give-access-agency

How to give your agency access to Search Console, Analytics, Tag Manager, Google Ads and more (step by step)

You've just hired a marketing agency, and the first thing they ask for is access. That's normal: without data from Search Console, Analytics, or Google Ads, any strategy is just guesswork.

The good news is that you don't have to share any passwords. Each tool allows you to add the agency as a user, with the highest level of permissions, and remove it whenever you want. This guide explains how to do this, tool by tool.

Before we begin: three rules

  • Your company always owns it. The accounts must be created with your corporate email address, never with the agency's email or with that of an employee who may leave.
  • It grants access to a named email address. Ask the agency for the exact address (it's usually a Gmail or Google Workspace account for the team) and always add the same one.
  • Always grant the highest level of permission. Administrator or owner, depending on the tool. With limited permissions, the agency can't link Analytics to Google Ads, publish tags, verify the domain, or create integrations, and each block delays the project by days or weeks. The highest permission level doesn't take away ownership: you can revoke it at any time.

What access does your agency need based on the service?

You don't need to give it your all on the first day: just what each contracted service requires.

ServiceRequired access
SEO and SEO for AI (GEO)Search Console, Analytics 4, Business Profile, web (CMS) and domain DNS
Google Ads and Paid MediaGoogle Ads, Merchant Center, Tag Manager, Analytics 4 and cookie manager
Social Networks and Social AdsMeta Business, LinkedIn and YouTube
Web design and ecommerceCMS (WordPress, Wix, Shopify or PrestaShop), hosting, domain/DNS and Cloudflare
Analytics and CROAnalytics 4, Tag Manager and Looker Studio
Automation, CRM and AIHolded, HubSpot, GoHighLevel, Brevo or Mailchimp

1. Google Search Console

Search Console shows you which searches your website appears for on Google and what errors are preventing it from being indexed. It's the first tool any SEO agency reviews.

To grant access, you must own the property.

  1. Enter Search Console and select your website property.
  2. In the side menu, go to Settings → Users and permissions.
  3. Click on Add user.
  4. Write the agency's email address.
  5. Choose the permission and press Add.

What permission to give: Owner. It is the highest level: it allows you to view all the data, submit sitemaps, validate errors, manage links with Analytics and Google Ads, and use the tools for changing domains or removing URLs.

2. Google Analytics 4

Analytics 4 measures what visitors do on your website: where they come from, which pages they view, and how many end up submitting a form or making a call. Without access, the agency can't know which channels are bringing you business.

You can grant access to the entire account or just a single property. If you only have one website, grant access to that property.

  1. Enter Google Analytics and tap the gear icon Manage (bottom left).
  2. In the property column, click on Property access management (either to the account (if you want to give access to everything).
  3. Press the button + and choose Add users.
  4. Write the agency and brand email address Notify new users by email.
  5. Choose the role and press Add.

What role to give: Administrator. GA4 has five roles, from most to least permissions. We always recommend the highest one, at the account level:

RoleWhat can you do?
Administrator (recommended)Everything: events, conversions, audiences, integrations with Google Ads, Search Console and BigQuery, and user management
EditorConfigure the property, without managing users
MarketingCreate audiences and conversions for campaigns
AnalystCreate reports and explorations
ReaderView reports only

3. Google Tag Manager

Tag Manager is the tag manager: it allows you to install the code for Analytics, Google Ads, Meta or LinkedIn and measure forms, phone clicks or catalog downloads without touching the website.

  1. Enter Tag Manager and open your account.
  2. Go to the tab Manage.
  3. In the account column, click on User management.
  4. Press + → Add users and write the agency's email address.
  5. In Account permissions Choose Administrator.
  6. In Container permits, Activate your website container and choose the level.
  7. Press Invite.

What permission to grant: Account Administrator and Publish to container. It's the highest level: the agency can create, test and publish labels, and manage environments and users without waiting for anyone.

4. Google Ads

In Google Ads, the usual practice is not to add a user account, but rather to link your account to the agency's manager account (MCC). This way, the agency manages the campaigns, and billing remains in your name.

  1. Ask the agency for the Customer ID from your account (ten digits, top right) or give it to him/her.
  2. The agency sends you a linking request from its MCC.
  3. In your Google Ads account, go to Administrator → Access and Security.
  4. Open the tab Managers, Review the application and press Accept.

