ALLMSP Blog

Audit Google Ads Users, Manager Accounts, and Conversion Ownership

Review Google Ads, GA4, Tag Manager, call tracking, CRM, consent, and website access so lead data remains accurate and company controlled.

A business owner and marketing administrator auditing Google Ads users, manager accounts, billing ownership, and conversion access

A lead tracking access review must cover more than Google Ads users. A person who can publish Tag Manager, edit website forms, change GA4 events, replace call tracking, alter consent behavior, or map CRM imports can change what Ads considers successful. The review should identify each control point and confirm that the business owns it.

Do not remove an agency, developer, Tag Manager publisher, Analytics administrator, website administrator, or CRM integration until replacement access and the production workflow have been tested. Preserve current container versions, conversion settings, linked accounts, field mappings, and working test evidence before changing authority.

Businesses can use ALLMSP for Google Ads measurement and conversion tracking for organizations in Lawrenceville and Suwanee, throughout Gwinnett County and Metro Atlanta, and across Georgia, with local assistance available when device, network, office, or employee work needs an on-site component.

Evidence to collect before changing Google Ads lead tracking

A useful review maps the Ads customer ID, GA4 property, Tag Manager container, Google tag, website, call system, consent platform, CRM, and import connection. It names owners, publishers, outside users, authentication expectations, data policies, and the last real lead test for each component.

  • Google Ads users, manager accounts, security requirements, conversion actions, and change history.
  • GA4 account and property roles, data restrictions, linked Ads accounts, events, and key events.
  • Tag Manager account and container permissions with Read, Edit, Approve, and Publish rights.
  • Website, form, call tracking, booking, chat, consent, DNS, and hosting administration.
  • CRM users, field mappings, import connections, service accounts, API credentials, and ownership.
  • A recent end-to-end test that connects the advertising interaction to a qualified business outcome.

Map ownership across every measurement system

Google Ads users and manager accounts

What to check: Record users, pending invitations, access levels, authentication methods, allowed domains, security settings, and linked manager accounts. Confirm the business controls the child account and recognizes every manager ID.

What to do next: Remove stale access after a tested internal administrator exists. Downgrade users who need reporting or campaign work but do not need account administration.

Conversion action authority

What to check: List people and manager accounts that created or changed conversion actions, values, primary status, counting, attribution, lookback windows, and imports. Compare changes with approved tickets or campaign decisions.

What to do next: Restore incorrect settings from evidence, limit administrator access, and retest conversions before automated bidding continues to rely on them.

GA4 account and property access

What to check: Capture direct and inherited users, groups, Administrator, Editor, Marketer, Analyst, and Viewer roles, plus cost and revenue restrictions. Confirm the reviewed property and stream IDs match the website.

What to do next: Remove stale access, apply the least role needed, and keep at least two tested internal administrators for the account and critical property.

Review who can change tags and conversion definitions

Tag Manager publishers

What to check: Record account and container permissions separately. Identify who can Read, Edit, Approve, and Publish, plus service accounts, environments, workspaces, and recent versions published by each user.

What to do next: Reserve Publish for trained, accountable users. Keep two internal administrators and remove external publishers only after a working version and replacement access are secured.

Website and form administration

What to check: List people who can add scripts, replace forms, alter confirmation states, change redirects, modify phone numbers, or publish landing pages. Record MFA, account owner, and change history where available.

What to do next: Remove shared accounts, enforce individual access, narrow roles, and connect production measurement changes to a ticket and post-publish test.

Call, booking, and chat platform access

What to check: Record administrators, agencies, number owners, call routing, recording rules, webhook or API access, booking calendars, chat destinations, and who can change conversion definitions.

What to do next: Transfer billing and number ownership to the business, remove stale users, rotate exposed credentials, and retest live calls or bookings after changes.

Consent platform authority

What to check: Identify who can change categories, default states, region behavior, Google consent signals, privacy links, and tag blocking. Compare production behavior with the approved policy.

What to do next: Limit configuration access, document legal ownership, and test accepted and declined states after every banner or tag change.

Inspect links, credentials, and data flow

CRM and offline import access

What to check: Record who can alter lifecycle stages, lead values, source fields, imports, matching data, credentials, and schedules. Identify personal accounts or agency-owned connectors.

What to do next: Move ownership to company-controlled accounts, use least privilege, rotate credentials when needed, and validate one controlled qualified lead after each access change.

Linked products and duplicate sources

What to check: List every connected product, account ID, owner, data shared, and conversion or audience dependency. Identify duplicate GA4 properties, old manager accounts, and imports from overlapping sources.

What to do next: Unlink only after confirming campaign, audience, product, and conversion dependencies. Keep one documented authoritative source for each primary business outcome.

Recovery and change evidence

What to check: Confirm two internal recovery paths, preserved container versions, website rollback, account IDs, billing control, and an end-to-end lead test. Record what happens if the agency or developer is unavailable.

What to do next: Create missing backup access, export or document configurations, and run the recovery procedure before removing the current owner.

Rank access findings by revenue and data risk

Treat unknown account ownership, unauthorized publishing, exposed credentials, broken consent, and conversion changes affecting automated bidding as urgent. Treat one-person recovery, agency-owned call numbers, and undocumented imports as continuity risks. Reporting-only access cleanup can follow once production control is protected.

Priority 1: Active measurement or access compromise

Use this level for unknown administrators, malicious or unexplained tags, exposed CRM credentials, consent behavior that contradicts policy, or primary conversion changes already influencing budget and bidding.

Priority 2: Ownership and continuity risk

Use this level when the business depends on one publisher, an agency-owned account or phone number, a personal integration, an untested import, or a property that cannot be recovered internally.

