Skip to content

GTM. Folder access control. Limit what agencies can edit in your container.

What this means for your store

Giving an agency full container edit access is how consent tags get changed without legal review. Folder-level access (GTM 360) assigns read, edit, or publish rights per folder: your team locks Consent and Core Analytics; contractors edit only Paid Social and Affiliate folders.

Scenario on a real storefront

A UK marketplace onboards a new paid-social agency. They need TikTok and Pinterest tags but should not touch consent initialization or GA4 configuration:

Admin → User Management → Agency - Performance Team
  Container: GTM-PROD → Custom
    Folder "00 - Core / Consent" → Read
    Folder "01 - GA4 & Data Layer" → Read
    Folder "20 - Paid Social" → Edit
    Folder "21 - Affiliate Pixels" → Edit
  Default workspace permission: Read

// Agencies submit workspaces; your team publishes to live

What to do next

  • On the free GTM tier, mimic boundaries with naming conventions and a publish approval gate - folders need 360.
  • Do not grant Publish on the production container to vendors; they submit, you approve and publish.
  • Audit folder membership quarterly; contractor accounts often outlive the contract.

Bottom line

Folder access keeps agencies productive without handing them consent and core analytics. Pair permissions with an internal publish gate you control.