Skip to content
tempkey ← Back to blog

Tempkey Blog

Google Analytics Permissions: How to Manage Contractor Access to Google Analytics Securely

Discover actionable frameworks to grant freelancers precise GA4 roles, protect confidential conversion metrics, and systematically revoke stale marketing credentials.

To securely manage contractor access to Google Analytics 4 (GA4), assign external users the lowest necessary role—typically Analyst or Marketer—strictly at the Property level rather than the Account level, and apply metric restrictions to mask revenue or cost data. Establishing time-bound access windows and an automated revocation workflow ensures that external collaborators lose access immediately when their project concludes.

For inbox-safety context, FTC phishing guidance recommends treating unexpected messages and requests for personal information with caution.

Understanding how to manage contractor access to google analytics is essential for modern marketing operations. Marketing analytics instances hold proprietary commercial intelligence: granular conversion funnels, customer acquisition costs, transactional ecommerce revenue, user demographic segments, and custom event telemetry. When organizations grant excessive permissions or forget to revoke access after an engagement ends, they expose critical business intelligence to data leakage, competitive exposure, and compliance infractions.

The Security and Privacy Risks of Stale Google Analytics Permissions

Marketing analytics platforms are frequently miscategorized as low-risk reporting dashboards. In reality, a GA4 property functions as a centralized database of real-time user behavior, business performance, and marketing efficiency. Granting unrestricted or unmonitored access to external freelancers introduces distinct operational vulnerabilities:

  • Exposure of Strategic Business Intelligence: GA4 stores unmasked financial metrics, including average order value (AOV), total ecommerce turnover, lifetime customer value (LTV), and product-level margins. Competitors or unauthorized third parties with persistent access can analyze your pricing elasticity, conversion weak points, and top-performing acquisition channels.
  • Orphaned and Stale Accounts: Freelance engagements are inherently transient. An agency brought on for a four-week paid search audit often retains property access for months or years simply because manual offboarding checklists fail. These dormant accounts become unmonitored entry points if the contractor's personal credentials are compromised.
  • Regulatory and Privacy Liabilities: Data privacy regulations such as GDPR and CCPA require strict access controls over systems processing user telemetry, pseudonymous identifiers (like client IDs), and behavioral events. Uncontrolled access by third-party contractors undermines data minimization mandates and complicates vendor data processing agreements.
  • Permission Sprawl Across Multi-Brand Workspaces: Agencies handling multiple sub-brands or regional domains frequently request broad administrative rights. Without strict containment, an external contractor hired to optimize a single regional landing page can gain visibility into global enterprise datasets.

Understanding GA4 Roles: Account vs Property-Level Permissions

Google Analytics 4 uses a hierarchical permission architecture. Understanding the operational boundary between Account-level and Property-level access is the foundation of secure contractor management, as detailed in the Google Analytics Account and Property structure documentation.

An Account is the top-level administrative container. Assigning a user a role at the Account level automatically cascades those identical permissions down to every single Property, data stream, and subproperty within that account. In contrast, assigning a role at the Property level isolates the user's access strictly to that designated reporting container, preventing visibility into other digital assets managed under the same parent organization.

Within GA4, permissions are governed by discrete access roles alongside specific data-restriction flags, as outlined in the official GA4 access and data-restriction role specifications:

  • Administrator: Grants full control over the property or account. Administrators can manage user permissions, link external ad accounts, create data streams, modify attribution models, and delete properties. Contractors should rarely be granted Administrator rights.
  • Editor: Grants complete control over property-level configuration settings, events, audiences, conversions, and custom definitions. Editors cannot manage user access roles. This role should be reserved exclusively for technical implementation engineers who must configure measurement architecture.
  • Marketer: Allows users to create, edit, and archive audiences, conversions, attribution events, and lookback windows, as well as view standard and custom exploration reports. This is suitable for performance marketing freelancers who need to configure campaign tracking parameters.
  • Analyst: Enables users to create, edit, share, and export exploratory dashboards, funnel visualizations, and custom segmentations. Analysts cannot alter measurement settings, audiences, or conversion definitions. This is the optimal role for SEO, content, and conversion rate optimization (CRO) contractors.
  • Viewer: Provides read-only access to standard out-of-the-box reports and shared explorations. Viewers cannot create saved private explorations or edit configurations.
  • None: Explicitly blocks access to the container when overriding higher-level inherited roles.

