A GA4 access review starts by identifying the correct Analytics account and property. Similar names and inherited permissions can make a user appear authorized in the wrong place. The review should capture direct and inherited roles, data restrictions, linked products, Tag Manager publishing rights, reporting dependencies, and the business owner for each critical output.
Do not remove an unfamiliar administrator, agency, developer, group, Tag Manager publisher, service account, or product link until its role is understood. First add and test company-controlled access, preserve the production container version and report definitions, then make changes during a documented window with lead tracking tests.
Evidence to collect before changing GA4 measurement
A useful access review proves that the business controls the correct GA4 account and property, can maintain the production tag, recognizes every administrator and outside user, limits sensitive cost or revenue data, and can reproduce important reports after a staff or provider change.
- Analytics account and property IDs, web stream and Measurement ID, business owner, technical owner, and last validated website test.
- Direct and inherited account and property users, groups, roles, data restrictions, last activity, and approved purpose.
- Tag Manager account and container permissions, live version, workspaces, environments, and publishing history.
- Google Ads, Search Console, BigQuery, Merchant Center, and other product links with exact account IDs and owners.
- Explorations, Looker Studio data sources, scheduled reports, alerts, APIs, service accounts, and shared report dependencies.
- A recent real lead reconciliation and a recovery test performed by a company-controlled backup administrator.
Identify the correct account, property, and effective users
Account and property identity
Review location: Google Analytics this access and risk review, GA4 Admin > Account settings, Property settings, and Data streams
Evidence to capture: Record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention. Compare them with website tags and business reports.
Response when the check fails: Rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed.
Direct and inherited users
Review location: Google Analytics this access and risk review, GA4 Admin > Account access management and Property access management
Evidence to capture: Export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation. Check both account and property levels.
Response when the check fails: Retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work.
Sensitive cost and revenue data
Review location: Google Analytics this access and risk review, GA4 access management, user roles, data restrictions, linked Ads accounts, and reporting tools
Evidence to capture: Identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information. Compare access with job responsibility and confidentiality requirements.
Response when the check fails: Apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role.
Review tag publishing and measurement authority
Tag Manager account and container roles
Review location: Google Analytics this access and risk review, Tag Manager > Admin > Account User Management and Container User Management
Evidence to capture: Record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users. Identify who can deploy code to production.
Response when the check fails: Keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes.
Website and plugin control
Review location: Google Analytics this access and risk review, CMS users, hosting, consent platform, analytics plugin, source code, DNS, and release process
Evidence to capture: List people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates. Record individual accounts, MFA, owners, and change history.
Response when the check fails: Remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases.
Product links and data destinations
Review location: Google Analytics this access and risk review, GA4 Admin > Product links
Evidence to capture: Record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links. Capture exact IDs, data shared, permissions, owner, and whether the destination remains active.
Response when the check fails: Remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies. Correct links that point to the wrong account.
Explorations and shared report assets
Review location: Google Analytics this access and risk review, GA4 Explore, Reports, Library, saved comparisons, and scheduled email where available
Evidence to capture: Identify business-critical explorations, report collections, filters, audiences, and ownership dependencies. Determine whether important analysis exists only in one employee’s private exploration.
Response when the check fails: Document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data.
Inspect reports, links, and external data access
Looker Studio and external connectors
Review location: Google Analytics this access and risk review, Looker Studio report sharing, data-source credentials, connector settings, Sheets exports, APIs, and service accounts
Evidence to capture: Record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies.
Response when the check fails: Transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access.
Change history and unexplained configuration
Review location: Google Analytics this access and risk review, GA4 Admin > Property change history, Tag Manager Versions, website release history, and support tickets
Evidence to capture: Compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting. Record unexplained changes and whether data quality shifted at the same time.
Response when the check fails: Investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record.
Backup administration and recovery test
Review location: Google Analytics this access and risk review, Company password manager, documented account IDs, Analytics and Tag Manager access, website rollback, and reporting inventory
Evidence to capture: Have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead. Record gaps that require the primary owner.
Response when the check fails: Add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help.
Rank access findings by data and continuity risk
Treat unknown administrators, exposed public reports, unexplained production tags, broken consent, and access to sensitive data as urgent. Next address one-person ownership, agency-controlled reporting, and undocumented product links. Viewer cleanup and naming improvements can follow after ownership and production measurement are stable.
