents of web requests, and active fingerprinting, where a site runs code to interrogate the browser further. The same document concludes that complete elimination of fingerprinting by a determined adversary, through technical means alone, is implausible.

The practical form is a browser fingerprint: user agent and client hints, screen geometry, timezone, language list, CPU core count, device memory, the exact rendering of a canvas draw, the WebGL vendor and renderer strings, audio processing quirks. No single value identifies anyone. The combination is the point, and the term for that is device entropy. Two ad accounts opened from the same laptop share a value on every one of those axes at once, which is a coincidence that does not happen between strangers.

Platforms do not publish that they compute this. It is inferred, and the inference is unremarkable: the signals are readable by any script on any page, and correlating them costs nothing.

2. The network

Same exit address, same accounts. This is the oldest join and still the one people trip on, usually at the least convenient moment: a proxy that fails silently and lets the browser fall back to the home connection, or a real address escaping around the proxy through a WebRTC leak. It is also more textured than one IP. A datacenter exit announces itself as commercial infrastructure by the network it sits on, which is a different fact about you than a residential address in the market you claim to sell into.

3. State the site wrote itself

Cookies, localStorage, IndexedDB, service worker caches. If two accounts were opened in the same browser profile, no fingerprint work matters, because the platform does not have to infer anything. It wrote an identifier the first time and read it back the second. That is what a per-profile cookie jar exists to prevent.

4. Payment instruments and legal identity

This is the join no browser touches, and the one people most often forget. Google's payments profile stores the name and address of the person or company legally responsible, the stored payment methods and the tax information, and it is associated with your Google services and products generally rather than with one ad account. Meta gates a business's ad account creation limit on a confirmed payment. A shared card, a shared billing entity or a shared tax ID is a documented, deliberate association. It is not something you route around; it is something you either intend or do not.

5. Assets you deliberately share

Pixels and datasets, catalogues, Pages, verified domains, an MCC parent. Meta's domain verification is a business claiming ownership of a domain so that only rightful parties can edit link previews and ad links pointing at it. That is useful, and it is also a public statement that this portfolio and this domain belong together. A pixel fired from one landing page into two ad accounts is a link you built on purpose.

None of these are problems. They are how the platform is meant to work. They become a problem only when a structure you never thought about routes the blast radius of one ban into six accounts.

6. Behaviour

Working hours, creative reuse, the same landing page under two domains, the same offer at the same price, ten accounts that all top up at 09:00 on a Monday. Google's unfair advantage policy is the proof that this bucket is enforceable on its own: promoting the same or similar content across accounts is a violation of a written rule, and no amount of device separation makes two identical funnels look different.

Three of the six are things a browser can separate. Three of them are not. That is the honest shape of what any tool in this category can offer, and it is why the rest of this post is about structure.

The structure that keeps a ban to one asset

The goal is containment: when an account goes down, the enforcement has nowhere obvious to spread, and you can prove the remaining accounts are separate businesses rather than spare tyres.

Meta's own advertising restrictions page describes the four levels enforcement lands on: the business portfolio, the ad account, the Page, and the user account. It also says something important about containment. If a user account is restricted from advertising, ad accounts where that person is the only attached user may also be disabled, but other members of the portfolio, ad account or Page may still be able to advertise. The level a restriction lands on determines what it takes with it, and you get to decide which level your assets hang from.

Six rules that follow from all of the above.

One legal entity per top container. A Meta business portfolio maps to a company; Meta will enforce that anyway unless you are agency-verified. A Google manager account maps to a book of business. A TikTok Business Center maps to the same. If you operate two genuinely separate companies, they get two containers, and the separation is real rather than cosmetic.

Do not let leaf assets straddle containers. Separate domain, separate pixel or dataset, separate Page, separate catalogue per brand. Every asset shared between two containers is a rope tying them together, and it will be there whether or not you remember tying it.

Separate the money. Different payment instruments, and where the entities are genuinely different, different payments profiles. This is the single highest-value item on the list and it involves no software at all.

Never make the only attached user a shared one. Structure access so that no single human account is the sole attached user across accounts you need to survive independently. Meta documents that this specific arrangement is what carries a user-level restriction into an ad account.

One browser identity per account, held for its whole life. Not rotated, not shared, not re-rolled between sessions. An identity that changes every login is a different anomaly, not a fix.

Write down the links you made on purpose. When you do get an appeal, the question you will be asked is which real business each account belongs to. Being able to answer in one screen is worth more than any evasion.

Notice what is not on that list: opening a replacement account for a suspended one. Meta's Account Integrity standard covers assets "created or repurposed to evade a previous account or entity removal", and Google says outright that accounts created after a suspension may be suspended too. That path is closed by design and this post is not going to pretend otherwise.

Where a browser helps, and where it does not

Rules one to four and rule six are organisational. Rule five is the one a tool can carry, and it is the reason anti-detect browsers exist at all.

In Argus, an ad account is a profile. Each profile starts from its own directory with its own storage, cache and cookie jar, and session restore is off, so nothing from a previous run resurfaces in a new one. That closes bucket three outright. On top of it sits a coherent hardware identity: platform, CPU cores, memory, screen, timezone and languages generated together so nothing contradicts anything else, with canvas, WebGL and audio applied in the renderer rather than wrapped in JavaScript that a page could read around. That addresses bucket one.

Bucket two is the proxy library: a shared pool rather than a text field per profile, health-checked for egress IP, country and latency, with a failed check blocking the launch instead of quietly falling back to your own connection. The check flags an exit sitting on a datacenter network and names the provider behind it. WebRTC is sealed as browser policy on every profile rather than as a toggle you can forget. Authenticated SOCKS5 works, which plain Chromium cannot do at all. Sessions live in cookie sets assigned to profiles rather than passwords in a group chat, and a project groups the profiles, proxies, cookie sets and datasets that serve one client, so the boundary between two books of business is visible to everyone sharing the workspace rather than held in one person's head.

Now the limits, because a list of capabilities with no edges is marketing.

Argus does not alter the TLS fingerprint. It does not spoof the Geolocation API, and it does not synthesize sensor input, because Event.isTrusted is not forgeable from page context and a synthesized event announces itself. It ships an optional captcha plugin rather than solving captchas itself. Scheduled entries fire only while the launcher is open, and a slot it was closed for is marked missed and skipped rather than caught up. The automation API is local, on your own machine, not a hosted service. Builds are Apple Silicon macOS and x64 Windows, with no Linux build and no mobile app.

And the larger limit, which is not about software at all: separation is not immunity. No browser separates a shared credit card, an MCC parent you attached yourself, a pixel firing into two accounts, or two campaigns running the same creative to the same offer at the same hour. Keeping accounts apart is a structural discipline that a browser supports at one layer of six.

Before you open the next account

A short pass that costs ten minutes and is worth more than any recovery attempt.

Question Where it is answered
Which legal entity owns this account? Your records, and the portfolio or manager account it will sit under
Which payment instrument and payments profile pays for it? Billing, before the first campaign
Which pixel, domain, Page and catalogue will it touch? The asset list of its container
Who is the sole attached user, if anyone? Access settings
Which browser profile and which proxy is it bound to, permanently? Your profile list
If it is banned tomorrow, what else goes with it? The answer should be "nothing"

The last row is the whole exercise. If you cannot answer it in one sentence, the structure is not contained yet, and the fix is upstream of any browser.