Setting up user permissions in Google Analytics is one of those tasks that seems small until it isn’t. Give someone the wrong level of access and they can see far more than you meant to share. Some roles can also change how your data gets collected.
The danger is how easily it happens. Someone asks for access to one website and gets added at the account level instead, which hands them the analytics for every site in that account.
What separates those two outcomes is a single setting. This guide walks through how Google Analytics user permissions work and how to manage them. You’ll learn how to share the right level of access with team members, contractors, or agencies — without giving up control of your data.
In This Article:
- What Are Google Analytics Permissions for Users?
- Google Analytics Permission Levels: Account vs. Property
- The 6 Google Analytics User Roles and What Each One Can Do
- Data Restrictions: Hiding Cost and Revenue Metrics
- Effective Roles vs. Direct Roles: Access You Didn't Grant
- Which Google Analytics Role to Give Each Person on Your Team
- How to Add a User to Google Analytics
- How to Edit or Remove a Google Analytics User
- How to Control Who Sees Your Analytics Data in WordPress
- FAQs About Google Analytics Permissions
What Are Google Analytics Permissions for Users?
User permissions are the different levels of access you can give people in your Google Analytics account.
The right permissions keep a contractor out of your whole account, and keep a stakeholder from changing how your data is collected. Every grant of access comes down to two decisions: which role someone gets, and where that role applies.
There are six roles you can assign:
- Administrator
- Editor
- Marketer
- Analyst
- Viewer
- None
And there are two levels where you can apply them:
- Account level
- Property level
As the owner of your Analytics account, you can see all of the data, manage properties, and manage users. You may not want to give an assistant or an advertising agency that same reach.
That’s what user permissions were designed for: sharing your data and your reports while keeping full control of the account.
If you’re still working out how accounts and properties fit together, see our beginner’s guide on how Google Analytics works.
Both decisions happen in the same panel, and it makes sense to settle the level first.
Google Analytics Permission Levels: Account vs. Property
Google Analytics lets you provide permissions at two different levels of your Google Analytics account. The levels are based on how every Analytics account is structured, and picking the wrong one is how access can spread further than you intended.
You’ll find both levels on the Admin page: the Account card and the Property card each carry their own access management entry.
Here’s what each level covers.
1. Account Level
An account is the top-most level of organization. It can include multiple properties (websites).
Providing access at the account level means allowing access to all of the properties in your account.
For example, let’s say your company owns a handful of restaurants. Your company is the account level, and each restaurant site is a property. If you provide access to Analytics at your account level, that user will have access to Analytics for each one of your restaurant sites.
2. Property Level
A property is typically a website. In the restaurant example, each of those websites is set up as its own property.
Providing access at property level means allowing access to just that one property in your Google Analytics account.
The list of roles is identical at both levels. Only the wording changes: the account-level descriptions say “account” everywhere the property-level ones say “property.”
So the level answers how much someone can see, and the role answers what they can do with it.
Get the Level Right First
Access granted at the account level reaches every property in that account, including sites you may have forgotten are sitting in there. When someone only works on one website, grant it on that property instead.
The 6 Google Analytics User Roles and What Each One Can Do
Picking a role is the difference between a teammate who can answer their own questions and a teammate who can quietly change how your data is collected.
Google Analytics gives you five standard roles plus None, all in the same panel when you add someone.
Each role carries a one-line description straight from the product, and two of them fold in another role: Marketer includes Analyst, and Analyst includes Viewer. The roles stack.
Here’s what each one means in practice.
1. Administrator
Google Analytics calls this one “full control of property,” which includes adding, editing, and removing other users. Keep it for yourself and, at most, one person you’d trust with everyone else’s access.
2. Editor
An Editor can “edit all data and settings for property,” but “cannot manage users.” They can change how the property is configured, just not who else gets in — the role for whoever owns your tracking setup.
3. Marketer
Marketer can “edit audiences, key events, attribution models, lookback windows, and events for property,” and it “includes Analyst role.”
That’s the campaign-focused set: the visitor groups you care about and the actions that count as a win. If audiences are new to you, start with our guide to Google Analytics segments.
4. Analyst
An Analyst “can share created explorations to other users of the property,” and it “includes Viewer role.” Explorations are the build-your-own analyses in Google Analytics, and our guide to custom reports in Google Analytics shows what they look like.
Analyst is the usual choice for freelancers: they can build and share the analyses they need without touching a setting.
5. Viewer
A Viewer can “see report data and configuration settings for property,” and that’s where it ends — the role for clients and stakeholders who want the numbers, not the controls.
6. None
None means “no role assigned” at that level. It’s worth knowing because someone with a role on one property shows up as None at the account level.
Here’s how the six compare, including what each role carries over from the one below it.
| Role | What Google Analytics says it can do | What it includes |
|---|---|---|
| Administrator | Full control of the account or property | Everything, plus adding and removing users |
| Editor | Edit all data and settings. Cannot manage users. | All settings and data, no user management |
| Marketer | Edit audiences, key events, attribution models, lookback windows, and events | The Analyst role, which in turn includes Viewer |
| Analyst | Share created explorations with other users | The Viewer role |
| Viewer | See report data and configuration settings | Reading only — no changes |
| None | No role assigned | No access at that level |
One thing the roles don’t settle on their own: whether the person can see what you spend and what you earn.
