For agencies

Get access to a client's Google Analytics

You never need a client’s password to manage their Google Analytics or Search Console. The client keeps ownership and adds you by email: in Analytics, Admin → Property access management → add you as Viewer; in Search Console, Settings → Users and permissions → add you with Restricted permission. Viewer access is read-only, every grant is listed by name, and the client can remove you in one click. Tools use a service account the same way — no login shared.

Password-free access takes each client about three minutes to set up, and it’s the setup that protects both sides of the engagement. Here’s the exact flow, including what to do when the client doesn’t actually own their own accounts.

Two ways into a client's Google data: the shared login versus the Viewer invite. A model diagram comparing two lanes. The login lane, marked wrong way with a cross: the password changes hands, then two-step codes get texted back and forth, then you're inside their account, and nothing is logged under your name. The invite lane, marked right way with a check: the client adds your email as Viewer, access is read-only — see everything, change nothing — you're listed by name in the access list, and you can be removed in one click, any time. No real accounts shown. TWO WAYS INTO A CLIENT'S DATA ✗ THE LOGIN LANE — WRONG WAY ✓ THE INVITE LANE — RIGHT WAY The password changes hands Two-step codes texted around You're inside their account Nothing logged under your name Client adds your email as Viewer Read-only: see all, change nothing Listed by name in the access list Removed in one click, any time
The two lanes. A shared login makes you responsible for everything in the account; a Viewer invite gives you everything the work needs — logged, read-only, revocable.

Why you never take the password

A shared login makes you responsible for everything that happens in that account, and read access is all the work actually needs.

Think about what the password really buys you: the ability to change things you shouldn’t be able to change, in an account you don’t own. The day something breaks (a deleted property, a changed setting, a billing surprise), the person holding the login is the first suspect, whether or not they touched it. Read-only access is a structural alibi: you couldn’t have changed it. Then there’s the practical mess of shared logins: the two-step code that has to be texted to you every time, Google challenging every new device, the password that gets rotated and locks you out mid-report. The invite isn’t just safer. It’s less work from week one. It’s also a quiet credential: the operator who asks for a Viewer invite has clearly done this before. The one who asks for the password hasn’t.

Google Analytics: the Viewer invite, click by click

Have the client open Google Analytics, click the Admin gear at the bottom left, then Property access management, and add your email with the Viewer role. One precondition: only an Administrator on the account or property can add users. A client who was themselves added as Editor or Viewer can’t grant you anything (that’s the lost-ownership problem covered below).

Google Analytics also has a request button you can press from your own account; it sends an access request that emails every administrator on the client’s account. It works, but the email below usually gets it done faster, with the read-only role spelled out in writing.

Two details keep this clean. First, the scope: next to Property access management sits Account access management. The account covers every site’s data in it, a property is one site’s. The property grant is the right ask unless you genuinely manage everything they own. Second, the role: Analytics offers Viewer, Analyst, Marketer, Editor, Administrator. You want Viewer: it opens every report and can alter none of them. If the access arrives above Viewer (it often does; clients grant Editor or Administrator without asking), request the downgrade in writing. The lowest role that does the job is the one that protects you both.

One check the moment the invite lands: open the property’s Realtime report while someone browses the live site, and confirm this property is the one actually recording it. Client organizations routinely hold several properties (a test property, an abandoned rebuild, one an old agency created), and they’ll add you to whichever they find first. A month of analysis on the dead one is time nobody gives back.

Use a proper work Google account for all of this (the email you’d put on an invoice), because that’s the name that will sit in their access list, and being findable there is part of the point.

Search Console: add a user, click by click

Have the client open Search Console, pick the site, then Settings → Users and permissions → Add user: your email, with Restricted permission.

The wrinkle here is that only an Owner can add users. A client who is merely a “Full user” on their own site can’t grant you anything (that usually means whoever set Search Console up kept ownership; see “When the client can’t grant access” below). On permission level: Restricted reads the reports, which covers the diagnostic work; Full additionally unlocks the action tools, like asking Google to remove a page from results or to ignore spammy links pointing at the site. The monthly read-the-reports work needs neither, so start Restricted and upgrade only when such a task actually lands on your desk. Same principle as Viewer in Analytics.

The email that gets it done

Don’t explain access on a call. Send the clicks in writing, so the client can do it in three minutes and you have a record of exactly what you asked for.

