Guides

Granting Google Tag Manager Access — Account vs. Container

Imagefactory · Published 2026-09-23

GTM permissions come in two layers — account and container — set separately. Granting one and not the other is why "I gave them access but they cannot see it" keeps happening.

The two layers

Account permissions — only two.

LevelWhat it allows
UserSee basic account information
AdministratorCreate containers, change user permissions

Container permissions — five, each including the ones below it.

LevelWhat it allows
No accessThe container is not listed
ReadView tags, triggers and variables
EditCreate and change workspaces. No versions, no publishing
ApproveCreate and change versions and workspaces. No publishing
PublishCreate, change and publish versions

What an agency needs — account User, container Publish

Leave the account level at User. Administrator exists to create containers and change who has access — neither is tag work. Guides that tell you to tick Administrator are handing the agency the ability to add accounts the advertiser never sees.

The container level has to be Publish. Edit builds workspaces but cannot create or publish a version, so nothing goes live; Approve still cannot publish. For an agency that ships its own conversion tags, Publish is the floor.

If the advertiser wants to review before anything goes live, leave the agency on Approve and publish yourself — at the cost of tying tag releases to the advertiser's schedule.

The procedure

  1. Open tagmanager.google.com and select the account
  2. The Admin tab at the top
  3. In the account column, User Management
  4. Top right + → Add users
  5. Enter the Google account email
  6. Leave account permissions on User
  7. Container permissions → Set all (or pick specific containers) → tick Publish → Done
  8. Invite

With several containers, grant only the ones in scope — "Set all" applies the same level to every container in the account.

The invitation goes to their Google account and must be accepted.

Revoking

Same path — Admin → User Management → remove the person. Then check each container's User Management to confirm no container permission is left.

See it alongside Meta and GA4 in the agency handover guide.