Fill in before sending
[account name][GTM account name][emails to keep and domain][emails of those who left, or write "not sure"]
A team member or our previous agency has left, and I want to see who still has access to our accounts and at what level. My Google Ads account: [account name]. My Tag Manager account: [GTM account name]. People who should keep access, and our company domain: [emails to keep and domain]. People whose access should be removed: [emails of those who left, or write "not sure"].
1. Google Ads users. With google_ads_query, pull email_address, access_role, access_creation_date_time and inviter_user_email_address from customer_user_access. Read customer_user_access_invitation as well for pending invitations.
2. Manager account links. With google_ads_query, pull linked manager accounts and their status from customer_manager_link. An agency's access often comes through its own manager account rather than individual users.
3. Who made recent changes. With google_ads_query, pull user_email and client_type for the last 30 days from change_event. Google keeps only the last 30 days in this resource and requires a LIMIT. If an email that is not in the user list is making changes, show it separately, because that person may be coming in through a manager account.
4. Tag Manager. Find the account with list_gtm_accounts and list each user's account permission (user, admin) and container permission (read, edit, approve, publish) with list_gtm_permissions.
Rules for judging:
1. Mark every email that is not on the keep list as "review". Call out personal addresses outside the company domain separately.
2. People with ADMIN in Google Ads, or admin or publish in Tag Manager, who are not on the keep list are the highest risk.
3. Every account must keep at least one administrator. Never propose removing the last one.
4. If an agency has a manager account link, note that cutting it may affect that agency's reporting and, where it applies, the billing setup.
Format the output like this: one table per platform: user, role, since when, invited by, made changes in the last 30 days, decision (keep, lower the role, remove, review). Then a to-do list.
To remove Tag Manager access, use manage_gtm_permissions: with action=revoke and the permission_path from list_gtm_permissions, show a preview with confirm=false first, wait for my approval, apply it and confirm by reading list_gtm_permissions again. There is no tool that removes Google Ads users or manager links; list them person by person so I can remove them on the Access and security page under the Admin menu in Google Ads.
Example result
An example of the output this prompt produces. Its structure comes from the tools' real output; numbers and names are fictional.
Example output (based on a fictional account, not real customer data)
Google Ads
| User | Role | Since | Invited by | Changes in 30 days | Decision |
|---|
| marketing@company.com | ADMIN | 2024-03-02 | | Yes | Keep |
| amy.k@gmail.com | ADMIN | 2025-06-18 | marketing@company.com | No | Remove (not on list, personal address) |
| intern@company.com | STANDARD | 2026-02-11 | marketing@company.com | No | Review |
Linked manager account: 123-456-7890, status ACTIVE. specialist@oldagency.com made changes in the last 30 days without being in the user list and is probably coming in through this link.
Tag Manager
| User | Account permission | Container permission | Decision |
|---|
| marketing@company.com | admin | publish | Keep |
| specialist@oldagency.com | user | publish | Remove |
To do
1. Remove specialist@oldagency.com from Tag Manager (preview ready, waiting for your approval).
2. Remove amy.k@gmail.com in Google Ads under Admin > Access and security.
3. Agree the last reporting date with the old agency before cutting its manager account link.