Google Merchant Center’s New Agency Roles: Why Access Control Just Became a Growth Lever for Ecommerce
Google’s new Merchant Center agency roles move client access from “person-based” to “agency-based.” That sounds administrative—until you manage 20+ stores, multiple contractors, and Shopping feeds that directly impact revenue. Here’s what changed, why it matters, and the operational playbook agencies and SMEs should adopt next.
By Marius Dosinescu (AYSA.ai)
Google just introduced new Merchant Center agency roles—and if you run ecommerce marketing for multiple brands (or you’re an SME that relies on an agency), this is one of those “boring admin updates” that quietly changes everything.
Because the real story isn’t the UI. The story is that Google is moving Merchant Center access from people to organizations—and that shift reduces risk, reduces churn pain, and makes it possible to scale operationally without turning your account stack into a fragile mess of one-off permissions.
Search Engine Land broke the news and the headline is straightforward: Google is rolling out new Agency Admin and Standard roles in Merchant Center for Agencies, linking clients to agencies (not individual users), and adding labels to group accounts for bulk access management. You can read the original coverage here: Google introduces new Merchant Center agency roles (Search Engine Land).
This editorial goes deeper: what changed, why it matters beyond permissions, what can go wrong during the transition, and what SMEs and agencies should do next—especially if your revenue depends on Shopping, product listings, and feed health.
Concise summary

- What changed: Merchant Center for Agencies now supports agency-level client linking and new role types (Agency Admin and Standard), plus labeling to group client accounts and manage access in bulk.
- Why it matters: It reduces “permission sprawl,” speeds onboarding/offboarding, and improves security—critical when agencies manage dozens (or hundreds) of stores, contractors, and seasonal campaigns.
- Who benefits most: Agencies, franchise operators, aggregators, multi-brand ecommerce groups, and SMEs that use multiple vendors.
- What to do next: Audit who has access today, define role boundaries, introduce labeling conventions, and build an access change process that’s as standardized as your reporting process.
- Where AYSA fits: Access control is only one side of operational maturity. The other side is execution: continuously Monitoring, preparing website changes, routing them for approval, and shipping the fixes that actually move performance. That’s the “Approved Execution” layer AYSA is built for (see AYSA Monitoring).
Table of contents

- What changed in Merchant Center for Agencies (and why it’s more than a UI tweak)
- Why Google is making this move now
- The hidden risk this update is addressing: “permission sprawl” in ecommerce operations
- Custom labels: the small feature that can save agencies hours
- How this changes day-to-day agency operations
- A practical SME scenario: a 12-person ecommerce brand + a small agency + contractors
- Security and compliance implications (practical, not theoretical)
- What can go wrong (and how to avoid it)
- What to monitor after you change access
- Implementation playbook: a role-and-process blueprint
- Where AYSA fits: monitoring, recommendations, and approved execution across teams
- What to do next
- Sources and further reading
What changed in Merchant Center for Agencies (and why it’s more than a UI tweak)

According to Search Engine Land’s report, Google is rolling out new roles for Merchant Center for Agencies:
- Agency Admin (full administrative privileges within the agency account)
- Standard (limited permissions aligned to least-privilege access)
The more important architectural change: clients are linked to the agency, not to individual users. That means your client relationships live at the organization level. Team members come and go, but the client linkage remains stable.
And Google introduced custom labels, so Agency Admins can organize client accounts into categories (e.g., brand, vertical, internal pod/team). Those labels can be used to grant Standard users access to groups of accounts in bulk.
Here’s why that matters in real life:
- When an agency employee leaves, you shouldn’t have to remember every client account they touched over 18 months.
- When a new hire starts, you shouldn’t need a spreadsheet plus 45 manual permission changes just to get them productive.
- When you use contractors, you should be able to grant narrow access for a short window without risking broad account exposure.
In other words, Google is shifting the model from “who is this person?” to “what is this person responsible for?” That’s a maturity move—and it aligns with how scalable operations work everywhere else in business.
If you want Google’s own documentation for how access works, Search Engine Land pointed to Google’s help resource: the article references ‘Managing user access in Merchant Center for Agencies’. (I’m not going to pretend I opened that help doc from here, but it’s the right “dig deeper” path.)
Why Google is making this move now
This update is about more than convenience. It’s about the reality of how ecommerce marketing is actually run in 2026:
- SMEs outsource more execution work (feeds, SEO, creative testing, paid media) to specialized partners.
- Agencies rely on distributed teams and contractors—and switch staffing frequently.
- Retailers operate across more surfaces (Shopping, free listings, marketplace ecosystems, paid social, email) and need tighter governance.
- Security expectations are rising. “We shared a login” isn’t just messy—it’s indefensible.
