Report & ad-account access
Grant access to existing reports and ad accounts from a role — batch, per object, with view or control levels.
Permissions decide what someone can create and configure. Access to things that already exist — this report, that ad account — is granted separately, and it's granted from the role: open a role and use its Reports and Ad accounts tabs to tick access for everyone who holds that role, across many objects at once.
Managing these grants takes the Manage Report Access and Manage Ad Account Access permissions respectively (see the catalogue).
Reports access
The role's Reports tab lists every report in the organization. Tick the ones this role should see. A report that isn't ticked simply doesn't exist for those members — it won't show in their list, the switcher, or search.

This is how the stakeholder pattern works: a role with no permissions at all and two reports ticked gives a client or an exec exactly those two reports and nothing else.
Ad accounts access
The role's Ad accounts tab lists the organization's ad accounts with a level per account:
| Level | What it allows |
|---|---|
| No access | The ad account is invisible to this role. |
| Can view | See the ad account and its sync status. |
| Can control | View, plus start, stop, and retry its sync. |
Deleting an ad account isn't part of these levels — it stays with the account's full-access holders (typically its creator and the Owner).

How grants combine
- A member with several roles gets the highest level any of their roles grants.
- The Owner role always has access to everything — that's part of its protection, not something you configure.
- New objects aren't auto-granted: when someone creates a report or ad account, extend the relevant roles' grants if others should see it.