If you also want to grant access to a specific person, on the same screen, tab Users, press +, Enter your email and choose Administrator, the highest level: allows you to manage campaigns, conversions, links and users.

5. Google Business Profile

Your Google Business Profile, which was called Google My Business until the end of 2021, is the one that appears on Maps and in searches for your name. In B2B, it adds trust and reviews.

  1. Search for your company name on Google while logged in, or log in business.google.com.
  2. Open the three-dot profile menu and choose Profile settings.
  3. Enter People and access and press Add.
  4. Write the agency's email address, choose Owner and press Invite.

Don't relinquish the role of Main OwnerIt should always remain within your company.

6. Meta (Facebook and Instagram)

In Meta, you don't add each person from the agency separately; you add the agency as a partner directly from the Business Manager. This way, when someone on your team changes, you won't have to do anything.

  1. Ask the agency for your Business ID from Meta.
  2. Enter Business setup with your business portfolio.
  3. Go to Users → Partners and press Add → Grant a partner access to your assets.
  4. Paste the agency's business ID.
  5. Select the assets to share: Facebook page, Instagram account, ad account, and data set (pixel).
  6. Choose the permissions for each asset and save.

What permission to grant: full control over all assets. It's the highest level: the agency can manage campaigns, publish content, configure the pixel and conversion API, and verify the domain.

7. LinkedIn (Company Page and Campaign Manager)

In B2B, LinkedIn is the channel where decision-makers are. They are two different access points.

Company page:

  1. Log in to your page as administrator and press Settings → Manage administrators.
  2. Press Add administrator and look for the profile of the person from the agency.
  3. Choose Super administrator, the highest level.

Campaign Manager (ads):

  1. Enter Campaign Manager and open the advertising account.
  2. Go to Manage access from the account menu.
  3. Add the agency person with the role Account Manager, the highest level.

In both cases, the agency representative must have an active LinkedIn profile; invitations are not sent by email.

8. Your website (WordPress)

To improve on-page SEO, speed, or create landing pages, the agency needs access to the website. In WordPress, this is done by creating a separate user account, never by sharing yours.

  1. Log in to your WordPress dashboard (yourdomain.com/wp-admin).
  2. Go to Users → Add new.
  3. Enter the agency's email address and an identifiable username (for example, Arctic agency).
  4. Choose the profile Administrator, the highest level: allows you to install plugins, modify the theme, and optimize speed.
  5. Brand Send notification to user and press Add new user.

If the agency also needs to work on the server (backups, migrations, speed), create a separate FTP/SFTP or hosting user; never give the provider's main access.

9. Holded or your CRM

If the agency is going to connect the web forms with sales, or automate processes, it will need to access your CRM or ERP.

In Holded, go to Settings → Users, invite them to the agency's email and grant them permissions to administrator. In ARTIC, as Holded Solution Partners, This allows us to configure modules, automations, and integrations without blocking.

10. Google Merchant Center

If you sell products online (spare parts, materials, supplies), Merchant Center is where your catalog for Google Shopping and Performance Max campaigns lives.

  1. Enter Merchant Center and open the gear icon Configuration.
  2. Go to People and access and press Add person.
  3. Write the agency's email address.
  4. Choose Administrator, the highest level: allows you to manage the feed, programs, and links with Google Adss.
  5. Press Add.

Next, the agency will link Merchant Center to your Google Ads account.

11. Domain, DNS, Cloudflare and hosting

It's the access point that's most often forgotten and the one that causes the most blocks. It's needed to verify the domain in Search Console and Meta, configure email (SPF, DKIM, DMARC), migrate a website, or improve its speed.

  • Domain registrar (DonDominio, Arsys, IONOS, GoDaddy…): many don't allow additional users. The safest option is for the agency to send you the exact DNS record, which you can then add yourself, or you can do it together in a video call.
  • Cloudflare: go to Manage account → Members, press Invite, Write the agency's email address and choose the Administrator role.
  • Hosting (cPanel, Plesk, or vendor panel): creates a FTP/SFTP user or a sub-user with full access to the website and its databases. Never give the primary user of the contract.

