WEBSITESfor Normal People2026

Part III: Go Live11

Chapter 11Add-on

Analytics: GA4, Tag Manager and Search Console

4 min read, 1 cheat sheet

Two terms screens. That's your whole job.

Do this before launch, not "sometime after". The day your site goes live is the first day of data you'll ever have, and you can't go back and collect the weeks you missed.

ToolJobIn plain terms
Google Analytics 4 (GA4)Counts visitors and what they doHow many people came, from where, and did they fill out the form
Google Tag Manager (GTM)Holds the tracking codeOne snippet on your site. Every tracking tool after this gets added in GTM, not in your code
Google Search ConsoleGoogle's view of your siteWhich searches you show up for, and whether Google can actually read your pages

How the Google key works

Google doesn't do simple API tokens here. It uses a service account: a robot Google user with its own email address. The robot gets access to your Analytics, Tag Manager and Search Console, and the agent works as the robot.

You don't create the robot. The agent does: you sign in to Google once in your browser, and it creates a Google Cloud project, turns on the right APIs, creates the robot, makes its key and saves it to your vault.

Two things Google insists a human does: accept the terms of service for Analytics and for Tag Manager. That's your part. The agent gives you the exact links and copies what you need to paste.

The analytics prompt

PromptCheat sheet 0158 lines
Set up analytics and Search Console for [DOMAIN], doing everything you can
through gcloud and the Google APIs. Only stop for me where Google requires a
human, and when you do, give me the exact link, copy anything I need to paste
to my clipboard, and tell me precisely what to click.

1. Google Cloud: sign me in with gcloud (browser flow, my Google account
   [EMAIL]). Create a project called "websites" (or reuse it if it exists).
   Enable: Google Analytics Admin API, Google Analytics Data API, Tag Manager
   API, Search Console API, Site Verification API.

2. Service account: create one called "claude-websites", create a JSON key,
   save the whole JSON to my vault as GOOGLE_SERVICE_ACCOUNT_JSON, and delete
   the key file from disk. Never print it.

3. Search Console (no clicks from me): as the service account, get a DNS
   verification token from the Site Verification API for the domain, add the
   TXT record through the Cloudflare API, verify, and add the domain property
   to Search Console. Then add [EMAIL] as an owner so I can see it in my own
   Google account.

4. The two human steps. Walk me through them one at a time and wait for me:
   a. GA4: send me to create a Google Analytics account for [BUSINESS NAME]
      and accept the terms. The wizard insists on a property too: tell me to
      name it after the site and click through the rest with any answers,
      you'll fix the settings. Then have me add the service account email
      (copy it to my clipboard) as an Administrator under Account access
      management.
   b. GTM: send me to create a Tag Manager account for [BUSINESS NAME] with a
      Web container for [DOMAIN] and accept the terms. Then have me add the
      service account email with BOTH: account Administrator, and Publish on
      the container. (Account Administrator alone can't edit or publish the
      container.)

5. GA4 via API: set the property's time zone to [TIME ZONE] and currency to
   [CAD/USD], create a web data stream for https://[DOMAIN] with enhanced
   measurement on, and add [EMAIL] as an Administrator.

6. GTM via API: in the container, create a Google tag with the GA4
   measurement ID firing on all pages, and GA4 event tags for what matters on
   this site: form submissions as generate_lead, [phone and email clicks,
   booking link clicks, purchases...]. Fire the form event from a data layer
   push in the site code, not a click trigger that breaks on the next
   redesign. Publish the container with a clear version name.

7. Site: add GTM to the site properly for Next.js, production only. Add a
   cookie consent banner with Google Consent Mode v2, analytics denied by
   default until the visitor accepts, styled to match the site.

8. Mark generate_lead (and purchase, if the site sells) as key events.

9. Make sure sitemap.xml and robots.txt are right, and submit the sitemap
   to Search Console.

10. Deploy, load the live site, accept cookies, trigger the form event, and
    prove GA4 received it with the realtime report API.

Report: GA4 measurement ID, GTM container ID and published version, events
tracked, Search Console status, and the key's name in my vault.

What you'll actually click

  1. Sign in to Google when the browser opens. Allow.
  2. Analytics: create the account (the wizard makes you name a property and answer a few business questions, any answers are fine), accept the terms, paste the robot's email into account access as Administrator. About two minutes.
  3. Tag Manager: create the account and container, accept the terms, paste the robot's email with Administrator on the account and Publish on the container. About a minute.
Watch itThe whole thing from the user's side: gcloud browser sign-in → GA account + terms + paste → GTM account + terms + paste. Show the agent's instructions next to the browser.

Personal details are blurred. Press play, it's silent and loops.

If you can't create a Google Cloud project

Brand-new Google accounts sometimes have to open console.cloud.google.com once and accept the Cloud terms before gcloud is allowed to create a project. If the agent hits that, it'll send you the link. One click, then it carries on.

On a phone, swipe left and right to turn pages.