Learn how to give an agency or external user access to Google Analytics 4, step by step. The difference between account and property level, roles and permissions.
If you're going to work with an agency, freelancer or consultant who needs to see or manage your site's data, the right move is to give them access to your Google Analytics 4 (GA4) account instead of sharing your username and password. It's safer, you keep full control, and you can revoke access at any time.
In this guide we explain how to do it step by step, what permission level is best to assign, and what best practices to follow.
Why sharing your Google password is never a good idea
Before getting into the step-by-step, it's worth spelling out why this method is the right one:
- Your Google account gives access to much more than Analytics: Gmail, Drive, YouTube, Photos, etc. Sharing the password compromises all of that.
- Google detects suspicious logins from other locations and tends to block the account or ask for constant verifications.
- There's no record of who made each change within the account.
- If you change the password, you cut off access for the whole team that was working.
GA4 is designed for you to invite users with their own Google email, assigning them the access level you decide.
Before you start: what you need
- Having the Administrator role on the GA4 account or property (without this, you won't be able to add users).
- The Google email of the person or agency you're going to give access to. It has to be an email associated with a Google account (it can be Gmail or a corporate Google Workspace).
- Being clear on the permission level you want to grant (below we explain which one is best in each case).
First, understand the GA4 structure: Account vs. Property
Before the step-by-step, it's key that you understand how Google Analytics 4 is organized, because the access level you grant depends on it.
GA4 has a two-level hierarchy:
- Account: it's the general container, the highest level. It usually represents your company, brand or overall project. An account can have one or several properties within it.
- Property: it's each specific website or app you measure. Each property has its own data stream, its own conversions, its own audiences.
A practical example: if your company has three websites (a corporate one, an e-commerce and a blog), the most common setup is to have one account with three properties inside.
What's the difference when giving access?
- If you give access at the Account level, the user will be able to see and/or manage all the properties within that account. If you later add a new property, they'll automatically see it too.
- If you give access at the Property level, the user will only be able to see and/or manage that specific property. The rest of the properties within the account stay out of their reach.
Which one is best in each case?
- An agency manages all of your company's sites → Account level.
- An agency manages only one of your sites → Property level.
- A freelancer who only needs to see reports for one specific site → Property level.
- An internal team that has to work across all the properties → Account level.
- An external vendor or temporary auditor → Property level (always as narrow as possible).
General rule: always give the lowest level necessary. If in doubt, start at the Property level — you can always add more access later.
— Gaucho Digital Team
Something important about permission inheritance
GA4 works with a top-down inheritance system: permissions assigned at the Account level are automatically inherited across all properties. This means that:
- If you give the Editor role at the Account level, that user will be an Editor across all the properties within that account, and you can't lower their permission on a specific property.
- You can do the opposite: give a low role at the Account level (for example, Viewer) and a higher role on a specific property (for example, Editor).
Keep it in mind before choosing the level.
How to reach the GA4 Admin menu
Whether you're going to give access at the Account level or the Property level, the first step is the same: get into the Admin menu.
- Go to https://analytics.google.com and sign in with the Google account that has the Administrator role.
- In the bottom-left corner of the screen, you'll see a gear icon. Click there.
Once inside Admin, you'll be able to choose whether you want to give access at the Account level or the Property level, depending on the case.
Step by step: how to give access at the Account level
This method gives the user access to all the properties within the GA4 account. It's the right one when an agency or team needs to work across your company's entire ecosystem.
Step 1: Check that you're in the right account
In the top-left corner, click the selector and check that the right account is selected. If you handle several companies or projects, make sure you don't get it wrong.
Step 2: Find the 'Account settings' block
Within Admin, you'll see the first block at the top that says 'ACCOUNT SETTINGS'. That's where the 'Account' card is, with all its options.
Step 3: Click 'Account access management'
Within the 'Account' card, you'll find the 'Account access management' option. Click there.
Step 4: Add the user
- Click the blue + button (top right).
- Select 'Add users'.
- Enter the user's or agency's Google email.
- Check the 'Notify new users by email' box.
Step 5: Assign the role and confirm
Choose the appropriate role (further on we explain each one in detail). Remember that this role will apply to all the properties within the account. Click Add and you're done.
Step by step: how to give access at the Property level
This method gives the user access to a specific property (a single website or app). It's the most recommended option when an agency or person is only going to work on one specific project.