Data Restrictions: Hiding Cost and Revenue Metrics
Say you want a freelance writer to see which posts earn the most traffic, but you’d rather not show them your ad spend or your revenue.
A role alone won’t do that, because even a Viewer can read report data. Google Analytics handles it with two data restrictions, which sit in the same panel as the roles, just below them:
- No Cost Metrics — “no access to cost-related metrics for property”
- No Revenue Metrics — “no access to revenue-related metrics for property”
You check them alongside the role, not instead of it. A Viewer with No Revenue Metrics still reads the traffic reports, with the money columns left out.
Both restrictions exist at the account level and the property level, so you can apply them wherever you granted the role.
No Cost Metrics can be the more useful of the two: someone who needs the traffic numbers doesn’t necessarily need the ad budget behind them.
One caveat: revenue metrics only appear in your reports if you’ve set up the tracking that produces them, which our guide to Google Analytics conversion tracking walks through.
Effective Roles vs. Direct Roles: Access You Didn’t Grant
This is the part of Google Analytics permissions where access can appear without you granting it.
Open any person in Property access management and you’ll see two cards, not one.
The Effective roles and data restrictions card is what that person can actually do right now. The Direct roles and data restrictions card below it is only what you granted at this level.
When the two disagree, the product tells you why. A banner on the Effective card reads “this user also has roles and data restrictions set in groups and/or higher-level,” with a See details button beside it.
In the capture below, the user’s effective role is Analyst while their direct role on the property is None. The Analyst role was granted at the account level and flows down to every property underneath.
So a Direct roles card that reads None is not proof that someone has no access to your data.
Roles reach a property two ways: from the account above it, or from a user group the person belongs to. Neither shows up on the Direct card.
Before You Audit Access
Read the Effective roles card, not the Direct roles card. A direct role of None can still sit underneath an inherited Analyst or Editor role from the account above it.
Which Google Analytics Role to Give Each Person on Your Team
Knowing what each role can do is one thing. Deciding which one to give the person actually asking is the harder part. The danger is that a guess could land on more access than you meant to give.
A role only reaches as far as the level you granted it at.
Administrator at the Account level can add, manage, and remove users across the account and every property inside it. The same role at the Property level can do that for one property only.
So, let’s go back to the restaurant example. For your business partner at your restaurant management company, you’d give permissions at the Account level, so they can access all of your different restaurant sites.
For a manager at one of your restaurants, you’d give access at the Property level so they can check on data just for that restaurant’s website.
Here’s a sensible starting point for some common access requests.
| Who needs access | Level | Role | Why |
|---|---|---|---|
| You, or a co-owner of every site | Account | Administrator | Full control, including adding and removing users |
| An agency running campaigns on one site | Property | Marketer | Edits audiences, key events and attribution, and reads everything an Analyst can |
| A developer who owns your tracking setup | Property | Editor | Changes any setting without managing users |
| A consultant digging into the data | Property | Analyst | Builds and shares explorations, changes nothing |
| A client who wants the numbers | Property | Viewer | Reads reports and configuration, nothing else |
| Anyone who shouldn’t see spend or earnings | Either | Any role, plus a data restriction | Hides cost or revenue metrics on top of the role |
When in doubt, start narrower than feels necessary. Widening access later takes a few seconds — explaining why a contractor could read your revenue for a year takes rather longer.
How to Add a User to Google Analytics
With the role and the level decided, granting the access is the quick part.
Start by signing in to Google Analytics and clicking Admin at the bottom of the left-hand menu. If signing in is the part giving you trouble, our guide on logging in to Google Analytics covers it.
On the Admin page, click Account access management to cover every property in the account, or Property access management to keep someone on one site. This walkthrough uses Property.
You’ll land on a list of everyone who already has access, with columns for Name, Email, and Roles and data restrictions. It’s worth reading that list before adding anyone, since it doubles as a quick access audit.
To add someone, click the blue + above the list, then choose Add users. The other option, Add user groups, grants the same access to a whole group at once.
Add users opens a panel titled Add roles and data restrictions. This is where the real decisions get made.
Type the person’s Google account address into the Email addresses field — that address is what they’ll sign in with. You can paste several at once if everyone gets the same access.
Notify new users by email is checked by default, and leaving it on means the person knows the access is waiting.
Then pick one of the standard roles and check a data restriction if you’d rather they didn’t see cost or revenue figures. Click Add in the top right, and the person has exactly the access you chose.
If none of this appears on your screen, it’s because managing users takes the Administrator role. Without it, Google Analytics explains that you have access to the account but not permission to manage its users, and offers Request access and View organization admins buttons.
Clicking Request access sends the ask to an Administrator, who can grant it.
