A business rarely has just one Google account. Email and files may live in Google Workspace, campaigns in Google Ads, website measurement in Google Analytics and Tag Manager, search data in Search Console, local listings in Business Profile, videos in YouTube, products in Merchant Center, and infrastructure in Google Cloud. Each service has its own ownership model, permission levels, billing contacts, and recovery risks.
This checklist shows how to find those assets, confirm that the business controls them, remove unsafe access, and document what should happen when an employee or service provider changes roles. It is written for a business owner or office administrator who understands the company but may not work in Google admin tools every day.
Do not remove an owner, administrator, verification token, billing profile, tag, or linked account until another authorized person has tested equivalent access. A rushed cleanup can interrupt email, break conversion tracking, hide website data, stop product listings, or lock the company out of a channel.
What to collect before you make changes
- A company-controlled Google account that can receive invitations and recovery messages.
- Access to the domain registrar and DNS provider used to verify Workspace and Search Console ownership.
- Recent Google invoices, Ads customer IDs, Analytics property IDs, Tag Manager container IDs, Merchant Center IDs, and Cloud billing account IDs.
- A list of current employees, former employees, agencies, developers, bookkeepers, and marketing contractors who may have access.
- A secure place to record account owners, backup administrators, recovery methods, and the date each access path was tested.
- A change log for every permission removed, role changed, account linked, or verification method replaced.
Keep passwords, backup codes, and recovery tokens out of the audit spreadsheet. Store secrets in the company password manager and record only who controls them and when they were tested.
What a healthy Google ecosystem looks like
- Every Google service is recorded with its account ID, property ID, container ID, profile, channel, project, or billing identifier.
- The business has at least two tested administrators for critical services, using individual accounts instead of a shared password.
- Daily users have the lowest role that still lets them complete their work.
- Former employees, old agencies, obsolete manager accounts, and unused integrations no longer have access.
- Team files that must survive employee turnover are stored in Shared drives when the company edition and workflow support them.
- Recovery methods, 2-Step Verification, billing contacts, ownership tokens, and emergency procedures are documented and tested.
- Marketing reports can be traced from the website action through the tag, Analytics property, Ads conversion, and final business result.
Step 1: Inventory every Google asset and account
Start with a spreadsheet or ticket that the company controls. Create one row for every Google service you find. Record the business purpose, account identifier, primary owner, backup owner, billing contact, connected website or domain, outside users, recovery method, and the date access was last tested.
Where to look
- Google Workspace: Sign in at admin.google.com. Open Directory > Users, Directory > Groups, and Account > Admin roles. Record the primary domain, secondary domains, aliases, super administrators, delegated administrators, and suspended users.
- Google Ads: Open each Ads account and note the 10-digit customer ID shown near the account name. If a manager account is involved, record both the manager ID and every child account ID.
- Google Analytics 4: Use the account and property selector in the upper left. Record the Analytics account, GA4 property ID, web data stream, Measurement ID, linked Ads accounts, and important key events.
- Google Tag Manager: Record the account name, container name, container ID such as GTM-XXXXXXX, environments, and the website or app where the container is installed.
- Search Console: List every Domain property and URL-prefix property. Record the verified owners and the verification method, such as DNS, an HTML file, an HTML tag, Google Analytics, or Tag Manager.
- Business Profile: Search for the business while signed in to Google. Record every location, the primary owner, other owners and managers, the website, phone number, category, and any duplicate or suspended profile.
- YouTube and Merchant Center: Record the channel URL and channel permissions, then record the Merchant Center ID, verified website, product data source, linked Ads account, and Business Profile connection.
- Google Cloud: Open the Cloud console and record organizations, folders, projects, billing accounts, service accounts, API keys, and production resources.
Fast ownership test
- Ask the named owner to sign in without using a shared credential.
- Confirm that the owner can reach the correct account, not a similarly named duplicate.
- Confirm that a second authorized person can manage access or complete the documented recovery path.
- Save the account identifier and a non-sensitive screenshot of the access page in the company documentation.
Pass: the business can identify and reach every important asset with at least one tested backup path. Fail: an asset exists only under a former employee, personal Gmail address, unknown agency, or inaccessible billing profile.
Step 2: Review ownership and access product by product
Google permissions do not work the same way in every product. Review each service in its own administration screen. Remove access only after the replacement owner has accepted the invitation and tested the role.
Google Workspace
- In the Admin console, open Directory > Users. Review active, suspended, archived, and recently deleted accounts.
- Open Account > Admin roles. Check super administrators first, then delegated and custom roles.
- Verify that daily email accounts are not being used as unrestricted super administrator accounts unless there is a documented operational reason.
- Check recovery email, recovery phone, 2-Step Verification enrollment, organizational unit, groups, aliases, and licenses for privileged users.