Applying Data Restrictions (Cost and Revenue Masking)

GA4 provides two critical granular restrictions that can be applied on top of any standard role:

  • No Cost Metrics: Restricts the user from viewing cost-per-click (CPC), total ad spend, return on ad spend (ROAS), and any imported advertising cost data from Google Ads, Campaign Manager 360, or manual CSV uploads.
  • No Revenue Metrics: Conceals ecommerce transaction values, purchase revenue, in-app purchase data, gross margin, and monetization reports. Affected metrics appear as blank or unpopulated across standard reports, explorations, and API queries.

Step-by-Step: How to Manage Contractor Access to Google Analytics

Following a structured technical workflow prevents unauthorized privilege escalation and ensures external collaborators receive only the specific scopes required to complete their deliverables.

Step 1: Audit Required Scopes Before Issuing an Invitation

Before opening the GA4 administration console, document the contractor's scope of work. Determine whether they require operational write permissions (Marketer) or purely observational read access (Analyst with data restrictions). Require the contractor to provide a designated corporate Google-managed email address rather than an unmanaged personal Gmail inbox whenever feasible.

Step 2: Assign Property-Scoped Permissions

  1. Sign in to Google Analytics and select the target Property from the account selector.
  2. Click the Admin gear icon in the lower-left navigation panel.
  3. In the Property column, select Property Access Management. (Avoid selecting Account Access Management unless managing internal enterprise platform owners).
  4. Click the blue + button in the upper-right corner and select Add users.
  5. Enter the contractor's Google account email address.
  6. Under Direct roles, select either Analyst (recommended for reporting/SEO) or Marketer (for campaign managers).

Step 3: Enforce Metric-Level Data Restrictions

  1. In the same Add users configuration window, scroll to the Data restrictions section.
  2. If the contractor is an organic SEO, copywriter, or technical UX auditor who does not manage media spend, check No Cost Metrics.
  3. If the contractor does not need to analyze commercial financial performance, check No Revenue Metrics.
  4. Click Add to finalize and dispatch the property invitation.

Step 4: Document Duration and Offboarding Criteria

Log the user grant inside your internal access register. Record the contractor's full name, agency affiliation, authorized property ID, granted role, metric restrictions, business justification, and the scheduled contract termination date.

Common Mistakes When Granting Google Analytics User Permissions

Even technical teams frequently commit governance errors when managing external access. Identifying these common operational pitfalls prevents systemic security blind spots.

1. Granting Full Account-Level Access

When an agency requests access, administrators often navigate to Account Access Management and assign the role there out of convenience. If your business operates multiple web properties, staging environments, or subsidiary apps under that account, the external agency immediately inherits visibility into all of them. often confine external invitations to individual properties.

2. Using Shared Generic Accounts

Inviting a single shared address like analytics@contractoragency.com eliminates individual attribution. If three different agency team members share those credentials, your internal access logs cannot distinguish who altered a key event definition or exported a proprietary customer segment. Enforce named user accounts for every external individual.

3. Overlooking Connected Downstream Toolchains

Google Analytics does not exist in isolation. Granting access to GA4 often leads teams to unintentionally grant corresponding access across connected data processing infrastructure, including:

  • Google Tag Manager (GTM): A contractor with GTM container edit access can inject arbitrary JavaScript, extract document object model (DOM) elements, or redirect user data to unapproved endpoints. GTM access must be governed under separate, strict access reviews.
  • BigQuery Data Exports: If GA4 is linked to a Google Cloud BigQuery project for raw event streaming, granting GA4 access does not grant BigQuery access automatically—but internal teams often grant broad GCP Viewer roles to help the contractor "query raw tables." This bypasses all GA4 UI metric restrictions.
  • Looker Studio Dashboards: Looker Studio reports can use the "Owner's Credentials" data source authorization setting. If an external contractor has access to a shared report configured this way, they can view underlying dataset metrics even if their direct GA4 account permissions are restricted or revoked.
  • Linked Advertising Accounts: Linking Google Ads to GA4 allows auto-tagging and audience sharing. Ensure contractors are not permitted to alter ad conversion actions unless explicitly contracted for paid media management.

