An agency user may authorize a broad advertising portfolio and see several Meta, Google, or TikTok properties. That does not mean every property belongs in every project report.
Authorize once at workspace level
OAuth belongs to the workspace because access is granted by an account user or agency operator. This avoids asking users to repeat authorization for every project when the same portfolio access can reveal multiple available properties.
The workspace Ads portfolio should therefore show authorized properties, their status, and whether they are assigned to one or more projects.
Assign deliberately at project level
The project connection flow should ask which property belongs to the selected project and which campaigns should be included. That is the reporting boundary that protects agencies from mixing clients.
A property can be available in the portfolio but unused by a project. It should remain manageable at workspace level until assigned, disabled, or deleted.
- Use Ads portfolio to add, disable, enable, or delete authorized properties.
- Use project connections to assign a property and select campaigns for that project.
- Use project analytics to compare only the sources and campaigns selected for that project.
Make management actions explicit
Deleting a property should be blocked while it is assigned to projects. Disabling a property should stop future use without hiding historical reporting context. Re-enabling should be available when access remains valid.
These states matter in the product UI because they explain why a property appears in the portfolio but not in a specific project setup.