ALLMSP Blog

Who Can See Your GA4 Data? An Analytics Access Audit

Review GA4 account ownership, property roles, data restrictions, product links, reporting access, Tag Manager publishers, and business continuity.

A business owner and analytics administrator reviewing GA4-style users, permissions, linked products, reports, and outside access

A GA4 access review starts by identifying the correct Analytics account and property. Similar names and inherited permissions can make a user appear authorized in the wrong place. The review should capture direct and inherited roles, data restrictions, linked products, Tag Manager publishing rights, reporting dependencies, and the business owner for each critical output.

Do not remove an unfamiliar administrator, agency, developer, group, Tag Manager publisher, service account, or product link until its role is understood. First add and test company-controlled access, preserve the production container version and report definitions, then make changes during a documented window with lead tracking tests.

ALLMSP handles Google Analytics access, ownership, and security review to teams near Lawrenceville and Suwanee, elsewhere in Gwinnett County and Metro Atlanta, and throughout Georgia, with planning, configuration, testing, and support completed by the same in-house team.

Evidence to collect before changing GA4 measurement

A useful access review proves that the business controls the correct GA4 account and property, can maintain the production tag, recognizes every administrator and outside user, limits sensitive cost or revenue data, and can reproduce important reports after a staff or provider change.

  • Analytics account and property IDs, web stream and Measurement ID, business owner, technical owner, and last validated website test.
  • Direct and inherited account and property users, groups, roles, data restrictions, last activity, and approved purpose.
  • Tag Manager account and container permissions, live version, workspaces, environments, and publishing history.
  • Google Ads, Search Console, BigQuery, Merchant Center, and other product links with exact account IDs and owners.
  • Explorations, Looker Studio data sources, scheduled reports, alerts, APIs, service accounts, and shared report dependencies.
  • A recent real lead reconciliation and a recovery test performed by a company-controlled backup administrator.

Identify the correct account, property, and effective users

Account and property identity

What to check: Record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention. Compare them with website tags and business reports.

What to do next: Rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed.

Direct and inherited users

What to check: Export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation. Check both account and property levels.

What to do next: Retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work.

Sensitive cost and revenue data

What to check: Identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information. Compare access with job responsibility and confidentiality requirements.

What to do next: Apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role.

Review tag publishing and measurement authority

Tag Manager account and container roles

What to check: Record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users. Identify who can deploy code to production.

What to do next: Keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes.

Website and plugin control

What to check: List people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates. Record individual accounts, MFA, owners, and change history.

What to do next: Remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases.

Product links and data destinations

What to check: Record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links. Capture exact IDs, data shared, permissions, owner, and whether the destination remains active.

What to do next: Remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies. Correct links that point to the wrong account.

Explorations and shared report assets

What to check: Identify business-critical explorations, report collections, filters, audiences, and ownership dependencies. Determine whether important analysis exists only in one employee's private exploration.

What to do next: Document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data.

Inspect reports, links, and external data access

Looker Studio and external connectors

What to check: Record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies.

What to do next: Transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access.

Change history and unexplained configuration

What to check: Compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting. Record unexplained changes and whether data quality shifted at the same time.

What to do next: Investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record.

Backup administration and recovery test

What to check: Have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead. Record gaps that require the primary owner.

What to do next: Add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help.

Rank access findings by data and continuity risk

Treat unknown administrators, exposed public reports, unexplained production tags, broken consent, and access to sensitive data as urgent. Next address one-person ownership, agency-controlled reporting, and undocumented product links. Viewer cleanup and naming improvements can follow after ownership and production measurement are stable.

Priority 1: Unauthorized access or data exposure

Use this level for unknown administrators, public access to sensitive reports, malicious or unexplained production tags, exposed credentials, or collection that contradicts consent requirements.

Priority 2: Measurement and continuity risk

Use this level for one-person administration, agency-owned reports, wrong product links, missing website control, untested publishers, and configuration changes affecting lead data.

Priority 3: Reporting and permission hygiene

Use this level for stale viewers, duplicate report assets, old workspaces, unclear naming, and missing review dates after critical access is controlled.

Official product documentation and ALLMSP resources

  • Google Analytics recommended events. Official GA4 event names and parameters designed to support useful reporting and future integrations, with the planning steps on this page applying it to the work needed to determine who can see GA4 data and confirm that analytics access is appropriate.
  • Google Analytics roles, filters, and data access. Official comparison of user roles, report filters, data filters, and options for restricting or presenting analytics data, with the configuration checks here applied to the controls needed to determine who can see GA4 data and confirm that analytics access is appropriate.
  • Google Analytics event parameters. Official guidance for collecting event context and making parameters available through dimensions and metrics, with the review process on this page using that guidance to help the organization determine who can see GA4 data and confirm that analytics access is appropriate.

