Granting GA4 Access — Property-Level Editor, Not Account Admin
Imagefactory · Published 2026-09-23
GA4 grants access at account level or property level. An agency belongs at property level — anything granted at account level is inherited by every property under that account. Run several brands in one account and an account-level grant hands over all of them at once.
The five roles
| Role | What it allows |
|---|---|
| Administrator | Full management of Analytics, including user management |
| Editor | Every property setting. No user management |
| Marketer | Create, edit and delete audiences, events and key events; attribution settings |
| Analyst | Create and share explorations |
| Viewer | See settings and data; change the data shown in reports |
Editor is the right default for an agency. Conversion events, audiences and data stream settings are the job, so anything lower blocks the work. Administrator, by contrast, can add and remove users and touch the property itself — the advertiser loses control.
Drop to Marketer or Analyst when the scope is audiences only, or reading reports only.
Two data restrictions
Applied per user, independent of role:
- No access to cost metrics
- No access to revenue metrics
Both hide those metrics across reports, explorations and insights. Useful when margins are not shared — but do not restrict revenue for an agency running to ROAS, or they cannot judge performance at all.
The procedure (property level)
Adding users requires the Administrator role on the account or the property, and removing users requires account-level Administrator. Access applies as soon as the user is added; there is no acceptance step. For the same reason, an agency given Editor cannot add its own contractors.
- Open analytics.google.com
- Admin (the gear, bottom left)
- In the Property section, Access Management
- Top right + → Add users
- Enter the Google account email
- Select Editor (tick a data restriction if needed)
- Add (top right)
To grant at account level instead — when every property in the account is in scope — use Access Management in the Account section at step 3. The rest is identical.
Where a property-level role is higher than the inherited account-level one, the property-level role applies.
Revoking
Admin → Property → Access Management → remove the person. If you also granted at account level, remove them in both places — otherwise the inherited access remains.
See it alongside Meta and GTM in the agency handover guide.