A compromised administrator account, a rushed handoff, or one mistaken approval can put campaigns and billing at risk. Google Ads multi-party approval reduces that one-person exposure by requiring a second eligible administrator to authorize certain sensitive changes before they take effect.
The control is useful, but it is not self-managing. You still need enough qualified approvers, a clear review standard, and a process for requests that are urgent, stale, denied, or simply missed. Here is how to build that process without turning every account change into a bottleneck.
What multi-party approval changes in Google Ads
Multi-party approval introduces dual control for selected high-risk account actions. An administrator initiates a sensitive change, but that administrator’s authority alone is not enough to finalize it. Google Ads sends an in-product approval request to other eligible administrators, one of whom must review and approve or deny the action.
The request remains actionable for 20 days. If nobody acts before that window closes, the request expires and the proposed change is not implemented. That fail-closed behavior matters: silence does not become permission merely because the request has been waiting.
You can find these requests in the Admin menu under Access and security. Google Ads labels their outcomes as Complete, Denied, or Expired, giving your team a visible record of how each approval request ended.
The important qualifier is that the workflow applies to specific sensitive changes, not every campaign edit. Do not describe it in policies, client documentation, or audit evidence as a universal two-person rule for the entire account. A more accurate statement is that Google Ads enforces a second-administrator decision when its multi-party approval workflow is triggered.
That distinction prevents a dangerous assumption. Multi-party approval reduces the risk attached to one administrator’s authority, but it does not replace authentication controls, access reviews, campaign monitoring, or ordinary change management.
Build an approval path before a request is urgent

The 20-day window is a technical expiration period, not a sensible operating target. A legitimate request can become outdated long before it expires because budgets, promotions, account ownership, or campaign plans have changed. Your internal process should therefore route requests promptly and force a fresh review when their original context no longer holds.
- Inventory eligible administrators. Record each person’s business role, account responsibility, and whether that person is expected to propose changes, approve them, or provide backup coverage.
- Confirm that every protected account has more than one eligible administrator. Do not wait for an important request to discover that nobody else can approve it.
- Designate a primary and backup approver. A request should have a named destination even though Google Ads can notify multiple eligible administrators.
- Create a change record before initiating the action. Include the account, requested outcome, reason, expected campaign or billing effect, requester, review owner, and any time dependency.
- Initiate the change in Google Ads and alert the designated reviewer through your normal work channel. Treat that message as a routing aid, not as the approval itself.
- Have the reviewer open Google Ads independently, inspect the request, and approve or deny it inside the platform. A reply in chat, email, or a ticket does not substitute for the in-product decision.
- Record the final Complete, Denied, or Expired status in the same change record. If the request was denied or expired, document whether it was abandoned, corrected, or submitted again.
This workflow separates three things teams often blur together: proposing a change, authorizing it, and documenting its outcome. Keeping those events distinct makes it easier to investigate an unexpected account state and harder for an informal message to be mistaken for permission.
Prevent the approval process from creating new weaknesses
A second administrator improves control only when that administrator is independent, identifiable, and capable of evaluating the request. Watch for these common failure modes:
- Only one eligible administrator exists. The workflow can stall until the request expires. Establish backup coverage before you depend on multi-party approval.
- Extra administrators are added merely for convenience. Administrator access is powerful, so increasing the number of administrators can expand your attack surface. Give that role only to people who genuinely need it and can fulfill the approval responsibility.
- Administrators share credentials. A shared login defeats person-level accountability and makes it difficult to establish who proposed or authorized a change. Use named user access instead.
- The approver rubber-stamps the request. Requiring a second click is not the same as receiving an independent review. The approver should validate the account, scope, purpose, timing, and likely consequence before acting.
- A chat or email response is treated as the final approval. Keep discussion wherever your team works, but complete the binding decision within Google Ads.
- An old request is approved because it is still available. Availability within the 20-day window does not prove that its business context is current. Deny a stale request and initiate a new one with updated evidence when the underlying conditions have changed.
- The team assumes dual control makes account compromise harmless. It reduces the danger of one compromised administrator, but it cannot protect you if multiple privileged accounts are compromised or if inappropriate access remains active.
You also need a plan for absence and urgency. Identify who covers the primary approver and how the requester escalates an unanswered request. The backup should perform the same review, not bypass it. An urgent change can have serious financial consequences, but urgency is a reason to route the request faster, not a reason to weaken authorization.
Use a consistent approve-or-deny standard

An approver should be able to answer the following questions from the Google Ads request and its accompanying change record. If a material answer is missing or inconsistent, denial is safer than assumption.
- Is the requester a known administrator acting within an assigned responsibility?
- Is this the intended Google Ads account, and is the requested scope no broader than necessary?
- Does the change record explain the business purpose clearly enough to evaluate the request?
- Could the action interrupt active campaigns, alter control of the account, or affect billing exposure?
- Does the requested action match what the team discussed, rather than a shortened or materially different version of it?
- Is the timing still valid, or has the request become stale since it was initiated?
- Is there a named owner who will verify the resulting account state and respond if the outcome is unexpected?
Denial is not an accusation against the requester. It is the correct outcome when the reviewer cannot establish that the change is authorized, accurate, and current. The requester can correct the scope or supporting record and begin again.
Approval should also create an operational handoff. Once a request reaches Complete status, the change owner should inspect the relevant account state rather than assuming that an approval label proves every downstream result is correct. Multi-party approval governs authorization; it does not perform campaign quality assurance for you.
Key takeaways
- Google Ads multi-party approval requires another eligible administrator to approve or deny certain sensitive changes.
- An unanswered request expires after 20 days, and the proposed change is not implemented.
- Requests and their Complete, Denied, or Expired outcomes are available under Admin, then Access and security.
- The feature is selective, so it should not be represented as two-person approval for every Google Ads edit.
- A useful internal process names the requester, primary approver, backup approver, business purpose, affected account, expected consequence, and final status.
- Multi-party approval complements named accounts, strong authentication, access reviews, monitoring, and change records; it does not replace them.
Your next step is simple: open Access and security, inventory the eligible administrators on each important Google Ads account, and assign a real approval path. Fix accounts with no backup approver first, then give every approver the same review checklist before a sensitive request arrives.
References


Leave a Reply