---
title: "Setting up a GA4 property the right way"
description: "Structure: accounts, properties and data streams GA4 organizes data in three levels: - Account — usually one per organization (the legal entity that owns…"
url: https://optimizeall.com/learn/web-analytics-with-ga4/ga4-property-setup
updated: 2026-10-05
---

Web Analytics with Google Analytics 4 · Measurement strategy before tools · lesson 3 of 20 · 10 min

# Setting up a GA4 property the right way

## Structure: accounts, properties and data streams

GA4 organizes data in three levels:

- **Account** — usually one per organization (the legal entity that owns the data).
- **Property** — a reporting unit, typically one per brand or product. A property can combine web and app data.
- **Data stream** — a source of data feeding the property: a website, an iOS app or an Android app.

Agencies should keep each client's property inside the **client's own account** and be granted access, not the other way round. Ownership matters when relationships end.

A common question is whether to use one property or several. Use one property when the same users move across domains or apps you want to analyze together (for example `shop.example.com` and `blog.example.com`). Use separate properties for genuinely separate businesses or brands with different audiences and owners.

## The configuration checklist

Work through these settings on day one; several cannot fix historical data later.

| Setting | What to do | Why it matters |
|---|---|---|
| Time zone and currency | Match the business's reporting conventions | Daily totals and revenue depend on it |
| Data retention | Review; standard properties default to 2 months and can be raised to 14 months | Controls how far back explorations can look at event-level data |
| Enhanced measurement | Review each option (page views, scrolls, outbound clicks, site search, video, file downloads, form interactions) | Free events, but some can double count or misfire |
| Internal traffic | Define internal IP rules, test, then activate the filter | Keeps staff visits out of reports |
| Developer traffic | Understand the developer traffic filter used with debug mode | Keeps QA hits out of production data |
| Unwanted referrals | List payment gateways and SSO domains | Stops checkout returns being credited as "referral" |
| Cross-domain measurement | Configure when journeys span domains | Preserves the session across domains |
| Key events | Mark the events agreed in your tracking plan | Powers conversion-focused reporting |
| Product links | Link Google Ads, Search Console, and BigQuery if used | Enables richer analysis and audience sharing |
| Access | Grant least-privilege roles to named individuals | Security and accountability |

## Enhanced measurement: helpful but check it

Enhanced measurement automatically collects events such as `scroll` (when a user reaches around 90% depth), `click` for outbound links, `view_search_results`, `file_download` and video engagement for embedded YouTube videos. Review these carefully:

- **Form interactions** can fire on forms you do not care about, or miss forms built with unusual frameworks. Many teams disable it and implement form tracking explicitly.
- **Site search** relies on query parameters such as `q` or `s`; add your site's parameter if it differs.
- **Page views on history changes** are useful for single-page applications but can double count if your developers also send manual page views.

## Filters and data hygiene

GA4 data filters (internal and developer traffic) are applied permanently once active — filtered data is not recoverable. Always create a filter in **testing** state first, check that the test dimension shows the expected traffic, then activate.

For referral spam or bot traffic, GA4 excludes known bots automatically, but you should still watch for suspicious spikes (for example many sessions from one city with zero engagement).

## Worked example: a Pakistani fashion brand with a hosted checkout

An online clothing brand in Karachi runs its storefront on its main domain but payment happens on a third-party gateway's domain before redirecting back. Without configuration, every returning buyer starts a new session attributed to the gateway as a referral, and paid campaigns look like they generate no sales. The fix:

1. Add the gateway domain to **unwanted referrals**.
2. Confirm the `purchase` event fires on the store's confirmation page with a unique `transaction_id`.
3. Compare channel revenue for a week before and after — paid and organic channels should now receive the credit.

## Access and governance

Use roles deliberately: **Administrator** for a very small number of owners, **Editor** for implementers, **Analyst** or **Viewer** for report users. Remove access when people leave. Keep a short **change log** (date, change, person, reason) — GA4's own change history helps, but a human-readable log explains *why*.

## What changed in 2026: data controls and AI in the interface

Two changes affect setup decisions this year:

- **Google signals and Google Ads data controls.** Google announced that from **June 15, 2026**, the Google signals setting in GA4 controls only the association of Analytics data with signed-in user information for **behavioral reporting**. For linked properties, Google Ads settings control Google Ads data (including data shared from Analytics), and Ads cookie and identifier collection is governed by **consent mode**, specifically `ad_storage`. Review your Ads links, consent configuration and privacy notice together, not in isolation. Check Google's current "Updates to Google Analytics data controls" help page for the latest detail.
- **Analytics Advisor.** Google has added a Gemini-powered, conversational assistant inside GA4 (Ask Advisor, in beta in 2026) that answers plain-language questions about your property. Treat its answers as a starting point and verify them in reports (module 5 and module 7 cover this).

