Analytics Mates

How to Grant Analytics Mates Access to Your Marketing and Analytics Platforms

By Gary Spagnoli
Person in an orange shirt looks at a dashboard with a user icon and a plus sign.

To review and fix your measurement, we need access to the platforms that hold the signal — not only Google Analytics 4.

Use the emails we sent you. For Google properties that is typically data@analyticsmates.com plus any named teammates. Bing Webmaster Tools and Microsoft Advertising need a Microsoft account. Use the address we sent for those. A Google login will not work there.

You already have to be able to manage users in each platform. If you cannot add a user, we cannot do this from a Viewer seat.

If you are unsure which permission to pick, use the recommended level in that section and tell us. We would rather have the access we need than guess.

Completing one section does not grant the others. GA4, GTM, Google Tag, Search Console, and the ad platforms are separate invitations.

Jump to a platform: GA4 · GTM · Google Tag · Search Console · Bing Webmaster Tools · Microsoft Advertising · Google Ads · Meta

Google Analytics 4 (GA4)

Property-level access is the usual choice. It limits us to the property we are supporting. Account-level access applies to every property in that Analytics account. Do not grant account-level unless we asked for it.

  1. Sign in to Google Analytics and select the correct account and GA4 property.

  2. Click Admin in the lower-left corner.

Google Analytics with the Admin gear highlighted in the left navigation.

  1. Under Property, click Property access management. Use Account access management only if we should see every property in the account.

Google Analytics Admin with Property access management highlighted.

  1. Click the + button in the upper-right, then Add users.

Property access management with the add-user control highlighted.

  1. Enter the Analytics Mates email addresses we sent. Leave Notify new users by email selected.

Add roles and data restrictions in GA4, with email addresses and role options.

  1. Assign the role.

Recommended access: Editor at the property level for implementation and troubleshooting. Grant Administrator only when we also need to manage users, destinations, or other admin settings — and only after we have confirmed that with you. Do not apply revenue or cost-metric restrictions unless the project requires them.

  1. Review the emails and permissions, then click Add.

GA4 add-user confirmation with the Add button highlighted.

Google Tag Manager (GTM)

GTM is where the tracking actually lives. Most measurement issues originate here, not inside GA4. GTM permissions are separate from GA4.

  1. Sign in to Google Tag Manager and open the correct account and web container.

Google Tag Manager account list with the website container selected.

  1. Click Admin.

Google Tag Manager with Admin highlighted.

  1. In the Container column, click User Management. That limits the invite to this container. Use User Management in the Account column only if we need the whole GTM account.

GTM Admin with Container User Management highlighted.

  1. Click +, then Add users.

GTM user management with Add users highlighted.

  1. Enter the Analytics Mates email addresses we sent.

  2. Assign container permissions.

Recommended access: Publish when we are implementing, testing, and publishing. Read when the engagement is an audit only. If your team must approve every release, use Edit or Approve and tell us so we know we cannot ship.

GTM invite screen with container permission options.

  1. Click Invite. The user shows as pending until we accept.

Google Tag

Even after GA4 and GTM, Google Tag access is often missed. Some tag settings stay locked without it.

The Google tag is the measurement tag on your GA4 web data stream. Its user list is related to GA4, but it is not always the same list.

  1. In the correct GA4 property, open Admin.

  2. Under Data collection and modification, click Data streams.

GA4 Admin with Data streams highlighted.

  1. Click the web data stream for the website.

GA4 Data streams list with the website stream selected.

  1. Under Google tag, click Configure tag settings.

GA4 web stream with Configure tag settings highlighted.

  1. At the top of the Google tag screen, click Admin.

Google tag settings with the Admin tab highlighted.

  1. Click Choose who can administer this tag or Choose who can edit this tag’s settings.

Google tag Admin with the two access options: administer this tag, and edit this tag’s settings.

  1. If direct invitations are available, add the emails we sent.

Recommended access: Admin when we need full control of the tag. Edit / Publish when we only need to change tag configuration.

If you do not see a direct-invite option: a Google tag with a single destination (one GA4 web stream) inherits access from the GA4 property role. In that case there is nothing extra to invite.

  • GA4 Administrator inherits Google tag Administrator and Publish.
  • GA4 Editor inherits User and Publish.
  • GA4 Analyst or Viewer inherits Read.

Direct user adds show up when the Google tag has multiple destinations, and they require Google tag Administrator access.

Google Search Console

Search Console access is per property. Add us on the property that matches the site we are working on — the domain property if you have one, otherwise the URL-prefix property. You must be an Owner to add another user.

  1. Sign in to Google Search Console and select the correct property.

  2. Click Settings at the bottom of the left navigation.

Google Search Console with Settings highlighted.

  1. Under General settings, click Users and permissions.

Search Console Settings with Users and permissions highlighted.

  1. Click Add user.

Search Console Users and permissions with Add user highlighted.

  1. Enter the Analytics Mates Google email we sent.

Recommended access: Full for SEO analysis, URL Inspection, sitemap work, and indexing. Keep your organization as the verified owner. Grant Owner only if we must manage users or ownership, and only after we have confirmed that. Restricted is reporting-only — not enough for an audit.

