Step 01
Authorize the Google account that owns the data
From Dashboard → Connect, continue with Google (or re-authorize). Approve access for the account that can view your Search Console, Analytics, Ads, and Tag Manager resources — inviting that user in those products first is often easier than switching mid-flow.
What to check
- One Google user can power multiple site workspaces
- Email-OTP accounts link Google later under Settings
- If Google says the app is in testing, ask your workspace admin to invite your account
Step 02
Map properties to each site
After consent, pick the Search Console property, GA4 property, Ads customer, and related GTM resources for each Conversion Console site. Agencies should keep one site (or workspace) per client property so credentials never cross.
What to check
- GSC + GA4 unlock the core graph on day one
- Add Ads when you need paid vs organic overlap
- GTM hygiene recipes need Tag Manager linked
Step 03
What read-only means for Ads
Google Ads permissions are used for reporting and opportunity insights only. Campaign edits still happen in Google Ads — Conversion Console will not pause, change bids, or rewrite ads through the API.
What to check
- Share the read-only posture with stakeholders before connect
- Re-authorize if Ads options are missing after an older login
- See Docs → OAuth for consent troubleshooting