What Account Access Should a Marketing Agency Request From a New Client?

An access-request matrix for agency operations: what to request, how narrowly to scope it, and how to prove the team can use the right account.

Article metadata

Franco Maccarone

Written by

Franco Maccarone

Founder, LeadUp

  • 5 min read

A marketing agency needs access to the accounts required to deliver its contracted work. Start with the task, then identify the asset and permission. A reporting engagement should not automatically receive the same access as a website migration or paid-media launch.

Build your marketing agency client access checklist as a register: resource, ID, purpose, recipient, requested role, client approver, status, and verification evidence. This article covers that register; use the broader onboarding checklist for scope, kickoff, and delivery planning.

Which accounts should you request?

Treat this matrix as a menu. Remove rows that do not serve a contracted task. Role names outside the Google products vary by platform, so confirm the permission that enables the stated task.

Account or assetRequest whenScope and verification
Google AdsManaging or auditing Google campaignsRecord customer ID; confirm the intended MCC link or named user and open the correct account
Google Analytics 4Reporting or configuring measurementRecord property ID and site; verify the required reports or settings
Google Tag ManagerAuditing or implementing tagsRecord each container ID; verify its installed use and required container permission
Other ad platformsManaging campaigns on those channelsRequest the specific advertising assets through the platform’s business-access controls
CRMReconciling lead quality or maintaining campaign integrationsLimit access to relevant pipelines, records, and integration tasks; inspect a permitted test lead
Call trackingMeasuring and reviewing phone leadsIdentify the account and numbers; test routing and the agreed reporting workflow
CMS or landing-page builderPublishing or changing campaign destinationsScope editing to needed sites; confirm the review and release process
Search ConsoleSEO diagnostics or search reportingConfirm the exact property; request permissions appropriate to the agreed SEO tasks
Social pages and profilesPublishing, moderation, or connected advertisingName each asset and the publishing or advertising responsibility
Creative libraryProducing client contentRequest current approved files and working assets; verify usage approval with the client
Product catalog or merchant accountShopping campaigns or feed workIdentify the catalog, destination market, feed source, and who fixes product issues
Domain, DNS, or hostingA specific technical change requires itPrefer a client technical owner making an approved change; document any temporary access

Do not collect payment-card details in the access register. Record who handles billing and whether the required setup is complete.

Set Google permissions by the work assignment

For Google Ads, distinguish a direct user invitation from an agency manager link. Use the Google Ads access guide to choose a route and complete client approval.

For GA4, decide whether one property is sufficient before asking for the entire account. Use the Analytics access guide to match the role to reporting, measurement configuration, or user administration.

For GTM, specify both account and container requirements. Use the Tag Manager access guide to agree who can prepare changes and who can publish them.

These are separate checks. Do not assume that connecting the advertising account makes every measurement resource available to the same agency user.

Send a request the client can route correctly

The day-to-day contact may not administer the accounts. Give them a forwardable request with the right technical detail:

For [deliverable], please ask [account administrator] to grant [recipient] access to [resource and ID] with [role]. We need this to [task] by [date]. Please confirm when complete, or introduce us to the person who manages this resource. Do not send passwords.

Group requests by the person who can resolve them. The marketing lead might handle brand files, IT might handle website permissions, and finance might handle billing. Sending everyone the entire list makes ownership less clear.

Verify access before marking a row complete

Use a short, explicit status sequence:

  1. Requested: the right client contact has the request.
  2. Granted, not verified: the client reports completion or an invitation arrives.
  3. Verified: the assigned specialist opens the intended resource and confirms the required capability.
  4. Blocked: record the exact problem, owner, next action, and affected deliverable.

Example: “GTM account visible, production container missing; agency access owner to check the requested container and role with the client; tracking QA blocked.” That is more useful than “GTM pending.”

Attach a resource link or a brief verification note without copying sensitive client data into a broadly shared project. Avoid unnecessary live edits, exports, or test spending to prove permission.

Keep ownership and offboarding in the same record

Record a client administrator and backup, the agency’s responsible person, and a review date. Use named work identities with two-step verification and keep client-controlled administration in place.

During handover, inventory existing agency connections before removing them. An old connection may still support reporting or an integration that needs a replacement. At the end of the engagement, reconcile direct users, manager or partner links, and integration access with the client.

For Google Ads accounts in an agency portfolio, record the manager link and responsible agency user alongside the client administrator. The multi-account management guide explains how those accounts fit into the agency hierarchy.

Collect supported Google access in one flow

If Ads, Analytics, and GTM are part of the request, LeadUp can collect account access in one flow. The agency configures its request, and the client signs in with Google and chooses accounts to share.

Account for the scope: Analytics requests are at the account level, and GTM account and container permissions can be configured directly in LeadUp. Keep CRM, call tracking, other advertising platforms, and technical website access as distinct rows in the register. Review results against the requested IDs before changing any row to Verified.

Related articles

Client Account Access

Need help collecting client account access?

See how LeadUp guides clients through sharing Google Ads, Analytics, and Tag Manager account access with your agency.

Pick the path that fits your timeline. Both go directly to our team.

Share your goals

Tell us about your stack, priorities, or blockers and we will recommend the next best step.