SEO agency contracts: which permissions to grant and which deliverables to receive
Add the SEO agency's accounts as a Full user in Search Console, a property-level Marketer in Analytics and an Editor in WordPress, and keep the Owner and Administrator roles on company accounts even during the contract.
If you separate, for each of Search Console, Analytics, WordPress and your ads account, the permissions the company keeps from those it hands to the agency, getting permissions back after the contract ends takes fewer steps.
1. Permission levels to give an SEO agency
During the pre-contract audit stage, give the agency read access only, and after the contract is signed, raise it to the level needed to submit sitemaps and publish posts. In its Do you need an SEO? document (updated June 11, 2026), Google advises that when a firm offers an audit, "don't grant write access at this stage." So during the audit stage, add the agency's account to Search Console as a Restricted user.
The same document states: "SEO firms that access your server through FTP should explain all changes to your website." Ask an agency that has server access to list the files and settings it changed on the server in the change log as well. An agency can also verify Search Console ownership through server access or Tag Manager publish permission, so every month the company checks the ownership history in Users and permissions for new owners.
2. Dividing permissions in Search Console, Analytics and the CMS
Keep the roles that can change other users' permissions on company accounts, and give the agency no more than the levels in the table below.
| Account | Level given to the agency | Level kept on the company account | What the agency's level allows |
|---|---|---|---|
| Search Console | Full user | Owner (verified) | View reports, submit sitemaps, inspect URLs, remove URLs and disavow links |
| Analytics | Marketer at the property level | Administrator at the account level | Create and edit audiences, events and key events |
| WordPress | Editor | Administrator | Publish and edit posts, manage other users' posts |
| Ads account | Standard | Admin, Billing | Edit campaigns, run performance reports, edit billing information |
| Domain and DNS | None | Registrar account in the company's name | None |
According to the permissions table in the Manage users, owners, and permissions help article, only owners can add users, while full users can also remove URLs and disavow links.
According to the Manage access and data restrictions help article, a role granted at the account level is inherited by every property in that account. The Verify your site ownership help article states that a user with Analytics edit permission (now the Editor role) can verify Search Console ownership using the site's Analytics tag. So do not give the agency's account an account-level role or the Editor role; give it the Marketer role on the property it works on.
The WordPress documentation page Roles and Capabilities (updated September 2, 2026) defines an Editor as "somebody who can publish and manage posts including the posts of other users." On a single site, installing plugins and managing users are capabilities that only an Administrator has.
According to the table in the About access levels in your Google Ads account help article, Standard access lets a user edit campaigns and billing information, but not grant account access or change access levels.
3. What goes wrong when you hand over owner permissions
An agency with owner-level access can remove the company's account from the property, and an agency that verified ownership with its own token can verify ownership again, even after the company removes its account, until the token is deleted. Search Console Help states that removing an owner from a property "does not delete or revoke the verification token."
If an SEO firm already has owner-level access, clean this up from the company account in the following order.
- In the Ownership verification row of Search Console settings, check whether the company account is a verified owner; if it is not, complete ownership verification with the company account from that row. The Users and permissions page is shown only to property owners. If the agency's account is an owner of a Domain property, verify ownership of the Domain property with the company account through a DNS record as well, then carry out steps 2 to 5 on the Domain property first.
- In Users and permissions, if the agency account's row shows Owner without Verified, use Change permission to downgrade that account to Full user.
- If the agency account's row shows Verified, its level cannot be lowered, so remove that account's access.
- Find that account's token in the list of unused ownership tokens, and first check whether the same token is also used for ownership verification in Merchant Center or Google Workspace. The help article warns that deleting such a token can negatively affect other services that use it. Then delete the HTML file or meta tag from the site and the DNS record from the domain management screen; if the Analytics method was used, revoke that account's Analytics edit permission, and if the Tag Manager method was used, revoke its publish and admin permissions.
- After removing every verification method, add that account back as a Full user, and keep the company account as the only owner.
