Step-by-step guide
Last updated: August 2026
Have these ready — it's what onboarding stalls on:
Grant the minimum the work needs. On Google Tag Manager, the levels are:
| Access level / role | What it can do |
|---|---|
| Read | View the container, no changes. |
| Edit | Create and edit tags, triggers and variables in a workspace. |
| Approve | Edit plus approve changes in workflow-enabled containers. |
| Publish | Edit, approve and publish container versions live. Agencies implementing tracking usually need Edit + Publish. |
1–2 minutes. Invite the user with container permissions; access is immediate.
Open Admin → User Management → Container and grant the access — a few minutes.
Accept and confirm from their side, then start work.
Access is granted when:
The most common problems and how to fix them:
GTM has two layers. Account access alone doesn't let them edit a container — set container-level permissions too.
They have Edit but not Publish. Raise the container permission to Publish.
Someone with Publish must publish the container version; drafts in a workspace aren't live until published.
The agency is invited by their own Google email with only the container permissions you choose — no password shared, removable anytime from User Management.
Everything above is why agencies switch to a single link. HandItSafe requests exactly this Google Tag Manager access for you — the client approves through Google Tag Manager's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.
FAQ
No. The agency is invited by their own Google email with only the container permissions you choose.
Usually Edit and Publish on the specific container. Approve is optional for workflow control.
Admin → User Management → remove the user. HandItSafe also gives your client one-tap removal.
Account controls who's on the account; container controls what they can do in a specific container. Agencies need container Edit + Publish on the containers they manage.
Yes. Grant account access with no account permissions, then set container permissions only on the container they work in.
Keep reading
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.