How to give Search Console access: which permission to ask your client for
Most guides stop at "add them as a user and you're done." None of them tell you which level to ask for based on the task, or what to do when the previous provider is gone and still sits as the owner of your client's account.
TL;DR
- ✓ Only an owner can add users. Settings → Users and permissions → Add user, with the Google account email. Never share the business's Gmail login and password.
- ✓ Ask for the minimum level, not the maximum. Restricted to read and report, Full to execute (sitemaps, removals, indexing), Owner only to link Analytics or run Change of Address, and only for as long as that task takes.
- ✓ If you control the domain, you don't need anyone to "hand over" anything. Verify yourself with a method you control (a DNS TXT record, for example) without depending on the previous provider.
- ✓ There is no "transfer ownership" button. Reclaiming it means verifying yourself, deleting the previous owner's tokens, and removing their access, in that order.
- ✓ There's an exit checklist for when a contract ends, whether you're the agency leaving or the client staying.
How to give Search Console access in 4 steps (without sharing your password)
The direct answer, before the details: the property's owner goes to Settings → Users and permissions → Add user, types the other person's Google account email, and picks a permission level. That's it. Only someone who is already an owner can do this, so if a client says "I can't find that option," the first thing to check is whether they're actually an owner or only have Full access.
Before the steps, a habit worth breaking: in a lot of small businesses across Latin America, giving Search Console access still means "here's the email and the password to the business's Gmail." It's the fastest way to lose control of the entire account — not just Search Console, but the inbox too, plus Google Ads and Google Business Profile if they exist — and it's never necessary. Search Console has had its own user system for years.
-
Step 1 · Sign in to the property as an owner
From search.google.com/search-console, pick the property (Domain or URL prefix) from the selector on the left. You'll only see the option to add users if your account already has owner level on that specific property.
-
Step 2 · Go to Settings → Users and permissions
The gear icon is usually at the bottom left of the menu. That's where you'll see the full list: who has access today, at what level, and — for owners — which verification method each one used.
-
Step 3 · Click Add user
Type the person's exact Google account email (it doesn't have to be a Gmail address, but it does need to be registered with Google) and choose Restricted or Full. Owner level is granted in a separate step, by promoting a user already on the list.
-
Step 4 · Confirm and have them check their access
The other person sees the property appear in their own Search Console as soon as you confirm. Ask them to log in and confirm they can see what they need — it's the fastest way to catch a permission level that's wrong.
The same steps work in reverse when an agency has to hand access back to a client once a project wraps up. The direction changes; the procedure doesn't.
Search Console permission levels: verified owner, delegated owner, Full, Restricted, and Associate
Search Console recognizes five access levels, and the difference between them isn't cosmetic — it defines what each person you share the property with is able to break. Worth understanding before asking for, or granting, any of them.
Verified owner
Has their own verification method: a DNS TXT record, an HTML tag on the site, an HTML file at the root, or verification through Google Analytics or Google Tag Manager. Can do everything: add and remove users, link Analytics, use Change of Address, and remove other owners. Per the official help, there's no cap on verified owners per property.
Delegated owner
Has the same control as a verified owner, but got there because another owner promoted them from the user list, without their own verification token. The difference matters in exactly one scenario: if every verified owner is removed, delegated owners lose access after a grace period.
Full access
Sees all the data and also executes: submits sitemaps, requests URL indexing, asks for removals, and changes property settings. The only things off-limits are managing users and linking Google Analytics, reserved for owners.
Restricted access
Sees the full Performance report (clicks, impressions, CTR, position, by query and by page), most other reports, and can check — not run — URL Inspection. It's the level anyone whose job is limited to reading data and reporting needs.
Associate
Not a user you add manually to this list. It shows up when you link the property to another Google product, like a verified app in Play Console: that associate sees aggregated data without being able to identify specific queries or pages, and doesn't take up a Search Console user slot.
The rule that falls out of this list, and that almost nobody applies: Owner isn't the "trust" level, it's the "risk" level. Every owner you add can, among other things, remove every other owner. Nobody needs Owner just to see numbers.
Which permission to ask your client for, based on the work you'll actually do
This is the least-privilege principle applied to Search Console: ask for the level today's task needs, not the level that would save you from asking again in three months. If you're only going to read and report, Restricted is enough. If your contract includes executing technical changes — submitting sitemaps, requesting URL removals, requesting indexing — you need Full. Owner should only be requested for tasks that genuinely require it, like linking Google Analytics or using Change of Address during a domain migration, and it's worth stepping back down to Full as soon as that task is done.
