ALLMSP Blog

Who Can See Your GA4 Data? An Analytics Access Audit

Review GA4 account ownership, property roles, data restrictions, product links, reporting access, Tag Manager publishers, and business continuity.

Google Analytics permission matrix covering Access, Data, Account, Links

A GA4 access review starts by identifying the correct Analytics account and property. Similar names and inherited permissions can make a user appear authorized in the wrong place. The review should capture direct and inherited roles, data restrictions, linked products, Tag Manager publishing rights, reporting dependencies, and the business owner for each critical output.

Do not remove an unfamiliar administrator, agency, developer, group, Tag Manager publisher, service account, or product link until its role is understood. First add and test company-controlled access, preserve the production container version and report definitions, then make changes during a documented window with lead tracking tests.

Evidence to collect before changing GA4 measurement

A useful access review proves that the business controls the correct GA4 account and property, can maintain the production tag, recognizes every administrator and outside user, limits sensitive cost or revenue data, and can reproduce important reports after a staff or provider change.

  • Analytics account and property IDs, web stream and Measurement ID, business owner, technical owner, and last validated website test.
  • Direct and inherited account and property users, groups, roles, data restrictions, last activity, and approved purpose.
  • Tag Manager account and container permissions, live version, workspaces, environments, and publishing history.
  • Google Ads, Search Console, BigQuery, Merchant Center, and other product links with exact account IDs and owners.
  • Explorations, Looker Studio data sources, scheduled reports, alerts, APIs, service accounts, and shared report dependencies.
  • A recent real lead reconciliation and a recovery test performed by a company-controlled backup administrator.

Identify the correct account, property, and effective users

Access and Data Quality icon

Account and property identity

Review location: Google Analytics this access and risk review, GA4 Admin > Account settings, Property settings, and Data streams

Evidence to capture: Record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention. Compare them with website tags and business reports.

Response when the check fails: Rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed.

Direct and inherited users

Review location: Google Analytics this access and risk review, GA4 Admin > Account access management and Property access management

Evidence to capture: Export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation. Check both account and property levels.

Response when the check fails: Retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work.

Sensitive cost and revenue data

Review location: Google Analytics this access and risk review, GA4 access management, user roles, data restrictions, linked Ads accounts, and reporting tools

Evidence to capture: Identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information. Compare access with job responsibility and confidentiality requirements.

Response when the check fails: Apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role.

Review tag publishing and measurement authority

Tags and Website Tracking icon

Tag Manager account and container roles

Review location: Google Analytics this access and risk review, Tag Manager > Admin > Account User Management and Container User Management

Evidence to capture: Record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users. Identify who can deploy code to production.

Response when the check fails: Keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes.

Website and plugin control

Review location: Google Analytics this access and risk review, CMS users, hosting, consent platform, analytics plugin, source code, DNS, and release process

Evidence to capture: List people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates. Record individual accounts, MFA, owners, and change history.

Response when the check fails: Remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases.

Product links and data destinations

Review location: Google Analytics this access and risk review, GA4 Admin > Product links

Evidence to capture: Record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links. Capture exact IDs, data shared, permissions, owner, and whether the destination remains active.

Response when the check fails: Remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies. Correct links that point to the wrong account.

Explorations and shared report assets

Review location: Google Analytics this access and risk review, GA4 Explore, Reports, Library, saved comparisons, and scheduled email where available

Evidence to capture: Identify business-critical explorations, report collections, filters, audiences, and ownership dependencies. Determine whether important analysis exists only in one employee’s private exploration.

Response when the check fails: Document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data.

Inspect reports, links, and external data access

Reporting and Insights icon

Looker Studio and external connectors

Review location: Google Analytics this access and risk review, Looker Studio report sharing, data-source credentials, connector settings, Sheets exports, APIs, and service accounts

Evidence to capture: Record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies.

Response when the check fails: Transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access.

Change history and unexplained configuration

Review location: Google Analytics this access and risk review, GA4 Admin > Property change history, Tag Manager Versions, website release history, and support tickets

Evidence to capture: Compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting. Record unexplained changes and whether data quality shifted at the same time.

Response when the check fails: Investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record.

