The Google Play Console is where your developer account actually lives — and in 2026, almost every serious account is touched by more than one person: a co-founder, a contract developer, a finance person, an agency, or the next owner of the account. Every one of those people is a potential strength and a potential risk. Play Console solves this with a permission system built on three access levels — account owner, admins, and users — plus granular account-level and app-level permissions underneath. Here is how to add people, give them exactly the access they need, and keep your developer account from becoming someone else’s.
Why access control is a 2026 problem
Developer accounts are verified, identity-bound, and expensive to replace. One carelessly shared password, one “temporary” admin invite that was never revoked, or one ex-partner who still holds user access can end with your apps republished, your payout details changed, or your account flagged. The official help center puts it simply: your access level determines what actions you can perform and what information you can access in Play Console. Managing that access deliberately is not bureaucracy — it is the cheapest insurance your account can buy.
The three access levels you need to know
According to Google’s Play Console documentation, every developer account has three access levels:
- Account owner — the top level, with full control of the account, including user management and financial details. Think of this as the “king” seat: it should belong to exactly one person who actually runs the business.
- Admins — administrators who can perform most management actions, including inviting and managing other users. Admins are the day-to-day operators of the account.
- Users — everyone else, whose access is defined by the specific permissions they are granted.
If you are a user and need more access, you do not escalate yourself — you “ask your account admin for an invite.” That single rule is what stops permission creep before it starts.
Account-level vs app-level permissions
Under the three levels, Play Console permissions are granular. Some permissions apply at the account level (for example, financial data or user management), while others apply to individual apps. The documentation shows how fine-grained this gets: a permission like “Edit and delete draft apps” exists at the app level, does “not allow users to start the roll-out of a release,” and has a read-only counterpart — “View app information (read-only).” The practical takeaway: a contract developer who works on one app can be granted access to that app only, with release-related permissions withheld, while a finance person gets financial access without touching code or listings.
Step-by-step: adding a user the right way
The exact wording in the Console can vary slightly by account type and region, but the flow has been stable for years:
- Sign in to Play Console with the account owner or an admin account.
- Open Settings and go to Users and permissions.
- Click Invite new user and enter the person’s email address. Everyone who works in your Console should have their own Google Account — never a shared login.
- Choose the access level: invite them as an admin (broad management rights) or as a user with selected permissions. When in doubt, start lower — you can always grant more later.
- Pick whether the permissions cover all apps or only specific apps, then tick the individual permissions they actually need.
- Send the invite. It appears as pending until the person accepts it, so confirm they have received it if nothing happens.
Least-privilege rules that keep accounts alive
- Grant the minimum, then raise it. A user who needs to upload a build does not need financial access, and a finance person does not need app-release rights.
- Do not hand out “admin” casually. Agencies and freelancers usually need app-level user access, not full administration.
- Revoke access the moment someone leaves. Removing a departed partner, employee, or agency from Users and permissions should be the first thing you do — before you even argue about who owns what.
- Audit pending invites. An invite that was never accepted is still an open door if the email address is later reclaimed.
- Keep one, and only one, account owner. If you genuinely need an ownership change, use Google’s official transfer mechanisms instead of “just making them admin.”
Security hygiene: 2-Step Verification is non-negotiable
Play Console access is tied to Google Accounts, and Google Account security starts with 2-Step Verification. Turn it on for the account owner’s Google Account first, then for every admin and user who holds console access. Combined with individual (never shared) logins, 2-Step Verification is the single highest-impact thing you can do — a leaked password alone is no longer enough to take over an account that has it enabled.
The one-line version
Google Play Console access in 2026 comes down to three levels — account owner, admins, and users — plus granular permissions that let you scope every teammate to exactly the apps and actions they need: invite people with their own Google Accounts, grant the minimum, scope by app, revoke fast, keep 2-Step Verification on, and never let a shared login replace a real permission system.
Sources
- Add developer account users and manage permissions — Play Console Help (Google)
- Turn on 2-Step Verification — Google Account Help
Managing a Google Play developer account, its team, and its compliance? KappS helps developers with Play Console account operations, access hygiene, and policy-safe publishing.
Talk to KappS →