Google has added 14 methods to the alpha version of its Google Marketing Platform Admin API that let organizations create user groups, manage who belongs to them and grant organization-level roles to users or groups through code. The developer changelog dates the change to September 18, 2026. Google Analytics followed with its own release note on October 5, 2026, describing the same capability under the name "User Groups Admin API."
In Short
Google built a way for companies to manage teams of Google Analytics users with software instead of clicking through settings screens one person at a time. This matters most to large advertisers and agencies that add and remove dozens of people from their analytics accounts. The tool is still an early test version, and Google's own pages describe it in slightly different ways, so some details about what it can and cannot do remain unclear.
What changed on September 18
The changelog for the Google Marketing Platform Admin API carries a single entry for September 18, 2026, titled "New access management methods." It lists three batches of methods, all added to v1alpha.
The first batch covers the groups themselves: GetUserGroup, ListUserGroups, CreateUserGroup, UpdateUserGroup and DeleteUserGroup. According to Google's documentation, these methods exist "to create and manage the user groups in a GMP organization."
The second batch handles membership. GetUserGroupMember, ListUserGroupMembers, CreateUserGroupMember, UpdateUserGroupMember and DeleteUserGroupMember are there "to add, update and remove the users and user groups that belong to a user group, including each member's owner or member role," according to the changelog. That wording carries a detail easy to miss: a member of a group can itself be a user group. Groups can therefore nest.
The third batch is the one with the widest reach. GetAdminAccessBinding, ListAdminAccessBindings, CreateAdminAccessBinding and UpdateAdminAccessBinding let an organization "grant organization roles, such as the organization admin, user admin and billing admin roles, to a user or a user group," according to Google's documentation.
Five plus five plus four makes 14. The two resources that predate the release, organizations and analyticsAccountLinks, list eight methods between them in the current reference. The September entry nearly triples that count in one release, and the access management surface now accounts for 14 of the 22 methods listed.
The REST reference
The API overview page, also last updated on September 18, 2026, according to its footer, sets out the full structure. The service runs at marketingplatformadmin.googleapis.com, with a discovery document at https://marketingplatformadmin.googleapis.com/$discovery/rest?version=v1alpha. Five REST resources sit under it:
- v1alpha.organizations - findSalesPartnerManagedClients, get, list and reportPropertyUsage
- v1alpha.organizations.adminAccessBindings - create, get, list and patch
- v1alpha.organizations.analyticsAccountLinks - create, delete, list and setPropertyServiceLevel
- v1alpha.organizations.userGroups - create, delete, get, list and patch
- v1alpha.organizations.userGroups.members - create, delete, get, list and patch
Paths follow Google's standard resource pattern. A group is created with POST /v1alpha/{parent=organizations/}/userGroups. A member is added with POST /v1alpha/{parent=organizations//userGroups/}/members, which the reference describes as a method that "Adds a member to the specified GMP user group." Role bindings are created with POST /v1alpha/{parent=organizations/}/adminAccessBindings and modified with PATCH /v1alpha/{adminAccessBinding.name=organizations//adminAccessBindings/}, which "Updates an admin access binding in the specified GMP organization."
Updates in both the userGroups and members resources use PATCH rather than PUT, which in Google's API conventions means partial updates of named fields. The changelog names these methods UpdateUserGroup and UpdateUserGroupMember; the reference lists them as patch.
The missing delete
One asymmetry stands out in the reference. User groups can be deleted. Members can be deleted. Analytics account links can be deleted. Admin access bindings cannot - at least not through any method listed on either page.
The changelog names exactly four binding methods: Get, List, Create and Update. The overview page matches, with create, get, list and patch under the adminAccessBindings resource. Neither document lists a DeleteAdminAccessBinding.
The practical effect is not spelled out anywhere in the source material. It may be that a role is meant to be removed by patching a binding, or by deleting the group to which the role was granted, which would drop every member's inherited access at once. It may also be that revocation remains a manual task in the interface while the API is in alpha. Google's documentation does not say which, and that gap matters for anyone building an offboarding script: granting an organization admin role is possible through the API, while taking one away is not documented as a single call.
