Step-by-step guide

How to give agency access to Google Tag Manager

Last updated: August 2026

How to give agency access to Google Tag Manager: use GTM container-level user management — the agency is invited by email with container permissions. Open Admin → User Management → Container, add the agency, choose the access level, and confirm. You never share a password and can remove access anytime.

Before you start

Have these ready — it's what onboarding stalls on:

Step-by-step

  1. In GTM, open Admin.
  2. Under the container, click User Management.
  3. Click + then Add users.
  4. Enter the agency's Google email.
  5. Set container permissions (Read, Edit, Approve, Publish) and invite.
Where 90% of onboardings fail: Granting account-level instead of container-level access is common and over-permissive. Request the specific container.

Which access level to grant

Grant the minimum the work needs. On Google Tag Manager, the levels are:

Access level / roleWhat it can do
ReadView the container, no changes.
EditCreate and edit tags, triggers and variables in a workspace.
ApproveEdit plus approve changes in workflow-enabled containers.
PublishEdit, approve and publish container versions live. Agencies implementing tracking usually need Edit + Publish.

How long it takes, and who does what

1–2 minutes. Invite the user with container permissions; access is immediate.

What you (the client) do

Open Admin → User Management → Container and grant the access — a few minutes.

What the agency does

Accept and confirm from their side, then start work.

How to check it worked

Access is granted when:

If it doesn't work

The most common problems and how to fix them:

Granted account access but not container access

GTM has two layers. Account access alone doesn't let them edit a container — set container-level permissions too.

Agency can edit but can't publish

They have Edit but not Publish. Raise the container permission to Publish.

Changes not going live

Someone with Publish must publish the container version; drafts in a workspace aren't live until published.

Why you don't share a password

The agency is invited by their own Google email with only the container permissions you choose — no password shared, removable anytime from User Management.

The faster way: one link

Everything above is why agencies switch to a single link. HandItSafe requests exactly this Google Tag Manager access for you — the client approves through Google Tag Manager's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.

FAQ

Giving Google Tag Manager access — questions

Do I share my login for Tag Manager?

No. The agency is invited by their own Google email with only the container permissions you choose.

What permissions does an agency need in GTM?

Usually Edit and Publish on the specific container. Approve is optional for workflow control.

How do I revoke GTM access?

Admin → User Management → remove the user. HandItSafe also gives your client one-tap removal.

Account vs container permissions?

Account controls who's on the account; container controls what they can do in a specific container. Agencies need container Edit + Publish on the containers they manage.

Can I limit an agency to one container?

Yes. Grant account access with no account permissions, then set container permissions only on the container they work in.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.