## Hands-on: a 30-minute setup audit script

Use this sequence on any property you inherit. Record answers in a sheet with a red/amber/green column:

```text
ADMIN > Account/property details: owner is the client? time zone, currency correct?
ADMIN > Data collection and modification > Data retention: 2 or 14 months? documented reason?
ADMIN > Data streams > Web > Enhanced measurement: each toggle reviewed? form interactions intended?
ADMIN > Data streams > Configure tag settings: internal traffic defined? unwanted referrals include gateways/SSO?
         cross-domain configured where journeys span domains?
ADMIN > Data filters: internal/developer filters active? were they tested first?
ADMIN > Events > Key events: only true business outcomes?
ADMIN > Product links: Google Ads, Search Console, BigQuery linked as intended?
ADMIN > Property access management: named users only, least privilege, no ex-staff/ex-agencies?
ADMIN > Data collection: Google signals and data controls reviewed against the June 2026 changes and consent setup?
```

You can also pull property settings programmatically with the Google Analytics Admin API, or via Google's experimental **Google Analytics MCP server**, which exposes read-only tools such as property details and account summaries to AI assistants. Use read-only credentials.

## Second worked example: a UAE clinic group

A healthcare group in Abu Dhabi and Dubai runs one website per clinic brand. The audit finds the properties under a former agency's account, retention at two months, no internal-traffic filter (staff check appointment pages all day) and no cross-domain setting for the shared booking domain. The fix plan: transfer ownership to the group's own account, raise retention with a documented reason, test and activate an internal filter, configure cross-domain measurement for the booking domain, and restrict access to named staff. The team also records in the change log that historical data before the fixes is not comparable.

## Common mistakes

- Creating the property under an agency or freelancer's personal account.
- Leaving data retention at the default and discovering too late that year-on-year explorations are impossible.
- Activating an internal-traffic filter without testing it.
- Forgetting unwanted referrals for payment gateways.
- Marking dozens of events as key events, making "conversions" meaningless.

## Activity preview

After this lesson, audit a GA4 property you have access to against the checklist above and note each gap along with its business impact.

## Video lecture: Setting up a GA4 property the right way

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

1. GA4 property setup
2. Why setup matters
3. Structure
4. Day-one checklist
5. Retention and filters
6. 2026 changes
7. Review enhanced measurement
8. Example 1: payment gateway referrals
9. Example 2: UAE clinic group
10. Watch me do it, part 1
11. Watch me do it, part 2
12. Common mistakes
13. Recap
14. Try this now

## Lecture transcript

### GA4 property setup

Some G A four settings are like the foundation of a house. You can repaint the walls any time, but if the foundation is wrong, you're living with it, and you can't fix the past. Data retention, filters and unwanted referrals all work this way. In this lecture you'll learn how accounts, properties and data streams fit together, the day-one configuration checklist, what changed in twenty twenty-six with data controls and AI in the interface, and a thirty-minute audit you can run on any property you inherit.

### Why setup matters

Why is setup so important? Because several settings can't be fixed retroactively. Filtered data is gone forever. A short retention window limits how far back explorations can look. Payment-gateway referrals, if not excluded, misattribute sales from day one. And ownership matters when relationships end. Agencies and freelancers come and go. If the property lives in someone else's account, the business can lose its own history. A good setup is cheap on day one and very expensive to fix later.

### Structure

Here's the structure. The account is usually one per organization, the legal entity that owns the data. The property is a reporting unit, typically one per brand or product, and it can combine web and app data. And the data stream is a source: a website, an iOS app or an Android app. Think of it like a company, its shops and the tills in each shop. Agencies should work inside the client's account with granted access, never the other way round.

### Day-one checklist

One property or several? Use one when the same users move across domains or apps you want to analyze together, like a shop subdomain and a blog subdomain. Use separate properties for genuinely separate businesses with different audiences and owners. Then work the day-one checklist: time zone and currency, data retention, enhanced measurement, internal and developer traffic, unwanted referrals, cross-domain measurement, key events, product links to Google Ads, Search Console and BigQuery, and access with least privilege.

### Retention and filters

Let's talk about data retention and filters, because they're the foundation. Standard properties default to two months of event-level retention, adjustable up to fourteen. That setting controls how far back explorations and funnel reports can look, not the standard reports. And data filters, for internal and developer traffic, are permanent once active. Filtered data isn't recoverable. So always create a filter in testing state first, check the test dimension shows the expected traffic, and only then activate it.

