Skip to content

Connect Google Analytics

WebDesktop

The Google Analytics connector lets Treasure AI Studio agents read your GA4 data during a chat. An agent can pull acquisition, page, event, and key-event reports for any property you have access to, build a custom report from whichever dimensions and metrics you name, and check who is on the site right now. Use it when a question about site behavior needs an answer next to the rest of your data — comparing the channels that drove a campaign's traffic against the segment that converted, for example — rather than a GA4 tab and an export.

This connection is read-only, and deliberately narrow. The agent can read reports and the dimensions and metrics available to build them. It cannot change anything in Analytics, and it cannot read a property's configuration or administration. Treasure AI requests a read-only Google scope, so a write is refused by Google before it reaches your account, and the surface is narrowed further by account policy. See What the Agent Can Do for the full list.

New to connections?

Read Connections first for the general model — the difference between a connector and a connection, and the administrator vs. user roles. This page covers the Google Analytics-specific steps.

Objective

Enable the Google Analytics connector for your account and authorize a connection, so the agent can read GA4 reports for your properties during a chat.

Prerequisites

  • Account administrator privileges in Treasure AI Studio — needed for Step 1 only (enabling the connector)
  • A Google account with access to at least one Google Analytics 4 property. The agent reads as this account, so its reach follows that account's own Analytics access — see What the Agent Can See
  • The property is a GA4 property. This connector uses Google's GA4 APIs; Universal Analytics properties are not supported

Who Does What

Setting up Google Analytics touches two roles, each doing its part once. There is nothing to configure on the Google Cloud side — Treasure AI manages the OAuth application.

Role What They Do How Often
Treasure AI Studio administratorAdds the Google Analytics connector in Connector Settings and saves it. There are no fields to fill in.Once for the organization
Each memberAuthorizes their own connection from Connections, choosing which Google account to use and approving the requested access.Once per person

There is no OAuth application to register, no service account to create and grant property access to, and no network policy rule to add. Each member's own Google account is the authorization.


Step 1 — Enable the Google Analytics Connector (Administrator)

Treasure AI manages the Google OAuth application for this connector, so there is nothing to create in the Google Cloud console and no client ID or secret to enter. The configuration form is empty.

  1. In Treasure AI Studio, open Settings → Connector Settings (under Organization).
  2. Click Add Connector (or Add your first connector) and choose Google Analytics.
  3. Click Save. There are no fields to fill in. The connector is saved already enabled, so Google Analytics appears under Available on every user's Connections tab straight away.
The Configure Google Analytics form in Connector Settings, with no input fields at all — only Save and Cancel buttons below the headingThe saved Google Analytics row in Connector Settings, showing its description, an expand chevron, an enable toggle, and a delete icon, with no network policy reminders

That is the whole administrator setup. The saved row carries an enable toggle, and turning it off does more than stop new authorizations: it withdraws Google Analytics from the agent's permitted actions at once, in chats that are already running as well as new ones. A chat in flight is not interrupted, but the next operation the agent attempts is refused, so every existing connection stops working until you turn it back on. Members keep their connections while it is off.

Enabling the connector grants read access only

Every member who connects gives the agent the ability to read their GA4 reporting data for every property that member can reach. It grants nothing else. The agent cannot change a property's settings, create or archive custom dimensions and metrics, or change data retention, and it cannot read a property's configuration or administration either. Treasure AI requests only Google's read-only Analytics scope, so Google refuses a write regardless of what a member asks the agent to do, and the write operations are separately blocked by account policy. What the member's own Google account can read is the only thing to weigh before enabling it.

No network policy change is needed

The Google Analytics connector lists no egress domains, and Connector Settings shows no "allow this domain" reminder for it. That is deliberate: the agent's sandbox never calls the Analytics APIs. The request is made by Treasure AI's connector service outside the sandbox, so your network policy — which governs sandbox egress — does not apply to it and does not need a new rule.


Step 2 — Authorize Your Connection (User)

Each member who wants the agent to work with GA4 data authorizes their own connection. You can do this ahead of time from Settings, or on demand from a chat.

  1. Open Settings → Connections.
  2. Under Available, find Google Analytics and click Connect.
The Connections page with Treasure AI Voice, Google Analytics, Google Calendar, Google Search Console, and Treasure Data all listed under Available, each with a Connect button
  1. In the Google popup, choose the Google account that holds your Analytics access. If you are signed in to more than one, pick deliberately — the connection carries whichever account you choose here.
  2. Review the requested access and approve it. Google asks for a single permission — viewing your Analytics data — covering every property that account can reach.
The Google permission screen listing one item, 'See and download your Google Analytics data', with Cancel and Allow buttons
  1. When the popup closes, Google Analytics appears in your connected list with the date you connected it.
The Connections page with Google Analytics in the connected list, showing the date it was connected and a delete icon

A connection authorizes one Google account, and through it every GA4 property that account has access to. Studio holds one Google Analytics connection per member at a time, so to switch to a different Google account you delete the connection and authorize again.

