Data Measured

artifact #A-014 · checklist · current

GA4 dashboard pre-publish checklist (access, personal data, restricted metrics)

Run this before anyone publishes a Google Analytics dashboard: every published dashboard is shared with the whole property, so the checks are about who will see it and what its cards can expose, not how it looks.

verified_on
2026-09-17
checked against
Google Analytics Help — About Google Analytics dashboardGoogle Analytics Help — Access and data-restriction managementGoogle Analytics Help — Reporting surfaces comparisonGoogle Analytics Help — Best practices to avoid sending PIIGoogle Analytics Help — Data redactionData Studio — Connect to Google Analytics
next re-check
2026-12-01
status
current
time
45 minutes
skill
you have Administrator access to the property

What's inside

  • The access pass: every account and user group in Property access management (and inherited from the account), with a keep or remove decision, since any role can view a published dashboard
  • The card rules: no Page location or query strings, no free-text or ID-like custom dimensions on table cards; data redaction on for email addresses and the query parameters that carry personal data
  • The restricted-metrics test: open a dashboard with revenue, cost or ROAS cards from an account with No Revenue Metrics or No Cost Metrics, the same hour it is published
  • The number labels: each card titled with what it counts, noting that reports include behavioral modeling and (other) rows, so it will not equal a BigQuery count
  • The where-it-belongs test: GA4 dashboard if the whole property may see it, Data Studio if the audience is narrower or wider, BigQuery if someone will reconcile it
  • The card spec sheet: metric, dimensions and date range for each of the 15 cards (30 on Analytics 360), kept outside GA4 because dashboards have no API

Install

  1. In Admin, open Account access management and Property access management, export the member list, and remove or downgrade anyone who should not see a KPI page.
  2. In Admin, Data collection and modification, Data streams, open your web stream and click Redact data under Events: turn on email redaction and list the query parameters that carry personal data. It applies to events collected from then on, not to history.
  3. Draft the dashboard, then check every table card's dimensions against the card rules before you click Publish.
  4. Straight after publishing, open the dashboard from a restricted account and confirm revenue and cost cards are hidden; if they are not, unpublish and move those cards to a Data Studio report shared by name.
  5. Copy each card's metric, dimensions and date range into your tracking plan, with the date the dashboard was published.

Breaks on

The logged changes that can invalidate this artifact. A new one triggers a re-check.

Stamped 17 Sept 2026 · re-checked quarterly or on change · corrections to team@datameasured.com · ← the library