A marketing agency needs access to the accounts required to deliver its contracted work. Start with the task, then identify the asset and permission. A reporting engagement should not automatically receive the same access as a website migration or paid-media launch.
Build your marketing agency client access checklist as a register: resource, ID, purpose, recipient, requested role, client approver, status, and verification evidence. This article covers that register; use the broader onboarding checklist for scope, kickoff, and delivery planning.
Which accounts should you request?
Treat this matrix as a menu. Remove rows that do not serve a contracted task. Role names outside the Google products vary by platform, so confirm the permission that enables the stated task.
| Account or asset | Request when | Scope and verification |
|---|---|---|
| Google Ads | Managing or auditing Google campaigns | Record customer ID; confirm the intended MCC link or named user and open the correct account |
| Google Analytics 4 | Reporting or configuring measurement | Record property ID and site; verify the required reports or settings |
| Google Tag Manager | Auditing or implementing tags | Record each container ID; verify its installed use and required container permission |
| Other ad platforms | Managing campaigns on those channels | Request the specific advertising assets through the platform’s business-access controls |
| CRM | Reconciling lead quality or maintaining campaign integrations | Limit access to relevant pipelines, records, and integration tasks; inspect a permitted test lead |
| Call tracking | Measuring and reviewing phone leads | Identify the account and numbers; test routing and the agreed reporting workflow |
| CMS or landing-page builder | Publishing or changing campaign destinations | Scope editing to needed sites; confirm the review and release process |
| Search Console | SEO diagnostics or search reporting | Confirm the exact property; request permissions appropriate to the agreed SEO tasks |
| Social pages and profiles | Publishing, moderation, or connected advertising | Name each asset and the publishing or advertising responsibility |
| Creative library | Producing client content | Request current approved files and working assets; verify usage approval with the client |
| Product catalog or merchant account | Shopping campaigns or feed work | Identify the catalog, destination market, feed source, and who fixes product issues |
| Domain, DNS, or hosting | A specific technical change requires it | Prefer a client technical owner making an approved change; document any temporary access |
Do not collect payment-card details in the access register. Record who handles billing and whether the required setup is complete.
Set Google permissions by the work assignment
For Google Ads, distinguish a direct user invitation from an agency manager link. Use the Google Ads access guide to choose a route and complete client approval.
For GA4, decide whether one property is sufficient before asking for the entire account. Use the Analytics access guide to match the role to reporting, measurement configuration, or user administration.
For GTM, specify both account and container requirements. Use the Tag Manager access guide to agree who can prepare changes and who can publish them.
These are separate checks. Do not assume that connecting the advertising account makes every measurement resource available to the same agency user.
Send a request the client can route correctly
The day-to-day contact may not administer the accounts. Give them a forwardable request with the right technical detail:
For [deliverable], please ask [account administrator] to grant [recipient] access to [resource and ID] with [role]. We need this to [task] by [date]. Please confirm when complete, or introduce us to the person who manages this resource. Do not send passwords.
Group requests by the person who can resolve them. The marketing lead might handle brand files, IT might handle website permissions, and finance might handle billing. Sending everyone the entire list makes ownership less clear.
Verify access before marking a row complete
Use a short, explicit status sequence:
- Requested: the right client contact has the request.
- Granted, not verified: the client reports completion or an invitation arrives.
- Verified: the assigned specialist opens the intended resource and confirms the required capability.
- Blocked: record the exact problem, owner, next action, and affected deliverable.
Example: “GTM account visible, production container missing; agency access owner to check the requested container and role with the client; tracking QA blocked.” That is more useful than “GTM pending.”
Attach a resource link or a brief verification note without copying sensitive client data into a broadly shared project. Avoid unnecessary live edits, exports, or test spending to prove permission.
Keep ownership and offboarding in the same record
Record a client administrator and backup, the agency’s responsible person, and a review date. Use named work identities with two-step verification and keep client-controlled administration in place.
During handover, inventory existing agency connections before removing them. An old connection may still support reporting or an integration that needs a replacement. At the end of the engagement, reconcile direct users, manager or partner links, and integration access with the client.
For Google Ads accounts in an agency portfolio, record the manager link and responsible agency user alongside the client administrator. The multi-account management guide explains how those accounts fit into the agency hierarchy.
Collect supported Google access in one flow
If Ads, Analytics, and GTM are part of the request, LeadUp can collect account access in one flow. The agency configures its request, and the client signs in with Google and chooses accounts to share.
Account for the scope: Analytics requests are at the account level, and GTM account and container permissions can be configured directly in LeadUp. Keep CRM, call tracking, other advertising platforms, and technical website access as distinct rows in the register. Review results against the requested IDs before changing any row to Verified.
