Changing Agencies? Transfer These 5 Google Assets Before Access Breaks
IMG SOURCE: RENDER_V2RES: 4K UHD
Index / Strategy
Posted2026-08-15
AuthorNG Technology
Est. Read11 MIN
Tags
Google Account AccessAgency HandoffAnalyticsDigital Asset Ownership

Changing Agencies? Transfer These 5 Google Assets Before Access Breaks

Keep Google Business Profile, Google Ads, GA4, Tag Manager, and Search Console history intact with a business-controlled handoff and acceptance checklist.

Changing marketing or website agencies should not mean rebuilding Google accounts or losing years of history. For a U.S. service business, the safest transition keeps the existing assets, establishes business-controlled access first, validates the live customer and measurement paths, and removes the outgoing agency last.

Do not start by deleting the old agency

Access removal is the final step, not the first. Deleting a user before you understand how an account is structured can break the only administrative path, obscure a billing responsibility, or leave a website verification token behind.

NG Technology's recommended order is:

  1. inventory the current state;
  2. establish business-controlled access;
  3. give the incoming agency least-privilege access;
  4. validate the live system during a defined overlap window;
  5. remove old access and preserve the acceptance record.

This is an operational handoff, not a legal determination of ownership. Contracts, disputed invoices, and contested data rights need separate advice.

The five-asset control-state checklist

These products do not use one universal definition of “owner.” Verify the control state inside each product instead of accepting a spreadsheet that says “access granted.”

AssetBusiness acceptance evidenceRemove old agency only after
Google Business ProfileA business-controlled Google Account is shown as Primary owner; another internal owner is documented.The new owner has cleared Google's seven-day limitation and profile actions work.
Google AdsA business user can sign directly into the client account with Administrative access; customer ID, billing, active campaigns, conversions, and manager links are recorded.The incoming manager link and billing responsibility are accepted, and reporting plus conversion paths are checked.
Google Analytics 4Business administrators are confirmed at the account and required property levels; property IDs, data streams, key events, and product links are inventoried.Collection and the reports used for decisions still populate, and access works without the outgoing user's login.
Google Tag ManagerAt least two organization-controlled account Administrators exist; required staff have container Publish access; the live version and JSON export are saved.The container is previewed, the current live version is identified, and critical lead events work without an unnecessary republish.
Google Search ConsoleThe business is a verified owner; Domain and URL-prefix properties, users, associations, and verification tokens are mapped.Ownership is rechecked and only the departing party's safe-to-remove tokens have been removed from DNS, HTML, GA, or GTM.

1. Google Business Profile: transfer the existing profile

Do not create a replacement profile merely because the agency relationship changed. Google's Business Profile ownership guidance says only the primary owner can transfer primary ownership and that transferring the existing profile preserves business information such as reviews.

Add the business-controlled account as an Owner early. Google limits some actions for new owners and managers for seven days, including removing users and transferring primary ownership. Build that waiting period into the transition schedule rather than discovering it on termination day.

After control is accepted, run the site's Google Business Profile accuracy audit before anyone changes categories, address, hours, phone, or website links.

2. Google Ads: keep a direct client-account administrator

An agency's manager account is useful, but it should not be the business's only route into the individual Google Ads account. Google distinguishes a linked manager from administrative ownership, and some actions require either a direct client-account administrator or an administratively owning manager. See Google's manager access-level documentation.

Confirm a business-controlled user can sign in directly before changing manager links. Google's unlinking guidance says an individual account can unlink from a manager account and does not lose its own campaign history or Google Ads features. Billing responsibility can be a separate process, so record who pays before approval.

3. GA4: check both account and property access

“I can see the dashboard” is not an acceptance test. GA4 permissions may be granted at the account or property level, and inherited access can make the user list look simpler than the real control chain. Google's Analytics user-management guidance says an Administrator at the relevant level can add and modify users.

Inventory the account ID, property ID, web data streams, key events, audiences the business relies on, and links to products such as Google Ads. Then test with the business administrator's own login. Do not use the departing agency's screen share as proof of independent access.

4. Tag Manager: preserve both administration and publishing

Tag Manager separates account permissions from container permissions. An account Administrator can manage users and containers, while container Publish permission controls whether someone can make a version live. Google's Tag Manager access guidance recommends at least two active administrators and says the account should be managed by someone in the organization rather than only an outside agency.

Before access changes, identify the live container and version, create a clearly named version if there are unversioned approved changes, and download a JSON export. Google documents that containers can be exported as JSON. Treat the export as a recovery artifact—not proof that tags fire correctly on the live site.

5. Search Console: map verified owners and their tokens

Search Console is different because verified ownership depends on a token: DNS record, HTML file, meta tag, Analytics, Tag Manager, or another supported method. Google's owner and permissions documentation distinguishes verified owners from delegated owners and says a property needs at least one verified owner for its users to retain access.

Removing a user from the interface may not remove that person's token. An old token can permit re-verification, but deleting it blindly can also affect another Google service that relies on the same token. Map each token to its owner and dependencies first. Google also permits multiple verification methods, which can reduce dependence on one access path.

