How to Get Access to a Client's Google Ads and GA4

The exact steps to get access to a client Google Ads account and their GA4 property, which permission level to ask for, plus a checklist you can copy today.

Ready to get started?

Set up in 2 minutes. White-label reports and AI insights.

14-day free trial - 2 min setup - no credit card required

How to Get Access to a Client's Google Ads and GA4

Last updated: September 2026

Every agency onboarding stalls in the same place. The contract is signed, the kickoff call went well, and then two weeks disappear while someone on the client's side tries to remember which Gmail address owns the Google Ads login and whether their old web developer still has admin on the analytics property.

Here is the short answer to how to get access to client Google Ads account data: send a link request from your manager account using the client's 10-digit customer ID, then have an admin on their side approve it under Admin, then Access and security, then Managers. GA4 is a completely separate job with a separate set of roles, and asking for both in one vague email is why so many access requests sit unanswered.

This guide covers both platforms, the exact permission level to ask for (lower than most agencies request), what changed in Google Ads security in 2026, and a client account access checklist you can paste straight into your onboarding document. If you want the product-specific version, our Google Ads connection docs spell out what ReportsMate itself needs.

Key takeaways

  • To get access to a client's Google Ads account, send a manager account link request from your MCC using their 10-digit customer ID; an admin on the client's account approves it under Admin, then Access and security, then Managers.
  • Google Ads has five access levels: Email only, Billing, Read only, Standard and Admin. Reporting only needs Read only.
  • GA4 access is granted separately at property level under Admin, then Property access management. Viewer is the minimum role, and it is enough for any reporting tool to read the data.
  • Google is rolling out passkey confirmation for sensitive actions such as user access changes and account linking, and free-domain email addresses like @gmail.com can be blocked from completing them.
  • In ReportsMate's own production data, every client with a Google Ads connection also has a GA4 connection. Not one has Google Ads on its own.

What this guide covers

  1. What access you actually need
  2. How to get access to a client Google Ads account
  3. How to send a GA4 access request that gets approved
  4. What changed in Google Ads access in 2026
  5. The client account access checklist
  6. What our own data says about access delays
  7. FAQs

What access do you actually need to report on Google Ads and GA4?

For reporting, you need Read only access in Google Ads and the Viewer role in GA4. Nothing higher. Most agencies ask for admin on both out of habit, which is exactly the request a cautious client or their IT team pushes back on.

Google Ads uses five access levels, and the differences matter when you are writing the access request email. Per Google Ads Help:

Google Ads access levelWhat it allowsRight for reporting?
Email onlyReceives notification emails and reports, cannot sign inNo, cannot pull data
BillingManages payment details and the payments profileNo
Read onlyViews campaigns, uses planning tools, runs reportsYes, the minimum you need
StandardEverything in Read only plus editing campaigns and creating conversions from Analytics eventsOnly if you are also managing the account
AdminFull control, including granting access and linking manager accountsOnly for the account owner

GA4 works differently. Roles are assigned per property (or per account) and come in five levels: Administrator, Editor, Marketer, Analyst and Viewer, according to Google Analytics Help. There are also two data restrictions, No Cost Metrics and No Revenue Metrics, which a nervous client can apply if they do not want an outside party seeing spend or revenue figures.

A quick vocabulary note, because these terms get used loosely. A manager account (still widely called an MCC, short for My Client Center) is the umbrella Google Ads account an agency uses to hold client accounts without owning them. Read only in Google Ads and Viewer in GA4 are both read permissions, but they are granted through completely different interfaces, so one does not imply the other.

How to get access to a client Google Ads account

There are two routes into a client's Google Ads account, and choosing the right one saves a week of back and forth.

Route 1: link the account to your manager account (recommended for agencies).

  1. Get the client's 10-digit Google Ads customer ID. It sits in the top right of their account interface. This is the single piece of information you need from them before you start.
  2. Sign in to your manager account, go to the Accounts page and choose the option to link an existing account.
  3. Enter the customer ID, one per line if you are requesting several at once, and send the request. Google Ads Help documents the full linking flow.
  4. Tell the client exactly where to approve it: Admin, then Access and security, then the Managers tab, then Accept under Link request. Screenshot that path in your email. This one instruction is the difference between same-day approval and a fortnight of silence.
  5. Once linked, set your own team's access level inside the manager account rather than asking the client again.

Route 2: ask for a user invitation (fine for one-off audits).

The client's admin goes to Admin, then Access and security, then the Users tab, adds your work email address and picks Read only. You will get an invitation email that expires, so accept it promptly. This route is faster for a single account but does not scale, because every account has to be invited and accepted individually and the access is tied to one person's login rather than to your agency.

Route 1 is worth the extra step almost every time. Manager account access survives staff turnover, gives you a single place to see spend across the roster, and makes manager account reporting far less painful at month end. One caveat worth knowing before you connect a reporting tool: your Google login generally needs permission at the individual account level inside the manager account, not just at the manager level.

