Share Search Console work with a team and clients
Share the result, not the keys. This playbook separates the two ways to share in SEOKit, a team invitation for people who work in the data and a saved report for clients who only read it, and gives a least-access routine, a seat count to check, an export-grain table and an offboarding checklist.
✓ Checked against Google documentation and the workspace · 7 October 2026
Share the result, not the keys
Teams go wrong in one of two ways: everybody uses one login, or nobody gets access and reports travel as screenshots. SEOKit offers a third route with two separate mechanisms. A team member signs in with their own account and works in the workspace on the properties you choose. A client opens one saved report and nothing else. Pick the mechanism by the job, then give the least access that does it.
Step 1: pick the mechanism by role
| Who | Mechanism | Access |
|---|---|---|
| Analyst or colleague who works in the data | team invitation | read on the properties they need |
| Colleague who changes things (submits sitemaps, adds properties) | team invitation | full, and your write permission must be approved |
| Marketer who needs GA4 beside Search Console | team invitation | read, with the GA4 switch on |
| Client who only needs to see results | shared report | one saved report, no workspace access |
Step 2: invite with the least access
- Choose properties one by one. Do not share the portfolio when the person works on one site.
- Start with read. Raise to full only for a person who must change something; a change also needs your approved write permission (team and shared reports).
- Leave GA4 off unless needed. GA4 data is available to a member only on properties where the switch is on.
- Mind the clock and the seats. An invitation expires after 7 days. Pending invitations count toward your seat limit together with active members.
Two things are worth knowing. The teammate reads data through your Search Console connection, so they see what your connection sees for those properties. And Google’s own roles are separate: in Search Console a full user has view rights to all data and can take some actions, while a restricted user has simple view rights on most data (owners, users and permissions). Do not add someone in Search Console itself just to let them use SEOKit; the invitation does that.
A seat count to check before you invite
The limit follows your plan: 1 seat on Starter, 3 on Pro, 10 on Business. Take Pro, with a limit of 3. Two active members and one pending invitation use all three seats, so a fourth invitation is refused with “seat limit reached” until you revoke the pending one or remove a member. Revoking an invitation nobody answered is the usual way to free a seat.
Step 3: give clients a report, not a login
- Save the report from its share dialog and give it a clear name.
- Add the clients by email, up to 25 per report. They are emailed the link when you save, which needs email delivery to be configured on the server; otherwise the dialog reports that delivery is not configured.
- Know the gate. The link is not open. It admits a signed-in person whose email is on the client list, and anyone else is refused. A saved report with no clients cannot be opened by anyone, including you.
- Test as a client before the real one receives it, and revoke access from the Shared Reports page when the engagement ends.
Step 4: export the right grain
An export is a copy that leaves your control, so decide its level of detail first.
| Audience | Grain | Why |
|---|---|---|
| Executives and clients | weekly totals by page group | answers the question without query-level detail |
| SEO colleague | query by page, for the period | enough to act on, without daily rows |
| Analyst or data team | daily rows by query, page, country, device | full detail, only for people who need it |
The interface export of Search Console itself is cut to 1,000 rows of representative examples (export data from a report), so the workspace’s export tool, which takes up to 25,000 rows per request and 50,000 per period, is the one to use for detail. Google also hides rare queries for privacy (data discrepancies), so an export never contains every query. Send the coarsest grain that serves the reader.
Step 5: offboarding checklist
- Revoke pending invitations and remove the member from the team page.
- Remove the person from the client lists of shared reports.
- Revoke any MCP API key they created or received, and rotate webhook secrets they have seen (MCP, alerts).
- If you had added them in Search Console as well, remove them there too; SEOKit’s removal does not touch Google’s list.
Team sharing, answered
Can a teammate see my other properties?
No, only the properties you shared; billing and keys stay private.
Can a client forward the report link?
The link opens only for signed-in people whose email is on the client list, so a forwarded link is refused for anyone else.
Why can I not invite another person?
Pending invitations count toward the seat limit of your plan; revoke one or remove a member.
What to read next
Open team access and shared reports for the screens, then filters and exports for the export tool.