Google can’t fix your internal processes, but it can design account access in a way that nudges the ecosystem toward safer defaults. Agency-level linking + role-based access is a nudge toward maturity.
There’s also a subtle incentive on Google’s side: when account management is less painful, agencies can manage more clients effectively. And when agencies manage more clients effectively, more commerce flows through Google surfaces. That doesn’t make the update cynical. It makes it aligned.
The hidden risk this update is addressing: “permission sprawl” in ecommerce operations
If you’ve never lived through “permission sprawl,” it’s basically this:
- You grant access to someone “just for a week.”
- They finish the task.
- No one removes access.
- Six months later, you don’t remember who they are, what they changed, or what they can still see.
Permission sprawl is not an enterprise-only problem. SMEs actually suffer more, because they often lack:
- Formal IT processes
- Dedicated security staff
- Documentation for who owns what
Now consider what Merchant Center controls. It is not a “nice-to-have tool.” Merchant Center sits close to revenue because it influences:
- Product eligibility and approvals
- Feed quality and consistency
- Whether products show in Shopping experiences and free product listings (depending on setup)
- Policy issues that can block visibility
If the wrong person has access (or the right person has too much access), you’re exposed to:
- Accidental changes that break Product Visibility
- Inconsistent feed edits across clients
- Slower recovery from disapprovals because nobody knows “who last touched it”
- Long-term governance problems (no clear owners)
Google’s new roles don’t remove responsibility from you. But they make it easier to implement least privilege: give people only the access they need, only for the accounts they should touch.
Custom labels: the small feature that can save agencies hours
Labels sound trivial until you map them to how agencies work.
Most agencies don’t truly manage “accounts.” They manage portfolios with structure:
- A pod for home goods
- A pod for apparel
- A pod for B2B ecommerce
- A senior strategist who oversees 10 brands
- A feed specialist who supports only clients with complex variants
Before labels, assigning access often meant doing it the hard way—one account at a time—especially when the system is keyed to individual users.
Labels change the unit of management from “account” to “group.” That creates three operational advantages:
1) Faster onboarding with fewer mistakes
When a new team member starts, you can grant access to a labeled set of accounts instead of hunting and pecking through dozens of clients. Less clicking, fewer omissions, fewer accidental grants to the wrong client.
2) Cleaner offboarding (the part everyone forgets)
Offboarding is where agencies get hurt: the person is gone, and you’re left unwinding access across tools under time pressure. Bulk access management makes it easier to remove access consistently.
3) Cleaner temporary rotations
Vacation coverage, maternity leave coverage, short-term contractor projects—labels make temporary access assignments practical without turning permissions into a permanent mess.
My recommendation: don’t treat labels as “nice UI metadata.” Treat them as part of your operating system. Which leads us to the agency operations shift.
How this changes day-to-day agency operations
In good agencies, operational excellence isn’t about having the best ideas. It’s about reliably shipping good work across many clients without breaking things.
Merchant Center’s new agency roles support that shift in a few ways.
Client ownership becomes organizational, not personal
When a client is linked to the agency (not a user), you reduce the chance that one employee becomes the “single point of access failure.” That’s a bigger deal than it sounds.
Agencies frequently face scenarios like:
- “Only Jamie can access this client’s Merchant Center.”
- “Jamie is out today.”
- “The feed disapproved 40% of SKUs today.”
That’s not just an inconvenience. That’s a revenue incident. Centralized client linking makes it harder for access to become accidentally siloed.
Separation of duties becomes easier to enforce
In practice, ecommerce agencies often need to split responsibilities:
- Paid media team needs visibility, but not full control of feed settings.
- Feed ops team needs to adjust product data, but shouldn’t touch billing or unrelated accounts.
- Account management needs oversight, but shouldn’t be the one making risky changes.
Role-based access makes that kind of separation easier to implement—and easier to explain to clients as a security best practice.
Standardization becomes the differentiator
The agencies that win long-term are the ones that can deliver consistent outcomes without heroics. This update makes it simpler to standardize:
- Who can link/unlink clients
- Who can grant access
- Which team sees which accounts
That’s not “admin.” That’s scalable production.
A practical SME scenario: a 12-person ecommerce brand + a small agency + contractors
Let’s make this concrete with a scenario that’s common for growing SMEs.
Business: a 12-person ecommerce brand selling premium home goods (DTC + some wholesale).
Team setup:
- Founder (still wants visibility into marketing, not daily controls)
- One in-house marketer (owns the calendar and vendor coordination)
- A small paid media agency (runs Google Ads + Shopping)
- A feed contractor (fixes product data issues, works 5–10 hours/week)
- A developer (part-time, handles site changes and tracking)
Before the new agency roles, access usually drifts into one of two unhealthy patterns:
Pattern #1: Everyone gets “too much” access
The founder grants admin access to everyone because it’s faster than figuring out granular permissions. That speeds up today, and increases risk forever.