4. Failing to Track Grant Approvers

In mid-sized organizations, multiple marketing managers possess property-level Administrator permissions. Without centralized grant auditing, administrators cannot verify who approved an external user's access, why it was granted, or when it should be terminated.

Revoking Contractor Access to Marketing Data: A Clean Offboarding Protocol

Systematic offboarding is the most critical stage of contractor lifecycle management. Revoking contractor access to marketing data requires a synchronized protocol that purges both direct UI permissions and secondary analytical bridges.

  1. Immediate Property Removal: Navigate to Admin > Property Access Management, locate the external user, select the three-dot menu, and click Remove access. If the user was inadvertently added at the Account level, remove them from Account Access Management.
  2. Audit Looker Studio and BI Asset Sharing: Review all analytical workspaces. Check whether the contractor was transferred ownership of shared reports or if their email remains an authorized viewer on internal dashboard URLs. Re-authenticate data source credentials using a dedicated internal service account.
  3. Revoke API Keys and Cloud IAM Roles: If the contractor utilized the Google Analytics Data API or BigQuery raw exports, rotate service account private keys and purge their IAM bindings in the Google Cloud Console.
  4. Audit Google Tag Manager Containers: Verify that the contractor's email is removed from GTM User Management. Check container version history to ensure no persistent tracking snippets or unvetted third-party vendor pixels were published prior to offboarding.
  5. Log Verification in Compliance Records: Archive the completed offboarding event in your access register, capturing the precise timestamp and the identity of the administrator who executed the revocation.

Automating Delegation: How to Manage Contractor Access to Google Analytics with Tempkey

Managing contractor permissions manually across Google Analytics, workspace identities, and connected SaaS applications creates operational overhead. Manual calendar reminders and spreadsheet trackers inevitably slip, leaving orphaned contractor accounts active indefinitely. Automating time-bound delegation eliminates this exposure at the root.

Organizations using Tempkey streamline external identity lifecycles across their entire operational stack. Using the Tempkey Contractor Access Manager, operations teams can provision temporary, time-delimited access windows that automatically revoke contractor privileges the moment an engagement concludes, removing the reliance on human memory.

Tempkey natively enforces access on 10 providers — Slack, Google Workspace, Microsoft 365, GitHub, GitLab, Zoom, AWS IAM, Figma, Dropbox, and Asana. Notion and Trello are limited-native (tracked, not fully enforced) and Zapier/Make are best-effort webhook bridges without automated verification. Explore the full list of supported platforms in the Tempkey native provider integrations directory.

When external marketing contractors require access to your Google ecosystem, managing their lifecycle via their underlying Google Workspace user identity or paired directory group ensures that when their temporary access window expires, their access across connected marketing platforms closes simultaneously. Tempkey executes revocation and reads provider state back to confirm it. Because revocation depends on third-party provider APIs, Tempkey does not guarantee removal within any specific time and surfaces failed or unenforceable revokes in the audit log.

For technical compliance documentation, Tempkey gives you an exportable, append-only audit trail to support your own compliance and offboarding records. Tempkey does not hold SOC 2, ISO 27001, HIPAA, or PCI certification. Every grant, extension, manual revocation, and automated offboarding confirmation is captured in an append-only format that can be exported to CSV or PDF for security reviews.

Developer and operations teams can also programmatically govern access lifecycles. Tempkey has a public REST API covering grants, extension, revocation with read-back verification, integrations, the audit trail, and API-key management. Keys are bearer tokens with read/write scopes; an OpenAPI 3 spec is published at api.tempkey.io/openapi.json and human docs at tempkey.io/docs/api.

