Google Tag Manager (Beta)
Connect Google Tag Manager to Ploy to see everyone who has access to your Tag Manager account, what they can do at the account level, and which containers they can read, edit, approve or publish. Ploy can also give people account access, change their account permission, add or remove their access to a single container, and remove them from the account.
This integration is in beta. It was built from Google's published Tag Manager API and has not yet been run against a live customer account. The first step of setup asks you to consent to that, and while it is in beta Ploy records redacted error details (never tokens, email addresses or names) when a call to Google fails, so we can fix problems quickly.
What Ploy reads and changes
People: everyone listed under Admin, User Management in your Tag Manager account.
Account permission: User or Administrator, shown as a role on the account.
Containers: every container in the account, with its public ID (GTM-XXXXXXX), and each person's permission on it: Read, Edit, Approve or Publish.
Changes Ploy can make when you ask it to: give a Google account User or Administrator access to the account, change someone's account permission, add someone to a container or remove them from it, and remove someone from the account (this removes their access to every container too).
Ploy connects to one Tag Manager account per connection. To scan another account, add another connection.
Tag Manager does not report sign-in activity, two-step verification or a history of permission changes, and access people get through a Google Group is not shown.
Before you begin
You need:
A Google account that is an Administrator of the Tag Manager account.
Access to a Google Cloud project where you can enable an API and create an OAuth client.
Step 1: Agree to the beta terms
Open Integrations in Ploy, choose Google Tag Manager, and tick the beta consent checkbox on the first page of the setup.
Step 2: Enable the Tag Manager API
In the Google Cloud console, open the project you will use for Ploy.
Go to APIs and Services, Library, search for Tag Manager API and select Enable.
Google answers every request with an "API not enabled" error until this is done.
Step 3: Create an OAuth client
In the same project, go to APIs and Services, Credentials.
If asked, configure the OAuth consent screen first. An internal app is enough if your Google accounts are in one Google Workspace.
Select Create credentials, OAuth client ID, and choose Web application.
Under Authorised redirect URIs, add the redirect URI shown in Ploy's setup.
Copy the Client ID and Client secret into the first page of the Ploy setup.
Step 4: Grant access
On the next page, select Connect to Google Tag Manager and sign in with the Administrator account. Google asks you to allow Ploy to:
see your Tag Manager accounts and containers, and
manage the users of your Tag Manager accounts.
Ploy only changes permissions when you ask it to, from a flow or the container page.
Step 5: Choose the account
On the last page, pick the Tag Manager account to scan from the list and finish the setup. Ploy tests the connection by listing the account's users.
Troubleshooting
"The Tag Manager API is not enabled": enable it in the Google Cloud project that owns the OAuth client (Step 2), then test again.
"Cannot manage this account's users": the Google account you signed in with is not an Administrator of the Tag Manager account. Grant access again with one that is.
The account list is empty: the Google account you signed in with has no access to any Tag Manager account.
Scans slow down: Google limits each Cloud project to a small number of Tag Manager requests per second and per day. Ploy waits and retries automatically.