Two pages, two descriptions
Google Analytics surfaced the release 17 days after the developer changelog. The October 5, 2026 entry on the "What's new in Google Analytics" help page is headed "User Groups Admin API" and states that "Google Analytics now supports a User Groups Admin API, allowing you to manage user group access to your Google Analytics properties and accounts at scale."
According to the help page, "User groups simplify the process of managing access for large teams, and the User Groups API enables you to maintain and update these configurations programmatically." It lists two capabilities: managing user groups ("Create new groups, edit existing group details, or delete groups using their unique identifier") and managing group membership ("Add users to specific user groups, remove users from groups, and assign permission levels as either a Member or Owner").
The Analytics entry also sets the permission threshold. "To use these API features, User Admin or Org Admin permissions are required on the given organization," according to the help page.
The two descriptions do not line up exactly, and the discrepancy is worth setting out rather than smoothing over.
First, the name. The help page calls the product a "User Groups Admin API." The developer documentation contains no API by that name. The methods belong to the Google Marketing Platform Admin API, service marketingplatformadmin.googleapis.com, version v1alpha. The help page points readers to "the reference docs" and "the Developer Changelog," which suggests the two pages describe one release under two labels.
Second, the scope. The Analytics note speaks of managing "user group access to your Google Analytics properties and accounts." The developer reference, however, attaches every new binding to the organization: each path begins with organizations/*, and the roles named in the changelog are organization roles - organization admin, user admin and billing admin. Neither PDF shows a method in this API that binds a user group to an individual Analytics property or account. That property-level binding may happen elsewhere, for instance through the separate Google Analytics Admin API, or the help page may be describing the downstream effect of organization groups in loose terms. The source documents do not settle it.
Third, the dates. The developer pages carry September 18, 2026. The Analytics release note carries October 5, 2026. The 17-day gap is consistent with methods shipping to developers first and being announced to Analytics users later, but neither page explains the timing.
Fourth, the overview text. Despite carrying a September 18 update date, the overview page still describes the API's purpose only in terms of its earlier functions. "You can use the Google Marketing Platform Admin API to manage links between your Google Marketing Platform organization and Google Analytics accounts, and to set the service level of your GA4 properties," according to the overview. User and access management is absent from that summary, though it now makes up most of the method list beneath it.
Alpha status
Every page of the developer documentation carries the same banner: "The Google Marketing Platform Admin API is in Alpha. Alpha is an unstable early preview stage." Google directs developers to the Google Marketing Platform API Notify Group for "official announcements about this API."
An alpha label means method names, fields and behavior may change without the deprecation windows attached to stable versions. The API has been in that state since its first release. According to the changelog, "Google Marketing Platform Admin API v1alpha is released" on March 6, 2024, and no v1beta or v1 has followed in the 31 months since.
For organizations considering automating access control, that duration cuts both ways. The API has been stable enough to accumulate methods across four changelog entries without a breaking change recorded in its changelog. It also has never carried a commitment that it will stay stable.
How the API grew
The changelog shows four dated entries, each widening the API's remit.
The initial release on March 6, 2024 established v1alpha. PPC Land covered that launch as a tool for upgrading and downgrading properties between standard Google Analytics and Analytics 360, and for linking Analytics accounts to Google Marketing Platform organizations. Those functions correspond to the analyticsAccountLinks resource and its setPropertyServiceLevel method, which "Updates the service level for an Analytics property," according to the reference.
On April 9, 2024, Google added GetOrganization, which "Looks up a single organization."
On October 29, 2025, three more methods followed: ListOrganizations, FindSalesPartnerManagedClients and ReportPropertyUsage. These pushed the API into commercial territory. FindSalesPartnerManagedClients "Returns a list of clients managed by the sales partner organization," according to the reference - a function aimed at the resellers that sell Google Marketing Platform products. Sales Partners were set up in 2018 as one of three partner categories, distinct from certified companies because they resell the technology on Google's behalf. ReportPropertyUsage "Gets the usage and billing data for properties within the organization for the specified month."
