A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.
What to expect
Connecting takes a couple of minutes. When you add the Facebook integration in Medialake, you'll be redirected to the official Facebook login screen, then walked through two steps:
Choose the Business(es) and Facebook Pages you want to share — Pages you manage through a Business portfolio appear once the business is opted in. We recommend opting in current assets only and selecting just what's in scope.
Review the access request — the permissions below, in Meta's own words.
You approve everything yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Meta's site, and once you approve you're returned to Medialake.
We follow the principle of least privilege: we only request the access the work actually needs — we never post, edit, reply, or delete anything on your Pages. All data is read through Meta's official Graph API.
You Medialake Meta│ connect source │ ││────────────────────────▶│ ││ redirect to Meta │ ││◀────────────────────────│ ││ log in & grant access │ ││──────────────────────────────────────────────────▶││ redirect with code │ ││◀──────────────────────────────────────────────────││ │ exchange code ││ │────────────────────────▶││ │ long-lived token ││ │◀────────────────────────││ source authorized │ ││◀────────────────────────│ │
Verifying it's really us
On the consent screen, check that the app requesting access is:
App name: MedialakeAI
App ID:
714235083542447Developer / business: Medialake AI (verified by Meta)
If the app name doesn't match, stop and contact us. Never approve a Meta connection request you weren't expecting.
Who should do the connecting
The connection is tied to the person who logs in (authorized with a Meta User access token), not just your business. Please have it done by someone who:
Has access to the Facebook Page(s) you want to sync — either directly (added to the Page with Facebook access) or through your Business portfolio (a member of the business with the Page assigned to them; business admins see all portfolio Pages). Only Pages they can access appear in the pickers.
Is a permanent member of your team. If the person who authorized us leaves your company or loses their Page or business access, the connection expires and someone else will need to reconnect.
Their personal Facebook login is used only to authorize the connection — we get access to your Pages' content and insights, never their personal profile, friends, or messages.
Limiting what we can access
Two layers keep this narrow. First, the asset pickers: choosing "current only" and selecting specific Businesses and Pages means we can never see anything you didn't tick — assets added later are excluded unless you reconnect and add them. Second, we inherit only the connecting person's own access — Pages they don't manage (directly or through their Business portfolio) never even appear in the picker. For the narrowest possible connection, have a business employee (not admin) with only the relevant Page(s) assigned do the connecting.
You choose what we sync
The pickers during consent are the selection: only the Businesses and Pages you opt in ever become visible to Medialake. After you're redirected back to Medialake, you choose which of those Pages to actively sync.
The permissions we request
On the review screen ("Review MedialakeAI's access request") you'll see these five, in Meta's wording:
Permission (scope) | Appears on the consent screen as | How we use it |
"Show a list of the Pages you manage" | READ ONLY — list your Pages so you can pick which to connect | |
"Read content posted on the Page" | READ ONLY — read the posts and videos your Page has published | |
"Read user content on your Page" | READ ONLY — read the engagement on your posts (reactions, comments, shares counts) | |
"Access your Page and App insights" | READ ONLY — read post performance insights, such as views | |
"Manage your business" | READ ONLY (see note) — makes Pages you manage through your Business portfolio available in the picker |
>Why business_management is here: many Pages aren't managed through direct personal Page roles — they're owned by a Business portfolio, and your team's access flows through the business. Without this permission, those Pages can't be offered in the picker, even though you manage them every day. That's its only job in our integration. Meta defines the permission broadly — its official description reads "allows your app to read and write with the Business Manager API" — and the consent screen's info box describes that ceiling, not our usage: we make no changes to your Business Manager, its people, or its assets — ever. And the asset pickers still rule: we only see the Businesses and Pages you opt in.
All five are read-only in effect — nothing on your Pages or in your Business Manager can be created, edited, replied to, or deleted by us. Meta's own description of every permission is in its Permissions Reference.
Verified by Meta
Our app doesn't get these permissions just by asking. Each one was individually approved through Meta's App Review, where we justify and demonstrate exactly how it's used; Medialake AI is a Meta-verified business; and every year Meta requires us to recertify how each permission is used through its Data Use Checkup. Unused or unjustified permissions are revoked by Meta.
What we can't see or do
Regardless of which permissions you grant, we cannot:
See or store your password, or log in as you
Post, edit, reply to, or delete anything on your Pages
Change anything in your Business Manager — people, asset assignments, settings
Access the connecting person's personal profile, friends, or messages
See Businesses or Pages you didn't opt in during consent
Staying connected
Meta access tokens expire periodically (roughly every 60 days) and Meta does not provide refresh tokens, so an expired connection can't be renewed in the background. Tokens are also revoked early if the authorizing person changes their Facebook password or resets two-factor authentication. If that happens, just reconnect from the Facebook integration in Medialake — this is normal and takes a minute.
Revoking access
You're in control at any time. To remove MedialakeAI:
Business Settings → Integrations → Connected apps → select MedialakeAI → Remove, or
Your personal Facebook Settings → Business Integrations → remove MedialakeAI
Revoking immediately stops all access; no action needed on our side.
Troubleshooting
The most common issues:
A Page doesn't appear in the picker — the connecting person doesn't have task access to it (check who manages the Page under Business Settings → Pages).
The connection succeeds but no Pages or content appear in Medialake — permissions alone aren't enough: Meta also needs you to opt Pages in on the picker during consent, and if a Page is managed through a Business portfolio, the business itself must be opted in too. If a step was skipped or nothing was ticked, we can see nothing. Reconnect and select them.
Otherwise, issues typically relate to organization settings restricting third-party OAuth apps. If you get stuck, contact [email protected] and we'll walk you through it.
Further reading (Meta documentation)
Permissions Reference — what each scope grants
Facebook Login for Business — the login flow Medialake uses
Pages a person manages — how Page discovery works
Access tokens & long-lived tokens — token lifetime and why there are no refresh tokens
You can review or withdraw any of these permissions at any time in Meta Business Settings.
