Governance

A one-pass GA4 user access audit

See who holds admin, editor, and viewer rights across every GA4 property and GTM container you administer. Filter by person, resource, or role, and export the whole thing as a CSV.

  • GA4 & GTM together
  • Role breakdown
  • Filter by user or resource
  • CSV export
app.tagfire.io/app/tools/access-governance
34
People with access
11
Administrators
19
Resources
6
External domains
  • ex-agency@vendor.com — Admin on 4 propertiesREVIEW
  • contractor@gmail.com — Publish on GTM-XXXXXXXREVIEW
  • analytics@company.com — Admin on 12 resourcesOWNER
  • marketing@company.com — Editor on 8 propertiesOK
  • reporting@company.com — Viewer on 19 resourcesOK
Filter: Admins onlyFilter: External domainsGroup by userExport CSV
The combined access matrix: every person with rights across properties and containers, with their role on each.

In short

How do I see who has access to my GA4 and GTM?

A user access audit reads the permission lists of every GA4 property and GTM container your Google account can administer and combines them into one report — each person, each resource, and the role they hold. Google itself only shows this one resource at a time, which is why stale access accumulates unnoticed.

Covers
GA4 properties and GTM containers
Shows
Admin, editor, and viewer roles
Filters
By user, resource, or role
Export
CSV for compliance records
Access needed
Admin on the resources you audit
Price
Free, no credit card

How the access audit works

Read-only across both platforms. Nothing is granted, changed, or revoked.

  1. 01

    Connect Google

    Sign in and grant read access to Analytics and Tag Manager. You will see permissions for the resources your account can administer — Google only exposes access lists to administrators, on both platforms.

  2. 02

    Pull every access list

    Tagfire reads the user list from each GA4 property and GTM container and combines them into one matrix, so the same person appearing across nine resources shows up as one row rather than nine separate lookups.

  3. 03

    Filter, review, export

    Filter to administrators only, to external email domains, or to one person. Export the result as CSV for your quarterly access review or whoever asks for evidence.

Guide

Why analytics access quietly gets out of hand

Access to a GA4 property or a GTM container is granted constantly and revoked almost never. A contractor needs to check something. An agency is onboarded. A developer needs publish rights for one release. Each grant is reasonable and takes thirty seconds. Nobody schedules the removal, and there is no expiry.

What makes it worse is that Google shows permissions one resource at a time. To answer "who has access to our analytics?" across twelve properties and seven containers, someone has to open nineteen separate admin screens and reconcile them by hand. That is why the question rarely gets asked, and why the answer is always more surprising than expected.

What you are actually looking for

  1. People who have left

    Former employees, ex-agencies, and finished contractors. Analytics access almost never appears on an offboarding checklist, because it is not in the identity provider — it is granted to a Google account directly. This is the most common finding, in every organisation.

  2. Administrators who do not need to be

    Admin can add and remove other users, change data retention, and delete a property. Most people granted Admin needed Editor, and most Editors needed Viewer. Grant escalates because it is easier than working out the right level in the moment.

  3. GTM publish rights

    The most consequential permission in the stack, and it is not the one people worry about. Publish rights mean the ability to execute arbitrary JavaScript on every page of the site through a Custom HTML tag. The GTM audit checks whether the container restricts that; this checks who could use it.

  4. External domains

    Personal Gmail addresses and vendor domains. Sometimes entirely legitimate — freelancers and agencies work this way. Worth a deliberate look rather than a discovery during an incident, particularly personal addresses belonging to people who now work somewhere else.

  5. Single points of failure

    The opposite risk. If exactly one person is Admin on a property and they leave, recovering control means a Google support process measured in weeks. Two administrators on every resource is the minimum sane configuration.

The roles, and what they actually let someone do

GA4 Administrator
Full control: manage users, change property settings, alter data retention, link products, and delete the property. Only the people responsible for the property should hold it — typically two or three.
GA4 Editor
Change configuration — events, conversions, audiences, custom definitions — but not users. This is the right level for most practitioners, and it is what most people who have Admin actually needed.
GA4 Viewer / Analyst
Read reports, and for Analyst, create shared assets. The correct default for anyone who only consumes data. Most people in most organisations should be here.
GTM Publish
Push changes live to the production site. Effectively production deploy rights, held by marketing teams and agencies rather than engineering, and usually with no review step at all. Treat it accordingly.

Making access review a routine

The value of an access audit comes from repetition, not from a single dramatic cleanup. A workable rhythm:

  • Quarterly, review the full list and remove anyone who no longer needs access
  • On every offboarding, check analytics explicitly — it is not in your identity provider, so it will not be caught automatically
  • When an agency relationship ends, before the final invoice, while you still have their attention
  • Before any compliance review, and export the CSV as evidence that the review happened
  • After any incident, because "who could have changed this?" is the first question and the access list is the answer

The export matters more than it sounds. An access review nobody recorded is indistinguishable from an access review nobody did, and a dated CSV is the cheapest possible evidence.

What this tool will not do

It is strictly read-only. It will not revoke anyone, and that is deliberate — removing the wrong person from a property mid-campaign is a worse outcome than a slightly stale list, and permission changes should be made deliberately in the platform that owns them. This produces the review; you act on it in GA4 and GTM.

It also only sees what your account can administer. Google exposes access lists to administrators only, on both platforms, so a property where you are merely an Editor will not appear.

Comparison

Tagfire vs. the alternatives

How a combined access audit compares to checking each platform by hand.

CapabilityTagfireGA4 adminGTM admin
All properties in one viewYesNoNo
GA4 and GTM togetherYesNoNo
Group by person across resourcesYesNoNo
Filter to administrators onlyYesNoNo
Highlight external email domainsYesBy eyeBy eye
CSV export for complianceYesNoNo
Time for 19 resourcesSeconds19 screens19 screens
Can revoke accessNoYesYes

Revocation stays in Google deliberately — this tool produces the review, you act on it in the platform that owns the permission.

FAQ

Frequently asked questions

Find out who still has the keys

One pass across every GA4 property and GTM container you administer, filtered how you need it and exportable as CSV.

Run an access audit