With read-only access you can already build most of a report: review the full Performance data, see each client's Search Console alongside the positions you track by city and device, and use URL Inspection to diagnose. That's the level worth asking for when you sign a new client. For organizing one project per client and splitting your quota across several, there's a guide on setting up one project per client and splitting your quota, which we won't repeat here.
| Task | Minimum level | Note |
|---|---|---|
| Read Performance (clicks, impressions, CTR, queries, pages) and build the report | Restricted | Sees full Performance |
| Review Links | Restricted | Visible at every level |
| Check URL Inspection | Restricted | View only; can't request indexing |
| Submit sitemaps, request indexing, request URL removals | Full | Restricted can only view |
| Change property settings | Full | Restricted can only view |
| Link Google Analytics | Owner | Full and Restricted cannot |
| Use Change of Address (domain migration) | Owner | Full and Restricted can only view |
| Add or remove users | Owner | Owners only |
| Connect the property to an external tool (rank tracker, Looker Studio) | Depends on the tool | Don't assume Restricted is enough; confirm first |
Table source: Search Console's official help, checked on September 10, 2026. Save it, or forward it straight to your client next time they ask "so which one do I give you?"
Adding a user in Search Console when the client has no idea where anything is
In practice, the step that stalls the most isn't technical — it's that the business owner has never opened Search Console, doesn't know what "Settings" means, and gives up before finding the button. A short message with the exact path, no jargon, does more than any screenshot.
Message ready to send over WhatsApp or email
"Hi, to give me access to your Search Console: go to search.google.com/search-console with your Google account, pick your property in the top left, tap the Settings gear, then Users and permissions, then Add user. Enter this email: [your email] and choose the Restricted permission. You can do this from your phone's browser, no app needed."
If the site has two properties — a Domain one (covers http, https, www, and subdomains all at once) and a URL-prefix one (only that exact version, like https://www.business.com/) — ask them to add you on the Domain property if it exists: it's the one that gives you the full picture. If only the URL-prefix property exists, that's what you work with.
The three most common trip-ups, in order of frequency: the email they hand you isn't registered as a Google account (the invite just sits pending, unnoticed); they add a group or distribution-list email, which Search Console doesn't accept; or you get added to the wrong property because the site has both and nobody checked which was which.
Once they confirm, log in yourself: under Settings → Users and permissions you'll see your own email on the list, with the exact level shown in the permission column. Don't take anyone's word for it, including your own from a month ago — confirm the real level every time you start relying on that access for something new.
The most common case: the provider who built the site is still the verified owner
This is the scenario that shows up the most when a new agency or freelancer joins a project: the site was built by someone else one, two, or three years ago, that someone verified the Search Console property with their own account, and the business owner never touched it again. Today that provider is still, technically, the owner of the property — even if they no longer work with the client, even if they don't answer the phone, even if the relationship ended a long time ago.
How to spot it: go to Settings → Users and permissions and look at the list of owners and, next to each one, their verification method. If the only verified owner is an email you don't recognize — an outside agency, a freelance developer, a generic address like webmaster@ — that's the case.
Why this is a real risk: that owner can remove every other user at any moment, submit sitemaps, and request full URL removals from the index. It's the exact reason "here's the email and the password" ends up costing months of SEO work when something goes wrong.
The rule that solves most cases: if you control the domain or the site, you don't need anyone to "hand over" Search Console. You can verify yourself with a method you control — a record in your own DNS, for example — without depending on the previous provider cooperating. The exact steps are in the next section.
There's a case that complicates this further: if the domain or DNS is also registered under the provider's name (it happens more than it should), you first need to reclaim control of the domain through the registrar, with whatever documentation that registrar requires. That's a separate process, with a different provider and different rules, and it's not legal guidance that fits in one paragraph of this post — if that's your situation, start there before touching Search Console.
How to reclaim or transfer ownership of Search Console, step by step
There is no "transfer ownership" button. There is this procedure, and it has to be followed in this order.
-
1. Confirm who controls the domain, the DNS, and the hosting
Before touching Search Console, verify that the client (or you, on their behalf) has real access to the domain registrar, the DNS panel, and the hosting or platform the site runs on. Without that you can't complete step 2.
-
2. Add the property and verify yourself with a method you control
Using the business's Google account, add the property (or open the existing one if it already shows up) and complete verification with your own method: a DNS TXT record for a Domain property; an HTML tag, an HTML file, Google Analytics, or Google Tag Manager for a URL-prefix property. This step makes you a verified owner without needing anything from the previous provider.
-
3. Review the full list of owners and their verification methods
In Users and permissions, now that your own access is active, check who else shows up as an owner and how each one is verified. You'll need this list for the next step.
-
4. Delete the previous owner's tokens
This is the step almost everyone skips, and it's why the previous provider tends to reappear weeks later. Check and remove: any leftover google-site-verification meta tag in the theme or SEO plugin, the HTML verification file at the site's root, the DNS TXT record under their name, and their editing permissions in Google Analytics or Tag Manager if that's how they verified.
-
5. Remove their access, and that of any delegated owners they added
With your own tokens active and theirs already deleted, remove them from Users and permissions. Also check whether they added anyone else as a delegated owner or user, and decide with the client who stays.
