How to give the portal read-only access
For anyone who would rather grant no write permissions to their ads account at all.
Why Google asks for so much
On its consent screen Google describes permissions broadly — including editing and deleting data. That is not what we ask for: the Google Ads API has no separate read-only access, the same scope covers both reading and writing.
The portal only reads: it has no button that changes campaigns or products. But if you want a guarantee that does not rely on our word, Google provides one through user roles.
How it works
An application can never hold wider permissions than the person who signed in. If the Google account has the Read only role in your account, neither it nor the portal acting on its behalf can change anything — Google rejects the attempt on its side.
You cannot lower your own role: you are the admin of your own account. So you will need
a separate Google account — for example reports@your-domain.
Google Ads: 5 steps
To be done by an account admin.
- Open Admin → Access and security (ads.google.com/aw/accountaccess/users).
- Select the + button.
- Enter the email address of the separate Google account.
- Choose the Read only access level.
- Select Send invitation.
The invitee accepts the email — and signs in to the portal with that account.
Merchant Center: if you want the feed analysis
Merchant Center is a separate product with its own list of people. A Google Ads role does not carry over to it.
- Open Access and services → the People and access tab.
- Select Add person and enter the same address.
- Choose the Read-only access type. If it is not offered right away, add the person and change the role in the access settings.
Skip this and the portal still works, but the feed section stays empty.
What will not change
Google will show the same list of permissions: it is built from scope names and knows nothing about your role. What changed is what stands behind it.
Easy to verify: the change history of your Google Ads account will show no edits from us.
If you later want automation
Write to us and we will connect the account separately. Today the portal is read-only; we have not shipped automatic-change features.