4. Deliverables to receive every month and at the end of the contract
Write into the contract that the company receives a change log, a list of published content and a monthly report every month, and the full change history and a keyword map when the contract ends.
| Deliverable | When received | What it includes |
|---|---|---|
| Change log | Monthly | URLs modified, items changed, date applied |
| List of published content | Monthly | Published URL, title, publication date, external links |
| Full change history | At the end of the contract | Cumulative version of the change log |
| Keyword map | At the end of the contract | Target search queries for each page |
Every month, use the external links column in the list of published content to check whether any links to the agency's site have been added. The same Google document warns: "You shouldn't link your site to the SEO firm."
If the change log includes fixes to bot access, status codes, index-blocking tags, canonical URLs or Core Web Vitals, the company checks whether they were applied using the verification methods and pass criteria in Essential technical SEO checks: a checklist to hand to your developers.
5. Permission and deliverable clauses to write into the contract
The company puts clauses in the contract covering the permission level for each account, when each deliverable is received, and the procedure for deleting the agency's accounts and ownership verification methods when the contract ends. In the permissions clause, write the levels from the table in section 2, together with a condition that URL removal, link disavowal and billing edits, which the agency can perform even at those levels, are carried out only after the company approves. In the deliverables clause, state who holds the copyright in published content after the contract ends. At the quote stage, use the deliverable ownership item in How to compare SEO agency quotes beyond price to check whether the quote includes this.
In the termination clause, set out the procedure for deleting unused ownership tokens and WordPress accounts. When deleting a WordPress account, follow the Users Screen document (updated October 23, 2024) and choose the option on the deletion screen that attributes the posts and links to a company account. If you choose a different option, the posts and links are deleted too.
In PION's GEO agency service too, the client holds the rights to the domain. PION receives the access and management permissions needed for the work from the client, publishes content to a blog connected to the client's domain through DNS, and provides a report every month. PION assigns the copyright in content that has been paid for to the client, and when the contract ends, it hands the operating permissions and accounts over to the client.
The four stages of PION's agency service and its fixed-fee, performance-based and hybrid pricing are described in the GEO agency service overview. If you answer the 8 questions in the AI answer visibility basics check, the results screen shows readiness scores for four areas, including AI search bot access and owned publishing, along with your weak areas.
Frequently asked questions
How much access should I give an SEO agency?
Give the agency no more than the Full user role in Search Console, the property-level Marketer role in Analytics and the Editor role in WordPress, and keep the Owner and Administrator roles on company accounts. Keep the billing account and the domain registrar account in the company's name as well. PION receives the access and management permissions needed for the work from the client, publishes content to a blog connected to the client's domain through DNS, and hands the operating permissions and accounts over to the client when the contract ends.
What should we do if an SEO firm is already registered as an owner in Search Console?
The company account must be a verified owner before it can clean up the firm's account. If the firm's account row does not show Verified, that account is a delegated owner, so the company downgrades it to Full user through Change permission. If it shows Verified, its level cannot be lowered, so the company removes that account's access, eliminates the method the firm used to verify ownership, and then adds the account back as a Full user.
Should we give an SEO company a WordPress administrator account if it asks for one?
If you are only handing over publishing and editing posts, the WordPress Editor role is enough. Only an Administrator can install plugins, so the company's staff member gets the plugin names and purposes from the firm and installs them with the company's administrator account. If you created an administrator account for the firm only for the duration of the work, check the user list and the plugin list after the work is finished, then delete that account.
What deliverables do we receive from an SEO agency when the contract ends?
You receive the change history for the entire contract period and a keyword map listing the target search queries for each page. The company deletes the agency's account using its Search Console owner account, and if the agency ever verified ownership, it also deletes the HTML file, meta tag or DNS record used for that.
Should GA4 permissions be granted at the account level or the property level?
At the property level. According to Analytics Help, a role granted at the account level is inherited by every property in that account. If the agency's account already has an account-level role, first remove it in Account access management, then grant the Marketer role on only the one property it works on in Property access management.
- Category
- Guide