Getting started.

Connecting an account, what permissions are needed and why, and what happens to your data.

Connecting an account

Send the account name from the Ad accounts screen. During beta, a human verifies the access and connects it. Wardio never asks for your Meta password and only stores encrypted read access.

  • Request the account inside Wardio
  • Read-only is enough for all thirteen checks
  • No write access is requested today
  • Google Ads is not live yet

What Wardio cannot do

It cannot see or use the payment method on your ad account. It cannot create an account, change business settings, edit a campaign or grant anyone else access.

The first pass

The first full check runs immediately after connection and usually completes within the hour. It tends to be the loudest one you will ever get, because it reports every existing fault at once rather than only new ones. That backlog is the point.

What happens after the first check

Open findings are ordered by severity. Read the evidence, verify the affected entity in Ads Manager and decide what to change. Wardio reports and keeps the history. It does not press the button for you.

How your data is separated

Each customer is a tenant and every table is protected by row level security keyed to the tenant, so isolation is enforced by the database rather than by application code. Access tokens are encrypted with a key held outside the database. There is an automated test that tries to read another tenant's accounts and is expected to fail.

Leaving

Revoke access at any time from Wardio or from Meta directly. When you close the account we delete the stored tokens immediately and the rest of your data after 30 days, which is the window for exporting it.