Adding users and permissions in Search Console
The four access levels, which one to give a contractor, how to hand over a property you no longer manage, and why verification survives user removal.
Search Console access is per-property and finer-grained than most people use. Getting it right matters most at the two moments it is usually got wrong: onboarding an agency, and losing access to your own site.
The four levels
- Verified owner. Proved ownership through a verification token they control — a DNS record, an HTML file, a meta tag. Full access, can add and remove users, and cannot be removed by another owner. Ownership ends only when the verification token is gone.
- Delegated owner. Granted owner-level access by a verified owner, without holding a token of their own. Same powers day to day, but a verified owner can remove them, and they cannot outlive the verified owner's token.
- Full user. Sees all data and can use most tools — inspect URLs, submit sitemaps, request indexing. Cannot add or remove users. This is the correct level for almost everyone.
- Restricted user. View-only across most reports. Right for a stakeholder who wants numbers and should not be able to submit anything.
There is also Associate, a separate mechanism for linking a property to a YouTube channel or Play account. Unrelated to team access.
Adding someone
- Settings → Users and permissions.
- Add user, enter their Google address, choose Full or Restricted.
Access is immediate and there is nothing to accept. Note that it is granted to a Google account: adding a work address on Google Workspace works, adding an address with no Google account behind it does not.
What to give an agency or contractor
Full user. They get everything needed to do the work and cannot add anyone else or remove you.
Do not make a contractor a verified owner by handing them your DNS. If they place their own verification token, they hold ownership independently and removing them later means finding and deleting a record you did not create. That is the mess this level of care exists to avoid.
If they need API or automated-reporting access, add their service account address as a Full user rather than sharing a human login. See the Search Console API.
Removing a user does not remove ownership. If someone verified the property with their own token, deleting them from Users and permissions changes nothing — they re-appear as a verified owner. You have to find and remove the underlying verification method, then check Settings → Ownership verification to confirm which tokens still exist. Worth auditing that page once on any site you inherited.
Taking over a property
You cannot be granted verified ownership. Verify it yourself, with your own method:
- Add the property, choosing domain if you have DNS.
- Verify with a token you control.
- Open Ownership verification and remove tokens belonging to people who should no longer have access.
- Re-add current team members as Full or Restricted users.
Historical data comes with the property, not the user, so you keep the full 16 months.
Housekeeping worth doing
- Audit users and ownership tokens when anyone leaves.
- Keep at least two verified owners on anything important. One person with the only token is a single point of failure.
- Prefer DNS verification. It survives redesigns, replatforming and file cleanups, which meta tags and uploaded HTML files do not.
Searchlight reads whatever your Google account can see, including properties shared with you as a user.
See how Searchlight shows it