Solo affiliate marketing means every password, funnel and number lives with one person. That works until the first hire. Then come questions that cost a media buying team as much money as bans do: who changed the flow settings, why does a buyer have access to the balance, how do you tell which of two buyers brings in the profit, and what do you do when someone leaves. Let us look at how to set up a team so these questions never come up.
Who is who in a media buying team
The line-up depends on size, but the typical roles repeat:
| Role | What they do | What they need to see |
|---|---|---|
| Team lead / owner | Sets tasks, allocates budget, makes funnel decisions | Everything |
| Media buyer | Buys traffic, launches and optimizes campaigns | Their own flows, clicks and conversions |
| Tech specialist | Landing pages, pre-landers, connection, integrations | Flows, connection, White Page |
| Analyst | Reports, slices, finding drops | Statistics and reports, no editing rights |
| Finance | Spend, payouts, paying for services | Finances and money by slice |
| Farmer / account manager | Preparing ad accounts | Usually no need for tracker or cloaker access |
In small teams the team lead is often also the tech person, and a buyer is their own analyst. Combining roles is fine; combining access is not. A buyer who can delete someone else's flow or sees the shared balance is a source of problems even with full trust. More about the media buyer profession in media buying: what a media buyer does, and about the roles teams hire for in affiliate marketing jobs.
The principle of least privilege
A simple rule: everyone sees what they need for their work and edits only what they are responsible for. This protects against three things:
- mistakes — accidentally switching off cloaking in someone else's flow can cost an account;
- leaks — the funnel, landing page and White Page of a working campaign are trade secrets;
- disputes — when everyone edits only their own things, it is clear who is responsible for what.
Access roles in ArtisanClo
In the dashboard all of this is set up in the Team section: the "Members", "Access roles", "Projects" and "Guest links" tabs.
How a role works
For each section of the dashboard a role sets one of three levels: "None", "View" or "Edit". A few specifics:
- Conversions — view only; they cannot be edited.
- "Edit" in the click log allows adding addresses to the account blacklist and removing them. A member with view-only access to the log sees the blacklist but cannot change it.
- The Finances section (payments, wallet, plans) is closed to members until a role explicitly opens it.
- A member always sees the dashboard, support and tutorials, and manages their own password, two-factor authentication and sessions. They cannot change their own role.
Role presets
You can create a role from scratch or from a preset:
- Administrator — for the team lead's deputy;
- Traffic manager — for a media buyer;
- Analyst — for whoever builds reports;
- Finance — for whoever is in charge of money;
- Viewer — for those who only need to look.
You can adjust a preset to fit: for example, give a tech specialist "Edit" on flows and White Page but "None" on finances.
Projects: splitting by buyer and client
Projects are groups of flows. A member can be given access only to the projects they need, and then they see only those flows, clicks and conversions. A member with project-only access has to choose a project when creating a flow — so no "orphan" campaigns appear.
How to group:
- by buyer — a "Buyer Andrew" project, a "Buyer Olivia" project;
- by client, if you are an agency — each client gets its own project;
- by vertical — nutra, gambling, finance;
- by direction — for example, a separate project for testing new funnels.
The flow list has an "All projects" filter, and the dashboard, log and reports can be filtered by project — the team lead sees the whole picture or any slice.
How to invite a member
- Create at least one access role — from a preset or from scratch.
- In the "Members" tab enter the email and choose the role.
- The member gets an email with a link (valid for 14 days) and accepts the invitation from an account with the same email.
To invite someone you need the owner's verified email and a free seat on the plan. A person who already belongs to another team or runs their own cannot be invited. The number of seats, custom roles and projects depends on the plan — see the pricing page. A seat is a person: the owner, accepted members and unanswered invitations.
How to count each buyer's results
Access is half the job. The other half is understanding who brings in the profit. For that you need to tag each buyer.
Tagging with campaign parameters
In flows with the tracker on, step 3 has custom SubIDs — "key = value" pairs. The number of parameters is not limited by plan: tag the creative, audience, buyer, funnel. For example:
sub1 = {campaign_id}
sub2 = {adset_id}
sub3 = andrew
Then in the Reports section the "Money by slice" table grouped by sub3 shows clicks, conversions, revenue, spend, profit and ROI for each buyer. Parameters sub1–sub10 are available right in the table, the rest in the report builder. About parameters and macros: UTM parameters and macros and click ID and sub ID.
