ALLMSP Blog

Who Controls Your Google Accounts? A Practical Access Audit

Audit owners, administrators, outside users, recovery methods, linked accounts, service accounts, and business continuity across the Google account ecosystem.

A security auditor and business owner reviewing administrators, recovery methods, outside users, service accounts, and dormant Google access

A Google account access review must examine each product separately. Workspace super administrator status does not automatically grant access to Ads, Analytics, Tag Manager, Search Console, Business Profile, YouTube, Merchant Center, or Cloud. The review should prove who can act, why that authority is needed, how the account is recovered, and whether linked data still reaches the right destination.

Collect evidence before removing access. An unfamiliar email address may control DNS verification, a production tag, a product feed, an automated report, or emergency recovery. Add and test replacement ownership first, then remove obsolete access during a documented change window. Never treat a display name alone as proof that two similar assets are the same account.

Our in-house team delivers Google business accounts access, ownership, and security review for businesses around Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and the rest of Georgia, while coordinating the applications, identities, devices, data, security controls, and employees affected by the work.

Evidence to collect before changing Google account ecosystem

A useful review produces a product-by-product record of owners, administrators, outside users, pending invitations, linked manager accounts, recovery methods, billing contacts, automation identities, and unresolved exceptions. It confirms that the business can maintain advertising, reporting, website verification, listings, video, commerce, files, and cloud systems after a staffing or provider change.

  • The asset register with exact IDs, URLs, business purpose, primary owner, backup owner, billing contact, and last access test.
  • Workspace administrator roles, 2-Step Verification status, recovery methods, inactive accounts, groups, organizational units, and Shared drive managers.
  • Ads, GA4, Tag Manager, Search Console, Business Profile, YouTube, and Merchant Center users, owners, managers, invitations, and links.
  • Cloud IAM bindings, service accounts, keys, OAuth clients, API credentials, Apps Script owners, and billing roles.
  • Real delivery, conversion, reporting, indexing, location, product, and recovery tests with dated results.
  • Business approval for retained outside access, exceptions, remediation owners, deadlines, and the next quarterly review.

Confirm the asset register and identity controls

Asset-register completeness

What to check: Compare all visible organizations, domains, customer IDs, properties, containers, website properties, location groups, channels, merchant accounts, Cloud projects, and billing accounts with the register. Record duplicate names, unknown assets, and missing identifiers.

What to do next: Research ownership and business use before adding or deleting anything. Mark abandoned assets for a separate retention and closure decision after access is secured.

Workspace administrators and recovery

What to check: Capture each administrator role, last activity, employment status, 2-Step Verification, recovery ownership, emergency access, and security alert recipient. Identify shared accounts and daily-use super administrators.

What to do next: Add and test named company administrators, reduce routine privileges, protect emergency accounts, correct recovery dependencies, and investigate unexpected privileged activity.

Users, groups, files, and offboarding

What to check: Review inactive and suspended users, aliases, groups, outside members, Shared drive managers, externally shared files, transfer status, forwarding, delegated access, and automation owned by departed users.

What to do next: Transfer durable work, correct group membership, remove obsolete external access, preserve required records, and verify that offboarding covers product access outside Workspace.

Review marketing, website, and public-presence access

Google Ads ownership and manager access

What to check: Record users, roles, manager links, pending invitations, billing ownership, payment access, linked Analytics and Merchant Center accounts, conversion creators, and significant changes. Confirm the customer ID against invoices and active campaigns.

What to do next: Retain company administration, approve outside manager access explicitly, remove stale invitations and users after testing, and correct billing or conversion ownership that depends on one person.

GA4 and Tag Manager authority

What to check: Capture inherited and direct Analytics roles, data restrictions, property links, Tag Manager account and container permissions, publish authority, active workspaces, recent versions, and agencies or developers with access.

What to do next: Use narrower roles, preserve two company publishers, close stale workspaces, document production containers, and test conversions before removing a user or integration.

Search Console ownership and verification

What to check: Record verified owners, delegated owners, full and restricted users, DNS records, HTML files, tags, Analytics or Tag Manager tokens, associations, sitemap access, and the person who controls DNS and the website.

