Facebook permissions
Required permissions
Boosterberg requires these Facebook permissions to function:| Permission | Purpose | Required |
|---|---|---|
| Manage Pages | View and manage your pages | ✅ Yes |
| Manage Ads | Create promoted posts | ✅ Yes |
| Read Insights | Access analytics data | ✅ Yes |
| Create Ads | Promote posts through Meta’s Marketing API | ✅ Yes |
Optional permissions
These permissions enhance functionality but aren’t required:| Permission | Purpose | Required |
|---|---|---|
| Manage Comments | Respond to comments on promoted posts | ❌ No |
| Access Messages | View message metrics | ❌ No |
Reviewing permissions
Check what permissions Boosterberg has:- Go to Facebook Settings > Business Integrations
- Find Boosterberg in the list
- Click View and Edit to see granted permissions
Revoking permissions
To revoke specific permissions:Two-factor authentication
Facebook 2FA
Enable two-factor authentication on your Facebook account for enhanced security:- Go to Facebook Settings > Security and Login
- Enable Two-Factor Authentication
- Choose authentication method (SMS, authenticator app, or security key)
Boosterberg works seamlessly with Facebook 2FA. You’ll only need to authenticate when connecting or reconnecting your account.
Boosterberg 2FA
Enable two-factor authentication for your Boosterberg account:- Go to Settings > Security
- Click Enable Two-Factor Authentication
- Scan QR code with your authenticator app
- Enter verification code to confirm
Team access control
User roles
Assign team members different access levels:Admin
- Full access to all features
- Manage billing and payments
- Add/remove team members
- Connect/disconnect Facebook accounts
- Delete campaigns and data
Manager
- Create and edit campaigns
- View all analytics
- Manage page settings
- Cannot access billing or team settings
Analyst
- View-only access to analytics
- Export reports
- Cannot create or edit campaigns
Viewer
- View campaigns and basic metrics
- No editing capabilities
- Limited report access
Adding team members
Managing team members
Change roles
- Go to Settings > Team Members
- Click on a team member
- Select new role and click Update
Remove access
- Go to Settings > Team Members
- Click Remove next to the team member
- Confirm removal
Page-specific access
Restrict team members to specific pages:API access
Generating API keys
For advanced integrations, generate API keys:- Go to Settings > API
- Click Generate New Key
- Name the key and set permissions
- Copy and securely store the key
API key permissions
Control what each API key can do:- Read-only: View campaigns and analytics
- Campaign management: Create and edit campaigns
- Full access: All operations including billing
Revoking API keys
Immediately revoke compromised keys:- Go to Settings > API
- Find the key to revoke
- Click Revoke
Security best practices
Use strong passwords
Use strong passwords
- Minimum 12 characters
- Mix of letters, numbers, and symbols
- Unique password for Boosterberg
- Use a password manager
Enable 2FA everywhere
Enable 2FA everywhere
- Enable on Facebook account
- Enable on Boosterberg account
- Use authenticator app (more secure than SMS)
Review access regularly
Review access regularly
- Audit team members quarterly
- Remove inactive users
- Review Facebook permissions monthly
- Check API key usage
Monitor account activity
Monitor account activity
- Enable login notifications
- Review activity logs
- Set up spending alerts
- Watch for unusual campaign activity
Activity logs
View all account activity:- Login attempts and locations
- Campaign creations and modifications
- Team member changes
- Permission updates
- API key usage
Compliance and data privacy
Data access
Boosterberg only accesses:- Page posts and public information
- Ad account for creating campaigns
- Analytics and insights data
- Personal Facebook profile data
- Private messages
- Friends lists
- Personal photos or posts
Data retention
- Campaign data: Retained indefinitely
- Analytics data: Retained for 2 years
- Deleted campaigns: Data removed after 30 days
- Removed pages: Data removed after 90 days
GDPR compliance
Boosterberg is GDPR compliant:- Request your data export
- Request account deletion
- Manage consent preferences
Next steps
Manage your team
Add members and assign roles
Configure security
Set up advanced security options