PPC TunerPPC Tuner
Agency Scaling

Google Ads MCC Structure for Agencies: Account Trees, Permissions, and Client Isolation

A technical blueprint for structuring Google Ads manager accounts around clean account trees, cascade-safe permission tiers, and strict client isolation. This guide covers single vs. multi-MCC topologies, exact access level mapping, isolation boundaries, and a migration playbook for agencies scaling from $5k to $200k+ in monthly spend.

Ryan RomanowskiRyan Romanowski12 min read

Quick answer

For agencies, the optimal Google Ads MCC structure is a shallow tree: one agency-owned root manager account with child accounts either directly beneath it or grouped under client-level MCCs when a client needs internal separation. Assign permissions at the minimum level per role (admin for senior managers, standard for optimizers, read-only for clients and auditors), and enforce isolation through separate conversion tags, remarketing lists, billing profiles, and 2FA per account.

Key takeaways

  • Choose a shallow tree: one agency-owned root MCC with direct child accounts for most clients, and add client-level MCCs only when a client needs sub-account separation or uses multiple sub-agencies.
  • Permission inheritance flows downward and is additive — grant the minimum access level per role and audit quarterly, because a Standard user on the root MCC can affect every child account beneath it.
  • Enforce client isolation at the data layer: separate conversion tags, remarketing lists, audience signals, and billing profiles per child account — never share them across clients unless the contract explicitly requires it.
  • Layer PPC Tuner's staged-review workflow on top of native MCC permissions so every AI-suggested optimization is inspected and approved inside the PPC Tuner web workspace before it mutates any managed account.
On this page

Why the MCC Structure Matters More Than the Bid Strategy

Most agencies treat their Google Ads manager account as an afterthought: create a manager account, link a few child accounts, and start optimizing. That works until you hit 15 clients, or 50 accounts, or a client asks for read-only reporting access and an auditor requests a permissions report. At that point, a messy MCC tree turns every routine task into a risk assessment: Who can see this client's data? Who can push a change? Which account owns the conversion tag?

The MCC structure — the hierarchy of manager accounts, child accounts, user access levels, and linked assets — is the actual control plane of the agency. Bid strategies, shared budgets, and portfolio goals sit on top of it, but none of them are safe if the underlying account tree is unstable. A well-built Google Ads manager account structure makes ownership, access boundaries, and client separation obvious to anyone who inherits the book of business. A poorly built one creates cross-client data leaks, accidental edits, and billing disputes.

  • Cross-client remarketing contamination when audiences or conversion goals are shared at the MCC level without a documented client isolation policy.
  • Permission creep from assigning Admin at the MCC level to junior staff because assigning granular child-level access felt too slow.
  • Lost access after a key employee leaves, because no one maintained the mapping between agency roles and Google Ads access levels.
  • Migrations that break conversion tracking because the account tree restructure was done without a pre-move audit.
  • Duplicate negative keyword lists, sitelinks, and audience signals drifting across child accounts because there is no canonical tree owner.
Before you restructure, quantify the waste

Run a Google Ads Waste Calculator audit on your current portfolio to identify which client accounts are hemorrhaging spend from structurally broken segments. That baseline makes the business case for an MCC reorganization far easier to present to partners.

Google Ads Manager Account Hierarchy: Anatomy of an Account Tree

A Google Ads manager account (MCC) is a container that can hold other manager accounts and child advertising accounts. An account tree is simply the way those containers nest. The structure must answer three questions in plain terms: who owns the root, where do client accounts live, and what happens when a client leaves with their account.

Level 0: The Agency Root MCC

The root MCC is the agency-owned entity that controls access to everything beneath it. It should be registered under the agency's legal entity, using a corporate email domain, and it should never be created inside a client's Google account. This is the single most common mistake in Google Ads MCC structure: an agency lets a client create the manager account 'for convenience,' then the agency spends two years trying to unwind ownership when the client relationship sours. The root MCC own the tree, not the client.

