
Your web designer or SEO person just asked for access to Google Analytics and Search Console, and you want to say yes without handing over a password or giving up control of your own data. Whether you need to add user to Google Analytics 4 or to Search Console, the move is the same: give one named person's Google Account the lowest role that covers their work, and keep the top role for your own business. Both tools let you do that in a few minutes, for free, and both let you take it back later. The part that trips people up is not the clicking. It is knowing which role to pick, which level to pick it at, and what to clean up when the work ends. This post gives you the exact menu paths, a role table for each tool, and a short check you can run in each account. If you also manage other business logins, the steps for adding a manager to a Google Business Profile, giving someone access to a Google Ads account and adding a user to WordPress follow the same idea.
Key Takeaways
Each person gets their own Google Account added as a user, so you can change or remove their access without touching anyone else.
Account level reaches every property in the account. Property level reaches only the one you choose, and that is what an agency normally needs.
An SEO provider doing active work can be a Full user. Owner access, especially verified ownership, stays with you.
Removing the person from the list is not enough if their verification token is still in place, so check the Unused ownership tokens list.
Add the person by Google Account email, at the lowest role that covers their work
The short answer for both tools is the same shape: open the access page, add the person's Google Account email, choose a role, save. Google's menu names change from time to time, so if a label below looks slightly different on your screen, look for the section with the named words in it. The person you add needs a Google Account; a work email can be linked to one if they do not have one yet.
Before you click anything, decide two things. First, which property is the site in question, since a business can have more than one. Second, what the person must actually do. A reporting job needs a different role from a job that changes tracking, and the answer for each tool is in the tables further down.
In Google Analytics 4
Google Analytics lets you add users at the account level or at the property level, as Google Analytics Help explains. The level you choose sets their starting access, so choose with care. You must be an Administrator to add or change users.
- Open Google Analytics and select the right account and property.
- Open Admin.
- Choose Account access management for account level, or Property access management for property level.
- Click the plus button, then Add users.
- Enter their Google Account email.
- Select the role, and any data restrictions you want.
- Click Add.
The person gets access at the level and role you picked, and you can change either one later from the same page.

In Search Console
Search Console works differently, because it has owners as well as users. A property owner adds people from Settings, as described in Search Console Help on owners, users and permissions.
- Open Search Console and select the correct property.
- Open Settings.
- Open Users and permissions.
- Click Add user.
- Enter a valid Google Account email.
- Choose Owner, Full, or Restricted permission.
- Save.
An email group cannot be added as a Search Console user, so add each person individually. Google also says a property must keep at least one verified owner, which matters more than it sounds and is covered below.
A property-level GA4 role is what an agency normally needs
GA4 has five roles: Administrator, Editor, Marketer, Analyst and Viewer. Each can be assigned at account or property level, per Google's role documentation. Account-level access applies to every property in that account unless a more permissive property-level role applies. That is why an agency working on one website normally gets property-level access, not account-level access. A person added at the account level can see every property in it, including any you did not mean to share.
| Role | What it can do | Fits |
|---|---|---|
| Viewer | Sees settings and data, and can create their own explorations | Reporting only |
| Analyst | Creates and shares explorations | A person building reports |
| Marketer | Manages audiences, events, key events and attribution settings | A person running campaigns and tracking |
| Editor | Full control of property settings, but cannot manage users | Broader tracking setup work |
| Administrator | Full control of Analytics, including users and permissions | Only a trusted person who must manage users or every setting |
Note one detail that surprises people. A Viewer cannot manage users, but a Viewer can still create, edit and delete their own explorations. Viewer does not mean the person can do nothing.
GA4 also has data restrictions, called No Cost Metrics and No Revenue Metrics. These hide cost and revenue figures from the person you are adding. They are a useful extra layer if your reports hold numbers you would rather keep private, but they do not replace choosing a lower role. Pick the lowest role first, then add the restriction if it is needed. Google's own advice, repeated on its access and data restriction page, is to grant only the access a person needs.
A GA4 role also does not reach your website. Analytics access controls Analytics, not your hosting, your website editor, your domain or your email. Adding an agency as a Viewer does not let them change a page. If they also need to change the site itself, that is a separate login, and the one worth planning carefully is the one for your site editor, such as the WordPress users covered in this series.
Search Console Full user fits SEO work while Owner stays with you
Search Console has three permission levels. Owners have full control, including settings, all reports and tools, and user administration. Full users can view all data and take many actions. Restricted users have view rights on most data and receive only the messages that specifically affect them.
| Permission | What it means | Fits |
|---|---|---|
| Owner | Adds and removes users, changes settings, sees all data, uses all tools | You, the business owner |
| Full user | Views all data and takes many actions, but cannot add or remove owners | An SEO provider doing active work |
| Restricted user | Views most data and gets only messages that affect them | Reporting only |
An SEO provider that needs to look at reports, submit sitemaps, inspect pages and check that a fix worked is usually well served by Full user. Restricted user covers a person who only needs to read the numbers. Owner is rarely needed by someone you hire, and handing it over means they can add and remove other people, including you.
So, if the question is whether to give a designer or agency Owner, the answer in most real work is no. Give them Full user and keep Owner yourself. That one choice protects the property if the relationship ends, because they cannot remove you or add their own successors.