September 18, 2026 then added identity and access. Seen as a sequence, the API moved from property tiers, to organization lookup, to reseller and billing data, to people. The addition of a billing admin role among the grantable organization roles ties the last two together: the same API that reports monthly usage and billing data can now assign who holds billing authority.
Why access control is a live issue
The release lands in a year when Google has repeatedly tightened who can change what inside advertising accounts.
In Google Ads, the company set a rule under which a passkey became required for sensitive actions from July 15, 2026, including user access changes. A day earlier, users reported that removing another user's access had begun to require a second administrator's approval, with unapproved requests expiring after 20 days. Both moves were framed around account hijacking.
Merchant Center went through a parallel restructuring. Google published a user access guide for Merchant Center for Agencies in June 2026, describing Admin and Standard users and label-based access to subsets of client accounts.
The Analytics change is different in kind. It does not add friction to access changes; it removes manual work from them. Nothing in either document mentions passkeys, second-approver workflows or audit logging for API-driven changes. Authentication for the API follows Google's usual pattern - the overview recommends Google-provided client libraries - which in practice means OAuth credentials tied to an account holding User Admin or Org Admin rights. Whoever holds those credentials can now add members to groups, and grant organization roles to groups, at script speed. The help page frames that as efficiency for "large teams." The same property makes the credentials themselves more valuable.
Who this affects
The practical audience is narrow but significant. Google Marketing Platform organizations are the administrative layer above Analytics accounts, used mainly by Analytics 360 customers, by companies running several Google Marketing Platform products, and by Sales Partners managing client estates.
For those organizations, user groups replace a familiar pattern: individual users added to individual accounts and properties, and removed one by one when they change teams or leave. Agencies that rotate staff across dozens of client properties, and in-house teams with joiner and leaver processes run from an identity system, are the obvious beneficiaries. A group created once can be granted a role once; membership changes then propagate through the group.
The nested membership model - groups containing groups - allows hierarchies such as a regional analytics group inside a global one. Each membership carries an owner or member role, according to the changelog, though neither document defines what a group owner can do that a member cannot.
Other recent Analytics release notes
The October 5 entry sits at the top of a dense run of Analytics releases. On September 29, 2026, according to the help page, Google extended cross-channel reporting and conversion management to app conversions, which "are now fully supported in your conversion reports, including performance, attribution analysis, and attribution models." Attribution settings for app conversions can now be adjusted independently. The help page adds that this "feature may not be available to your Google Analytics property" and that "Cross-channel budgeting features currently support web conversions only."
On September 21, 2026, Google added Include filters for hostnames, turning hostname filtering into an allowlist. On September 9, Dashboards arrived in Google Analytics. In August, the fixed three-day engaged-view conversion window gave way to any integer from 1 to 30 days, with click-through windows editable from 1 to 90 days.
The developer side has moved in parallel. On May 4, 2026, cross-channel conversion data reached the Google Analytics Data API in alpha. On May 7, the help page records that the Data Manager API became an alternative to Measurement Protocol for sending server-to-server events to Analytics. A month later, version 1.7 of the Data Manager API extended offline conversion ingestion to Campaign Manager 360, Search Ads 360 and Display and Video 360.
Taken together, a pattern is visible across 2026: functions that once required the Analytics interface - conversion reporting, event ingestion, and now user and role management - are being exposed through APIs, most of them still marked alpha.
What the documents leave open
Several questions are not answered by the three source pages.
Is there a way to remove an organization role binding through the API? The method lists say no, or at least not directly.
Does the API bind user groups to specific Analytics properties and accounts, as the Analytics release note implies, or only to organization roles, as the developer reference shows?
What can a group owner do that a group member cannot?
Are changes made through the API logged in the same change history as changes made in the interface?