Level 1: Client MCCs vs. Direct Child Accounts

Direct child accounts are individual Google Ads accounts (one per client, or one per campaign set for large advertisers) linked straight to the root MCC. Client-level MCCs are intermediate manager accounts that sit between the root and the client's accounts. You use a client MCC when the client is large enough to have multiple business units, multiple agencies working on separate accounts, or internal teams that need their own manager account view. Creating a client MCC for every account is over-engineering; it adds a layer of permissions that must be maintained without adding clarity.

Two-Tier vs. Three-Tier Topology

Two-tier topology (root MCC → child accounts) is the default for most agencies. Three-tier topology (root MCC → client MCC → child accounts) is justified only when clients require internal sub-agency isolation or separate manager-account-level audiences. Choose your topology by agency spend and account count, not by pride in complexity.

Recommended Google Ads MCC structure by agency size and managed spend
Agency monthly managed spendActive child accountsRecommended topologyMCC countRationale
$5k–$20k1–10Two-tier: root MCC → client accounts1Flat structure keeps permissions readable; one admin owns the entire tree.
$20k–$80k10–50Two-tier with optional department sub-MCCs1–3Group by vertical or team only if you need separate reporting views; otherwise stay flat.
$80k–$200k50–200Two-tier for most clients, three-tier for enterprise clients3–10Add client MCCs only for accounts with multiple business units, sub-agencies, or separate brand portfolios.
$200k+200–500Three-tier: root MCC → client MCCs → child accounts10–20Multi-MCC trees pay off when you need to grant a client user access to a sub-tree without exposing unrelated clients.

Google Ads Manager Account Permissions: Access Levels and Inheritance

Google Ads defines five access levels for manager account users. Each level grants a distinct set of capabilities on the accounts it applies to. When a user is added at the MCC level, their access cascades to all child accounts in that manager account — unless you explicitly reduce it at the child level. That cascade is powerful and dangerous: a Standard user on the root MCC can edit campaigns in every child account under it, not just the one they are assigned to.

Google Ads manager account access levels and agency use cases
Access levelWhat the user can doTypical agency grant
AdminManage users and permissions, edit campaigns, access billing, link accounts, accept invitationsSenior account managers and agency owners only
StandardView and edit campaigns, create ads, view performance reports, no user or billing administrationDay-to-day optimizers and media buyers
Read-onlyView campaigns, performance data, and reports; cannot change anythingClients, reporting stakeholders, auditors, interns
BillingManage billing profile, view invoices, update payment methods; no campaign accessAgency finance team only
EmailReceive MCC emails and notifications; no access to account dataExecutives who need alert awareness without account access

How Permissions Cascade (and Where They Don't)

Permissions inherit down the tree. If you add a user to the root MCC with Admin access, they can access every child account and every nested client MCC. The exception is that you can reduce a user's access on a specific child account, which makes that child an isolated branch for that user. The practical rule: assign the minimum level at the highest node, then elevate within specific child accounts where needed. Never grant Admin at the root to someone who only needs Standard on three client accounts. Set a quarterly calendar reminder to pull the MCC permissions report, export it to CSV, and diff it against your agency role registry. Accounts named after clients you lost last quarter are the first place permission rot appears.

The Admin-at-root single point of failure

One Admin user at the root MCC with a shared password and no 2FA is the fastest route to a client data breach. Enforce 2FA on every manager account user, grant Admin only to the agency principal and a named backup, and store the agency's Google account identities in a password manager with a documented succession plan.

Client Isolation Models That Hold at 500 Accounts

Client isolation is the discipline of ensuring that no data, asset, audience list, or billing signal from one client can leak into another client's accounts — and that no user who should see only Client A ever sees Client B. Isolation has three layers: data, billing, and identity.

