Attribution tools for agencies with many client accounts
Ask which GA4 role the vendor's login needs, whether each client authorized it, whether it reuses client data, where data is stored and what happens at the end. Causality Engine reads one brand's GA4 export and is not a multi-client agency dashboard.
€99 once, excl. VAT. Full refund within 30 days, no questions asked. You keep the read.
By Joris van Huët, Founder & CEOPublished 5 min read
Ask any attribution vendor five things before you connect any client: which GA4 role its login needs, whether that client has authorized the tool in writing, whether the vendor reuses client data for its own purposes, where the data is stored, and what happens to it when you stop. Google's documentation covers the GA4 side: an account holds data owned by one legal entity, and a role granted at account level applies to every property in it. The EDPB guidelines cover the GDPR side: a processor acts only on the controller's instructions, and adding a purpose of its own makes it a controller for that use.
The company that publishes this page sells a one-brand attribution read, not a multi-client dashboard. The last section says what that means for an agency.
Where should each client's GA4 data live, and who gets access?
Google defines an account as a collection of properties whose data is owned by a single legal entity, and advises one account per company and one property per brand or business unit. Its hierarchy page says you can have up to a maximum of 100 accounts, each with up to 2,000 properties. Roles flow downwards: a role given at account level applies to every property in that account, and a user's effective permission is the most permissive role they hold for a resource. So one agency-owned account holding several brands means anyone with an account-level role sees them all. That is an inference from Google's rules, not something Google says about agencies. A separate account per client, owned by that client, with your agency added as a user, avoids it.
GA4's Viewer role can see settings and data, so a tool that only reads has no obvious reason to ask for more. Ask which role the vendor's login needs and why. If a tool reads the BigQuery export instead, Google says you own the exported data and manage access with BigQuery ACLs. Standard properties have a daily export limit of 1 million events, which applies to each client's property.
Who is the controller, and who is the processor?
The EDPB's guidelines on controller and processor roles (Guidelines 07/2020, final version of 07 July 2021) rest on two definitions. A controller determines the purposes and means of processing personal data. A processor acts under the controller's instructions only, on its behalf. The EDPB's guide for small businesses adds what follows: a contract must govern the relationship, a processor may not engage another processor without the controller's prior written authorization, at the controller's choice it deletes or returns all personal data when the service ends, and the controller is liable for its own compliance and for the processor it chooses.
For an agency that suggests three layers, which is reasoning and not a legal opinion: the brand decides why its buyers' data is processed, the agency acts on its instructions, and any tool the agency adds that processes that data is a sub-processor the brand has to authorize. The guidelines say the role comes from what an entity actually does, not from its label, and give an example of a marketing provider that uses a company's customer database for its own business purposes: that use makes it a controller for that processing, and the processing would infringe the GDPR. Asking whether a vendor's benchmarks or model training draw on your clients' data is asking that question.
What should you ask a vendor before you connect any client?
- Which role does its login need? Pass: a read role on that client's own property. Fail: administrator access, or access at account level.
- Has that client authorized it? Pass: the vendor is on the sub-processor list in your contract with that client, in writing. Fail: no list, or a general clause allowing any partner.
- Is client data used for anything except the service? Benchmarks, model training, product improvement. Pass: a written no, or an opt-in each client controls. Fail: silence, or "anonymized and aggregated" with no purpose stated.
- Where is the data stored, and does it leave the EEA? Pass: locations named in writing, with transfers only on your client's instructions. Fail: no named locations.
- What happens when you stop? Pass: deletion or return at your client's choice, confirmed in writing. Fail: retention for as long as needed, or no answer.
Can an agency run a read on each client?
A causal attribution read like Causality Engine's takes one brand's GA4 export. It is not a multi-client agency dashboard: an agency that uses it runs one read per client brand, each from that client's own export.
Sources, 30 September 2026: Google Analytics hierarchy (Google, 2026); Google Analytics account structure (Google, 2026); Access and data-restriction management (Google, 2026); BigQuery Export (Google, 2026); Guidelines 07/2020 on the concepts of controller and processor in the GDPR (EDPB, 2021); Guidelines 07/2020, full text (EDPB, 2021); Data controller or data processor (EDPB data protection guide for small business, 2026).
Related answers
Frequently asked questions
Does Causality Engine work as a multi-client agency dashboard?
No. A read takes one brand's GA4 export, so an agency runs one read per client brand, each from that client's own export. It is not a multi-client agency dashboard.Should each client have its own GA4 account?
Google describes an account as a collection of properties whose data is owned by a single legal entity and advises one account per company. A role granted at account level applies to every property in that account, so separate accounts keep clients apart.Is an agency a controller or a processor for client analytics data?
It depends on who decides the purposes and means of processing. A processor acts only on the controller's instructions, and one that adds a purpose of its own becomes a controller for that use (EDPB Guidelines 07/2020). Put the roles in a written contract.
Go deeper: Causal attribution, explained.
Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.
Keep reading
Terms in this article
- AnalyticsAnalytics is the systematic computational analysis of data. It reveals customer behavior and measures campaign performance.
- AttributionAttribution identifies user actions that contribute to a desired outcome and assigns value to each. It reveals which marketing touchpoints drive conversions.
- Attribution PlatformAttribution Platform is a software tool that connects marketing activities to customer actions. It tracks touchpoints across channels to measure campaign impact.
- Attribution SoftwareAttribution Software measures campaign impact by tracking customer interactions across touchpoints. It assigns value to each channel, showing what drives conversions.
- Causal AttributionCausal Attribution uses causal inference to determine which marketing touchpoints genuinely cause conversions, not just correlate with them.
- CausalityCausality is the relationship where one event directly causes another, essential for identifying specific actions that drive desired outcomes in marketing.
- DashboardA dashboard is a visual display of key information required to achieve specific objectives. It consolidates data onto a single screen for quick review.
- Google AnalyticsGoogle Analytics is a web analytics service that tracks and reports website traffic.