Users, owners & permissions

Understand verified owners, delegated owners, full users, restricted users, and associations.

Partially automatable Beginner

Search Console access is granted per property. The role determines which private data a person can see and which actions they can perform, while verification tokens determine who can prove ownership independently.

The central governance rule is simple: give ownership only to people who must control the property, and give everyone else the least powerful user role that supports their work.

The four access concepts

Verified owner

A verified owner proved control of the website using a verification token such as a DNS record, HTML file, or meta tag. Verified owners have full control of the property.

Removing a verified owner from the interface does not permanently remove their ability to return if the token remains on the site or in DNS. Their tokens must be removed as part of offboarding.

Delegated owner

A delegated owner is promoted by an existing owner without placing a personal verification token. Delegated and verified owners have the same Search Console permissions, but a delegated owner can be removed through the user-management screen.

A property still needs at least one verified owner. If every verified owner loses verification, delegated owners and users eventually lose access.

Full user

A full user can view all data and perform several operational actions, such as submitting sitemaps, using URL Inspection, validating fixes, and working with reports. A full user cannot manage owners or perform every owner-only configuration.

This is usually the appropriate role for an in-house SEO, developer, or trusted agency operator who needs to investigate and act but does not need to control ownership.

Restricted user

A restricted user has simple viewing rights to most data and fewer actions. It suits stakeholders, analysts, writers, or auditors who need visibility without operational control.

Google's permission matrix can change as reports evolve. Check the current owners and permissions documentation before relying on a specific action.

Associates are not ordinary users

An association connects a Search Console property to another Google service or account for a specific capability. Associates do not automatically receive permission to open the property or view Search Console reports.

Do not confuse:

  • A Search Console user who can open private reports.
  • An associated service authorized for a defined integration.
  • A Google Analytics user who can see GA4.
  • An API client authorized by an individual OAuth user.

Each has separate permissions and should be audited separately.

What owners can do

Owners have full control, including:

  • View all reports and messages.
  • Use all available tools.
  • Add and remove users and delegated owners.
  • Change user permissions.
  • Manage ownership and property settings.
  • Create certain product links and exports.
  • Submit reconsideration requests and perform other sensitive actions.

Ownership is an administrative role, not a badge for seniority. Someone who only reads dashboards does not need it.

Verified and delegated owners have equal power

The difference is how ownership is established and revoked, not what the owner can do in Search Console.

  • A verified owner can re-establish access while their valid token remains.
  • A delegated owner depends on ownership granted through Search Console and can be removed there.

For external partners, delegated ownership is safer than placing their verification token, but full-user access is usually safer still.

Parent properties affect child properties

An owner of a containing property can have implicit owner rights on child properties. For example, ownership of a Domain property can establish control over a URL-prefix property for a host or path inside that domain.

Consequences:

  • A parent owner cannot be downgraded to a full or restricted user on the child.
  • Removing the account from the child list does not remove its parent ownership.
  • A path-level property limits ordinary user access but does not isolate data from the verified owner of its parent.

When access appears impossible to remove, inspect the containing properties and verification tokens.

Organization owner or platform administrator

Use verified owner, with at least one other organization-controlled verified owner as backup.

SEO lead

Use full user by default. Use delegated owner only if they must manage users, property settings, exports, or integrations.

Developer

Use full user when URL Inspection, sitemaps, or fix validation is required. Use restricted access for read-only diagnosis.

Content or marketing team

Use restricted user for reporting. Use full user only when operational actions are part of the role.

Agency

Use individual full-user accounts with a documented expiration or review date. Avoid personal verification tokens and avoid ownership unless the contract requires property administration.

Executive or client stakeholder

Use restricted user, a dashboard, or scheduled report. Do not grant owner access merely to make data visible.

Automation or API integration

Use a dedicated organization-controlled identity and the minimum Search Console property permission plus minimum OAuth scope required. Do not build production automation around a departing employee's personal account.

