Skip to main content
Patronage logo

Share Google Ads & GA4 access safely

Patronage uses a Google Ads Manager Account link and GA4 Viewer access to run your assessment. You stay in control — you can revoke access anytime, and we never ask for billing access or administrative ownership.

Google Ads
Manager Account link — no ownership
Google Analytics 4
Viewer role — read-only
Search Console
Optional, but helpful
Billing access
Never requested

What we need, and why

The assessment reviews your account — it does not change campaigns or settings. We use a Manager Account link so Patronage can review Google Ads through the API, plus the least-privilege roles available in the other systems.

Access requested for the assessment
SystemAccess levelWhy we need it
Google Ads (Grant account)Manager Account linkReview campaigns, keywords, spend, search terms, and conversion setup
Google Analytics 4ViewerVerify meaningful conversions and landing-page performance
Search Console (optional)Restricted userOrganic context for search recommendations

Linked, not owned

Accepting Patronage's Manager Account request does not grant administrative ownership or billing access. Patronage uses the link for assessment and API review only.

Before you start

  • You need Admin access to the Google Ads Grant account yourself, or a Google for Nonprofits admin who can approve access.

  • Have your Google Ads customer ID handy — the 10-digit number shown as XXX-XXX-XXXX in the top-right account picker.

  • For GA4, know which property is tied to your main website.

  • For GA4 and Search Console, invite automation@patronage-analytics.iam.gserviceaccount.com. Use this same address for both.

  • For Google Ads, verify that the request comes from Patronage Ads Management (268-423-6203). Google Ads does not use an email invitation.

If an agency or parent manager already manages the account

A Grant account can already sit beneath an agency, diocese, or parent organization's Manager Account. Patronage's request still applies only to the Grant child account.

  • Ask the current manager to accept

    An admin of the existing owner manager can accept Patronage's pending request for the Grant child account.

  • Keep the scope to one child account

    Do not link Patronage to the agency or parent Manager Account. Patronage does not need visibility into any other account in that hierarchy.

Part 2 — Google Analytics 4 access (required)

  1. 01

    Open Admin in Analytics

    Go to analytics.google.com and open Admin.

  2. 02

    Open Property access management

    Under the property tied to your website, select Property access management.

  3. 03

    Add the Patronage service account

    Click + → Add users and paste automation@patronage-analytics.iam.gserviceaccount.com.

  4. 04

    Assign the Viewer role

    Choose Viewer — read-only — and save.

Video walkthrough · How to share GA4 property Viewer access

Part 3 — Search Console (optional but helpful)

  1. 01

    Open your site's Search Console

    Go to Settings → Users and permissions for the property that matches your website.

  2. 02

    Add the Patronage service account

    Add automation@patronage-analytics.iam.gserviceaccount.com as a Restricted user. Patronage only needs read access to query and page performance.

If you can't find or accept the request

  • The Manager Account request is missing

    Confirm that you sent Patronage the customer ID for the individual Grant account, not an agency or parent Manager Account. Ask Patronage to verify or resend the request.

  • The Accept action is unavailable

    You need Admin access to the Grant account, or an admin of its current owner Manager Account must accept the request.

  • The Analytics property looks wrong

    Stop before adding access. Match the GA4 property and Search Console property to the website domain in your assessment request.

  • The account details do not match

    Do not accept the request. Contact Patronage and verify that it should come from Patronage Ads Management (268-423-6203).

Revoke access anytime

Access ends when you unlink the Patronage manager — no call required. In Google Ads, go to Admin → Access and security → Managers and unlink Patronage. In GA4 or Search Console, remove the Patronage service account. Nothing is installed on your site or in your accounts.

How we handle your data

  • Access is used only for the assessment and, if you proceed, the agreed pilot work.

  • We do not sell or share your account data with third parties.

  • Results are shared with your organization only, unless you explicitly approve a case study.

FAQ

Frequently asked questions

Common questions about access levels, revocation, and account setups. Anything else — ask on the result-review call.

Which email address should we invite?
For GA4 and Search Console, invite automation@patronage-analytics.iam.gserviceaccount.com. Google Ads does not use an email invite; verify the Manager Account request from Patronage Ads Management (268-423-6203).
What Google Ads access does Patronage need?
A link from Patronage's Google Ads Manager Account to the Grant account. The link supports API review but does not require administrative ownership or billing access.
What Search Console access does Patronage need?
Restricted user access is sufficient for the optional review of query and page performance. Patronage does not need Owner access.
Do you need billing or payment profile access?
Never. Grant accounts are non-billed, and Patronage never requests billing profile access. Treat any request for billing access on a Grant account as a red flag.
Can we revoke access later?
Yes, anytime. Unlink the Patronage manager under Google Ads Access and security → Managers, then remove the Patronage service account in GA4 or Search Console.
We use an agency or an MCC — how does this work?
An admin for the Grant account or its owner manager accepts Patronage's link request for the Grant child account only. Patronage does not need access to the agency or parent manager's other accounts.
We can't find our Google Ads customer ID — where is it?
Sign in to Google Ads and open the account picker in the top-right corner. The 10-digit number under the account name, formatted XXX-XXX-XXXX, is your customer ID.

Haven't requested your assessment yet?

The intake takes about five minutes. Access sharing happens after you book your result-review call.

Request a free assessment