What to do next: Add a durable company-controlled owner and verification method, test access, then retire stale tokens and users carefully so the property remains verified.

Business Profile access and public responsibilities

What to check: Record primary owners, owners, managers, location groups, pending invitations, connected Ads accounts, notification recipients, phone and website accuracy, suspension warnings, and who answers reviews and edits public details.

What to do next: Preserve company primary ownership, add backup access, correct stale providers and notifications, and assign public-response responsibility with an escalation path.

Inspect automation, billing, and recovery dependencies

YouTube and Merchant Center access

What to check: Capture channel or Brand Account ownership, roles, recovery, linked Ads accounts, merchant administrators, feed owners, website claims, payment or shipping contacts, and unresolved product issues.

What to do next: Add tested company owners, separate publishing from administration, document feeds and linked accounts, and remove obsolete access after channel and product continuity tests pass.

Cloud IAM, service accounts, OAuth, and APIs

What to check: Record direct and inherited roles, basic roles, inactive principals, external domains, service accounts, keys, impersonation, OAuth clients, API keys, allowed redirect URIs, application owners, project ownership, and billing roles.

What to do next: Remove unused credentials, replace broad roles, prefer keyless methods where supported, separate billing authority, and test each production dependency before revocation.

Recovery, billing, alerts, and continuity test

What to check: Verify recovery phones and emails, security keys, backup codes, billing contacts, payment status, alert recipients, support access, emergency administrators, rollback records, and last successful continuity test.

What to do next: Correct personal dependencies, add authorized backups, protect recovery material, update billing and alerts, and run the failed-administrator exercise until the written plan works unaided.

Prioritize findings without interrupting operations

Treat loss of company ownership, compromised administrators, unexpected Cloud credentials, broken billing, and unmanaged access to customer or financial data as urgent. Next address single-person dependencies, stale outside access, broken measurement, and unverified recovery. Duplicate assets and minor naming cleanup can follow after control and continuity are proven.

Priority 1: Control or security failure

Use this level when the company lacks an owner, a privileged account may be compromised, a production credential is unexplained, billing threatens service continuity, or sensitive data is exposed.

Priority 2: Single point of failure or unreliable data

Use this level for one-person ownership, personal recovery dependencies, stale vendors, broken conversions, unclear verification, unsupported automation, and missing recovery tests.

Priority 3: Governance and account hygiene

Use this level for pending invitations, low-risk inactive access, duplicate names, old workspaces, documentation gaps, and scheduled cleanup after critical controls are stable.

Official product documentation and ALLMSP resources

  • Google Workspace administrator privilege definitions. Official definitions for delegated administrator privileges and the controls available to each role, with the planning steps on this page applying it to the work needed to identify who controls each Google account and complete a practical access audit.
  • Assign specific Google Workspace administrator roles. Official steps for assigning prebuilt or custom roles to users and groups with appropriate scope, with the configuration checks here applied to the controls needed to identify who controls each Google account and complete a practical access audit.

Frequently Asked Questions

How can a business verify that its Google account inventory is complete?

Review the following systems and records: Every Google product switcher plus the current account register. Compare all visible organizations, domains, customer IDs, properties, containers, website properties, location groups, channels, merchant accounts, Cloud projects, and billing accounts with the register. Record duplicate names, unknown assets, and missing identifiers. If evidence is incomplete or a control fails, research ownership and business use before adding or deleting anything. Mark abandoned assets for a separate retention and closure decision after access is secured. Retest and document closure.

What should be reviewed for Google Workspace administrators?

Review the following systems and records: Admin console > Account > Admin roles, Directory > Users, Security, and Reporting. Capture each administrator role, last activity, employment status, 2-Step Verification, recovery ownership, emergency access, and security alert recipient. Identify shared accounts and daily-use super administrators. If evidence is incomplete or a control fails, add and test named company administrators, reduce routine privileges, protect emergency accounts, correct recovery dependencies, and investigate unexpected privileged activity. Retest and document closure.

What Google access can remain after an employee is suspended?