Adding a user or delegated owner

Only an owner of the property or a containing parent property can add or remove another user.

  1. Open the correct property.
  2. Go to Settings → Users and permissions.
  3. Select Add user.
  4. Enter an individual Google Account email address.
  5. Select Restricted, Full, or Owner according to the responsibility.
  6. Save and ask the user to confirm access to the intended property.
  7. Record the owner, business reason, and review date in the access register.

Search Console does not accept an email group as a user. This makes individual access reviews important.

Current account limits

Google currently documents these per-property limits:

  • Up to 100 full, restricted, and associate non-owners.
  • Delegated owners can be added until the property reaches 500 total verified plus delegated owners.
  • Verified owners have no documented maximum.

These are technical ceilings, not recommended team sizes. A property with dozens of owners is difficult to govern even when it remains within the product limit.

Removing access safely

Full user, restricted user, or delegated owner

Remove the account from Users and permissions. The change should take effect quickly.

Verified owner

Use a complete process:

  1. Confirm another valid verified owner exists.
  2. Remove the account in Search Console.
  3. Review the displayed tokens and the Unused ownership tokens list.
  4. Remove all of the former owner's DNS, HTML-file, meta-tag, Analytics, or Tag Manager proofs.
  5. Confirm the account cannot verify again.
  6. Review ownership history.

If the person verified through Analytics or Tag Manager, removing Search Console access may not be enough. Remove the permission in the associated product or retire the relevant verification method.

Unrecognized owner

Treat an unknown verified owner as a possible security incident. Simply deleting the visible account is insufficient because someone who controls the site can add the token again. Secure the website, DNS, deployment access, Analytics, Tag Manager, and Google Accounts, then rotate or remove unauthorized proofs.

Avoid the single-owner failure

If the only verified owner leaves or loses access, all other users can eventually lose access. Prevent this by maintaining:

  • At least two verified owners controlled by the organization.
  • A durable DNS proof where possible.
  • Documented recovery ownership not tied to one employee's device.
  • Strong account security and recovery methods.
  • An inventory of tokens and external-product dependencies.

Do not use one shared password. Use separate organization-managed Google Accounts so actions and offboarding remain attributable.

Agency onboarding checklist

  1. Confirm the exact property scope required.
  2. Add named agency users rather than a shared login.
  3. Grant Full or Restricted access by default.
  4. Document any owner-only action the client must perform.
  5. Set an access-review date tied to the contract.
  6. Avoid agency verification tokens unless explicitly required.
  7. Keep the client as the durable verified owner.

Agency offboarding checklist

  1. Export or transfer agreed reporting artifacts.
  2. Remove all agency users and delegated owners.
  3. Remove any agency-owned verification tokens.
  4. Remove or replace API OAuth grants and automation credentials.
  5. Review Analytics, Tag Manager, BigQuery, Looker Studio, Merchant Center, and other associations separately.
  6. Review ownership history and unused tokens.
  7. Confirm that at least two client-controlled verified owners remain.

Search Console removal does not revoke access in other connected products.

Quarterly access audit

For every property, record:

  • Account email.
  • Role and whether ownership is verified or delegated.
  • Parent property that grants implicit access.
  • Verification method and token location.
  • Employer or vendor.
  • Business purpose.
  • Last successful review.
  • Contract or employment end date.
  • API and product associations.

Remove unused access promptly. Downgrade owners who no longer need administration. Verify that tokens in DNS and site templates correspond to known active owners.

Common permission mistakes

  • Making every SEO or developer an owner.
  • Assuming delegated owners are less powerful inside Search Console.
  • Removing a verified owner from the list but leaving their token.
  • Forgetting that a parent owner inherits control of child properties.
  • Using a contractor's personal account for durable ownership or automation.
  • Treating GA4, Tag Manager, BigQuery, or Looker Studio access as if it were removed with Search Console access.
  • Removing the last verified owner.
  • Sharing one Google Account across a team.
  • Failing to review access after an acquisition, migration, or agency change.

Official sources