Expected result: critical administration is available to more than one authorized person, while routine users and applications do not have unnecessary domain-wide privileges.
Google Ads
- Open Admin > Access and security.
- Review the Users list, pending invitations, access levels, authentication methods, allowed email domains, and security requirements.
- Review linked manager accounts. Confirm which manager owns the client account and whether any unrelated manager remains connected.
- Use Change history to investigate unfamiliar budget, campaign, conversion, or user changes before removing evidence.
Expected result: each person has an individual login, administrators are limited, former users are removed, and the business can identify every linked manager account.
Google Analytics 4 and Tag Manager
- In Analytics, open Admin > Account access management and Property access management. Compare direct access with permissions inherited from the account or a user group.
- Use Viewer, Analyst, Marketer, Editor, and Administrator roles according to the work each person performs. Apply cost or revenue restrictions when reporting users do not need financial data.
- In Tag Manager, open Admin > User Management in both the Account and Container columns. Separate Read, Edit, Approve, and Publish rights.
- Confirm that at least two internal administrators can reach the Tag Manager account. Google warns that a container can become unrecoverable when the only administrator disappears.
Expected result: analysts can report without publishing tags, marketers can manage approved events without controlling every user, and the company retains administrative access.
Search Console and Business Profile
- In Search Console, open Settings > Users and permissions. Identify verified owners, delegated owners, full users, and restricted users.
- Open Settings > Ownership verification. Remove unused verification tokens only after another verified owner and method are confirmed.
- For Business Profile, open Business Profile settings > People and access. Confirm the primary owner is controlled by the business and give service providers Manager access when ownership is unnecessary.
Expected result: the company controls website verification and the local listing, while outside users have only the access needed for their assigned work.
YouTube, Merchant Center, and Google Cloud
- In YouTube Studio, open Settings > Permissions. Use channel permissions instead of sharing the Google Account password.
- In Merchant Center, open Access and services > People and access. Check administrators, standard users, read-only users, the verified website owner, and linked applications.
- In Google Cloud, open IAM & Admin > IAM for each organization and project. Review owners, editors, custom roles, service accounts, API keys, and billing access separately.
Expected result: content, commerce, infrastructure, and billing access are assigned through named roles that can be reviewed and revoked without changing a shared password.
Step 3: Fix identity, file ownership, and third-party access
Once ownership is known, correct the risks that can cause a lockout, data loss, or silent tracking failure. Make one controlled change at a time and keep a record of the before state.
Protect privileged accounts
- Require 2-Step Verification for administrators and other high-impact accounts. Prefer phishing-resistant security keys or passkeys where the organization can support them.
- Keep emergency recovery information in a controlled company system. Do not leave the only recovery phone or email with one employee.
- Use delegated or custom Workspace admin roles for help desk, groups, devices, reports, and user management instead of granting super administrator access by default.
Review third-party applications
- In the Workspace Admin console, open Security > Access and data control > API controls.
- Review configured apps, accessed apps, pending requests, requested Google services, OAuth scopes, verification status, and the number of users.
- Classify each app as trusted, limited, restricted to specific Google data, or blocked. Document the business owner and renewal date for approved high-risk access.
- Remove obsolete browser extensions, mobile app connections, automation tools, and service accounts only after confirming that no production workflow depends on them.
Move durable team files out of personal ownership
Use Shared drives for department, project, client, template, and operational files that must remain with the company. Files in a Shared drive belong to the organization rather than an individual user. Before moving a folder, review external sharing and inherited permissions because a move can change who can see the contents.
Build offboarding around the whole ecosystem
- Suspend the Workspace user according to the company offboarding procedure.
- Transfer or preserve My Drive files, calendars, email, contacts, and business records according to legal and operational requirements.
- Remove the person from Ads, Analytics, Tag Manager, Search Console, Business Profile, YouTube, Merchant Center, Cloud projects, billing profiles, and third-party applications.
- Rotate credentials or keys only when the person knew a shared secret or controlled an integration that cannot use individual access.
- Test customer forms, conversion tracking, scheduled reports, product feeds, automated workflows, and website verification after the change.
Step 4: Complete the cleanup without breaking business systems
A good cleanup produces evidence, not just a shorter user list. Use this 30-day sequence to make changes without losing ownership, reporting, or business continuity.
Days 1 and 2: Capture the current state
- Build the asset inventory and save all account identifiers.
- Export user and app lists where the product supports it.
- Record active campaigns, key events, tags, verification methods, billing contacts, and critical automations.
Days 3 through 5: Establish business ownership
- Add and test internal backup administrators.
- Move primary ownership away from former employees and personal accounts where the product permits it.
