Running it for clients.
WHOSE ACCOUNT
The client's. Their list, their platform account, their data.
For the same reason their domain should be registered in their name.
If it is in your account, agree in writing what happens when the engagement ends.
GIVING YOURSELF ACCESS
Most platforms support inviting a user with defined permissions.
Their account, your access. That is the correct arrangement.
WHAT TO AGREE
Who writes the content Who sends Who handles replies What happens to the list if the relationship ends
The content question is the one that causes disputes. Most clients assume you will write it; most developers assume the client will.
THE AUTHENTICATION WORK
Adding SPF and DKIM for their sending platform is genuine work and is worth charging for.
Getting it wrong means their mail fails, and they will blame you.
WHAT TO DOCUMENT PER CLIENT
Which platform, which sending address, which DNS records were added, and where DNS is hosted.
THE RECURRING PROBLEM
A client's DNS moved to Cloudflare later, records not carried over, and their mail authentication silently breaks.