How to Edit or Remove a Google Analytics User
Access can pile up. For instance, a contractor who finished in March may still be on the property in December, which is why this is worth doing once a quarter.
To change what someone can do, open access management at the level where their access lives, search for their name, and click it. Their panel carries Remove and Save in the top bar, so you adjust the role or the data restrictions and click Save.
To take access away entirely, you don’t need to open their panel at all. Simply check the box next to each person in the list instead, and the header switches to a count like “1 of 2 selected” with a red Remove beside it.
Remove only appears once a row is checked, so it won’t be there if you go looking before selecting someone.
There’s one catch, and it’s why the Effective roles card matters. Removing someone from a property doesn’t touch access they inherited from the account above it.
If their Effective card still shows a role, you’ll need to open Account access management and remove them there as well.
Removing a user doesn’t delete any of your historical data, and it doesn’t remove the property itself. If that’s what you’re after, our guide to deleting a Google Analytics property covers it.
How to Control Who Sees Your Analytics Data in WordPress
There’s a second permissions question, and it lives on your own website rather than in Google Analytics: who on your WordPress team gets to look at the numbers?
If your site runs on WordPress and you use MonsterInsights, the WordPress analytics plugin, the defaults already answer part of it.
Out of the box, Administrators and Editors can both see the reports, while only Administrators can save the settings. Read the data, don’t touch the setup — that’s a sensible default split, and it’s already on.
You’ll find the controls under Insights » Settings » Advanced, in the panel called Permissions. There are three fields:
- Allow These User Roles To See Reports — “users that have at least one of these roles will be able to view the reports.” Administrator and Editor by default.
- Allow These User Roles To Save Settings — “users that have at least one of these roles will be able to view and save the settings panel.” Administrator by default.
- Exclude These User Roles From Tracking — “users that have at least one of these roles will not be tracked into Google Analytics.” Administrator and Editor by default.
On the two Allow fields, the Administrator chip has no × on it: roles that can manage your WordPress options are locked in, so you can widen access without locking yourself out.
Administrator is removable from the tracking exclusion, since that field only decides whose visits get counted.
Add Author to the See Reports field and your writers can open Insights » Reports to see how their posts are doing. They won’t see a Settings item at all, since those screens are tied to the save-settings permission.
The Google connection is stored once for the whole site, not per person, so a WordPress user you’ve given report access needs no Google account and no entry in Google Analytics’ own access management list.
This is the WordPress-side answer to the same question, not a replacement for Google Analytics’ own permissions. A Viewer in Google Analytics gets the whole property inside Google’s interface; the Permissions panel gets a teammate to the numbers through the login they already have.
The two work together. The panel is available on every MonsterInsights plan, and the only prerequisite is a site already connected to Google Analytics.
Give Your Team Report Access Without a Google Login
Our documentation walks through the Permissions panel field by field, including which roles to add when someone should read the reports and nothing else.
Set Up Report PermissionsFAQs About Google Analytics Permissions
What’s the difference between Admin and Editor permissions in Google Analytics?
Administrator is full control, including adding, editing, and removing other users. Editor covers everything else: Google Analytics describes it as “edit all data and settings for property. Cannot manage users.” Editor suits whoever owns your tracking setup.
How do I remove a user from Google Analytics?
Open Admin, then Account access management or Property access management — whichever level granted the access. Check the box next to their name and click the red Remove in the list header. If they also hold a role at the account level, remove them there too, or their Effective roles card will still show it.
Can I give someone access to only view specific reports in Google Analytics?
Roles apply to a whole property rather than to individual reports, so even Viewer covers every report in that property. You can tighten it two ways: grant the role at property level, and add a data restriction to hide cost or revenue metrics. On the WordPress side, MonsterInsights lets you pick which user roles can open the reports.
What permissions do marketing agencies typically need?
It depends on the work. An agency running campaigns needs Marketer or Editor at the property level; one that only analyzes data needs Analyst. Marketer covers audiences, key events and attribution, and carries the Analyst role with it; Editor adds every other setting. Skip Administrator unless they genuinely need to manage users, since that gives them control of the account.
Do you need a Google account to be added to Google Analytics?
Yes. Access is granted to an email address, and that address is what Google Analytics checks at sign-in. If it isn’t tied to a Google account yet, the person needs to create one on it first.
Why can’t I add users to my Google Analytics property?
Managing users takes the Administrator role. With anything less, Google Analytics offers a Request access button that sends the ask to an Administrator, who can grant it.
Getting permissions right comes down to one habit: grant the narrowest access that does the job, then review the access list once a quarter. If you liked this article, check out the following beginner-friendly guides:
- What is Google Analytics 4? Should You Use It?
- MonsterInsights vs. Google Analytics – What’s the Real Difference?
- How to Create Google Analytics (GA4) Dashboards
- Google Analytics (GA4) Events: A Quick-Start Guide for Beginners
- Best Ways to Learn Google Analytics: Courses, Training, and More
Follow us on Twitter, Facebook, and YouTube for more Google Analytics tips.