A client asked us a question last month that almost no client asks. Most people either hand over owner access without reading the screen, or they refuse everything and then wonder why the reports are empty. This one did neither. He wrote:
“So can you tell me precisely what permissions you need in my GSC and GA4 accounts? I will grant whatever permissions are needed, but I need to be explicit about which owner permissions are required and why.”
— CEO of an enterprise media brand we work with
That is the correct question. It is also the question our own team fumbled for two rounds before we answered it cleanly — we had asked for owner and admin early on, not because we needed it, but because it saved us from emailing him every time we wanted to add a teammate. Convenience for us, risk for him. He was right to push back.
So here is the answer we should have given in one line, and the reasoning underneath it. This is the allocation model we now run on every account.
The short answer
For a standard SEO and reporting engagement, an agency needs exactly this:
| Platform | What the agency needs | What the client keeps |
|---|---|---|
| Google Search Console | Full user | Verified Owner |
| Google Analytics (GA4) | Analyst — or Editor only while configuring measurement | Administrator |
No owner. No admin. Not ever, as a standing arrangement.
If an agency tells you they need owner access to do SEO, ask them which specific task requires it. There are only a few honest answers — adding users, changing the site address, uploading a disavow file, and creating the GA4-to-Search-Console link — and all of them are one-time or rare jobs the client can do themselves in about ninety seconds.
The naming trap: “Full” is not “Owner”
Here is the thing that causes most of the confusion, and it is entirely Google’s fault.
In Search Console, the permission named Full sounds like it means full control of the account. It does not. A Full user cannot add or remove users, cannot run a change of address, cannot link a Google Analytics account, and cannot remove the property from anyone else’s account. Every one of those is owner-only.
What Full actually buys is the day-to-day work: submitting sitemaps, URL Inspection and requesting indexing, the removals tool, reconsideration requests, and sharing report links. That is the job.
Meanwhile the tier below it — Restricted — sounds like a reasonable middle ground and is in practice close to useless for an agency. It is view-mostly. It cannot submit sitemaps, cannot submit removal requests (it can only look at the history of them), cannot share report links, and its URL Inspection is capped at fetch-only, so no requesting indexing. If you grant Restricted and then ask why your agency hasn’t submitted the new sitemap, this is why.
Full is the working tier. Restricted is the reading tier. Owner is the keys. An agency should live in the middle one.

Google Search Console access levels, precisely
| Level | Can | Cannot |
|---|---|---|
| Owner (verified) | Everything. Add and remove users and other owners, all reports and tools, property settings, change of address, upload a disavow file, link Google Analytics and Merchant Center. | Be downgraded to a lower level — a verified owner can only be removed outright. See the warning below. |
| Owner (delegated) | The same as a verified owner, granted by a verified owner rather than by placing a token. | Persist independently — any owner can remove a delegated owner in the Users and permissions screen. |
| Full user | View all data and reports. Submit sitemaps. URL Inspection and request indexing. Submit removals. Reconsideration requests and verify fixes. Share report links. | Add or remove any user. Link Google Analytics. Change of address (view only). Remove the property from anyone else’s account. |
| Restricted user | View most reports — performance, links, blocked URLs, rich results. URL Inspection, fetch only. | Submit sitemaps. Submit removals (view only). Share report links. Most settings are view-only. Receives only messages that specifically affect them. |
| Associate | Act on the property from another linked product without holding a Search Console seat. | Log into Search Console directly. |
A note on the disavow tool. Google’s own documentation contradicts itself here — the permissions matrix shows Full users with disavow access, while the disavow tool’s own help page says plainly that you must be a property owner to upload a disavow list. We plan around the stricter version: assume disavow is owner-only and have the client upload the file. It is a once-a-year action at most, and if you’re reaching for it monthly you have a different problem.
The verified-owner trap
Read this part twice, because it is the single most expensive mistake in this whole article — and the version of it circulating on most SEO blogs is wrong.
What people usually say is that a verified owner can never be removed through the interface. That is not accurate. You can remove a verified owner from the Users and permissions screen, and they lose access immediately. But there is a second step almost nobody takes: their verification token is still sitting on your site — a DNS record, an HTML file, a meta tag, or a Google Analytics or Tag Manager snippet. Until you find and delete that token, the person you just removed can simply re-verify themselves and walk back in.