12. Other website and online store managers

If your website is not on WordPress, the process is just as simple:

PlatformWhere is access provided?Recommended permit
WixSettings → Roles and permissions → Invite peopleAdministrator (co-owner)
ShopifyThe agency sends you a collaborator request; you accept it in Settings → UsersContributor with full permissions
WooCommerceUsers → Add new (in WordPress)Administrator
PrestaShopAdvanced parameters → Team → Add new employeeSuperAdmin

At Shopify, collaborator access does not take up a user license from your plan.

13. CRM and email marketing

In order for website leads to reach sales and be nurtured with automated emails, the agency needs access to your CRM or email tool.

ToolWhere is access provided?Recommended permit
HubSpotSettings → Users and devices → Create userSuperintendent
GoHighLevelSubaccount → Settings → My team → Add employeeAdministrator
BrevoSettings → Users → Invite userAdministrator (all permissions)
MailchimpProfile → Settings → Users → Invite userAdmin

With administrator permissions, the agency can connect forms, create automations, and integrate the CRM with the web and with Holded without waiting for someone to enable each module.

14. Cookie manager (Cookiebot, CookieYes…)

Since 2024, Google has required the Consent Mode v2 To measure and remarket to users in the European Union. If your cookie banner is not configured correctly, Analytics and Google Ads will lose data.

In your Cookiebot, CookieYes or similar dashboard, go to the section Users either Equipment and invite the agency's email as administrator.

Checklist: Access for your agency

Mark each access as you grant it:

  • Google Search Console: Owner
  • Google Analytics 4: Administrator of the account
  • Google Tag Manager: Administrator account + Post in the container
  • Google Ads: linking with the agency's MCC + user Administrator
  • Google Business Profile (formerly Google My Business): Owner
  • Meta Business: agency added as partner with total control on page, Instagram, ad account and pixel
  • LinkedIn: Superintendent from page + Account Manager in Campaign Manager
  • Web (WordPress, Wix, Shopify or PrestaShop): Administrator
  • Holded: Administrator
  • Google Merchant Center: Administrator
  • Domain, DNS, Cloudflare and hosting: Administrator or user with full access
  • CRM and email (HubSpot, GoHighLevel, Brevo, Mailchimp): Administrator
  • Cookie manager: Administrator

Common mistakes when granting access

  • Share your password. You lose control, security alerts go off, and you won't know who made each change.
  • The account must be in the agency's name. If you switch providers one day, you could lose years of Analytics data or your Google Ads history.
  • Granting access to an employee who is no longer there. Before you begin, check who has access and remove anyone who no longer needs it.
  • Falling short on permits. A reader or editor role requires requesting additional access halfway through the project and delays launch. Give it your all from day one.
  • Do not remove access when finished. When a collaboration ends, remove the users from each tool: it takes five minutes.

Frequently Asked Questions

Is it safe to give an agency access to Google Analytics? Yes, if you grant user access to an agency email address and never share your password, you can see what they're doing and revoke access whenever you want.

What permissions does an SEO agency need in Search Console? Owner, the highest level. This allows them to manage links, validate errors, and use all the tools without depending on you, while you remain the verified owner.

Will I lose my Google Ads campaigns if I change agencies? No, not if the account is yours and is only linked to the agency's MCC. By unlinking it, you retain campaigns, history, and billing.

How long does it take to grant all access? About five minutes per tool. With the basic ones (Search Console, Analytics, Tag Manager, Google Ads and Business Profile), less than half an hour; the rest, only if you subscribe to the services that use them.

What do I do if I don't know who owns my accounts? It's more common than you might think, especially if the website was built by another agency. An agency like ARTIC can help you regain ownership by verifying the domain or requesting it from Google and Meta.

Can we help you do it?

At ARTIC, we begin every B2B project with an onboarding call where we guide you through all the steps, live and step-by-step. Then, in the first week, we deliver a diagnostic report on your SEO, analytics, and campaigns.

Contact ARTIC or call us on +34 93 049 68 32.

Table of contents

Share:

Blog

B2B marketing sector news

Tips to get the most out of your blog

If you need advice on how to make the most of your blog, you've come to the right place. We'll explain...

How to generate qualified leads and stop attracting contacts that don't convert

Generating qualified leads is one of the most reasonable obsessions for any company that wants to…

What is the best SEO company in Barcelona?

All agencies work differently, but we have to say that the best positioning company…