Tagging with projects and sources
If a buyer works in their own project, their results show up when you filter the report by project. If buyers share platforms, it helps to create separate traffic sources — the source list has a table with clicks, leads, CR, EPC, CPC, revenue, spend, profit and ROI.
Which metrics to look at
Profit alone is not enough to compare buyers: one has a bigger budget, another a more expensive geo. Look at ROI, EPC, CR and approval rate. All the metrics are explained in affiliate marketing metrics, and the formulas in how to calculate ROI.
Tip. Agree on tagging rules before launch, not after. If half the buyers put their name in sub3 and the other half in sub5, the team report turns into manual spreadsheet reconciliation.
Guest links: a report for clients and partners
An agency or a team working for an external advertiser needs a way to show results without dashboard access. That is what guest links are for — the "Guest links" tab in the "Team" section.
- Scope: the whole account, one flow or a project.
- Period: 24 hours, 7 or 30 days — within the plan's history depth.
- Language: any of seven; the page opens entirely in the chosen language.
- Lifetime: 30 days by default, up to 365, "0" means no expiry. The link can be revoked, and views are counted.
| The client sees | The client does not see |
|---|---|
| Clicks, passed and filtered, unique | Spend, profit, ROI |
| Leads, revenue, CR, EPC | Filter reasons |
| Trends, rhythm by hour and day | ISPs |
| Breakdown by flow, geo, device, OS and browser | Flow settings |
So your margin and your technical kitchen stay inside the team.
Processes: agreements that save money
Access rights decide who can do what. Processes decide how the team works every day. A few rules that take hold almost everywhere:
- Consistent flow naming. For example, "Platform — Vertical — Geo — Buyer": "FB — Nutra — DE — Andrew". The flow list search looks at name, ID, status and note, so a clear name saves everyone time.
- Notes in flows. Write in the note what is not visible in the settings: "creatives from 12.09", "new pre-lander test", "budget agreed with team lead". Only you and the team see the note.
- Filtering presets for the team. Save a good set of rules as a preset — buyers will apply it to new flows instead of building filters from scratch each time in their own way. Applying is one-off: editing a preset does not change flows already created.
- Whoever changes protection writes it down. Changes to strictness, geo and White Page in a live campaign change who reaches the offer and immediately affect the whole team's numbers. Agree that such changes are approved by the team lead and checked in Diagnostics before saving.
- Weekly review. Once a week look at the per-buyer report and flow Diagnostics: which filters are cutting traffic, where the share of bots is growing, which funnels are burning out.
Example role setup
An illustration for a team of five:
| Person | Role in the dashboard | Projects |
|---|---|---|
| Team lead | Account owner | All |
| Buyer 1 | Traffic manager | "Buyer 1" |
| Buyer 2 | Traffic manager | "Buyer 2" |
| Tech | Custom role: flows and White Page — "Edit", finances — "None" | All |
| Analyst | Analyst | All, view only |
Team security
The more people, the higher the cost of a leak. The minimum set:
- Two-factor authentication — each member turns it on in the "Security" section. After that a code is requested at every login.
- Sessions — "Security" shows active sessions, and you can end them. That is the first thing to do when someone leaves, together with removing them from the team.
- Notifications by role — a member sees in the bell and gets in Telegram only what relates to their role's sections. A buyer does not get invoices; the finance person does not get flow alerts.
- IP blacklist — shared across the account. Give "Edit" on the click log to people who understand the consequences: an address on the blacklist will not see the offer in any flow.
When the team grows or shrinks
If you move to a plan with fewer seats, nothing is lost: unanswered invitations are frozen first, then the newest members are suspended. Their role and projects are kept; in "Team" they have the "Suspended" status and Bring back and Swap buttons. When a seat frees up or the plan is upgraded, members come back on their own.
Summary
A media buying team rests on three things: roles with least-privilege access, projects to separate buyers and clients, and a single tagging convention for honest result tracking. Finances are closed by default, clients get a guest link without spend or margin, and every member uses two-factor authentication. Other dashboard features teams rely on are on the features page, and if the team is just starting out, it helps to refresh the basics in affiliate marketing for beginners.



