The rule that generates the whole list
There is one rule, and every row of the table below falls out of it: you own the account, the agency gets a named seat inside it. Not your login. Not a password in a shared vault. A seat granted to their work email, at the lowest role that lets them do the job, which you can remove yourself in about ten seconds.
Almost every access mess we get called into traces back to a decision made on day three, when nobody wanted to slow the kickoff down. Someone said "just make me admin, it's faster", and it was faster, and eight months later the Business Profile that produces most of the phone calls sits in an account nobody at the company can open.
This is not a trust judgement about the agency you're hiring. It's a continuity decision. People leave agencies, agencies fold, and the account has to outlive both.
Property by property: the permission to grant
Here is the whole list with the correct answer for each. Two things to notice: nothing here needs a shared password, and nothing here needs the agency to own anything.
The Google Business Profile row is the one people get wrong most often and the most expensive one to get wrong. A manager can edit the listing, post, reply to reviews and read the insights — everything the day-to-day work needs. What a manager cannot do is add or remove users, or delete the profile. That is exactly the pair of powers that turns an ordinary breakup into a month of unanswered emails.
| Property | Grant this | Not this | Why |
|---|---|---|---|
| Google Search Console | Full user | Delegated owner | Full users see every report and can act on it. Owners can add and remove other users — that job stays with you. |
| Google Analytics 4 | Editor | Administrator | Editor is full control of property settings. Administrator adds user management, which is the one power worth keeping. |
| Google Business Profile | Manager | Owner | Managers do everything operational. Owners control who else is in the profile and whether it continues to exist. |
| Google Ads | A link from their manager account to yours | Your login, or admin on your account | The link is requested against your customer ID and accepted by you, and you can unlink it from Access and security. |
| Meta — Facebook and Instagram | Partner access to named assets in your Business Manager | Admin on your Business Manager | The Page and the ad account stay in your business. Their business gets scoped access to the assets you list. |
| CMS — WordPress or similar | Editor | Administrator | Editor publishes and edits everything, including other people's posts. Administrator installs plugins and creates users. |
| Hosting and server | Nothing by default | Root, SSH, cPanel, database | Route server changes through whoever owns the server. If a scoped account is genuinely needed, close it when the task ships. |
| Domain registrar and DNS | Nothing, ever | Anything at all | This is the company. Read the DNS record out to them if they need one added — don't hand over the keys. |
The two we won't take, and what to do if someone already has them
Two accesses no marketing agency should hold: your domain registrar and your hosting root.
The registrar is the company. Whoever controls it controls the nameservers, and whoever controls the nameservers controls the website, the email, and your ability to prove to Google that any of it is yours — a Search Console domain property is verified by a DNS record, so DNS control and search ownership move together. There is no support ticket that fixes a registrar you cannot log into and cannot prove is yours.
Hosting root is the same problem with a shorter fuse. Root gets you the database, every customer record in it, and the ability to take the site down at 2am. An SEO team needs to change titles, add schema, edit robots.txt and ship redirects. None of that requires root — it requires a scoped account, or a developer who takes the ticket.
If an agency already holds either one, don't announce the fix. Do it, then tell them.
- Registrar first. Log in, change the password, change the recovery email and phone to yours, enable 2FA on your own device, then remove every other contact. Do this before anything else on the list.
- If the domain is registered in the agency's name rather than your company's, this is a transfer, not a password change. Ask for the auth code in writing, expect it to take days, and stay polite while it does — you need their cooperation exactly once.
- Hosting. Rotate root credentials and SSH keys, then re-issue scoped accounts only to people who genuinely need them.
- Google Business Profile. If the agency is the verified owner, you request ownership through the profile. The current owner is notified by email and gets three days to respond; if nobody responds you may be able to claim it. Slow, but it works.
- Then write down who holds what, in one document, with dates. If that document doesn't exist, the access problem is yours rather than the agency's.
What we ask for on day one, and what we decline
Our own list, published so you can hold us to it. This is all of it.
- Registrar and DNS — declined. Tell us the record you need and we'll give you the exact string to paste, once.
- Hosting root, SSH, cPanel, database — declined. Server-side changes go to whoever owns the server, as a written ticket with a diff.
- Your personal Google account password — declined, and if any agency asks for it, that's the meeting over.
- Payment methods on ad accounts — your card, your billing profile. Ad spend is billed to you directly with no media markup, which only works if the account is yours.
- Search Console — full user on the domain property. If the property doesn't exist yet, we tell you which DNS record to add; you add it, and the verification stays with you.
- GA4 — editor. We build the key events and the reports; you keep the ability to remove us.
- Google Business Profile — manager, on the profiles in scope. Never owner.
- CMS — editor, or whatever scoped role your setup has. If your team would rather we file pull requests than touch the CMS at all, that's better, not worse.
- Google Ads, only if we're running it — a link from our manager account to yours, requested by us and accepted by you.
- Everything else read-only — past reports, crawl exports, backlink exports, the old agency's deliverable log. Sent as files, not as logins.
Why day three decides how bad exit day is
Offboarding an agency that only ever held delegated access is a twenty-minute job. You open five screens, remove one user from each, and you're done. Nothing breaks, no data moves, no history is lost, because nothing was ever theirs to begin with.
Offboarding an agency that holds ownership is a negotiation — and the party holding the account sets the pace of it. Ask anyone who has priced the real cost of switching SEO agencies: the notice period is rarely the expensive part.
So run the access audit twice a year, and again on the day anyone leaves either side. Open each property, read the user list out loud, and remove every name you can't account for. Fifteen minutes.
- Search Console → Settings → Users and permissions
- GA4 → Admin → Property access management
- Google Business Profile → the profile → Managers
- Google Ads → Admin → Access and security, then the Managers tab for linked manager accounts
- Meta Business Manager → Settings → Partners
- Your CMS user list, your registrar's contacts, your hosting accounts