There is also a smaller trap that bites more often: you cannot downgrade a verified owner. There is no path from Owner to Full user. If you want to move someone down a level, you have to remove them entirely, delete their token, and then add them back as a Full user.
Now picture the common version of all this. An agency sets up Search Console for a new client, verifies it with their own DNS record or their own GTM container, and becomes the verified owner. The client is added afterward as a user. Two years later the relationship ends, and the client discovers they cannot cleanly evict the agency without touching DNS they may not control either.
This is not hypothetical and it is not rare. It is the reason we set up Search Console under the client’s Google account, verified with the client’s own method, every single time — even though it is slower and even though the client usually asks us to just handle it. Ten extra minutes on day one beats a hostage negotiation on day seven hundred.
Google Analytics (GA4) access levels, precisely
GA4 is structured differently and, honestly, better. The roles are cleaner and the low tiers are genuinely usable.
| Role | Can | Cannot |
|---|---|---|
| Administrator | Everything, including adding and removing users and assigning roles and data restrictions. | — |
| Editor | Full control of property settings — data streams, key events, custom dimensions, audiences, product links. Can view users. | Manage users. |
| Marketer | Everything Analyst can, plus create, edit and archive audiences, events, and key events, and edit attribution models. | Manage users. Reach full property settings. |
| Analyst | Everything Viewer can, plus share explorations and other assets with other users on the property. | Manage users. Create or archive audiences. Change settings. |
| Viewer | See all report data and configuration. Create, edit and delete their own explorations. Customize report displays. | Share explorations with anyone else. Change any setting. Manage users. |
Three things worth knowing that most agencies never mention to clients:
Viewer versus Analyst is about sharing, not seeing. This is the distinction that trips people up. A Viewer can build a full exploration — they are not stuck with canned reports. What they cannot do is share it with anyone else on the property. So if your agency is building explorations for you to look at, Viewer will quietly fail and nobody will understand why. Analyst is the right agency default, and it is still read-only where it counts: no settings, no audiences, no users.
You can layer data restrictions on top of any role. GA4 has two — No Cost Metrics and No Revenue Metrics. If you want an agency in the data but not in the margins, this is the control you’re looking for, and it’s in the same dialog where you assign the role. Two caveats: the restricted metrics don’t disappear from the interface, they report as zero, so anyone paying attention knows they’re restricted. And a restriction on an Administrator means nothing, because an Administrator can grant themselves full permissions.
Restrictions can leak through linked products. Google warns that a user may escape these restrictions if they hold permissions in another Google product linked to Analytics — Google Ads being the obvious one. If restrictions matter to you, check the linked accounts too.

The one case where an agency genuinely needs more
We should be honest about this, because a blanket “never grant owner” is its own kind of dishonesty.
There is one common task that requires elevated access in both tools at once: linking GA4 to Search Console. Google’s requirement is specific — you need the Editor role on the GA4 property and you must be a verified owner of the Search Console property. Not a Full user. A verified owner.
So when an agency asks for owner access “to connect Analytics and Search Console,” they are not making it up. The right response is not to grant it permanently, though. The right response is: the client does the link, once, while the agency is on the call. It takes under two minutes, it happens one time in the life of the account, and Search Console ownership can even be verified during the linking flow itself. Worth knowing for later: deleting that link needs only the GA4 Editor role, no Search Console permission at all.
Same pattern for change of address during a domain migration, same pattern for a disavow upload, same pattern for adding a new person. Do it live on a call, once, rather than granting permanent access to cover an occasional need. That is the whole principle: scope access to the ongoing work, not to the rare exception.
Who gets what: agency, client, team member
| Role | Search Console | GA4 | Why |
|---|---|---|---|
| Client (business owner) | Verified Owner | Administrator | They own the asset. They must be able to remove anyone, including us, without asking permission. |
| Client’s internal marketing lead | Full user | Editor | Does the work, but shouldn’t be able to lock the owner out. |
| Agency (us) | Full user | Analyst — Editor only during measurement setup | Everything we need to do SEO and share analysis, nothing we need to hold the account hostage. |
| Agency analyst / junior team member | Covered by the shared access identity | Covered by the shared access identity | Never added individually. See below. |
| Contractor or freelancer | Restricted, or nothing | Viewer with both data restrictions | Short engagement, narrow need, easy removal. |
| Client’s accountant, lawyer, board | Nothing | Viewer with No Revenue Metrics, if they truly need a login at all | They want a number, not a login. Send a report. |
One identity, not ten logins
This is the operational half of the answer, and it is where most agencies quietly create a mess.