Review the following systems and records: Admin console > Directory, Apps > Google Workspace > Drive and Docs, Shared drives, and audit reports. Review inactive and suspended users, aliases, groups, outside members, Shared drive managers, externally shared files, transfer status, forwarding, delegated access, and automation owned by departed users. If evidence is incomplete or a control fails, transfer durable work, correct group membership, remove obsolete external access, preserve required records, and verify that offboarding covers product access outside Workspace. Retest and document closure.

What should be included in a Google Ads access review?

Review the following systems and records: Google Ads > Admin > Access and security, Managers, Billing, Linked accounts, Conversions, and Change history. Record users, roles, manager links, pending invitations, billing ownership, payment access, linked Analytics and Merchant Center accounts, conversion creators, and significant changes. Confirm the customer ID against invoices and active campaigns. If evidence is incomplete or a control fails, retain company administration, approve outside manager access explicitly, remove stale invitations and users after testing, and correct billing or conversion ownership that depends on one person. Retest and document closure.

How are Google Analytics and Tag Manager permissions reviewed together?

Review the following systems and records: Google Analytics > Admin > Account and Property access management, then Tag Manager > Admin > User Management, Versions, and Workspaces. Capture inherited and direct Analytics roles, data restrictions, property links, Tag Manager account and container permissions, publish authority, active workspaces, recent versions, and agencies or developers with access. If evidence is incomplete or a control fails, use narrower roles, preserve two company publishers, close stale workspaces, document production containers, and test conversions before removing a user or integration. Retest and document closure.

What can cause a business to lose Google Search Console access?

Review the following systems and records: Search Console > Settings > Users and permissions, Ownership verification, Associations, and Change of address. Record verified owners, delegated owners, full and restricted users, DNS records, HTML files, tags, Analytics or Tag Manager tokens, associations, sitemap access, and the person who controls DNS and the website. If evidence is incomplete or a control fails, add a durable company-controlled owner and verification method, test access, then retire stale tokens and users carefully so the property remains verified. Retest and document closure.

How should Google Business Profile owners and managers be audited?

For an ecosystem-wide access audit, inspect Business Profile settings > People and access plus location and notification settings. Record primary owners, owners, managers, location groups, pending invitations, connected Ads accounts, notification recipients, phone and website accuracy, suspension warnings, and who answers reviews and edits public details. If evidence is incomplete or a control fails, preserve company primary ownership, add backup access, correct stale providers and notifications, and assign public-response responsibility with an escalation path. Retest and document closure.

What access should be reviewed for YouTube and Merchant Center?

Review the following systems and records: YouTube Studio > Settings > Permissions and Merchant Center > Settings > People and access, Business information, Data sources, and Linked accounts. Capture channel or Brand Account ownership, roles, recovery, linked Ads accounts, merchant administrators, feed owners, website claims, payment or shipping contacts, and unresolved product issues. If evidence is incomplete or a control fails, add tested company owners, separate publishing from administration, document feeds and linked accounts, and remove obsolete access after channel and product continuity tests pass. Retest and document closure.

Which automation identities belong in a Google access review?

Review the following systems and records: Cloud console > IAM & Admin, Service Accounts, APIs & Services > Credentials, OAuth consent, Audit Logs, and Billing. Record direct and inherited roles, basic roles, inactive principals, external domains, service accounts, keys, impersonation, OAuth clients, API keys, allowed redirect URIs, application owners, project ownership, and billing roles. If evidence is incomplete or a control fails, remove unused credentials, replace broad roles, prefer keyless methods where supported, separate billing authority, and test each production dependency before revocation. Retest and document closure.

How should recovery and billing be tested during a Google account review?

Review the following systems and records: Product security and notification settings, billing profiles, password manager, help desk, and documented recovery plan. Verify recovery phones and emails, security keys, backup codes, billing contacts, payment status, alert recipients, support access, emergency administrators, rollback records, and last successful continuity test. If evidence is incomplete or a control fails, correct personal dependencies, add authorized backups, protect recovery material, update billing and alerts, and run the failed-administrator exercise until the written plan works unaided. Retest and document closure.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Latest Articles