  1. Click Add.

Search Console add-user dialog with permission level and Add highlighted.

Bing Webmaster Tools

Bing Webmaster Tools is a separate product from Google Search Console. It needs a Microsoft account.

  1. Sign in at bing.com/webmasters and select the correct website.

  2. Open Settings, then User Management. Depending on the UI, User Management may also sit in the main navigation.

Bing Webmaster Tools with User Management highlighted.

  1. Click Add User.

Bing Webmaster Tools Add User dialog.

  1. Enter the Microsoft account email we sent. Select the website or websites we should see.

Recommended access: Read/Write for ongoing SEO support and diagnostics (sitemaps, site-level tools). Read Only for a reporting-only engagement. Administrator only when we must manage other users or finish administrative setup.

  1. Click Add or Save. Tell us once it is done so we can confirm the correct site appears.

Bing Webmaster Tools user list after the invitation.

Microsoft Advertising

Microsoft Advertising (formerly Bing Ads) is a separate access list from Bing Webmaster Tools. Grant only the advertiser accounts in the engagement.

  1. Sign in at ads.microsoft.com and open the correct manager or advertiser account.

  2. From the left navigation, open SettingsUser management.

Microsoft Advertising with User management highlighted.

  1. Select Invite user.

Microsoft Advertising Invite user screen.

  1. Enter the first name, last name, and Microsoft email we sent.

  2. Choose the account scope: all accounts under the manager, or only the advertiser accounts in the project.

Recommended access: Advertiser Campaign Manager for day-to-day work in selected accounts, or Viewer for an audit. If we must configure UET tags, conversion goals, account linking, or shared assets, tell us before you grant Standard User or Super Admin — those are the roles that can change tracking.

  1. Select Send invitation. Access is live after we accept.

Alternative: we may send a Microsoft Advertising manager-account number and ask you to link the advertiser account instead of inviting a person. Your Super Admin has to accept that link. You keep ownership of the advertiser account.

Add us to the customer account that runs the campaigns, not only a manager account we cannot drill into.

There is no screenshot pack for this section. The path is: Admin → Access and security.

  1. In Google Ads, go to AdminAccess and security.
  2. Invite the Google email we sent.
  3. Grant Admin, or Standard if Admin is not allowed — tell us, so we know the conversion-action limitation.
  4. If spend or conversions live under a manager (MCC), add us there too so we can switch accounts.

Recommended access: Admin, or Standard with access to conversion actions and Data Manager. Viewer is not enough if we are diagnosing conversion imports or linking.

If we are implementing offline conversion import, we also need permission to create or edit conversion actions and to see Data Manager. UI access to campaigns alone is not the same thing.

Meta Business Manager

Meta Business Manager is now a Business Portfolio in Meta Business Suite. Pixel events and Conversions API events land on a dataset. Add us as a partner so you keep ownership and we only get the assets in the engagement.

Before you start: we will send our Business Portfolio ID and which assets we need. You need full control of your company’s Business Portfolio to add a partner.

  1. Go to business.facebook.com and select the correct Business Portfolio.

  2. Open All tools, then Business settings (you may need More business settings).

Meta All tools with Business settings highlighted.

  1. Under Users, click Partners, then Add.

Meta Business settings with Partners highlighted.

  1. Select Give a partner access to your assets.

Meta partner flow with Give a partner access to your assets selected.

  1. Enter the Analytics Mates Business Portfolio ID, then Next.

Meta partner invite with the Business Portfolio ID field.

  1. Select only the assets in the project. Depending on scope, that may include:
  • Facebook Page
  • Instagram account
  • Ad account
  • Dataset / Meta Pixel (confirm the ID matches the live campaigns)
  • Catalog
  • Verified domain
  1. Assign permissions on each asset.

Recommended access: partial access on the required assets. For measurement work that usually means viewing Page/Instagram insights, viewing ad performance, and viewing or managing the Pixel / dataset (Events Manager diagnostics, including Event Match Quality). Grant campaign management only if it is in the project. Grant full control only when we must manage permissions or integrations.

  1. Save. We should appear under Partners. Email us when it is done so we can confirm the ad account and the dataset ID match the live campaigns.

If Events Manager sits under a different Business Portfolio than the ad account, add us there too and send both IDs.


After the invitations go out, tell us which access levels you granted. We will confirm we can open:

  • The correct GA4 property
  • The correct GTM account and web container
  • The Google tag on that site’s GA4 data stream
  • The correct Search Console property
  • The correct Bing Webmaster Tools site
  • The Microsoft Advertising account (if in scope)
  • The Google Ads customer account (if in scope)
  • The Meta Business Portfolio, ad account, and dataset (if in scope)

If something is missing, we will tell you which permission to change. You can remove access later from the same user-management, account-link, or partner screens.

We start with the properties you granted. We do not go looking for accounts you did not invite us to.

If you would rather walk through this on a call, book a consultation.

Work with us

Need this done for your property?

Analytics Mates handles GA4 setup, GTM implementation, Looker Studio dashboards, and the ongoing measurement operations that agencies and in-house teams don't have bandwidth for.