Advertising · Integration

Share Google Tag Manager access without sharing a password

Last updated: August 2026

To give an agency access to Google Tag Manager, use GTM container-level user management — the agency is invited by email with container permissions. No password is shared, the client keeps ownership of Google Tag Manager containers, and access can be removed anytime.
Full step-by-step guide

The official way to grant Google Tag Manager access

GTM container-level user management — the agency is invited by email with container permissions. You'll find it under Admin → User Management → Container. The client keeps ownership of Google Tag Manager containers; the agency is granted only what you assign.

The mistake almost everyone makes: Granting account-level instead of container-level access is common and over-permissive. Request the specific container.

What you'll need first

Access levels explained

Grant the least access the work needs. Here's what each level on Google Tag Manager can do:

Access level / roleWhat it can do
ReadView the container, no changes.
EditCreate and edit tags, triggers and variables in a workspace.
ApproveEdit plus approve changes in workflow-enabled containers.
PublishEdit, approve and publish container versions live. Agencies implementing tracking usually need Edit + Publish.

How long it takes

1–2 minutes. Invite the user with container permissions; access is immediate.

Why this is safer than sharing a password

The agency is invited by their own Google email with only the container permissions you choose — no password shared, removable anytime from User Management.

Or do it in one link

Every step above is why agencies move to a single link. HandItSafe requests exactly the Google Tag Manager access you need — the client approves it through Google Tag Manager's own process in about three minutes, no password shared, and keeps a panel to see and remove access anytime. That visibility is why clients approve faster, and it makes offboarding a one-tap job later.

Read the full step-by-step guide to giving Google Tag Manager access

FAQ

Google Tag Manager access — your questions answered

Do I share my login for Tag Manager?

No. The agency is invited by their own Google email with only the container permissions you choose.

What permissions does an agency need in GTM?

Usually Edit and Publish on the specific container. Approve is optional for workflow control.

How do I revoke GTM access?

Admin → User Management → remove the user. HandItSafe also gives your client one-tap removal.

Account vs container permissions?

Account controls who's on the account; container controls what they can do in a specific container. Agencies need container Edit + Publish on the containers they manage.

Can I limit an agency to one container?

Yes. Grant account access with no account permissions, then set container permissions only on the container they work in.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.