Enterprise IT suites (e.g. Rippling, Okta, JumpCloud) bundle contractor offboarding inside larger, per-employee-priced products; their pricing changes often and is frequently quote-gated. Tempkey prices per active contractor grant. Plans are month-to-month (Free / $39 Team / $99 Business) with active-grant limits of 2 / 10 / 30. Business includes extended audit-history retention. Review the details on the Tempkey transparent pricing page.

From an infrastructure security perspective, provider admin tokens are write-only in the browser and encrypted at rest using AWS KMS in production; they are never displayed again after submission. Sign-in is passwordless — magic links plus WebAuthn/passkeys. Tempkey does not offer SSO/SAML today. Furthermore, Tempkey is a hosted cloud service; there is no self-hosted or on-premise deployment option, and Tempkey does not offer customer custom or vanity domains today. Learn more about platform controls in the Tempkey security overview.

Contractor Access Governance Checklist for Marketing Operations

Use this operational framework across each phase of a contractor engagement to enforce strict access governance across your analytics stack:

Pre-Onboarding Phase

  • Identify exact deliverables (e.g., CRO audit, SEO dashboarding, attribution modeling).
  • Select the minimum viable GA4 role (Viewer, Analyst, or Marketer).
  • Apply data restrictions (check No Cost Metrics and/or No Revenue Metrics).
  • Define explicit start and expiration dates aligned with the statement of work (SOW).
  • Obtain signed non-disclosure agreements (NDAs) covering proprietary analytics telemetry.

Active Engagement Phase

  • Perform bi-weekly access reviews of the GA4 Property Access Management console.
  • Monitor Google Tag Manager container publish history for unauthorized tracking script deployments.
  • Confirm that contractor access remains restricted to property-level scopes and has not escalated to Account-level administrative roles.
  • Ensure contractor queries to connected databases (e.g., BigQuery) use dedicated service accounts with view-only table permissions.

Offboarding Phase

  • Revoke direct GA4 Property permissions.
  • Sever Looker Studio data source sharing and re-authenticate reports with internal credentials.
  • Remove contractor accounts from Google Tag Manager, Google Search Console, and Google Ads manager accounts.
  • Rotate any shared API keys, service account credentials, or database query tokens.
  • Export the append-only access event log to CSV or PDF and archive it with project offboarding records.

Frequently Asked Questions

What is the safest GA4 permission role to assign to a freelance SEO or PPC contractor?

For freelance SEO auditors and content strategists, the Analyst role assigned strictly at the Property level is the safest configuration. It enables the contractor to create custom exploration reports, segment traffic, and evaluate landing page performance without granting rights to alter measurement parameters, conversions, or user lists. For PPC contractors who must manage campaign conversions and import ad audiences, the Marketer role is appropriate. Neither group requires Administrator or Editor permissions.

Can a contractor export or download raw user data from Google Analytics 4?

Users assigned the Analyst, Marketer, Editor, or Administrator roles can export summarized reporting tables, exploration grids, and aggregated chart data directly to Google Sheets, CSV, or PDF formats. However, standard GA4 reporting interfaces do not expose raw, unaggregated hit-level event data or personal identifying information (PII). Hit-level data extraction is only possible if the contractor has direct read permissions on an export destination such as a connected Google Cloud BigQuery dataset.

How do I restrict a contractor from seeing revenue and cost metrics in GA4?

When adding or editing a user in Property Access Management, scroll to the Data restrictions section at the bottom of the permission panel. Check No Cost Metrics to hide advertising costs, CPC, and ROAS calculations. Check No Revenue Metrics to mask ecommerce purchase totals, gross revenue, and monetization reports. These restrictions apply across standard reports, explorations, and API queries.

What happens to Looker Studio reports when contractor access to GA4 is revoked?

The outcome depends on the credential configuration of the Looker Studio data source. If the data source was configured to use the Viewer's Credentials, the contractor will immediately lose the ability to view data in the report once their GA4 property role is revoked. However, if the data source was configured using an internal administrator's Owner Credentials, anyone with the report link can continue viewing the rendered data. To ensure total revocation, administrators must remove the contractor from both the GA4 property and the Looker Studio report sharing settings.


Explore how Tempkey automates time-bound access and offboarding across your team's core tool stack. Start a free month-to-month workspace today.