GA4 Permissions: Roles, Sharing and Access Troubleshooting

Published:
Last Updated:
Category: Web Analytics
Authors: Shusaku Yosa
To share GA4 with a colleague or an external partner, assign a role to their Google Account through access management at the account or property level. Adding users requires Administrator access at the scope you are managing.
Start by defining which site's data the person needs and what they need to do. This guide explains the five roles, the steps for adding or changing access, and what to check when permissions do not work as expected.
Account-level and property-level permissions
An account is the higher-level container for properties. A property holds measurement data for a website or app. Access assigned at account level is inherited by its properties.
For example, if a company website and online store share an account, a partner working only on the store can receive access to the store's property. Check the property name and ID first to avoid sharing the wrong site's data.
You cannot downgrade an inherited account-level Editor role by assigning Viewer at property level. Narrowing access requires reviewing the higher-level assignment. Effective permissions combine direct assignments with access inherited through resources such as accounts or groups.
The five GA4 roles and when to use them
Role | Main capability | Typical reason to assign it |
|---|---|---|
Administrator | Manage users and roles as well as Analytics settings | Internal ownership of access management |
Editor | Manage property settings, without managing users | Configure the measurement environment |
Marketer | Manage events, key events and audiences, among other marketing settings | Maintain settings used in marketing work |
Analyst | Share created explorations with other property users | Share exploratory analysis with the team |
Viewer | View data and create, edit or delete their own explorations | Review data and conduct individual analysis |
A Viewer can create their own explorations. Do not assume that creating one always requires Analyst access; check whether sharing or configuration changes are actually needed. Consult Google's access and data-restriction documentation for the complete permission details.
Restrict cost or revenue data separately
The No Cost Metrics and No Revenue Metrics restrictions are separate from roles. They can help limit financial information visible to someone who needs behavioral data. They do not automatically change access to every external dashboard or previously exported report, so review those sharing settings separately.
How to add a GA4 user
- Confirm the person's Google Account email address and the work they need to perform. It can be a non-Gmail address if it is registered as a Google Account.
- Select the correct property in GA4 and open Admin.
- Choose Account access management or Property access management, depending on the intended scope.
- Select the plus button, then Add users, and enter the email address.
- Choose the role and any required data restrictions. Check the email-notification option.
- Recheck the recipient and scope, then add the user.
- Ask the person to sign in with that Google Account and confirm that they can open the property and perform the intended work.
You do not need to share a Google Account password. Individual access makes it possible to remove a person's permissions when responsibilities change. If menu placement changes, look for access management within Admin.
Example access request for an external partner
“Please analyze traffic and the path to purchase for our store, property ID XXXX. We will assign Analyst so you can share explorations. If you need to change event settings, discuss the proposed change with us first. We will review access when the engagement ends.”
This is a sample request, not a universal permission prescription. Choose the role based on the actual work. A clear task description helps avoid granting Administrator simply because the requested scope was unclear.
How to change or remove permissions
Open the relevant access-management page, select the user, change the role or restrictions and save. Check the same scope used for the original assignment and review any inherited access that might remain.
To remove access, select the relevant user in access management and use its removal action. Removing a user at account level can affect the properties beneath it. Confirm the replacement owner can access what they need before changing management access.
See Google's instructions for adding, editing and deleting users for the detailed workflow. Treat access changes as a handover task: record the reason and check the result rather than assuming the smallest visible change has the smallest impact.
Troubleshooting: cannot add a user or see a property
Symptom | Check first | Next step |
|---|---|---|
You cannot add users. | Whether you are an Administrator at the relevant scope | Ask the account or property administrator to make the change. |
An email address cannot be added. | Spelling and Google Account registration | Confirm the address the recipient actually uses to sign in. |
The recipient cannot see the property. | Whether they signed in with another Google Account | Switch accounts and compare the property ID. |
Someone can still edit after being assigned Viewer. | Inherited access from accounts or groups | Compare direct assignments with effective permissions. |
Some financial figures are unavailable. | Cost or revenue restrictions | Ask an administrator to review them if access is needed for the task. |
You cannot edit a GTM tag. | GTM permissions | Review Tag Manager access separately from GA4. |
Not every missing-data issue is a permissions issue. If the property opens but the expected data is absent, also inspect date ranges, filters, tracking and data-processing status.
Maintain permissions after sharing
- Record who received access, to which property and with which role.
- Schedule an access review when an external engagement ends or ownership changes.
- Periodically look for unused accounts and roles broader than the task requires.
- Review related access in GTM, Search Console and reporting destinations.
Choose permissions in this order: scope, required actions, then role. If the work involves measurement changes, use the GTM click-event setup guide to agree on the implementation owner and validation steps.
For recurring reports across several sources, NeX-Ray offers data aggregation and reporting options for supported services. Review source-service permissions and report-viewer access as separate parts of the setup.
Official information reviewed: September 22, 2026.