Quick setup so I can read your Google data without ever needing a password:

  1. Google Analytics: analytics.google.com → Admin (gear, bottom left) → Property access management+ → Add users → add you@youragency.com with the Viewer role.
  2. Search Console: search.google.com/search-console → your site → Settings → Users and permissions → Add useryou@youragency.com, permission Restricted.

Both are read-only: I can see the numbers, and I can’t change anything. You’ll see me listed by name in both places, and you can remove me in one click whenever you like.

If either screen doesn’t show those options, or says you don’t have permission, don’t fight it. It usually means the account is owned by someone else; just reply with what you see (a screenshot is perfect) and I’ll take it from there.

The removal line is doing real work: telling the client how to get rid of you, before they’ve paid you a cent, is the fastest trust you can build in week one. The last line matters too. Roughly a third of clients hit a wall here, and it routes them back to you instead of into silence.

When the client can’t grant access

One distinction decides everything here: Search Console ownership can be rebuilt by anyone who controls the website; Analytics access has to come back through Google’s front desk.

The snag itself is the most common one in onboarding: Analytics was set up years ago by a web person who’s gone, under a personal Gmail nobody can reach, or Search Console’s only Owner is a defunct agency. Search Console is rebuildable the same day: anyone who controls the website can prove that control to Google (Google calls it verifying) and add themselves as a fresh Owner, using the site’s domain settings (DNS), an uploaded file, or a small tag placed in the site’s HTML. The new Owner then grants everyone else. Analytics is slower and less certain: Google’s official recovery process has you prove control of the site (an analytics.txt file uploaded to the domain root), submit its support form, and wait. It’s support-mediated, takes days to weeks, and isn’t guaranteed. When it works, the client regains Administrator and the history comes with it. When nobody can prove control, the fallback is a fresh Analytics account under the client’s own Google login, a new property, and the new tag installed, collecting from today forward while the old years stay locked. Lost Search Console is an afternoon of your own clicks; lost Analytics is a support ticket with homework.

The harder version is the owner who’s reachable but won’t move: the incumbent agency or freelancer holding Administrator who stalls, or answers that access “isn’t necessary, we send reports.” For Search Console it doesn’t matter: the client verifies fresh ownership through the site and the holdout is bypassed. For Analytics there’s no bypass, so the request has to come from the client, in writing, as the paying customer. The ask is that the client’s account be granted Administrator, not that you be given anything; your Viewer invite comes afterward, from the client. An incumbent who refuses to give a business admin rights over its own data has just handed you your first finding to report.

Two consequences for how you work. Quote access recovery as its own piece of work, scoped before the monthly engagement starts; it can eat a week of someone else’s inbox. And on every new client, make one of your first deliverables a check that they hold Administrator and Owner on their own accounts. Being the person who hands a client back the keys to their own data is a better first impression than any audit.

Service accounts: how a tool gets the same access

When a tool needs to read the client’s data, nobody’s login gets shared either. The tool has its own Google identity, called a service account, and the client adds that email exactly like they added yours.

Same screens, same Viewer role, same one-click removal, but no human password exists anywhere in the arrangement, so there’s nothing for the client to hand over, rotate, or text codes for. Each client grants their own data, so one client’s numbers never sit behind another client’s login, and revoking the tool on one site touches nothing else. This is the model SEO Audit Flow uses: its viewer email goes into each client’s Analytics and Search Console, added and removed on the same screens where the client added you.

Access is step one — here’s step two

Once the invites land, the access is only as valuable as the loop you run on top of it: the monthly site crawl matched to their own traffic data, the traffic-ranked fix list, the same-day recheck: the whole per-client operating model. And the first thing worth running with fresh access to a client’s numbers is the traffic-drop diagnosis: it shows you, before the first call is over, which pages have been quietly losing and since when.

While you wait for a client’s invite to arrive, you don’t need any access at all to start: the free 60-second check needs none of what this post sets up (no invite, no login, nothing granted) and gives you the first findings to bring to the kickoff call.

Free · no signup

See this on your own site

Run the free 60-second check — no account, nothing to install — and see what's visible from the outside. When you're ready, connect your own Google Analytics and Search Console, read-only, and see exactly which pages lost traffic and what each issue is costing you.

Needs nothing but a URL · read-only access · revoke in one click.