Priority 1: Unauthorized access or data exposure
Use this level for unknown administrators, public access to sensitive reports, malicious or unexplained production tags, exposed credentials, or collection that contradicts consent requirements.
Priority 2: Measurement and continuity risk
Use this level for one-person administration, agency-owned reports, wrong product links, missing website control, untested publishers, and configuration changes affecting lead data.
Priority 3: Reporting and permission hygiene
Use this level for stale viewers, duplicate report assets, old workspaces, unclear naming, and missing review dates after critical access is controlled.
Official Google Analytics 4 review references and related ALLMSP services
Confirm the current official google Analytics documentation for Who Can See Your GA4 Data? An Analytics Access Audit against the live administration screen before approving a procedure.
- Set up Analytics for a website or app.
- Create and manage GA4 events.
- Mark events as key events.
- Manage GA4 access and data restrictions.
- Link Google Analytics and Google Ads.
- Use Tag Assistant for implementation testing.
Google Analytics review data work can draw on Google Analytics support, Google marketing services, online marketing services from ALLMSP.
Frequently Asked Questions
How do we confirm that a GA4 property belongs to the right website?
Review gA4 Admin > Account settings, Property settings, and Data streams and retain current evidence that record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention, Compare them with website tags and business reports. If the evidence is incomplete or the control fails, assign an owner to rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed, then retest before closure.
What is inherited access in Google Analytics?
Review gA4 Admin > Account access management and Property access management and retain current evidence that export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation, Check both account and property levels. If the evidence is incomplete or the control fails, assign an owner to retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work, then retest before closure.
Can GA4 access be restricted for cost and revenue data?
Review gA4 access management, user roles, data restrictions, linked Ads accounts, and reporting tools and retain current evidence that identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information, Compare access with job responsibility and confidentiality requirements. If the evidence is incomplete or the control fails, assign an owner to apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role, then retest before closure.
Why must Tag Manager permissions be reviewed with GA4 access?
Review tag Manager > Admin > Account User Management and Container User Management and retain current evidence that record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users, Identify who can deploy code to production. If the evidence is incomplete or the control fails, assign an owner to keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes, then retest before closure.
Who can change GA4 without having Analytics administrator access?
Review cMS users, hosting, consent platform, analytics plugin, source code, DNS, and release process and retain current evidence that list people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates, Record individual accounts, MFA, owners, and change history. If the evidence is incomplete or the control fails, assign an owner to remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases, then retest before closure.
Which GA4 product links should be included in an access review?
Review gA4 Admin > Product links and retain current evidence that record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links, Capture exact IDs, data shared, permissions, owner, and whether the destination remains active. If the evidence is incomplete or the control fails, assign an owner to remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies, Correct links that point to the wrong account, then retest before closure.
Are GA4 Explorations automatically shared with other users?
Review gA4 Explore, Reports, Library, saved comparisons, and scheduled email where available and retain current evidence that identify business-critical explorations, report collections, filters, audiences, and ownership dependencies, Determine whether important analysis exists only in one employee’s private exploration. If the evidence is incomplete or the control fails, assign an owner to document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data, then retest before closure.
What should be reviewed for Looker Studio reports connected to GA4?
Review looker Studio report sharing, data-source credentials, connector settings, Sheets exports, APIs, and service accounts and retain current evidence that record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies. If the evidence is incomplete or the control fails, assign an owner to transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access, then retest before closure.
How can GA4 change history support an access audit?
Review gA4 Admin > Property change history, Tag Manager Versions, website release history, and support tickets and retain current evidence that compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting, Record unexplained changes and whether data quality shifted at the same time. If the evidence is incomplete or the control fails, assign an owner to investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record, then retest before closure.
What proves that a business can recover control of Google Analytics?
Review company password manager, documented account IDs, Analytics and Tag Manager access, website rollback, and reporting inventory and retain current evidence that have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead, Record gaps that require the primary owner. If the evidence is incomplete or the control fails, assign an owner to add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help, then retest before closure.
























































