artifact #A-014 · checklist · current
GA4 dashboard pre-publish checklist (access, personal data, restricted metrics)
Run this before anyone publishes a Google Analytics dashboard: every published dashboard is shared with the whole property, so the checks are about who will see it and what its cards can expose, not how it looks.
- verified_on
- 2026-09-17
- checked against
- Google Analytics Help — About Google Analytics dashboardGoogle Analytics Help — Access and data-restriction managementGoogle Analytics Help — Reporting surfaces comparisonGoogle Analytics Help — Best practices to avoid sending PIIGoogle Analytics Help — Data redactionData Studio — Connect to Google Analytics
- next re-check
- 2026-12-01
- status
- current
- time
- 45 minutes
- skill
- you have Administrator access to the property
What's inside
- The access pass: every account and user group in Property access management (and inherited from the account), with a keep or remove decision, since any role can view a published dashboard
- The card rules: no Page location or query strings, no free-text or ID-like custom dimensions on table cards; data redaction on for email addresses and the query parameters that carry personal data
- The restricted-metrics test: open a dashboard with revenue, cost or ROAS cards from an account with No Revenue Metrics or No Cost Metrics, the same hour it is published
- The number labels: each card titled with what it counts, noting that reports include behavioral modeling and (other) rows, so it will not equal a BigQuery count
- The where-it-belongs test: GA4 dashboard if the whole property may see it, Data Studio if the audience is narrower or wider, BigQuery if someone will reconcile it
- The card spec sheet: metric, dimensions and date range for each of the 15 cards (30 on Analytics 360), kept outside GA4 because dashboards have no API
Install
- In Admin, open Account access management and Property access management, export the member list, and remove or downgrade anyone who should not see a KPI page.
- In Admin, Data collection and modification, Data streams, open your web stream and click Redact data under Events: turn on email redaction and list the query parameters that carry personal data. It applies to events collected from then on, not to history.
- Draft the dashboard, then check every table card's dimensions against the card rules before you click Publish.
- Straight after publishing, open the dashboard from a restricted account and confirm revenue and cost cards are hidden; if they are not, unpublish and move those cards to a Data Studio report shared by name.
- Copy each card's metric, dimensions and date range into your tracking plan, with the date the dashboard was published.
Breaks on
The logged changes that can invalidate this artifact. A new one triggers a re-check.
Stamped 17 Sept 2026 · re-checked quarterly or on change · corrections to team@datameasured.com · ← the library