Advertising · Integration
Last updated: August 2026
GTM container-level user management — the agency is invited by email with container permissions. You'll find it under Admin → User Management → Container. The client keeps ownership of Google Tag Manager containers; the agency is granted only what you assign.
Grant the least access the work needs. Here's what each level on Google Tag Manager can do:
| Access level / role | What it can do |
|---|---|
| Read | View the container, no changes. |
| Edit | Create and edit tags, triggers and variables in a workspace. |
| Approve | Edit plus approve changes in workflow-enabled containers. |
| Publish | Edit, approve and publish container versions live. Agencies implementing tracking usually need Edit + Publish. |
1–2 minutes. Invite the user with container permissions; access is immediate.
The agency is invited by their own Google email with only the container permissions you choose — no password shared, removable anytime from User Management.
Every step above is why agencies move to a single link. HandItSafe requests exactly the Google Tag Manager access you need — the client approves it through Google Tag Manager's own process in about three minutes, no password shared, and keeps a panel to see and remove access anytime. That visibility is why clients approve faster, and it makes offboarding a one-tap job later.
Read the full step-by-step guide to giving Google Tag Manager access
FAQ
No. The agency is invited by their own Google email with only the container permissions you choose.
Usually Edit and Publish on the specific container. Approve is optional for workflow control.
Admin → User Management → remove the user. HandItSafe also gives your client one-tap removal.
Account controls who's on the account; container controls what they can do in a specific container. Agencies need container Edit + Publish on the containers they manage.
Yes. Grant account access with no account permissions, then set container permissions only on the container they work in.
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.