How to send a GA4 access request that gets approved

A GA4 access request is granted at property level, not account level, and the person granting it must be an Administrator on that property. The most common reason an access request fails is that the client asks the wrong colleague, usually whoever built the website five years ago and no longer has admin themselves.

Send the client these steps verbatim:

  1. Open Google Analytics and click Admin in the bottom left.
  2. Check the Property column at the top shows the correct property. Agencies routinely get access to a decommissioned property and spend a day wondering why sessions read zero.
  3. Click Property access management.
  4. Click the plus icon in the top right and choose Add users.
  5. Enter the agency email address, tick Viewer, and click Add.

That is all it takes to grant agency access to Google Analytics for reporting purposes. If the client wants extra caution, ask them to apply the No Revenue Metrics restriction rather than refusing access outright, so you can still report traffic, engagement and conversions.

Two things to confirm at the same time. First, ask which property is the source of truth if they have more than one, and get the property ID rather than the name. Second, make sure GA4 is what you are being given: Universal Analytics properties are long gone and any reporting tool worth connecting, ReportsMate included, reads GA4 properties only.

What changed in Google Ads access in 2026

Google has tightened the security around what it calls sensitive actions, and that directly affects agency onboarding. Sensitive actions include account linking updates and user access changes, which is to say, the exact two things you are asking your client to do.

Two changes matter for your access request:

  • Passkey confirmation. Google is rolling out a requirement, gradually and to a subset of advertisers, for a passkey to confirm identity when completing sensitive actions. A passkey is a device-bound credential unlocked with biometrics or a PIN rather than a password. Google Ads Help notes that after creating a passkey you should allow about one to two days before using it for sensitive actions, and that account administrators can set a "Required as of" enforcement date up to 30 days out.
  • Corporate email domains. Google's guidance says users on free domains such as @gmail.com or @yahoo.com may be blocked from completing sensitive actions and should move to a Google Account on a corporate email domain.

The practical consequence for agencies is simple. If your team still runs client work through a personal Gmail address, your access approvals can fail at the last step with no obvious explanation. Move your practitioners onto your agency domain, get a passkey set up before onboarding season rather than during it, and warn clients that their own approval may now require a passkey prompt they were not expecting.

The client account access checklist

Turn access into a standard onboarding step rather than a scramble. Here is the client account access checklist we would put in front of a new client in week one.

Before you ask:

  • Confirm who on the client side actually holds Admin on Google Ads and Administrator on the GA4 property. Ask for the person, not the department.
  • Confirm your own agency email addresses are on your domain, not a free one.
  • Have your manager account customer ID ready in case they want to verify you.

What to request, platform by platform:

PlatformWhat to ask forWhere the client does it
Google AdsManager account link request approval, or a Read only user invitationAdmin, then Access and security, then Managers or Users
Google Analytics 4Viewer role on the named propertyAdmin, then Property access management
Google Search ConsoleFull or Restricted user on the correct propertySettings, then Users and permissions
Google Business ProfileManager access on the business profileBusiness Profile settings, then People and access
Meta AdsPartner access to the ad account via Business ManagerBusiness settings, then Partners

After access lands:

  • Connect each platform to your reporting tool the same day. Access you do not use is access you discover is broken six weeks later.
  • Record which login holds the access, so a staff departure does not quietly take reporting with it.
  • Set the reporting cadence (how often the client gets a report) at the same moment, while the account is fresh in everyone's mind. Our guide to onboarding clients with automated reports from day one goes deeper on sequencing this.
  • Diarise a check for expiring connections. Google refresh tokens persist until revoked, but other platforms expire on a timer.

What our own data says about access delays

We looked at our own production database while writing this, and the numbers are a decent mirror of how agency onboarding really goes. Across the 43 client records that currently have at least one platform connected in ReportsMate:

  • GA4 is the most-connected platform, present on about 7 in 10 of those clients. Google Ads sits on roughly 3 in 10.
  • Every single client with Google Ads connected also has GA4 connected. Not one client in the database has Google Ads without analytics alongside it, which says something about how agencies think about proving performance: spend data on its own does not answer the client's question.
  • The median gap between a client being set up and their first platform connection going live is about 25 days. But roughly 1 in 3 of those connections happened within an hour of the client record being created.

That split is the whole story of access. When the agency has the credentials in hand, connection is a matter of minutes. When they do not, the request sits in an inbox for three weeks and the first report slips a month. The fix is not a better tool, it is asking for the right permission level, from the right person, with the click path written out.

One more detail from the same data: of the 54 platform connections in our database, every Google connection is currently active, and the only expired ones are Meta. That matches how the platforms behave. Google refresh tokens hold until someone revokes them, while Meta access tokens expire on a schedule, so Meta is the connection your team should be re-checking.

We built ReportsMate email-first because, after years around agency reporting, we watched clients ignore login-required dashboards almost entirely while the same numbers in an inbox got read. That design choice starts here: no branded report ever lands in a client's inbox until the access step is done, which is why we treat it as part of the product rather than an afterthought. Once a platform is connected, you can see how the reports get built and scheduled without anyone touching a spreadsheet.

