Signed-in devices
You can see every signed-in device on an account and sign others out, which is the first thing to do if credentials may have been exposed.
New-device sign-in alerts
Email alerts are sent on sign-in from a new device. An alert nobody recognises should be treated as a compromise: change the password and sign out other sessions immediately.
Practical policy for operators
- One login per person. Never share credentials — see Sign-in and account access problems.
- Invite team members individually to the admin panel. There are no per-seat fees, so there's no reason to share.
- Treat API keys and AI Connector credentials like passwords. Don't paste them into shared documents or third-party tools. Rotate anything that may have been exposed. See AI Connector (MCP).
- Keep the account email current — that's where security alerts go.
Why this matters more on a DSP than most platforms
An account holds a spending balance. A compromised advertiser account isn't just a data problem; it can spend real money before anyone notices. This is worth stating plainly to your advertisers at onboarding.
Related: Onboarding your first advertisers
Sep 7, 2026