Read-only access: how to let an auditor in without handing over the keys
An audit of your own data doesn't need your passwords, your database or admin rights. Here is the access an auditor actually needs in Search Console, Analytics, your code and your logs, what it can't do, and how to take it back.
Sooner or later someone who offers to help with your website asks for access. Often they ask for everything: the admin login, the hosting panel, “whatever you have”. It is the fastest way for them, and the riskiest for you.
An audit reads. It doesn’t need to change anything, so it shouldn’t be able to. This is what we ask for in our deep audit, and what you can ask of anyone else.
The rule: add a person, never share a password
Every tool worth using lets you add a user with a limited role. A shared password gives everything you can do, to whoever ends up holding it, with no record of who did what. An added user gets only the role you choose, appears in the list of users, and can be removed with one click.
What each tool needs
- Search Console: a user with Restricted permission. They can see your search data. They can’t change settings, submit pages or add other users.
- Google Analytics: the Viewer role. They can see reports. They can’t edit the configuration, the conversions or the filters.
- Your code: read access to the repository. They can read and copy the code. They can’t push a change.
- Server logs: no access at all. You download the files from your hosting panel and send them.
- Ad accounts: read-only access. They see campaigns and spend. They can’t touch a budget.
For our audits it is one address, added as a viewer. Each source is optional: what you don’t share, the report lists as not seen.
What nobody needs for an audit
- Your own login, to anything.
- Owner or administrator roles.
- Your database, or any customer records.
- The admin of your website or your store.
- Your hosting or your domain account.
If an audit can’t be done without one of these, ask why. There is rarely a good answer.
Take it back when it’s done
Access should end when the work does. Open the list of users in each tool and remove the address. It takes a minute, and it is worth doing the same day the report arrives, for us and for every vendor you have ever added. Most companies find a few names in those lists that nobody remembers.
Why we go further and keep it read-only afterwards
Even when the audit turns into work, our first month runs the same way: we read, and your team applies each fix. Nothing changes on your site that your own people didn’t put there.
Ten minutes, once a year
- Open the users list in Search Console, Analytics, your repository and your ad accounts.
- Remove everyone who no longer works with you.
- Lower every role that is higher than the job needs.
- Change any password that was ever sent by email or chat.
Written from our engineers’ work on production systems. Want a second opinion on your project? Talk to an engineer.
See the work →