### 2026 changes

Now, what changed in twenty twenty-six. First, data controls. Google announced that from June fifteenth, twenty twenty-six, the Google signals setting controls only the association of analytics data with signed-in user information for behavioral reporting. For linked properties, Google Ads settings control Ads data, and Ads cookie collection is governed by consent mode's ad storage signal. So review your Ads links, consent setup and privacy notice together. Second, Analytics Advisor: a Gemini-powered assistant inside G A four that answers plain-language questions. Useful, but verify its answers.

### Review enhanced measurement

Enhanced measurement deserves its own review. It collects useful events for free: scrolls at around ninety percent depth, outbound clicks, site search, file downloads and embedded video engagement. But check each one. Form interactions can fire on forms you don't care about or miss forms built with unusual frameworks, so many teams switch it off and track forms explicitly. Site search relies on query parameters like q or s, so add yours if it differs. And page views on history changes help single-page apps, but can double count if developers also send manual page views.

### Example 1: payment gateway referrals

First example, a simple one. A Karachi fashion brand's checkout runs through a third-party payment gateway on a different domain. Without configuration, every returning buyer starts a new session attributed to the gateway as a referral, and paid campaigns look like they generate no sales. The fix: add the gateway domain to unwanted referrals, confirm the purchase event fires on the confirmation page with a unique transaction id, and compare channel revenue for a week before and after. Paid and organic channels now get the credit.

### Example 2: UAE clinic group

Second example, a business case. A healthcare group in Abu Dhabi and Dubai runs one site per clinic brand. The audit finds the properties under a former agency's account, retention at two months, no internal traffic filter while staff check appointment pages all day, and no cross-domain setting for the shared booking domain. The fix plan: transfer ownership to the group's own account, raise retention with a documented reason, test and activate an internal filter, configure cross-domain, and restrict access. And the change log records that data before the fixes isn't comparable.

### Watch me do it, part 1

Watch me run the thirty-minute audit. I open a sheet with a red, amber, green column, and walk through admin in order. Property details: is the client the owner? Time zone and currency right? Data retention: two or fourteen months, and is there a documented reason? Enhanced measurement: did someone actually review each toggle, especially form interactions? Tag settings: internal traffic defined, unwanted referrals including payment gateways and single sign-on domains, cross-domain where journeys span domains.

### Watch me do it, part 2

Then filters: active, and were they tested first? Key events: only true business outcomes, not add to cart and page view. Product links: Google Ads, Search Console and BigQuery linked as intended. Access: named people only, least privilege, no ex-staff or ex-agencies. And data controls: Google signals and Ads settings reviewed against the June twenty twenty-six changes and your consent setup. If you prefer, you can pull settings programmatically with the Admin API, or with Google's experimental Analytics M C P server, using read-only credentials.

### Common mistakes

Common mistakes. Creating the property under an agency or freelancer's personal account. Leaving retention at the default and discovering too late that year-over-year explorations are impossible. Activating an internal-traffic filter without testing it. Forgetting unwanted referrals for payment gateways. Marking dozens of events as key events, which makes conversion rates meaningless. And changing Ads data settings without looking at consent mode, which since June twenty twenty-six is where Ads identifier collection is controlled.

### Recap

Recap. Account, property, data stream: organization, reporting unit, source. The client owns the account. Work the day-one checklist, with extra care for retention, filters and unwanted referrals, because they can't fix the past. Know the twenty twenty-six changes to data controls and the new Advisor. And run the thirty-minute audit on anything you inherit. Most properties you'll meet have at least three of the problems we covered today, usually retention, filters and referrals. Finding them early is one of the most valuable things an analyst can do in their first week.

### Try this now

Try this now. Audit a G A four property you have access to, using the sequence from the lesson. For every amber or red item, write the business impact and the fix, then sort them by impact. Present the top three to whoever owns the site this week, and log each change with a date so future you knows when the data changed.

## Key takeaways

- Account = organization, property = reporting unit, data stream = source of data.
- Clients should own their GA4 accounts; agencies are granted access.
- Review retention, filters, unwanted referrals and cross-domain settings on day one.
- Test data filters before activating — filtered data cannot be recovered.

## Try it

Audit a GA4 property against the configuration checklist and list each gap, its business impact and the fix, in priority order.

- [Previous: Designing a tracking plan and naming conventions](https://optimizeall.com/learn/web-analytics-with-ga4/tracking-plan-and-naming)
- [Next: Events, parameters and user properties](https://optimizeall.com/learn/web-analytics-with-ga4/events-parameters-user-properties)
- [All lessons of Web Analytics with Google Analytics 4](https://optimizeall.com/learn/web-analytics-with-ga4)
