Agency_
How to Connect Google Analytics to Agency: A Complete Guide
Estimated Time to Complete: ~5 Minutes
Beta Notice
Agency's Google Analytics integration is currently in beta. This app has not yet been submitted for approval to Google, as the feature is very new. We will update this guide once the verification process is complete after initial feedback from beta users.
Welcome to the Agentic Web
The internet is evolving. We are moving away from traditional software where you have to click around to find insights, and entering the era of the Agentic Web—where autonomous AI "Agents" do the heavy lifting for you.
To power this securely, Agency uses a 2-Step Verification system. First, you prove ownership of your property using standard Google OAuth. Then, you grant read access to our Background Service Account, which gives your autonomous AI team a secure 24/7 pipeline to your raw data even while you sleep.
Connecting Google Analytics 4 (GA4) to Agency allows the platform to fetch your traffic metrics, analyze user behavior, track conversion trends, attribute traffic sources, and automatically update your master crawl records.
1Connect with Google (Verify Ownership)
Before our background bots are allowed to fetch any data, you must first prove that you actually own the analytics property you are trying to connect.
- Navigate to your Analytics Settings (
https://thisisagency.ai/analytics/settings). - Click the Connect with Google button.
- Approve the
analytics.readonlypermission screen. The button will turn green and say "✅ Connected via OAuth".
2Grant Access to the AI Service Account
Because Agency operates autonomously in the background to fetch traffic data, it cannot use a simple "Log in with Google" button for its 24/7 agents. Instead, it uses a Google Service Account—a special type of invisible user account that works entirely in the background.
- On your Analytics Settings page, locate the Your Master Worker Email box (e.g.,
data-reader@...) and copy it. - Open https://analytics.google.com/ and select the correct Property.
- Click on the Admin gear icon in the bottom left.
- Under the Property settings column, click on Property Access Management.
- Click the blue + button in the top right and select Add users.
- In the Email addresses field, paste the Master Worker Email.
- Under Standard roles, select exactly Viewer. (Do not select anything higher).
- Click Add.
3Unlock the Background Bot
Finally, tell Agency which client "door" to open and verify the connection.
- In Google Analytics Admin, click on Property Settings. Look for the PROPERTY ID in the top right (a number like
123456789). Copy this number. - In Agency, ensure you have selected your project from the top-left dropdown.
- Navigate back to your Analytics Settings (
https://thisisagency.ai/analytics/settings). - Under the Property ID field, paste the ID and click Verify. The system will use your OAuth token from Step 1 to verify you own the property, and then permanently unlock the background bot!
Security & Privacy
We take the security of your Google Analytics data very seriously. Here is exactly how your credentials are treated:
- Read-Only Access: When Agency connects to Google Analytics on your behalf, it forces a Read-Only scope (
https://www.googleapis.com/auth/analytics.readonly). It is physically impossible for Agency to make changes to your GA4 settings, delete users, or modify your property data. - The OAuth Lock: We force you to verify ownership via standard Google OAuth before our bots are allowed to fetch data. This prevents malicious users from guessing your Property ID and stealing your data using the master key.
- Why a Service Account?: Using a Service Account allows Agency to perform background tasks (like updating your crawl records with live popularity data) without your browser needing to be open. It restricts access strictly to the bot.
How the System Works Under the Hood
Automated Tasks
After a successful connection, Agency will immediately begin working:
- Background Syncs: Agency will automatically pull the last 90 days of traffic and engagement data.
- Reporting: You will be able to view Traffic Sources, User Behavior, and Conversion metrics directly inside the Agency interface at
https://thisisagency.ai/analytics.
Troubleshooting
If Agency reports an error accessing your analytics:
- Ensure you added the exact Service Account email to the correct GA4 property.
- Ensure you pasted the correct numerical Property ID into your Agency Project settings.
How to Navigate the Analytics Console
Once your Google Analytics data is flowing, you can explore it via the tabs at the top of your Analytics interface.
- Overview (https://thisisagency.ai/analytics/): Your primary dashboard showing traffic trends (Active Users, Sessions), engagement rates, average engagement time, real-time active users, and algorithm impact analysis.
- Traffic Sources (https://thisisagency.ai/analytics/traffic-sources/): Explore the channels, sources, and mediums driving traffic and conversions to your site.
- Locations (https://thisisagency.ai/analytics/locations/): Monitor where your users are coming from geographically.
- Devices (https://thisisagency.ai/analytics/devices/): Break down your audience by device category (Mobile, Desktop, Tablet) to identify potential mobile usability issues.
- Top Pages (https://thisisagency.ai/analytics/top-pages/): See your most popular landing pages, along with pageviews, active users, bounce rates, and average engagement times.Talking to Elsa: Because Agency uses "frontend grounding," all the Analytics data you see in your browser is securely passed to Elsa behind the scenes. You don't need any special commands—just open the chat sidebar and ask her things like, "Summarize my top traffic sources" or "Which pages have the highest bounce rate?", and she already knows exactly what you're looking at.
- Settings (https://thisisagency.ai/analytics/settings/): The setup area where you connect your Google Account and verify your GA4 Property ID.
Works Perfectly with Google Search Console (GSC)
The best part of this "Keys vs. Doors" setup is that it works exactly the same for Google Search Console! Once you create your master Service Account key in Google Cloud, you can use the exact same email address for all of your clients' Search Console properties.
Read the Search Console Integration Guide →Is this Best Practice?
Yes. The hybrid OAuth + Service Account model is the ultimate enterprise-grade security standard.
By forcing a manual OAuth check first, we completely eliminate the risk of a user hijacking the master key to view a competitor's data.
However, in the Agentic Era, software must also work for you in the background while you sleep. To achieve this securely, Google explicitly designed Service Accounts. As stated in Google's official documentation:
"A service account is a special type of Google account intended to represent a non-human user that needs to authenticate and be authorized to access data in Google APIs... It is a credential used for server-to-server interactions, such as an application without a user interface that runs as a process to access data or perform operations."
How to Disconnect
Revoking Verification (OAuth): You can revoke your personal OAuth access at any time by going to your Google Account Security settings (myaccount.google.com/connections) and removing Agency.
Revoking Bot Access (Service Account): Simply log into Google Analytics, navigate to Admin > Property Access Management, and remove the Service Account email address. Access is revoked immediately.
Shaun Anderson
Shaun Anderson, AKA @hobo_web, is the Lead AI Architect behind Agency (thisisagency.ai). Shaun has over 25 years of experience in forensic SEO auditing. He was the primary investigator of the Google Search Leak of 2024, the writer of The Hobo SEO Quadrilogy, and a Keynote speaker at SMX Paris 2026.