Meta Business Manager API

business_management Permission: Why Meta Rejects It and How to Get It Approved (2026)

business_management looks like a simple asset-management permission until you actually submit for it. Meta’s own App Review template for this permission still asks for an ads-performance-data screencast — even when your app has nothing to do with ads. That mismatch alone accounts for a large share of the rejections we see.

What business_management actually lets your app do

Per Meta’s official Permissions Reference, business_management allows an app to read and write with the Business Manager API. Its allowed usage is narrow and specific: manage business assets such as an ad account, and claim ad accounts on behalf of a Business Manager. It depends on two other permissions — pages_read_engagement and pages_show_list — which must already be in place before Meta will review it.

Most apps never request business_management for its own sake. It shows up as a dependency: catalog_management requires it to manage product catalogs, and leads_retrieval requires it (alongside ads_management, ads_read, and pages_manage_ads) to pull lead-form data. If your app touches Business Manager assets at all, this permission is probably already on your list whether you planned for it or not. See our Facebook App Review service for how we scope a full permission set before submission.

Four things that catch teams off guard

The screencast wants ads data, not asset data

Meta’s published screencast requirement for business_management asks you to demonstrate a business accessing ads performance data — Impressions, Conversions, Spend, Clicks, Reach — after granting the permission. If your app claims ad accounts but never displays ads reporting, that requirement does not fit cleanly, and reviewers reject submissions that don’t address it.

It's rarely the “main” permission

Meta’s own guidance says: if business_management is requested as a dependency of another permission such as pages_messaging or pages_show_list, your use case description must name that main permission. Submitting a generic business_management justification without naming what it's actually for is a common rejection reason.

Advanced Access changes the bar

Scaling past a small number of connected businesses generally pushes business_management into Advanced Access, and Meta requires Business Verification for any Advanced Access permission. Skipping verification first is one of the most common reasons a submission stalls before a reviewer even looks at the use case. Background in our Meta Advanced Access guide.

Dependencies must already be approved

pages_read_engagement and pages_show_list are hard dependencies. Submitting business_management before those are in place — or without the Facebook Login for Business flow that grants all three together — is a straightforward, avoidable rejection.

Where business_management submissions actually get rejected

  • Screencast shows asset management but not ads reporting. Meta’s template explicitly calls for ads performance data on screen, even for apps built around catalogs, leads, or Page management rather than ad spend.
  • Use case description never names the parent permission. A vague “we need to manage business assets” explanation, with no mention of catalog_management, leads_retrieval, or whichever permission actually depends on it, reads as incomplete to a reviewer.
  • Business Verification wasn’t completed first. Requesting Advanced Access on business_management without a verified Business Manager behind it stalls the whole submission, not just this one permission.
  • Dependency permissions aren’t live yet. pages_read_engagement and pages_show_list have to already be granted; submitting out of order is a frequent, entirely avoidable mistake.
  • The app requests it “just in case.” Meta’s own guidance is explicit that requesting unneeded permissions is a common rejection reason across every permission, not just this one.

How we approach a business_management submission

1

Identify the real parent permission

catalog_management, leads_retrieval, or a Page/asset workflow — the submission gets built around whichever one is actually driving the request, not around business_management in isolation.

2

Confirm Business Verification status

If the request needs Advanced Access, verification has to be complete before submission, not attempted alongside it.

3

Build the screencast Meta actually asks for

Matching the published screencast requirement — including the ads-performance-data segment where relevant — instead of a generic product walkthrough.

4

Write the use case description around the dependency

Naming the main permission and the specific business workflow it unlocks, the way Meta’s own instructions ask for.

The exact screencast script and use-case wording that gets this approved on the first pass is deliberately not spelled out here — that is the part of the work we do for clients.

What a rejection here actually costs

  • It blocks whatever depends on it. Since catalog_management and leads_retrieval both require business_management first, a rejection here stalls those permissions too, not just this one.
  • Resubmission means a new screencast. If the original recording didn’t show ads performance data the way Meta’s template expects, the fix usually means re-recording, not just editing the written explanation.
  • Advanced Access gaps surface late. Discovering a Business Verification requirement after a rejection adds a full verification cycle on top of the resubmission.

Frequently asked questions

What does business_management actually let my app do?

Per Meta’s Permissions Reference, it lets your app read and write with the Business Manager API — specifically to manage business assets such as an ad account, and to claim ad accounts. It is not a general-purpose “access everything” permission.

Does business_management need Business Verification?

Business Verification is required for any permission requested at Advanced Access. Whether business_management needs it depends on your access level and scale — worth confirming before you submit, not after a rejection.

Why does the screencast ask for ads performance data if my app isn't about ads?

Meta’s published screencast requirement for this permission is written around ad account access, since “manage business assets such as an ad account” is the permission’s core allowed usage. Apps requesting it for catalog or lead-management reasons still need to address that requirement in their submission.

Can I request business_management on its own?

Technically yes, but Meta’s guidance asks you to name the main permission it supports if it's a dependency — and reviewers routinely reject standalone requests that don’t explain what larger workflow the asset access is actually for.

Facts here are drawn from Meta’s official Permissions Reference documentation, reviewed July 2026. Permission requirements and screencast templates change over time — verify against Meta’s current developer docs before submitting. This is technical implementation guidance, not legal advice, and is not affiliated with or endorsed by Meta Platforms, Inc. Meta makes all App Review, verification and enforcement decisions independently; no specific outcome or timeline can be guaranteed. Related reading: our Meta Ads API rejection case study covers a business_management-adjacent rejection in detail, and you can hire a Facebook API developer to run a submission end to end. Questions? Reach out through the contact options in the footer.