Pattern #2: One person becomes the gatekeeper
The in-house marketer becomes the bottleneck because they’re the only one who knows how access is configured. That reduces risk, but slows down execution—especially during incidents.
With agency roles + labels, the healthier model looks like this:
- Agency Admin: one or two senior people at the agency (not the whole team)
- Standard users: paid specialists and feed specialists scoped to only the clients they manage
- Labels: “Home Goods Pod,” “Feed Support Needed,” “Tier 1 Clients,” etc.
Now onboarding the feed contractor is a controlled process:
- Give access only to the labeled set of accounts where they work
- Remove access automatically when the contract ends
- Maintain client linkage at the agency level so staffing changes don’t break support
This is how you scale without accumulating operational debt.
Security and compliance implications (practical, not theoretical)
Most SMEs don’t think about compliance until a platform forces the issue. In ecommerce, platforms are increasingly forcing the issue.
Even if you’re not in a regulated industry, you still have:
- Customer data in multiple systems
- Financial exposure through ad spend and revenue Attribution
- Brand exposure through product representation and policy compliance
Least-privilege access is the simplest security principle that delivers real-world benefit. These new roles make it easier to implement least privilege in Merchant Center for Agencies by restricting Standard users to only what they need.
But here’s the key business takeaway: security is now part of performance. Not because security “ranks,” but because operational incidents are performance events:
- A broken feed can tank Shopping visibility.
- Slow recovery can cost days of revenue.
- Client trust erodes when governance is sloppy.
Agencies should treat this update as an opportunity to reset expectations with clients:
- Document roles and who holds them
- Explain why not everyone gets Admin
- Build offboarding into the contract and the process
What can go wrong (and how to avoid it)
Any time permissions change, there’s risk. Here are the most common failure modes I’ve seen in similar transitions across marketing platforms—plus how to avoid them.
1) Too many Agency Admins
If everyone is an admin, nobody is accountable. Keep Agency Admin to a small set of senior operators. Make it boring and controlled.
Mitigation: Cap Agency Admin to 1–3 people per agency account; use Standard roles for most staff.
2) Label chaos (no taxonomy)
Labels are powerful, but without a naming convention they become noise. Then bulk access becomes dangerous.
Mitigation: Create a label taxonomy that mirrors your org structure. Examples:
- Team: POD-Home, POD-Apparel
- Client tier: T1, T2
- Needs: FEED-ComplexVariants, FEED-HighDisapprovalRisk
- Region: NA, EU (if relevant)
3) Contractors get permanent access by default
Contractors are essential, but their access should be time-bound and scoped.
Mitigation: Use a checklist: grant access + set a calendar reminder to remove it. Make this part of monthly ops.
4) Client confusion about “who owns what”
Clients sometimes believe that if the agency controls access, the agency “owns” the account. That’s not what this is about.
Mitigation: Put it in writing: the business owns the underlying Merchant Center; the agency manages access and operations under agreed scope.
5) Thinking access control solves feed quality
This is the big one. Access control reduces risk. It doesn’t fix the system that produces errors, disapprovals, missing attributes, or mismatched landing pages.
Mitigation: Pair governance with execution: monitoring, QA, change control, and fast remediation loops. This is where modern automation (done safely) matters.
What to monitor after you change access
When you restructure access, you should expect a temporary “operations dip” as people adjust. The mistake is letting that dip turn into performance loss because nobody is watching the right signals.
Monitoring should include two layers:
Operational monitoring (access + workflow)
- Do the right people still have access to do urgent work?
- Are requests piling up because one Admin is a bottleneck?
- Are contractors blocked when they need to fix feed issues?
Performance monitoring (commerce visibility outcomes)
Even though this update is “access,” the reason you care is performance. Watch for:
- Unexpected drops in product visibility (which can show up as drops in Clicks and conversions)
- Increasing disapprovals or unresolved issues (often a workflow ownership problem)
- Slower response time to urgent fixes
If you’re building a modern visibility stack, consider monitoring not just classic SEO metrics but also “AI search visibility” and brand presence across answer engines. AYSA is built to support that broader shift with dedicated tooling and monitoring workflows—see AYSA AI Search Visibility and AYSA Monitoring.
(Important note: I’m not claiming Merchant Center roles directly impact AI Search. I’m saying operational maturity—access control + execution—matters across the entire search and discovery landscape.)
Implementation playbook: a role-and-process blueprint
If you’re an agency, you should treat this like an opportunity to upgrade your internal operating system. If you’re an SME, you should treat this like a chance to demand a higher standard of governance from partners.
Here’s a practical playbook.
Step 1: Build an access inventory (even if it’s ugly)
List:
- All people with Merchant Center access
- Their role (what they do, not their job title)
- Which client accounts they should touch
- Which accounts they should not touch
This is the “you can’t improve what you can’t see” step.