Step 1: Select the right property
In the top-left corner, click the property selector. Make sure you have the specific property you want to give access to selected. This step is key: if you pick the wrong property, you'll end up giving permissions on a site that wasn't the one.
Step 2: Find the 'Property settings' block
Within Admin, scroll to the second block that says 'PROPERTY SETTINGS'. That's where the 'Property' card is, with its options.
Step 3: Click 'Property access management'
Within the 'Property' card, find and click the 'Property access management' option.
Step 4: Add the user
- Click the blue + button (top right).
- Select 'Add users'.
- Enter the user's or agency's Google email.
- Check the 'Notify new users by email' box.
Step 5: Choose the role and review the restrictions
Here you'll see the full panel where you assign the role and configure data restrictions.
These permissions will only apply to this specific property, not to the account's other properties.
If the agency is going to set up conversions, audiences, key events or Google Ads links, it needs the Administrator role or, at minimum, Editor. If it's only going to view reports, Analyst or Viewer is enough.
— Gaucho Digital Team
Step 6: Review the data restrictions
In the same panel you'll see two restriction options:
- No cost metrics: hides advertising spend data.
- No revenue metrics: hides income and revenue data.
Important: if the agency has to measure performance, ROAS or value-based conversions, leave both boxes unchecked. If you enable them, the person will get incomplete reports and won't be able to optimize properly.
Step 7: Confirm
Click Add. The user now has access only to this property.
Roles available in GA4: which one to assign?
GA4 offers five roles. These are their scopes:
- Administrator: full control. Can manage other users, change settings and link GA4 with other platforms (like Google Ads or Search Console). Recommended if the agency is going to set up conversions, audiences, links or custom events.
- Editor: can change property settings but not manage users. A good middle ground for technical teams.
- Marketer: can edit audiences, conversions, attribution models and key events, but doesn't touch general settings.
- Analyst: can create and edit shared assets like dashboards and explorations.
- Viewer: only views reports. Ideal for audits or external reporting.
For an agency that's going to manage your campaigns and measurement, the most common and practical choice is Administrator or, at minimum, Editor. If it only needs to view data, Analyst or Viewer is enough.
— Gaucho Digital Team
Summary: Account or Property?
Choose Account if:
- You want to give access to all the existing and future properties of that account.
- It's an internal team or lead agency managing your whole digital ecosystem.
- You don't mind the user seeing data from additional properties.
Choose Property if:
- You only want the user to access one specific site or app.
- You work with several agencies, each on a different project.
- You want to keep information segmented between projects.
- It's temporary access or low-trust.
How to revoke or change access later
If you stop working with that agency or want to change the permissions, you can do it at any time:
- Go back to Admin > Property access management (or account).
- Find the user in the list.
- Click the three vertical dots to the right of the name.
- Choose Modify permissions or Remove access.
Your historical data always stays within your account, so you can switch providers without losing anything.
Best practices when giving GA4 access
- Always grant the minimum permission level necessary. If someone is only going to view reports, don't give them the Administrator role.
- Periodically review the user list and remove access for people or vendors you no longer work with.
- Don't enable data restrictions for an agency that needs to measure conversions or revenue: it'll generate incomplete reports for them.
- Share access only with verified emails, not with generic or unknown addresses.
Frequently asked questions
Can I give GA4 access without sharing my password? Yes, that's precisely the right way. Each user signs in with their own Google account and you define what they can see or do.
Does the person need a Gmail account? They need an email associated with a Google account. It can be Gmail or a corporate email registered with Google Workspace.
How many users can I add? There's no practical limit. You can add as many as you need.
Is access immediate? Yes. Once you click Add, the user can log in with their account. The notification email is just a heads-up, it doesn't require prior acceptance.
What happens to the data if I remove access? Nothing. The data always stays in your GA4 property. Removing a user only stops them from continuing to view or change it, but the historical information stays intact.
What's the difference between giving access at the account level and at the property level? At the account level, the user accesses all the properties within that account. At the property level, they only access one specific property. For security, the recommendation is to always give the lowest level necessary.
With that sorted, giving access to your GA4 is a matter of minutes. If you need help setting up the permissions, key events or links for your account, get in touch: it's one of the services where we generate impact fastest.
Want to apply this to your business?
Let's talk. We analyze your situation and tell you what we'd do.