FAQs

Q: How do I get access to a client's Google Ads account without their password?

A: You never need their password, and asking for one is a red flag to any client with decent security practices. The correct method is a manager account link request: you send it from your MCC using their 10-digit customer ID, and an admin on their account approves it under Admin, then Access and security, then the Managers tab. Alternatively they can invite your work email address as a Read only user under the Users tab. Both methods tie the access to your own Google login, so it survives their password changes and yours. If a client insists on sharing a login, push back politely, because shared logins break the moment two-factor authentication or a passkey requirement kicks in.

Q: What is the difference between Read only and Standard access in Google Ads?

A: Read only lets a user view campaigns, use planning tools and run reports, but change nothing. Standard adds the ability to edit campaigns and create conversions from Google Analytics events. If your agency is only reporting on the account, Read only is the correct request and it is easier for the client to approve. If you are also managing bids, budgets and creative, you need Standard. Neither level lets you add other users or change account links; that is Admin. Asking for the lowest level that does the job is both good security practice and a faster path to a yes.

Q: Why can't I see the client's GA4 property after they granted access?

A: Nine times out of ten they granted access on the wrong property, or granted it at account level to a different account than the one holding the property you need. Ask them for the numeric property ID rather than the property name and check it matches. The other common cause is that the person who granted access was not an Administrator on that property, so the change never applied. You can also hit this if you authenticated your reporting tool with a different Google account than the one they invited, which happens constantly when practitioners have both a personal and an agency login in the same browser.

Q: Do I need a Google Ads manager account to report on client accounts?

A: No, but it makes agency life much easier. Without a manager account you rely on individual user invitations, which are tied to one person and have to be repeated for every client. With google ads manager account access you get one place to see every linked account, consistent permissions across your team, and access that survives staff changes. For connecting a reporting tool, note that your Google login usually needs access at the individual account level inside the manager account, not just at the manager level, which is a frequent cause of accounts not appearing in the connection list.

Q: How long should client access take to set up?

A: When the client's admin is on the call and knows where the settings live, both Google Ads and GA4 take under ten minutes combined. In our own data the split is stark: about 1 in 3 client connections go live within an hour, while the overall median is around 25 days. The difference is almost always administrative, not technical. Send the click path in writing, name the exact person who needs to do it, and set a deadline tied to the first report date rather than leaving it open ended.

Q: What access do I need for Search Console and Google Business Profile?

A: Search Console uses Full and Restricted user roles, granted under Settings, then Users and permissions, and Restricted is enough to read performance data. Google Business Profile uses Owner and Manager roles, and Manager is the right ask for an agency reporting on local visibility. Both are worth requesting in the same email as Google Ads and GA4, because a second round of access requests two weeks later is where onboarding momentum dies. Our integrations page lists which platforms feed into a single client report.

Q: What happens to reporting if a client revokes access?

A: The connection stops returning data and your next scheduled report either fails or arrives with a gap, which is a bad way to find out. Revocation usually happens innocently: a staff member leaves, their Google account is deleted, and the access that was tied to them goes with it. Protect against it by connecting through a manager account and a shared agency login rather than an individual's personal account, and by checking connection status before each reporting cycle rather than after. Reporting tools, ours included, will flag an expired or revoked connection, but only if someone is watching the notification.

Q: Is it safe to give a reporting tool access to client ad accounts?

A: It depends entirely on what the tool asks for. A reporting platform should request read scopes only, because it has no business editing campaigns. ReportsMate connects with read-only permissions, and needs Read only or Standard on Google Ads and Viewer on GA4, which is the level any reporting tool should be satisfied with. Be sceptical of anything requesting write access it cannot justify, check the consent screen before approving, and remember that you can revoke a tool's access from your Google Account permissions at any time without disturbing the underlying client relationship.

Final tips before you send the access request

Knowing how to get access to client Google Ads account data and GA4 properties is an onboarding problem dressed up as a technical one. The agencies that get connected same-day are not more technical, they just ask better: one email, the right permission level, the exact click path, and a named person on the client side who actually holds admin.

Three habits worth adopting. Ask for the lowest access level that does the job, because Read only and Viewer clear internal approval far faster than admin. Request every platform in one message rather than drip-feeding them. And connect each platform the day access lands, so a broken permission surfaces immediately rather than the night before the first report is due.

Once the access step is done, reporting should stop being a job. Connect the platforms once, set a cadence, and the report writes and sends itself under your branding. You can compare what each plan includes on our pricing page.

Stop losing your Sundays to client reports. Start your free 14-day trial - no credit card, no setup fees, cancel anytime. Your clients get branded reports in their inbox automatically, the day after access lands.

Automate Your Marketing Reporting

Join agencies automating client reporting with ReportsMate.

14-day free trial - 2 min setup - no credit card required