-
6. Check the list again a few days later
If the previous provider shows back up as an owner, a token you missed in step 4 is still alive — most often a meta tag in a template that never got touched, or a separate verification field in an SEO plugin. Go back to step 4 and dig deeper.
There's no faster legitimate shortcut. Any offer of "I'll transfer the property to you" from a provider who's no longer cooperating is, at best, this same procedure done from their end.
Removing access in Search Console: the exit checklist when a contract ends
Getting access right at the start matters as much as removing it cleanly at the end. Two checklists, depending on which side you're on.
If you're the agency or freelancer leaving
- · Export the historical data before you lose access, especially if it's useful for your own portfolio or the final report.
- · Document which verification tokens you added (TXT, HTML tag, file) so the next provider doesn't have to guess what to delete.
- · If you ended up as a delegated or verified owner, remove yourself — or ask to be removed — as soon as you hand the project off.
- · Confirm in writing, by email, that you returned the access — it saves an argument months later if something breaks and nobody remembers who had what.
If you're the client staying on
- · Review the full Users and permissions list: users, delegated owners, and each owner's verification method.
- · Remove the outgoing agency or freelancer from the list, and check they weren't left as a delegated owner by accident.
- · Also review any access that agency had in Google Analytics and Google Tag Manager — separate products with their own lists.
- · When you bring someone new on board, give them the minimum level for their task (usually Restricted), not Owner "so they don't have to ask again."
Four permission mistakes that get expensive
1. Leaving the property with only delegated owners
With no verified owner as a backup, if the original delegated owner loses access to their Google account, leaves the company without warning, or simply gets removed by mistake, the whole property can end up with nobody able to get back in after the grace period. Always keep at least one verified owner with their own token.
2. Inviting an intern's or temporary collaborator's personal email
Six months later nobody remembers that person is still on the list, they no longer work on the project, and their personal email is still watching performance data for a business they have nothing to do with anymore. Use work accounts, not personal ones, and review the list when someone leaves.
3. Giving Owner to a tool or a temporary freelancer
No monitoring tool needs Owner level to work, and no freelancer hired for a one-off task — a two-week audit, say — needs it either. It's the easiest mistake to make out of laziness ("so I don't have to ask again") and the most expensive one to undo if something goes wrong.
4. Not knowing whether a tool connects to the Domain property or the URL-prefix one
When a site has both properties, granting access on the wrong one — the one your rank tracker or reporting tool isn't actually reading — makes "no data shows up" happen without anyone understanding why. Confirm which property a tool expects before inviting anyone.
One separate case worth a mention: when a client migrates domains, Change of Address requires Owner level on both properties and has its own rules that don't fit in this post.
One property per client, connected from day one
Sorting out Search Console permissions is Google's job. What Rankiamos does is smaller, and we're not going to oversell it.
🔒 One project per client
2 projects on the Free plan and exactly 5 projects on Pro, each one with its own connected Search Console property. It isn't a shared connection pool — it's 5 separate clients, one per project.
👀 Read-only connection
Rankiamos requests read-only permission (webmasters.readonly) on properties your own Google account already has access to. It doesn't add users, doesn't submit sitemaps, doesn't request removals, and doesn't touch any setting on your client's property.
📊 Performance without leaving the app
Up to 250 queries from the last 28 days with clicks, impressions, CTR, and average position per query, plus a top 50 of the queries with the most impressions. It updates manually, whenever you choose to refresh it.
📄 A report with your branding, not ours
The PDF (Pro) ships with your studio's name and accent color, no logo of your own, and no automatic sending — you export it and share it yourself, with the right client.
An honest note, without overselling the product: Rankiamos doesn't manage Search Console users and it isn't a way to grant access to a third party — that's always handled inside Search Console itself, the way explained above. There's no client access or team invites inside the app either: every account is individual. What you can do is connect each client's property, with permission they granted you by following this guide, to the tools Rankiamos gives you for working with several clients. And each project's history starts the day you connect it, not before — the biggest reason to connect a new client's Search Console property on day one of the contract, not whenever you finally remember to.
If you handle several clients at once, the 5 projects on the Pro plan cover 5 separate accounts, each with its own property, quota, and history.
Free plan: 2 projects, 6 keywords, Search Console included · iPhone · iPad · Mac · Apple Watch
Frequently asked questions
What is the difference between a Full user and a Restricted user in Search Console? ▾
What is a delegated owner in Search Console? ▾
Can I give Search Console access to an email that isn't a Gmail address? ▾
How many users can a Search Console property have? ▾
What happens if I remove the property's only verified owner? ▾
Does giving Search Console access also give access to Google Analytics or Google Ads? ▾
Can I give access to just one folder of the site, like the blog? ▾
Read also
Connecting Google Search Console to a rank tracker
What read-only scope Rankiamos asks for, and how to read its data alongside the positions you track.
Agency guideRank tracker for agencies: one project per client
How to split your project and keyword quota across several clients without mixing their data.