
Agency Onboarding
Part of Changing agencies
Planning a handover without losing access to accounts
Map account administrators, confirm incoming permissions and check Google Ads dependencies before removing an outgoing agency’s access.
Before removing an outgoing agency’s access, confirm a named person in your business can sign in and manage access to each account, and that the incoming team can perform its agreed tasks. Check each system while the outgoing team can still help resolve gaps.
Control of an ad account does not establish control of analytics, the website or billing.
Make an access map
List the systems needed to keep work running: advertising accounts, analytics properties, tag manager, website and hosting, social profiles, file storage, reporting tools and billing arrangements. For each, record its ID, current administrator, billing contact, agency users, any Google Ads manager account (MCC) link, and the client person authorised to change access.
Match each incoming user’s access to the task. Viewing a report, editing a campaign and managing account security need different permissions. Ask a named user to confirm the required task works, and retain a client administrator who can manage access.
Where a platform provides its own delegation feature, use it instead of sharing passwords, and assign access to a named user’s own account.
| Checkpoint | What to confirm |
|---|---|
| Client control | An authorised client user can sign in and manage relevant access. |
| Incoming access | A named user can perform the agreed task in the correct account. |
| Outgoing access | Users, groups, manager links and shared credentials are identified for review. |
| Dependencies | Shared lists, tracking, integrations and billing have an owner. |
Platform Access Management Methods
- Method
- Use platform delegation (e.g., Google Ads, Google Analytics)
- Risk
- Sharing passwords or using shared credentials
- Best Practice
- Assign access to a named user’s own account with role-based permissions
Check platform dependencies before unlinking
Google Ads manager accounts are also called manager accounts (MCC). Before changing access, check the client-account ownership relationship using Google Ads Help’s “Manager accounts (MCC): About ownership of client accounts”.
Before removing a manager-account link, consult “About unlinking accounts from your manager account” and identify what the client account depends on. Confirm the client administrator and incoming user can still reach the account before unlinking.
Check the account’s billing arrangement and plan any change before cutover, so work is not interrupted. Arrangements on one platform do not describe another; check each platform separately.
Google Analytics access is managed through roles and permissions. Use “Access and data-restriction management” to review the property’s access settings, then have the incoming named user confirm their agreed task works while a client administrator retains access.
Key Account Access Requirements
- Google Ads Manager Account (MCC) Link
- Must be reviewed before unlinking; check ownership via Google Ads Help
- Google Analytics Access
- Managed through roles and permissions; confirm access settings
- Billing Arrangements
- Check separately per platform—no cross-platform assumption
Cut over and close access
Set a cutover time for each system and work through the access map. First, the client administrator signs in and confirms they can manage access; next, the incoming named user signs in and completes the agreed task. Confirm tracking, integrations and billing arrangements have an owner before removing outgoing access.
Then remove outgoing users, groups and manager-account links that are no longer needed. Review shared credentials separately and use platform delegation instead of password sharing where available; give any temporary exception an owner and expiry.
Record the account, user, task, checker and time for each completed check. Until someone performs that check in the real system, the access map is a plan, not proof of access.