Data Isolation: Conversion Tags, Audiences, and Remarketing Lists

Conversion tags must be generated inside each child account, not copied from one account to another. If an agency creates a Google tag in Client A's account and installs it on Client B's site, Google attributes Client B's conversions to Client A's tag, polluting optimization signals in both. The same rule applies to remarketing lists and audience segments: a shared audience at the MCC level is only acceptable when the clients operate in the same legal group and data-sharing is contractually documented. For standard agency books of business, every audience list, customer match segment, and conversion action must live in the owning client's account tree.

Billing Boundary Enforcement

Billing should never be shared across client accounts. If a child account is moved from one client MCC to another, its billing profile and payment method move with it. During migration, verify that the billing profile's legal entity matches the client's contract, and confirm that automatic payment thresholds are set per account, not inherited from an MCC-level invoice that bundles unrelated clients. Mixing billing across clients creates GST/VAT reporting headaches and turns a simple account transfer into a finance audit.

Login, Session, and 2FA Separation

Isolation also applies to agency identity. Each employee should have a distinct Google identity for MCC access, never a shared agency account. Clients who need reporting access should receive read-only access to their own account only, and that access should be revoked the day the contract ends. Write a checklist for account-level access review and run it every time a client's contract renews, a team member changes roles, or a migration moves accounts between nodes.

  • One Google Ads account per client per business unit; no multi-tenant campaigns under a single account.
  • Conversion tags, remarketing lists, and customer match segments created and stored only in the owning client's account.
  • Billing profile legal entity matches the client contract; separate payment methods per client where possible.
  • No shared logins; every staff member uses a unique Google identity with 2FA enforced.
  • Client access limited to Read-only on their own child account, never at the root MCC.
  • Quarterly export of the MCC permissions report reviewed by the agency principal or operations lead.

Mapping Agency Roles to Google Ads Access Tiers

A Google Ads MCC structure is only as clean as the user-to-role mapping that feeds it. Create a role registry that maps each agency function to a Google Ads access level and a corresponding PPC Tuner workspace role, so that when a new hire joins, access provisioning takes minutes instead of days.

Agency role mapping to Google Ads MCC permissions and PPC Tuner workspace roles
Agency roleMCC-level accessChild-level accessPPC Tuner workspace role
Account DirectorAdmin on root MCCAdmin on assigned client accountsApprover — can approve staged mutations
Senior Account ManagerStandard on root MCCStandard on assigned client accountsApprover on their book of business
Media Buyer / OptimizerStandard on root MCCStandard on assigned client accountsEditor — proposes changes, cannot approve
Analyst (reporting)Read-only on root MCCRead-only on assigned client accountsReviewer — comment and annotate only
Contractor / FreelancerEmail onlyStandard on a single client account, time-boxedEditor scoped to that account only
FinanceBilling accessBilling access on all client accountsRead-only billing dashboard access
Client stakeholderNo root accessRead-only on their own accountRead-only in their client workspace

The pattern to notice: most agency roles should be Standard, not Admin. Admin is for the few people who own user management. Everything else can be done with Standard access on the specific child accounts the person actually manages. When a contractor finishes a project, revoke their access at the root and remove them from every linked child account — then run the quarterly permissions diff to catch stragglers.

MCC Migration Playbook: Restructuring Without Breaking Performance

Restructuring a Google Ads manager account tree is a surgical operation. Moving a child account from one MCC to another is easy from a UI perspective; preserving conversion tracking, audience lists, and billing integrity is the hard part. Use this playbook every time.

Pre-Migration Audit

Before moving anything, document the current state of every account in the subtree. This audit is non-negotiable, because Google does not maintain a rollback history for MCC re-parenting. Export the full account list, capture each account's manager link history, and record which conversion tags and audience lists exist per account.

  • Export the full list of child accounts and their current manager account parents.
  • Record conversion actions and Google tag IDs per account; flag any tag that appears in more than one account.
  • List all shared remarketing lists and shared negative keyword lists at the MCC level that will be affected by the move.
  • Snapshot performance for the last 28 days so you can compare pre- and post-migration metrics.
  • Identify which users have access to the subtree so you can re-provision access after the move completes.

