On July 27, 2026, Google Ads began requiring a second administrator to sign off on sensitive account actions — a control it calls multi-party approval. Adding a user, removing a user, or changing a user’s role no longer takes effect the moment an admin clicks save; instead the change is held as a pending request that a different administrator has to approve. It is a small mechanical change with outsized operational consequences, and for B2B SaaS teams that run lean or lean on an agency, it is the kind of thing that quietly breaks a routine until you understand it.
The reasoning is defensive. Account takeovers became a serious problem as attackers targeted advertiser accounts to run scam ads and burn budgets, and the fastest move in a takeover is to add a rogue user or strip out the real owners. Requiring a second party to approve exactly those actions removes the single-click compromise. This guide explains what the rule covers, how it interacts with the passkey requirement that landed twelve days earlier, and the concrete access setup a SaaS team should put in place so the control protects you instead of locking you out.
What actually changed on July 27
The change is narrow in scope but specific in effect. According to Google’s own documentation, sensitive actions — currently adding a new user, removing an existing user, and changing user roles — now require a second administrator’s approval before they complete. When you initiate one of these actions, Google Ads does not apply it immediately. It creates a request that another admin on the account must approve or reject, and only then does the change take effect. Google has signaled that the set of covered actions may grow, framing this as a foundation rather than a one-off.
Two details matter for planning. First, the approver has to be a different administrator — the system will not let the initiator approve their own request, which is the entire point of a two-person rule. Second, a pending request does not wait forever: it must be actioned within 20 days or it expires without applying the change. That window is generous enough to survive someone being on holiday, but short enough that a forgotten request silently reverts, so a change you assumed had gone through may not have. Treat the approval as part of the task, not an afterthought.
The passkey requirement that came first
Multi-party approval did not arrive alone. On July 15, 2026 — twelve days earlier — Google made passkeys required for sensitive account actions, replacing the reliance on a password plus a legacy second factor with a phishing-resistant, device-bound credential. The two changes are halves of the same security posture: passkeys make it far harder for an attacker to authenticate as an admin at all, and multi-party approval ensures that even a compromised admin cannot unilaterally hand themselves the keys by editing the user list.
For a B2B SaaS team this means the account-access review you run should cover both layers at once. Every administrator needs a working passkey enrolled on a device they control, and you need at least two such admins so the approval step can function. If your admins share a single login or rely on an SMS code that a support-desk social-engineering call could intercept, you have neither the passkey protection nor a real second party — you have one credential wearing two hats. Fixing that is the prerequisite to everything else in this guide, and it belongs on the same checklist you use for a broader SaaS Google Ads audit.
The solo-admin trap — and how to avoid it
The sharpest edge of this change lands on accounts with a single administrator. If exactly one person holds admin access, there is no second party to approve a sensitive user action, so the very control meant to protect the account can leave that sole admin unable to add or remove users cleanly. Reporting on the rollout flagged this gap directly: the requirement surfaced without a documented fallback for single-admin accounts, which is precisely the configuration a small SaaS team tends to run.
The remedy is to provision a second administrator before you need one. Choose a second trusted internal owner — a co-founder, a head of growth, or a marketing lead who will still be around next quarter — rather than a contractor or a shared inbox. Give them their own login with a passkey, confirm they can see and action pending approval requests, and document who they are. Do this now, while granting admin access is still straightforward, because adding that backup admin is itself a sensitive action; the longer you wait, the more likely you are to need the second approver at the exact moment you do not have one.
If an agency runs your account
Agency-managed accounts are where this rule needs the most deliberate thought, because admin access usually spans two organizations. When both the client and the agency hold admin rights, user changes on either side can now trigger an approval step, and the questions that were implicit before become explicit: who is allowed to add or remove users, who approves those requests, and how does the client keep an independent administrator so it can never be shut out of an account it owns. Settle these before signing, not during a dispute.
The practical stance for a SaaS buyer is to always retain at least one admin seat under the company’s own control, with its own passkey, independent of the agency. That way the account survives an agency transition intact and the client can approve or reject access changes on its own terms. This dovetails with the access and ownership terms you should already be negotiating around billing and reporting — the same due diligence covered in Google Ads agency pricing for B2B SaaS and worth revisiting when you are hiring a Google Ads agency. Account access is part of the contract, not an afterthought.
A setup checklist for B2B SaaS teams
Turning this from a surprise into a non-event takes a short, concrete setup pass. Confirm the account has at least two administrators, each with their own login and an enrolled passkey. Verify that both can view the pending-approvals area so a request never stalls for lack of an approver. Map who initiates user changes and who approves them, and write that down where the team can find it. If an agency is involved, confirm the client organization holds an independent admin seat that no agency change can revoke. None of these steps is heavy, but each one closes a specific way the new rule could bite.
Then fold approvals into how the team already works. A pending request that expires after 20 days is a silent failure — the removal you thought happened did not, and a former employee or offboarded contractor still has access. Treat approving legitimate requests as a same-day chore, and treat an unexpected request as a security signal worth a second look before you approve it, since an unexplained attempt to add a user is exactly the event this control exists to catch. Handled this way, multi-party approval is a genuine upgrade to account hygiene rather than a tax, and it belongs alongside the operational discipline in your Google Ads optimization checklist.