To remove the connection later, click the delete (trash) icon next to it. The agent immediately loses access. Because the connection never writes, there is nothing in Analytics to undo. Google still lists Treasure AI Studio under your account's third-party access until you remove it there as well.

Connect from a chat instead

You don't have to authorize in advance. If you ask the agent about your site traffic before you've connected, it shows a Connection Required card in the chat — click Connect there to run the same authorization without leaving the conversation. The card names the connector by its internal id, google_analytics. See Connect from a chat.


Step 3 — Use Google Analytics in a Chat

Once Google Analytics is connected, ask the agent in plain language — no commands and no configuration in the chat. For example:

  • "Which channels drove the most engaged sessions on our site last month, and how does that compare with the month before?"
  • "List my GA4 properties so I can tell you which one to use."
  • "Show me the top 20 landing pages by users for the last 28 days, with engagement rate and average engagement time."
  • "Which countries are growing fastest in key events this quarter?"
  • "How many people are on the site right now, and what are they looking at?"
  • "Break last week's conversions down by device and browser."
  • "Cross-check the traffic sources for the campaign against the CDP segment that actually purchased."

The agent chooses its own operations. It typically lists your properties first, then runs a report against the one you named. A GA4 property is identified by its numeric property ID, with or without the properties/ prefix; if you do not know it, ask the agent to list your properties and pick from what it returns.

GA4 reporting has real constraints that shape what the agent can answer, and they are Google's, not Treasure AI's. Not every dimension can be combined with every metric — the agent can check a combination before running it, and will tell you when one is not queryable. Reports are also subject to per-property API quotas, which a long series of large reports can exhaust; the agent can ask for the remaining quota to be returned alongside a report.

For anything that changes GA4 — editing a property, adding a custom dimension, changing data retention — the agent can tell you what it sees and what looks wrong, and you make the change in Google Analytics. The same goes for questions about how a property is set up: the agent works from reporting data, not from the property's configuration.


What the Agent Can Do

These are the operations the agent can use. It picks them itself from what you ask for — there is no command syntax for running one directly, though naming an operation in your message does steer the agent toward it.

Area Operations What They Do
Finding a propertygoogle_analytics.list_propertiesList the GA4 properties the connected Google account can see, with their account context, so you can say which one to use. Up to 200 per page, paged.
Prepared reportsgoogle_analytics.run_pages_report, google_analytics.run_events_report, google_analytics.run_acquisition_report, google_analytics.run_key_events_reportFour ready-made reports covering the questions asked most often: page views, users, sessions, and engagement per page; event volume, users, key events, and value; where sessions and users came from; and key-event volume with conversion rates.
Custom reportsgoogle_analytics.run_report, google_analytics.run_pivot_reportBuild a report from whichever dimensions, metrics, date ranges, filters, ordering, cohorts, comparisons, and aggregations you need, as a flat table or a cross-tabbed pivot. Anything the prepared reports cover can also be expressed here.
Right nowgoogle_analytics.run_realtime_reportRead the realtime report — the users and events active on the site at this moment.
Before reportinggoogle_analytics.get_metadata, google_analytics.check_compatibilityList the dimensions and metrics available on a property, including its custom ones, and check whether a chosen set can be queried together before spending a report on it.

What the Google Analytics Connector Does Not Expose

Nothing in Google Analytics changes through the agent, and the read surface stops at reporting. The cases worth knowing about:

  • No property changes. The agent cannot edit a property's settings — its name, time zone, or currency. A time-zone change in particular shifts how every historical report is bucketed by day, which is why it stays a deliberate human action.
  • No custom dimension or metric changes. The agent cannot create one, and cannot archive one. Archiving is irreversible in GA4 and the slots are capped, so a mistake there cannot be undone.
  • No data retention changes. The agent cannot change a property's data retention setting. Shortening it deletes history permanently.
  • No configuration reads. The agent cannot list a property's data streams, custom dimensions, or custom metrics as configuration, or read a property's setup summary. It sees custom dimensions and metrics only as reportable fields, through the metadata it reads before building a report.
  • No account or user administration. The agent cannot create properties or accounts, or change who has access to them.
  • No Universal Analytics. This connector reads GA4 properties through Google's GA4 APIs. Universal Analytics properties are out of scope.
  • No other Google products. This connector reaches Google Analytics only. Google Search Console and Google Calendar are separate connectors, each with its own authorization.