Step 2: Define role boundaries in plain language
Define:
- What Agency Admins can do (and when)
- What Standard users can do (and what they cannot)
- What actions require a second set of eyes (internal approval)
Don’t write a policy doc nobody reads. Write a one-page rule set and make it part of onboarding.
Step 3: Create a label taxonomy that matches delivery pods
Labels should reflect how work is delivered. Good labels:
- Map to teams
- Map to support type
- Map to regions or verticals if those reflect staffing
Bad labels are emotional or vague: “Important,” “VIP,” “Hard client,” etc. They don’t translate into access logic.
Step 4: Introduce an onboarding/offboarding checklist
A good checklist includes:
- Grant access via label group(s)
- Confirm access works
- Set reminders for contractor access expiration
- Remove access immediately on offboarding
- Verify nothing critical is tied to the person (documentation, alerts, ownership)
Step 5: Pair access control with a change-management process
This is where many organizations stop short. Governance without execution discipline still produces chaos—just slower chaos.
Change-management doesn’t need to be heavyweight. It just needs:
- A request path (who asks for what)
- An approval path (who approves changes that can cause revenue impact)
- A deployment path (who executes, when, and how it’s verified)
And if you want this to actually work, you need a system that makes it easy to execute consistently—not just talk about it. That’s a core idea behind AYSA.
Where AYSA fits: monitoring, recommendations, and approved execution across teams
Merchant Center roles solve an important problem: who can touch what.
But for most SMEs and agencies, the bigger bottleneck is: what actually gets done—and how fast.
In ecommerce, performance is a product of many small improvements shipped consistently:
- Technical fixes that unblock crawling and indexing
- Content updates that improve category clarity and product discovery
- Structured data improvements to reduce ambiguity
- Internal linking and navigation improvements that help both users and search systems
Teams fail here for a simple reason: execution is fragmented.
- Someone notices an issue.
- They write it in Slack.
- It becomes a Jira ticket.
- It sits for 3 weeks.
- It ships without QA—or never ships.
AYSA is designed as an execution system: it monitors, prepares changes, routes them for approval, and executes accepted website changes. That matters because it turns “insight” into “improvement” with governance built in.
Relevant AYSA resources if you want to see how we think about this operationally:
- Monitoring (the foundation: know what changed, what broke, what drifted)
- AI SEO Tools (tooling designed for modern search workflows)
- AI Search Visibility (track and improve presence in AI-driven discovery)
- Pricing (so you can evaluate fit without a sales maze)
- Blog (ongoing playbooks and field notes)
Here’s the key connection: Google is making account governance more scalable. That’s good. But scalable governance only pays off if you also build scalable execution—because ecommerce is too competitive to run on manual checklists forever.
What to do next
Whether you’re an agency leader or an SME owner, here’s the practical action list I’d implement over the next 30 days.
If you’re an agency
- Appoint 1–3 Agency Admins and make it explicit who they are.
- Audit current access and remove anyone who shouldn’t be there.
- Design a label taxonomy that matches your delivery pods and client tiers.
- Rebuild onboarding around labels + Standard users.
- Formalize offboarding (include contractors) as a monthly recurring ops task.
- Update your client-facing security language to explain why you restrict access (this builds trust).
- Pair governance with execution: define how feed issues, policy issues, and site issues get detected, approved, and shipped.
If you’re an SME working with an agency
- Ask who is Agency Admin and why.
- Request a quarterly access review across key marketing systems (Merchant Center, Ads, analytics, CMS).
- Insist on least privilege for contractors and short-term vendors.
- Demand a change log culture: what changed, when, why, and what was the result.
- Invest in monitoring + execution discipline, not just reporting. Reporting tells you what happened. Execution changes what happens next.
If you want to operationalize monitoring and turn recommendations into approved execution, start here: AYSA Monitoring.
Sources and further reading
- Search Engine Land: Google introduces new Merchant Center agency roles
- Search Engine Land: Google adds Channel Diagnostics to Performance Max (context: commerce account management keeps getting more complex)
- Search Engine Land: Google tests AI-generated summaries in Search ads (context: Google surfaces are evolving; operational discipline matters)
- Search Engine Land: How competitors target your branded traffic with Google Ads (context: governance + defense is part of growth)
- Search Engine Land: GraphRAG: What entity-first retrieval means for SEO (context: modern search systems reward clarity and consistency)
Continue the AI search topic inside AYSA.
Use these pages to connect the article with AI SEO tools, AI visibility monitoring, AI Overviews and approved website execution.
Turn this topic into a website action plan.
Use these AYSA hubs to move from reading to technical fixes, AI visibility monitoring, research, glossary context and approval-first SEO execution.