Build the evidence package before the overlap window closes

Store the handoff record in a business-controlled location. Include:

  • each account, customer, property, data-stream, and container ID;
  • every owner, administrator, manager, publisher, full user, and inherited group that matters;
  • accepted invitations and the business-controlled recovery path;
  • Google Ads billing responsibility, manager links, active campaigns, and conversion definitions;
  • GA4 key events, product links, filters, audiences used operationally, and report owners;
  • the current GTM live version, workspace status, container JSON export, and critical tag map;
  • Search Console property types, associations, verified owners, and verification-token locations;
  • the current GBP primary owner, other owners/managers, location group, and customer-facing facts;
  • a timestamped acceptance result for the live website, calls, forms, bookings, and other qualified-lead paths.

Passwords do not belong in this record. Use named accounts and the organization's approved credential and recovery process.

Assign one owner to every handoff action

PartyOwns during transitionMust not do alone
BusinessNames internal administrators, accepts invitations, approves billing and access removals, stores evidence, signs acceptance.Assume a manager link equals ownership or approve deletion before testing.
Outgoing agencyDiscloses IDs, roles, links, billing dependencies, live configurations, token locations, and pending changes.Create replacements, delete history, rotate access, or publish tag changes outside the agreed change window.
Incoming agencyVerifies independent access, reconciles inventory, tests the customer/measurement path, documents exceptions.Remove the outgoing team before the business accepts control and continuity.

Run a no-downtime acceptance check

“No downtime” is a target, not a guarantee. Test the actual system before and after access removal:

  1. The Business Profile opens from the business owner's login and its phone, hours, website, directions, and messaging options remain correct.
  2. Active Google Ads campaigns, billing, landing pages, and the conversions used for decisions remain visible to the business administrator.
  3. GA4 receives the expected test activity and the business can access the reports it uses.
  4. Tag Manager shows the expected live version; preview the critical lead path and avoid publishing merely to prove access.
  5. Search Console ownership, properties, messages, associations, and performance access remain available.
  6. A real test inquiry reaches the intended business destination, with privacy-safe test data and a documented cleanup step.

Freeze unrelated campaign, tag, site, and profile changes during this acceptance window. Otherwise a handoff defect and a routine optimization can become impossible to separate.

If access is already lost

Use the narrowest official recovery path and preserve evidence before making new assets.

  • Business Profile: Submit Google's ownership request. Google gives the current owner three days to respond, but warns that a claim option after no response is not always available.
  • Google Ads: Identify the customer ID, billing evidence, direct administrators, and manager hierarchy. Ask an existing administrator to restore access or use the account-access path surfaced by Google; do not create a new client account as the first response.
  • GA4: Inventory the account and property IDs plus any organization or group that may grant inherited access. Restore a business Administrator at the correct level before removing anyone.
  • Tag Manager: Escalate immediately to another existing Administrator or organization owner. Google explicitly warns that support cannot be relied on to add users around in-product permissions; starting over can lose operational history and require retagging.
  • Search Console: Verify the business independently through an appropriate supported method, then review old owners and tokens. Do not delete a DNS or HTML token until its other service dependencies are understood.

If control is disputed, stop destructive changes. Preserve contracts, invoices, account IDs, invitation emails, screenshots, and change timestamps for the business's legal or platform-support process.

Frequently asked questions

Should the new agency create new Google accounts?

Usually not for an agency change alone. Preserve the existing business assets, histories, identifiers, and product links; add controlled access to them. Create a replacement only when a documented technical or policy reason requires it and the migration consequences are accepted.

Can the outgoing Google Ads manager be unlinked without losing campaigns?

Google says the individual client account keeps its own campaign history and access to Google Ads features after unlinking. Confirm the client account still has a direct user or qualifying manager and resolve billing responsibility first.

Is GA4 property access enough?

It may be enough for bounded work on one property, but it is not the same as account-level administration. Map where each role is assigned and where it is inherited before deciding what the business needs.

Why does Tag Manager need two internal administrators?

Because a sole administrator can become unavailable. Google's own guidance recommends an additional Administrator and organization-controlled management. Container Publish access still needs to be checked separately.

Can we delete the old Search Console verification record?

Only after mapping it. A removed user's token can allow re-verification, but Google warns the same token may support Search Console, Merchant Center, Workspace, or another service. Remove only the departing party's token and verify dependent services afterward.

What about the domain, DNS, website, email, call tracking, and CRM?

They are outside this five-product deep dive but belong in the dependency check. If the website stack itself may be locked to the old agency, run the broader website ownership and exit test before the overlap window ends.

Make the business the durable control point

The goal is not to give every person maximum access. It is to keep at least one durable, business-controlled administrative path in every essential asset, then grant each agency only the role it needs.

NG Technology can map the website, analytics, tag, search, and lead-path dependencies; define acceptance evidence; and coordinate a controlled technical handoff without treating an account screen as proof that the system still works. Our growth website service includes analytics and Search Console foundations when a broader website transition is also required.

Request a digital-asset handoff assessment