The instinct is to add each team member individually — the strategist, the analyst, the intern who pulls the monthly numbers. It feels tidy. It is not. Six months later you have four people on the account, two of whom left the company, and nobody remembers which client properties they were added to. The client has no idea who those Gmail addresses belong to. Offboarding becomes archaeology.
We use a single access identity per platform instead. Ours are public, because there is nothing secret about them:
| Platform | Identity |
|---|---|
| Google — Search Console, Analytics, Business Profile, Tag Manager | access@localservicespotlight.com |
| Google Ads | Manager (MCC) ID 487-320-8131 |
| Meta — Facebook, Instagram, Ads | Business ID 552854764819146 |
| Anything requiring a password | A secure vault link, never email or text |
One address on the client’s account. Access inside our team is managed on our side, in our own Google Workspace, where it belongs. When someone leaves us, we remove them from our group and their access to every client evaporates at once — no client has to do anything, and no client is left holding a stale account they can’t identify.
And when a client asks “who exactly at your company can see my data,” we can answer honestly and specifically, in one sentence, without an audit.
That is the whole reason our Access Checklist lists one email and one ID per platform rather than a roster of names.
Five ways this goes wrong
- The agency is the verified owner. The client doesn’t own their own property and finds out at the worst possible moment. Check this today: in Search Console, go to Settings → Users and permissions and confirm your own email shows as Owner, not Full.
- Individual team members were added and never removed. Open any client account you’ve held for more than a year and read the user list out loud. If you can’t identify every address, you have a problem — and so does the client.
- Restricted was granted and everyone assumed the work was happening. The agency can see the data, so nothing looks broken. But no sitemap has been submitted in eight months, because they can’t. This one hides for a long time.
- Owner was granted “temporarily” for a migration. Nobody ever removes it — and because verified owners can’t be downgraded, the cleanup is more annoying than the grant was. Put a calendar reminder on the same day you grant it, or don’t grant it.
- Access lives in a personal Gmail. Someone’s
firstname.lastname@gmail.comowns a business-critical property. When they leave, change phones, or lose the account, the property goes with them. Business assets belong to business identities.
The offboarding test
If you want one question to evaluate any access arrangement — yours or your agency’s — it’s this:
If we ended this relationship this afternoon, could the client remove us entirely, by themselves, in under five minutes, without calling anyone?
If the answer is yes, the access is set up correctly. If the answer involves DNS records, a former employee’s Gmail, or a call to a developer, it is not — and you should fix it while everyone is still on good terms.
The client who prompted this article passed that test, because he insisted on it before he granted anything. He kept owner and admin, gave us Full and read-level access, and asked us to justify every level. It took two extra rounds of email and it was worth all of them.
Frequently asked
Does Full access in Search Console let an agency remove me as owner?
No. Full users cannot add or remove any user, including owners. Only an owner can do that.
Is Viewer enough in GA4 for an agency?
Only if they never need to share an exploration with you — Viewers can build them but not share them. Analyst is the better default and is still read-only on settings. Editor becomes necessary the moment someone configures key events, custom dimensions, audiences, or product links.
Can I give access and then take it back later?
In GA4, always. In Search Console, yes for Full, Restricted and delegated owners. A verified owner can be removed but not downgraded — and you must also delete their verification token from your site, or they can re-verify themselves.
What if my agency insists on owner access?
Ask which specific task requires it. If the answer is “linking GA4 to Search Console,” “change of address,” or “uploading a disavow file,” those are one-time jobs you can do yourself on a screenshare. If there is no specific answer, that tells you something.
Should I just share a login instead?
No. Never share a Google password with a vendor. Every tool discussed here supports proper delegated access, which is auditable, revocable, and survives a password change. Sharing a login is worse for both sides.
Related
- How to Grant Access to Your Google Search Console — the click-by-click version
- How to Grant Access to Your Google Analytics (GA4)
- How to Grant Access to Your Google Tag Manager
- The full Access Checklist — every account, one page
Permission tables verified against Google’s Managing owners, users, and permissions, Disavow links, Analytics access and data-restriction management, and the GA4 Search Console integration doc. Google changes these periodically — this article reflects the levels as of August 2026.