Frequently Asked Questions

How do we confirm that a GA4 property belongs to the right website?

To verify analytics access and property ownership, inspect GA4 Admin > Account settings, Property settings, and Data streams. Record account ID, property ID, property name, time zone, currency, web stream URL, stream ID, Measurement ID, and data retention. Compare them with website tags and business reports. If evidence is incomplete or a control fails, rename ambiguous assets, correct documentation, and stop relying on a report until its property and production data source are confirmed. Retest and document closure.

What is inherited access in Google Analytics?

To verify analytics access and property ownership, inspect GA4 Admin > Account access management and Property access management. Export or record users and groups, whether access is inherited, assigned roles, data restrictions, employment or vendor status, business purpose, and last confirmation. Check both account and property levels. If evidence is incomplete or a control fails, retain two tested internal administrators, remove stale direct or group access after validation, and assign the least role that supports the work. Retest and document closure.

Can GA4 access be restricted for cost and revenue data?

Review the following systems and records: GA4 access management, user roles, data restrictions, linked Ads accounts, and reporting tools. Identify users who can view cost metrics, revenue metrics, user-level exploration data, audiences, and linked advertising information. Compare access with job responsibility and confidentiality requirements. If evidence is incomplete or a control fails, apply cost or revenue restrictions where supported, narrow reports and data sources, and remove broad exports or sharing that bypasses the intended role. Retest and document closure.

Why must Tag Manager permissions be reviewed with GA4 access?

To understand who can change GA4 collection, inspect Tag Manager > Admin > Account User Management and Container User Management. Record account permissions, container Read, Edit, Approve, and Publish rights, recent versions, active workspaces, environments, and outside users. Identify who can deploy code to production. If evidence is incomplete or a control fails, keep two company-controlled administrators, reserve Publish for accountable users, close stale workspaces, and test production measurement after access changes. Retest and document closure.

Who can change GA4 without having Analytics administrator access?

Review the following systems and records: CMS users, hosting, consent platform, analytics plugin, source code, DNS, and release process. List people who can replace the Measurement ID, add scripts, change consent, alter forms, or publish website updates. Record individual accounts, MFA, owners, and change history. If evidence is incomplete or a control fails, remove shared access, narrow roles, document the supported tag method, and require a GA4 regression test after measurement-affecting releases. Retest and document closure.

Which GA4 product links should be included in an access review?

To verify analytics access and property ownership, inspect GA4 Admin > Product links. Record linked Google Ads accounts, Search Console properties, BigQuery projects, Merchant Center accounts, and other available links. Capture exact IDs, data shared, permissions, owner, and whether the destination remains active. If evidence is incomplete or a control fails, remove obsolete links only after reviewing audiences, conversions, reports, exports, billing, and campaign dependencies. Correct links that point to the wrong account. Retest and document closure.

Are GA4 Explorations automatically shared with other users?

Review the following systems and records: GA4 Explore, Reports, Library, saved comparisons, and scheduled email where available. Identify business-critical explorations, report collections, filters, audiences, and ownership dependencies. Determine whether important analysis exists only in one employee's private exploration. If evidence is incomplete or a control fails, document or recreate essential analysis in a governed shared reporting process, and assign a backup owner who can reproduce it from the source data. Retest and document closure.

What should be reviewed for Looker Studio reports connected to GA4?

Review the following systems and records: Looker Studio report sharing, data-source credentials, connector settings, Sheets exports, APIs, and service accounts. Record report owners, editors, viewers, embedded links, data credentials, extracts, scheduled delivery, third-party connectors, service accounts, and billing dependencies. If evidence is incomplete or a control fails, transfer ownership to company-controlled accounts, restrict public links, rotate exposed credentials, and test refreshes and filters after changing access. Retest and document closure.

How can GA4 change history support an access audit?

To verify analytics access and property ownership, inspect GA4 Admin > Property change history, Tag Manager Versions, website release history, and support tickets. Compare user activity with changes to events, key events, audiences, links, data retention, filters, and reporting. Record unexplained changes and whether data quality shifted at the same time. If evidence is incomplete or a control fails, investigate unauthorized or accidental changes, restore settings from evidence where possible, reduce authority, and create a mandatory change and test record. Retest and document closure.

What proves that a business can recover control of Google Analytics?

Review the following systems and records: Company password manager, documented account IDs, Analytics and Tag Manager access, website rollback, and reporting inventory. Have a backup administrator sign in independently, inspect property settings, open the production container, access essential reports, and complete a labeled test lead. Record gaps that require the primary owner. If evidence is incomplete or a control fails, add missing internal access, transfer report ownership, preserve production versions, document recovery, and repeat the test until it works without verbal help. Retest and document closure.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Latest Articles