Guide
Why analytics access quietly gets out of hand
Access to a GA4 property or a GTM container is granted constantly and revoked almost never. A contractor needs to check something. An agency is onboarded. A developer needs publish rights for one release. Each grant is reasonable and takes thirty seconds. Nobody schedules the removal, and there is no expiry.
What makes it worse is that Google shows permissions one resource at a time. To answer "who has access to our analytics?" across twelve properties and seven containers, someone has to open nineteen separate admin screens and reconcile them by hand. That is why the question rarely gets asked, and why the answer is always more surprising than expected.
What you are actually looking for
People who have left
Former employees, ex-agencies, and finished contractors. Analytics access almost never appears on an offboarding checklist, because it is not in the identity provider — it is granted to a Google account directly. This is the most common finding, in every organisation.
Administrators who do not need to be
Admin can add and remove other users, change data retention, and delete a property. Most people granted Admin needed Editor, and most Editors needed Viewer. Grant escalates because it is easier than working out the right level in the moment.
GTM publish rights
The most consequential permission in the stack, and it is not the one people worry about. Publish rights mean the ability to execute arbitrary JavaScript on every page of the site through a Custom HTML tag. The GTM audit checks whether the container restricts that; this checks who could use it.
External domains
Personal Gmail addresses and vendor domains. Sometimes entirely legitimate — freelancers and agencies work this way. Worth a deliberate look rather than a discovery during an incident, particularly personal addresses belonging to people who now work somewhere else.
Single points of failure
The opposite risk. If exactly one person is Admin on a property and they leave, recovering control means a Google support process measured in weeks. Two administrators on every resource is the minimum sane configuration.
The roles, and what they actually let someone do
- GA4 Administrator
- Full control: manage users, change property settings, alter data retention, link products, and delete the property. Only the people responsible for the property should hold it — typically two or three.
- GA4 Editor
- Change configuration — events, conversions, audiences, custom definitions — but not users. This is the right level for most practitioners, and it is what most people who have Admin actually needed.
- GA4 Viewer / Analyst
- Read reports, and for Analyst, create shared assets. The correct default for anyone who only consumes data. Most people in most organisations should be here.
- GTM Publish
- Push changes live to the production site. Effectively production deploy rights, held by marketing teams and agencies rather than engineering, and usually with no review step at all. Treat it accordingly.
Making access review a routine
The value of an access audit comes from repetition, not from a single dramatic cleanup. A workable rhythm:
- Quarterly, review the full list and remove anyone who no longer needs access
- On every offboarding, check analytics explicitly — it is not in your identity provider, so it will not be caught automatically
- When an agency relationship ends, before the final invoice, while you still have their attention
- Before any compliance review, and export the CSV as evidence that the review happened
- After any incident, because "who could have changed this?" is the first question and the access list is the answer
The export matters more than it sounds. An access review nobody recorded is indistinguishable from an access review nobody did, and a dated CSV is the cheapest possible evidence.
What this tool will not do
It is strictly read-only. It will not revoke anyone, and that is deliberate — removing the wrong person from a property mid-campaign is a worse outcome than a slightly stale list, and permission changes should be made deliberately in the platform that owns them. This produces the review; you act on it in GA4 and GTM.
It also only sees what your account can administer. Google exposes access lists to administrators only, on both platforms, so a property where you are merely an Editor will not appear.