Move Order and Cutover

Move accounts in dependency order: first move accounts that contain no shared assets, then move accounts that reference MCC-level shared lists, and finally update billing profiles. When an account moves from one MCC to another, its manager account links change but its conversion tags and campaign data move with the account. The risk is not lost data — it is lost access to shared assets that were anchored in the previous MCC. Re-create any necessary shared assets in the new parent before the cutover, and schedule the move during the client's lowest conversion window, typically early in the week, so you have time to react to tracking anomalies.

Post-Move Verification

  • Verify conversion tracking fires by checking the tag diagnostics in each moved account within 24 hours.
  • Confirm remarketing list membership is still populating; a list that stops growing after a move was anchored to a shared asset that was lost.
  • Check billing access and invoice history for the moved accounts; confirm the correct payment method is attached.
  • Re-apply user permissions per the role registry; do not rely on inheritance from the new parent automatically matching the old tree.
  • Compare 7-day post-move impressions, clicks, and conversion counts against the pre-migration snapshot to identify any tracking breakage.

Staged Change Review Across the Tree: Where PPC Tuner Fits

Native Google Ads permissions control who can act, but they do not control what automated tools can do with those permissions. Most optimization platforms connect to your MCC via the Google Ads API and push changes directly into child accounts the moment a model suggests them. That is a structural risk on top of an MCC tree: an autonomous agent with full API access can mutate 500 client accounts overnight, and the account tree's permission boundaries are the only thing standing between you and a client-facing catastrophe.

PPC Tuner is a different layer. It connects to the same Google Ads API, but every optimization it suggests — bid changes, budget adjustments, keyword modifications, asset replacements, campaign structure edits — is staged as a proposed mutation inside the PPC Tuner secure web application workspace. No change touches a live child account until a human with the appropriate approval role reviews and approves it. That means your MCC structure's permission boundaries are respected twice: once by Google Ads access levels, and again by PPC Tuner's staged-review workflow. The Gemini 3.8 AI model powering PPC Tuner analyzes account trees and performance telemetry to produce prioritized recommendations, but it never acts unilaterally.

  • Per-account change proposals visible in a single web workspace, not scattered across dashboards or email threads.
  • Approval rules mapped to your agency role registry: directors approve, optimizers propose, analysts review.
  • A full audit trail of every staged mutation, including who approved it, when, and what the expected impact was.
  • Conversion-lag-aware pacing logic that respects each account's typical conversion delay before recommending spend changes.
  • Client isolation enforced at the workspace level: each client's suggested changes are visible only to users with access to that client's sub-tree.
The difference is the human gate

Automation platforms like Optmyzr and Adzooma have built optimization engines on the same MCC API model, but many of them push changes automatically or batch-apply recommendations with minimal review friction. Compare PPC Tuner vs Optmyzr and Compare PPC Tuner vs Adzooma to see where the human-in-the-loop gate sits. PPC Tuner is built specifically for agencies that want AI-driven suggestions without handing over the keys to the account tree.

Free account audit

Structured MCC, human-approved changes

Clean up your Google Ads manager account structure, then make sure every optimization is staged for review. PPC Tuner gives you a centralized web workspace where AI recommendations wait for approval before they touch your client accounts. Run your own profitability analysis with the [Google Ads Waste Calculator](/tools/google-ads-waste-calculator), then try PPC Tuner on your tree.

No credit card required • 100% read-only audit • Takes 60 seconds

Interactive Tool for this Playbook

Agency Capacity Modeler

Model accounts per media buyer, loaded labor cost, and margin expansion.

About the author

Ryan Romanowski
Ryan Romanowski
Founder, PPC Tuner

10+ years in paid media and analytics, managing over $1M/month in Google Ads spend across home services, legal, insurance, and SaaS.

Ryan is the founder of PPC Tuner and Double R Marketing. He specializes in Google Ads automation, Smart Bidding reverse-engineering, and high-performance search infrastructure.

Connect on LinkedIn