What the Agent Can See

The Google Analytics connector carries your own Google authorization, so the connected Google account's Analytics access decides its reach:

  • Every GA4 property that account can open in Google Analytics, and no others — there is no way to restrict a connection to one property.
  • The data each property's role allows. Google assigns an account a role per property or account, and the agent inherits exactly that. A property you can only view in Analytics is a property the agent can only read.
  • Reporting data only. Even within a property, the agent reads reports and the fields available to build them — not the property's configuration or its user list.
  • Nothing beyond reading. The authorization carries no write capability at all, on any property, whatever the account's role is.

Google enforces this when the request arrives, not Treasure AI Studio, and no prompt can widen it. The agent can narrow the view — tell it to look at one property, or one date range — but never widen it.


Reference

ItemValue
ConnectorGoogle Analytics
Internal idgoogle_analytics — the id the Connection Required card shows in a chat
AuthenticationOAuth 2.0 Authorization Code with PKCE (user-to-machine), platform-managed Google OAuth application
Google scope requestedOne: https://www.googleapis.com/auth/analytics.readonly. The read-write analytics.edit scope is deliberately not requested
Required configurationNone. The administrator saves the connector with no fields to fill in
AccessRead-only, and narrowed to reporting — listing properties, four prepared reports, custom and pivot reports, the realtime report, and the metadata and compatibility checks needed to build a report. Nothing in Analytics can be changed through the agent, and its configuration cannot be read
Google APIs usedAnalytics Data API v1beta (https://analyticsdata.googleapis.com/v1beta), its v1alpha endpoints for realtime and quota, and the Analytics Admin API v1beta (https://analyticsadmin.googleapis.com/v1beta)
Property supportGA4 properties only. Universal Analytics is not supported
Property identifierThe numeric GA4 property ID, with or without the properties/ prefix
Properties per page200 maximum, paged with a token
Dimension and metric compatibilityNot every combination is queryable. The agent can check a set before running it rather than discovering the failure in the report
QuotasGoogle applies Data API quotas per property. A long series of large reports can exhaust them. The remaining quota can be returned alongside a report, but there is no way to read it without running one
Agent identityReads as the authorizing Google account. Nothing is written, so nothing is recorded in Analytics as that account's action
Where requests are madeTreasure AI's connector service, outside the agent's sandbox
Egress domainsNone — the sandbox never reaches the Analytics APIs, so no network policy rule is required
Token lifetimeShort-lived access tokens, refreshed automatically, so a connection keeps working across sessions without reconnecting
Connections per memberOne, covering one Google account and every GA4 property that account can access

Troubleshooting

IssueSolution
Google Analytics isn't listed on the Connections tabAn administrator must add the Google Analytics connector in Connector Settings and enable it.
The agent finds none of your propertiesConfirm you authorized the Google account that actually holds the Analytics access — the popup's account picker is easy to click through. Delete the connection and reconnect with the right account. Universal Analytics properties do not appear at all; only GA4 properties do.
The agent reports a property as not foundUse the numeric GA4 property ID. Ask the agent to list your properties and use the identifier it returns, rather than the property's display name.
A report fails saying the dimensions and metrics are incompatibleGA4 does not allow every combination. Ask the agent to check compatibility first and to propose a set that works, or to split the request into two reports.
Numbers don't match the GA4 interfaceCheck that the date range, property, and any filters match. GA4 also applies data thresholding and sampling of its own, so a report broken down finely can legitimately total less than the same report at a higher level.
Reports start failing after several large onesThe property's Data API quota is exhausted. Ask the agent to return the remaining quota with its next report, then to run fewer or smaller reports, or retry later.
You asked the agent to change a property setting and it refusedExpected. The connection is read-only: editing a property, creating or archiving custom dimensions and metrics, and changing data retention are all blocked, and the read-only scope would refuse them anyway. Make the change in Google Analytics.
You asked which data streams a property has and the agent couldn't sayExpected. Configuration reads are outside this connector's surface. Check the property's data streams in Google Analytics. If the question is really "what do these numbers cover", ask the agent to break a report down by stream instead.
The agent says the connection needs to be reconnectedThe authorization expired or was revoked on the Google side — including by removing Treasure AI Studio from your Google account's third-party access. Reconnect from Settings → Connections.
The connector disappeared from the Connections tabAn administrator may have disabled it. Your connection is kept, but the agent cannot use Google Analytics until the connector is enabled again.

Next Steps