A verified owner who leaves can come back unless you clear the token
Search Console has two kinds of owner, and the difference matters when someone departs. A verified owner proved ownership by placing a Google verification token on the site, using an HTML file, an HTML tag, a DNS record, a Google Analytics account or a Google Tag Manager account. A delegated owner was given ownership by another owner without using a personal token. Both have the same permissions while they are listed.
When a delegated owner leaves, you remove them from Users and permissions and that is the end of it. When a verified owner leaves, the same removal is not enough. Google explains in its announcement about Search Console user management that the token they placed can let them verify themselves again and regain access. Search Console includes an Unused ownership tokens list for exactly this reason. After you remove the person, open that list, then remove the matching token from the site or from DNS.
This cleanup can need whoever controls your site files or DNS records, which is sometimes the same former agency. Plan for that before the relationship ends, not after.
One more rule runs the other way. If every verified owner disappears, the remaining users and delegated owners eventually lose access until someone verifies the property again. So, keep at least one verified owner who belongs to your business, using an email you control.
Removing access takes a minute in each tool
Taking someone out is the same short path as putting them in, and it is worth doing the day the work stops. In GA4, open Access management at the account or property level, select the user and click Remove. Account-level Administrator access is needed to delete users. If a person was added at both levels, check both lists.
In Search Console, open Settings, then Users and permissions, use the menu beside the person and choose Remove access. If they were a verified owner, follow the token cleanup above.
When a person cannot be removed, the usual cause is a role they inherit from a higher level, such as the account or a group, which you cannot reduce lower down. Change the assignment at the level where it is granted. Linked products such as Google Ads can also add access you did not expect, so a thorough review looks there as well. The Google Ads access steps in this series cover the linked-account side.
Ten minutes in each tool gives you a full access list
You can audit who has access to both tools in one sitting. Do this when you first hear from a new vendor, when someone leaves, and on a regular schedule.
In GA4:
- Open Google Analytics and select the right account and property.
- Open Admin.
- Under Account, open Account access management, and under Property, open Property access management.
- Write down each user, their role, whether it is direct or inherited, and any data restriction.
- Check whether an account-level role exposes more properties than you meant to share.
In Search Console:
- Open the property and go to Settings, then Users and permissions.
- Write down every Owner, Full user and Restricted user.
- Note which owners are verified and which are delegated.
- Open the Unused ownership tokens list.
- Confirm that at least one verified owner belongs to your business.
Anyone you do not recognize, and anyone whose work has ended, comes off the list or drops to a lower role. Google recommends granting only the permission a person needs and revoking or changing access when someone no longer works on the property.

You can do the basic change yourself, and some jobs are worth handing off
Adding and removing a user is free and quick. You do not need a consultant to click Add user or Remove access. Start with the steps above, and if they work, you are finished.
Some situations are more tangled than a menu click. You may not know which Google Account owns the property. You may have lost Administrator access, and Google has a recovery process for when no one has administrative access. A former agency may still be a verified owner. Permissions may be inherited from an account or group, or several properties and linked Google products may be involved. In those cases a specialist can document who controls each property, trim unneeded permissions, protect sensitive metrics, remove old users and tokens, and leave you with access you manage yourself. A good handoff ends with you holding the keys, not with a new dependency.

If you are also setting these accounts up from scratch, the GA4 setup post covers installing the tracking first.
Check your access choices
Pick an answer to begin.
1. You want a designer to see reports for one website without reaching your other properties. Which GA4 level fits?
2. An SEO provider needs to submit sitemaps and inspect pages in Search Console, and you want to keep control. Which permission fits?
3. A former verified owner has been removed from Users and permissions. What should you also do?
Frequently Asked Questions About add user to google analytics 4
Can I give an agency GA4 access without giving ownership?
Yes. GA4 uses Administrator, Editor, Marketer, Analyst and Viewer roles rather than a Search Console style owner. Assign access at the property level when you can.
What GA4 role should an SEO agency receive?
Viewer covers reporting and Analyst covers explorations. Marketer covers audiences, events, key events and attribution settings. Use Editor or Administrator only when the work requires it.
What Search Console permission should an agency receive?
Full user suits active SEO work and Restricted user suits limited reporting. Owner is unnecessary for ordinary agency access.
Can I remove a Search Console owner?
Yes, but a verified owner may have a token that lets them verify again. Review the Unused ownership tokens list and remove the token as well.
Does GA4 access let someone edit my website?
No. GA4 access controls Analytics resources, not your hosting or website editor.
Can GA4 access be limited to one property?
Yes. Add the user at the property level instead of the account level.
Moving Forward
Adding someone to GA4 and Search Console comes down to a few choices. Add people by their own Google Account email, choose the level before the role, give an agency property-level access in GA4 and Full user in Search Console, and keep Owner with your business. When the work ends, remove the person in each tool and clear any verification token they placed.
Done once, this gives you a short list you can read at a glance, with no shared passwords and no surprise users. The next time a vendor asks for access, you will know what to give and how to take it back.
If your accounts are more tangled than a menu click, Web Leveling can sort out who controls what, from lost Administrator access to a former agency's verification token. Our search engine optimization work includes a clean handoff, so you finish holding the keys to your own data. We work with small and medium businesses across the country and overseas. Tell us what your access list looks like, and we will tell you what to change and what to leave alone.
Terms
Access words in this post
Tap a term to see what it means.
Property. In Google Analytics, the container for one website's or app's data, which sits inside an account.
Account level. Access that applies to every property in a Google Analytics account.
Property level. Access that applies only to the one property you choose.
Data restriction. A GA4 setting, No Cost Metrics or No Revenue Metrics, that hides those figures from a user.
Verified owner. A Search Console owner who proved ownership with a verification token on the site.
Delegated owner. A Search Console owner who was given ownership by another owner without a personal token.
Unused ownership tokens. A Search Console list of verification tokens that no longer match a listed owner.