Priority 3: Permission and documentation debt

Use this level for excessive reporting roles, stale viewers, unclear naming, missing review dates, and incomplete account maps after production and recovery risks are controlled.

Official product documentation and ALLMSP resources

  • Google Ads conversion measurement options. Official guidance for choosing website, app, phone, and offline conversion actions and reporting goals, with the planning steps on this page applying it to the work needed to audit Google Ads users, manager accounts, and conversion ownership.
  • Manage Google Ads manager-account users and access. Official steps for reviewing users, invitations, access levels, account hierarchy, and administrative ownership, with the configuration checks here applied to the controls needed to audit Google Ads users, manager accounts, and conversion ownership.
  • Set up a Google Ads campaign for success. Official recommendations for conversion tracking, bidding, targeting, campaign organization, ads, and assets, with the review process on this page using that guidance to help the organization audit Google Ads users, manager accounts, and conversion ownership.

Frequently Asked Questions

Who should have administrative access to a Google Ads account?

Review the following systems and records: Google Ads > Admin > Access and security. Record users, pending invitations, access levels, authentication methods, allowed domains, security settings, and linked manager accounts. Confirm the business controls the child account and recognizes every manager ID. If evidence is incomplete or a control fails, remove stale access after a tested internal administrator exists. Downgrade users who need reporting or campaign work but do not need account administration. Retest and document closure.

How can a review find unauthorized Google Ads conversion changes?

Review the following systems and records: Google Ads > Goals > Conversions > Summary and Change history. List people and manager accounts that created or changed conversion actions, values, primary status, counting, attribution, lookback windows, and imports. Compare changes with approved tickets or campaign decisions. If evidence is incomplete or a control fails, restore incorrect settings from evidence, limit administrator access, and retest conversions before automated bidding continues to rely on them. Retest and document closure.

Which GA4 roles should be reviewed for lead tracking?

To verify Google Ads lead-tracking ownership, inspect GA4 Admin > Account access management and Property access management. Capture direct and inherited users, groups, Administrator, Editor, Marketer, Analyst, and Viewer roles, plus cost and revenue restrictions. Confirm the reviewed property and stream IDs match the website. If evidence is incomplete or a control fails, remove stale access, apply the least role needed, and keep at least two tested internal administrators for the account and critical property. Retest and document closure.

Why is Tag Manager Publish access more sensitive than Edit access?

To protect conversion publishing connected to Google Ads, inspect Tag Manager > Admin > Account User Management and Container User Management. Record account and container permissions separately. Identify who can Read, Edit, Approve, and Publish, plus service accounts, environments, workspaces, and recent versions published by each user. If evidence is incomplete or a control fails, reserve Publish for trained, accountable users. Keep two internal administrators and remove external publishers only after a working version and replacement access are secured. Retest and document closure.

Why should website access be included in a Google Ads tracking review?

Review the following systems and records: CMS users, hosting panel, form plugin, landing page platform, DNS, and deployment process. List people who can add scripts, replace forms, alter confirmation states, change redirects, modify phone numbers, or publish landing pages. Record MFA, account owner, and change history where available. If evidence is incomplete or a control fails, remove shared accounts, enforce individual access, narrow roles, and connect production measurement changes to a ticket and post-publish test. Retest and document closure.

What access should be reviewed in call tracking and booking systems?

Review the following systems and records: Provider user lists, number inventory, routing, integrations, and billing ownership. Record administrators, agencies, number owners, call routing, recording rules, webhook or API access, booking calendars, chat destinations, and who can change conversion definitions. If evidence is incomplete or a control fails, transfer billing and number ownership to the business, remove stale users, rotate exposed credentials, and retest live calls or bookings after changes. Retest and document closure.

Who should control consent settings used by Google Ads tags?

Review the following systems and records: Consent management platform users, banner configuration, region rules, tag integrations, and website deployment. Identify who can change categories, default states, region behavior, Google consent signals, privacy links, and tag blocking. Compare production behavior with the approved policy. If evidence is incomplete or a control fails, limit configuration access, document legal ownership, and test accepted and declined states after every banner or tag change. Retest and document closure.

What should be reviewed before changing a Google Ads CRM import?

Review the following systems and records: CRM users, integration settings, Data Manager, API credentials, service accounts, and field mappings. Record who can alter lifecycle stages, lead values, source fields, imports, matching data, credentials, and schedules. Identify personal accounts or agency-owned connectors. If evidence is incomplete or a control fails, move ownership to company-controlled accounts, use least privilege, rotate credentials when needed, and validate one controlled qualified lead after each access change. Retest and document closure.

How can linked Google products create duplicate lead conversions?

Review the following systems and records: Google Ads Data manager, GA4 Product links, Merchant Center, Business Profile, YouTube, and call providers. List every connected product, account ID, owner, data shared, and conversion or audience dependency. Identify duplicate GA4 properties, old manager accounts, and imports from overlapping sources. If evidence is incomplete or a control fails, unlink only after confirming campaign, audience, product, and conversion dependencies. Keep one documented authoritative source for each primary business outcome. Retest and document closure.

What proves a business can recover its Google Ads tracking setup?

Review the following systems and records: Password manager, company documentation, Tag Manager versions, website backups, Ads Change history, and GA4 change history. Confirm two internal recovery paths, preserved container versions, website rollback, account IDs, billing control, and an end-to-end lead test. Record what happens if the agency or developer is unavailable. If evidence is incomplete or a control fails, create missing backup access, export or document configurations, and run the recovery procedure before removing the current owner. Retest and document closure.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Latest Articles