- Confirm that the company controls the domain, DNS, website, payment methods, and recovery channels.
Days 6 through 10: Reduce unnecessary access
- Remove stale invitations and accounts that no longer have a valid business purpose.
- Downgrade excessive roles before removing access when a person still needs the product.
- Review third-party OAuth apps, manager accounts, service accounts, API keys, and external sharing.
Days 11 through 20: Validate data and workflows
- Submit a real test form, phone call, purchase, or other lead action and trace it through Tag Manager, GA4, Ads, and the destination system.
- Check that Search Console remains verified and that Business Profile, Merchant Center, and YouTube connections still work.
- Ask a novice user to follow the recovery and support documentation without verbal coaching. Correct every step that depends on tribal knowledge.
Days 21 through 30: Close the review
- Obtain business approval for remaining owners, administrators, exceptions, and outside access.
- Schedule quarterly access reviews and immediate reviews after departures, agency changes, acquisitions, domain changes, or security incidents.
- Assign a named person to investigate Google alerts, billing failures, suspended listings, tracking drops, and verification warnings.
Completion standard: the business can identify every critical Google asset, reach it with two authorized paths, explain every privileged user, trace important marketing data, and recover from a staff or service provider change without losing control.
Official product documentation and ALLMSP resources
- Google Workspace administrator privilege definitions. Official definitions for delegated administrator privileges and the controls available to each role, with the planning steps on this page applying it to the work needed to fix google account ownership, recovery, and data connections.
- Assign specific Google Workspace administrator roles. Official steps for assigning prebuilt or custom roles to users and groups with appropriate scope, with the configuration checks here applied to the controls needed to fix google account ownership, recovery, and data connections.
Frequently Asked Questions
Where should a small business begin a Google account audit?
Begin with an inventory. List every Workspace domain, Ads customer ID, GA4 property, Tag Manager container, Search Console property, Business Profile, YouTube channel, Merchant Center account, and Cloud project. For each asset, record the primary owner, backup owner, billing contact, recovery method, and last successful access test.
Should company Google assets be owned by a personal Gmail account?
A personal Gmail account can create many Google assets, but it creates continuity risk when the business cannot control that account. Critical assets should have tested company-controlled administrators and recovery methods. Move ownership where the product supports it, and never remove the original owner until replacement access has been verified.
How many administrators should a critical Google service have?
Critical services should normally have at least two active, authorized administrators so one unavailable person does not lock out the business. Keep the group small, use individual accounts, require strong 2-Step Verification, and review the administrator list after every staffing or provider change.
Is a Google Workspace administrator automatically an administrator in Ads or Analytics?
No. Google Workspace, Ads, Analytics, Tag Manager, Search Console, Business Profile, YouTube, Merchant Center, and Cloud have separate permission systems. A Workspace super administrator may still have no access to an Ads account, Analytics property, or YouTube channel unless access was granted inside that product.
How can we find who owns our website in Google Search Console?
Open the property in Search Console and go to Settings, then Users and permissions. Review verified owners and delegated owners. Then open Ownership verification to identify DNS records, HTML files, tags, Analytics, or Tag Manager tokens that can restore ownership. Do not remove an old token until another verified owner and method are tested.
How should an agency or contractor access Google marketing accounts?
Give each person or approved manager account its own access rather than sharing a password. Use the lowest role that supports the assigned work. The business should retain primary ownership, know which manager accounts are linked, and remove access promptly when the engagement ends.
What Google access must be removed when an employee leaves?
Review more than the Workspace login. Remove or transfer access in Ads, Analytics, Tag Manager, Search Console, Business Profile, YouTube, Merchant Center, Cloud projects, billing profiles, Shared drives, OAuth applications, service accounts, API keys, and any automation that used the person’s credentials.
What should be checked during a quarterly Google access review?
Check administrators, inactive users, pending invitations, outside domains, manager accounts, recovery methods, 2-Step Verification, OAuth applications, service accounts, API keys, billing contacts, ownership verification, Shared drive membership, and whether important conversions and reports still produce trustworthy data.
Can account cleanup break Google Ads or Analytics tracking?
Yes. Removing a Tag Manager publisher, deleting a service account, changing a website verification token, unlinking an Ads account, or removing the only owner can interrupt data and access. Capture the current state, add replacement access, test a real conversion, and maintain a rollback plan before removing anything.
Can ALLMSP complete the entire Google ecosystem review in house?
Yes. ALLMSP can inventory accounts, recover ownership, review permissions, secure administrators, clean up third-party access, organize files, validate tags and conversions, document procedures, train users, and provide ongoing support for businesses in Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and throughout Georgia.
























































