Granting Google Tag Manager access
- For
- Whoever administers your Google Tag Manager account
- Grant access to
admin@laurenmilligan.pro- Access needed
- Account permission User, container permission Publish
- Time required
- About two minutes
The one thing that usually goes wrong
Tag Manager has two separate permission settings on the same screen, and it is easy to set one and miss the other:
- Account permission controls whether we can see the account at all. User is correct. Admin is not needed and should not be granted.
- Container permission controls what we can actually do inside the container. Publish is what we need.
If only the account permission is set, we will be able to see that the container exists and nothing else. That looks like access has been granted, right up until the moment it matters.
Steps
- Sign in at
tagmanager.google.comwith an account that has Admin on the Tag Manager account. - Confirm you are in the right container. The container ID, in the form
GTM-XXXXXXX, is shown at the top right of the workspace. - Click Admin.
- In the Account column, click User Management.
- Click the add icon (+), then select Add users.
- Enter
admin@laurenmilligan.pro. - Under Account Permissions, select User.
- Under Container Permissions, find the container running on your main site and select Publish.
- Click Invite.
Back in Admin → User Management, our email should be listed, and opening the row should show the container set to Publish.
Why Publish, and not Edit or Approve
Tag Manager container permissions run No access → Read → Edit → Approve → Publish.
| Level | What it allows |
|---|---|
| Read | Can look, cannot change anything |
| Edit | Can build changes but cannot create a version or push anything live |
| Approve | Can create versions but still cannot push live |
| Publish | Can build, version, and push live |
Everything a measurement engagement does in Tag Manager ends in a publish: the conversion tracking that goes live before launch, event tracking on key interactions, and server-side transport configuration. At Edit or Approve, every one of those becomes a request to you, at the exact points in the build where waiting costs the most.
Publish access does not let us delete the container, remove users, or change the account. Those are account-Admin functions, and we are deliberately not asking for them.
If your site has more than one container
Grant Publish only on the container running on your main site. If you see other containers in the account, leave them at No access. If you are not certain which container is live, send us the list and we will tell you which one we mean.
If a blog or subdomain runs on a separate platform, it may or may not use the same container. That is usually a later-phase question and does not need answering in the first week.
Questions about anything on this page: admin@laurenmilligan.pro