And when, if ever, will the Google Marketing Platform Admin API leave alpha? After 31 months and four rounds of additions, Google's documentation still describes it as "an unstable early preview stage."
Timeline
- July 1, 2018 - Google Marketing Platform Partners program set up with Sales Partners as resellers of the technology
- March 6, 2024 - Google Marketing Platform Admin API v1alpha released
- April 9, 2024 - GetOrganization method added
- October 29, 2025 - ListOrganizations, FindSalesPartnerManagedClients and ReportPropertyUsage methods added
- May 4, 2026 - Cross-channel conversion data reaches the Google Analytics Data API in alpha
- May 7, 2026 - Data Manager API support for Google Analytics server-to-server events
- May 28, 2026 - Data Manager API v1.7 extends offline conversion ingestion to Campaign Manager 360, Search Ads 360 and Display and Video 360
- June 2026 - Google publishes a user access guide for Merchant Center for Agencies
- July 14, 2026 - Google Ads user removals reported to require a second admin's approval
- July 15, 2026 - Google Ads begins requiring passkeys for sensitive actions
- August 11, 2026 - Google Analytics makes conversion windows editable to any integer
- September 9, 2026 - Dashboards arrive in Google Analytics
- September 18, 2026 - 14 user group, membership and admin access binding methods added to the Google Marketing Platform Admin API v1alpha
- September 21, 2026 - Google Analytics adds hostname Include filters
- September 29, 2026 - App conversions supported in Google Analytics cross-channel conversion reports
- October 5, 2026 - Google Analytics release note describes the "User Groups Admin API"
Related PPC Land coverage
- Google unveils new Marketing Platform Admin API - The March 2024 launch of the API for Analytics 360 upgrades, downgrades and organization linking.
- Google Analytics filter blocks data from domains not on an approved list - The September 21, 2026 Include mode for hostname data filters.
- Google Analytics gains drag-and-drop dashboards limited to 15 cards - The September 2026 Dashboards release and its card limits for standard and premium properties.
- Google Analytics drops the fixed 3-day engaged-view conversion window - The August 2026 move to custom integer conversion windows.
- Google Analytics opens conversion data to developers via Data API - Cross-channel conversion reporting exposed through the Data API alpha in May 2026.
- Google Data Manager API v1.7 finally brings GMP into the signal loop - Offline conversion ingestion extended to Google Marketing Platform products.
- Google Ads will require passkeys for sensitive actions from July 15 - Passkey requirements for user access changes and account linking in Google Ads.
- Google Ads forces second admin approval, leaving solo admins stuck - The two-administrator workflow for removing users from Google Ads accounts.
- Google publishes user access guide for Merchant Center for Agencies - Admin and Standard user types and label-based access in Merchant Center for Agencies.
- Google Marketing Platform Partners launched with certified individuals, companies plus sales partners - The 2018 partner program that created the Sales Partner category.
Summary
Who: Google, through the Google Marketing Platform Admin API and Google Analytics. The changes affect Google Marketing Platform organizations, Analytics 360 customers, agencies and Sales Partners that manage user access across many Analytics accounts and properties. Using the new features requires User Admin or Org Admin permissions on the organization.
What: Google added 14 methods to the alpha Google Marketing Platform Admin API to create and delete user groups, manage nested group membership with owner or member roles, and grant organization roles such as organization admin, user admin and billing admin to users or groups. No method to delete an admin access binding is listed. Google Analytics describes the release as a "User Groups Admin API," in terms that differ from the developer reference on naming and scope.
When: The developer changelog dates the methods to September 18, 2026. The Google Analytics release note is dated October 5, 2026.
Where: The API runs at marketingplatformadmin.googleapis.com, version v1alpha, and applies to Google Marketing Platform organizations and their linked Google Analytics accounts.
Why: According to Google's help page, user groups "simplify the process of managing access for large teams," and the API lets organizations "maintain and update these configurations programmatically." The release continues a 2026 pattern of moving Analytics functions into APIs, and arrives as Google tightens access controls elsewhere in its advertising products.
Discussion