Backup administration and recovery test

Review location: Google Analytics this access and risk review, Company password manager, documented account IDs, Analytics and Tag Manager access, website rollback, and reporting inventory

Evidence to capture: Have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead. Record gaps that require the primary owner.

Response when the check fails: Add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help.

Rank access findings by data and continuity risk

Treat unknown administrators, exposed public reports, unexplained production tags, broken consent, and access to sensitive data as urgent. Next address one-person ownership, agency-controlled reporting, and undocumented product links. Viewer cleanup and naming improvements can follow after ownership and production measurement are stable.

Priority 1: Unauthorized access or data exposure

Use this level for unknown administrators, public access to sensitive reports, malicious or unexplained production tags, exposed credentials, or collection that contradicts consent requirements.

Priority 2: Measurement and continuity risk

Use this level for one-person administration, agency-owned reports, wrong product links, missing website control, untested publishers, and configuration changes affecting lead data.

Priority 3: Reporting and permission hygiene

Use this level for stale viewers, duplicate report assets, old workspaces, unclear naming, and missing review dates after critical access is controlled.

Official Google Analytics 4 review references and related ALLMSP services

Confirm the current official google Analytics documentation for Who Can See Your GA4 Data? An Analytics Access Audit against the live administration screen before approving a procedure.

Google Analytics review data work can draw on Google Analytics support, Google marketing services, online marketing services from ALLMSP.

Frequently Asked Questions

How do we confirm that a GA4 property belongs to the right website?

Review gA4 Admin > Account settings, Property settings, and Data streams and retain current evidence that record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention, Compare them with website tags and business reports. If the evidence is incomplete or the control fails, assign an owner to rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed, then retest before closure.

What is inherited access in Google Analytics?

Review gA4 Admin > Account access management and Property access management and retain current evidence that export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation, Check both account and property levels. If the evidence is incomplete or the control fails, assign an owner to retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work, then retest before closure.

Can GA4 access be restricted for cost and revenue data?

Review gA4 access management, user roles, data restrictions, linked Ads accounts, and reporting tools and retain current evidence that identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information, Compare access with job responsibility and confidentiality requirements. If the evidence is incomplete or the control fails, assign an owner to apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role, then retest before closure.

Why must Tag Manager permissions be reviewed with GA4 access?

Review tag Manager > Admin > Account User Management and Container User Management and retain current evidence that record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users, Identify who can deploy code to production. If the evidence is incomplete or the control fails, assign an owner to keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes, then retest before closure.

Who can change GA4 without having Analytics administrator access?

Review cMS users, hosting, consent platform, analytics plugin, source code, DNS, and release process and retain current evidence that list people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates, Record individual accounts, MFA, owners, and change history. If the evidence is incomplete or the control fails, assign an owner to remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases, then retest before closure.

Which GA4 product links should be included in an access review?

Review gA4 Admin > Product links and retain current evidence that record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links, Capture exact IDs, data shared, permissions, owner, and whether the destination remains active. If the evidence is incomplete or the control fails, assign an owner to remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies, Correct links that point to the wrong account, then retest before closure.

Are GA4 Explorations automatically shared with other users?

Review gA4 Explore, Reports, Library, saved comparisons, and scheduled email where available and retain current evidence that identify business-critical explorations, report collections, filters, audiences, and ownership dependencies, Determine whether important analysis exists only in one employee’s private exploration. If the evidence is incomplete or the control fails, assign an owner to document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data, then retest before closure.

What should be reviewed for Looker Studio reports connected to GA4?

Review looker Studio report sharing, data-source credentials, connector settings, Sheets exports, APIs, and service accounts and retain current evidence that record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies. If the evidence is incomplete or the control fails, assign an owner to transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access, then retest before closure.

How can GA4 change history support an access audit?

Review gA4 Admin > Property change history, Tag Manager Versions, website release history, and support tickets and retain current evidence that compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting, Record unexplained changes and whether data quality shifted at the same time. If the evidence is incomplete or the control fails, assign an owner to investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record, then retest before closure.

What proves that a business can recover control of Google Analytics?

Review company password manager, documented account IDs, Analytics and Tag Manager access, website rollback, and reporting inventory and retain current evidence that have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead, Record gaps that require the primary owner. If the evidence is incomplete or the control fails, assign an owner to add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help, then retest before closure.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Latest Articles