Why We Built Brass-SEO Read-Only (On Purpose)
When you connect Google Search Console or GA4 to Brass-SEO, you will notice something on the consent screen: we only ask to view your data. Not manage it. Not edit it. Not control it.
That is not a limitation. It is a deliberate design choice — and it is one of the reasons your data is safer with Brass-SEO than with tools that ask for more.
Quick Navigation
- What Read-Only Actually Means
- Why Most Tools Ask for More
- Why We Chose Less
- What You Can Still Do
- The Broader Privacy Architecture
- Frequently Asked Questions
What Read-Only Actually Means
Google's OAuth system uses "scopes" to define what an application can do with your data. Brass-SEO uses two scopes:
For Google Search Console: webmasters.readonly — View search performance data, check indexing status, see which keywords bring traffic. Cannot submit URLs, remove pages, add users, or change settings.
For Google Analytics 4: analytics.readonly — View traffic data, landing pages, engagement metrics, and user behavior. Cannot create goals, modify reports, add tracking code, or change configuration.
These are the most restrictive scopes Google offers for these services. If there were a "view even less" option, we would use it.
Why Most Tools Ask for More
Some SEO tools request write access to your Google accounts. Common reasons include:
Sitemap submission. Some tools offer to submit your XML sitemap to Google Search Console on your behalf. This requires write access to your GSC property.
URL removal requests. Tools that manage indexing may request permission to submit URL removal requests through GSC.
Property management. Some platforms manage multiple GSC or GA4 properties and need write access to add or configure them.
These are legitimate features — but they require trusting the tool with the ability to change your Google configuration. If you do not need those features, you are granting access you do not use.
Why We Chose Less
Brass-SEO is an analysis tool. It reads your data, interprets it, and gives you answers. It does not need to change anything in your Google accounts to do that.
The principle is simple: request only the access you need. If we do not need write access to analyze your keywords, check your indexing status, or review your traffic patterns, we should not ask for it.
This is not just about philosophy. It is about reducing risk:
Reduced blast radius. If a security incident occurred, read-only access means nothing in your Google accounts could be modified. Your data could be viewed but not changed, deleted, or corrupted.
No accidental changes. With write access, a bug in the software could theoretically submit unwanted URLs, remove pages from the index, or modify your GA4 setup. With read-only access, that is impossible.
Simpler trust model. You do not need to evaluate whether we will use write permissions responsibly. We do not have them.
What You Can Still Do
Read-only access does not limit the analysis Brass-SEO can provide:
| What You Can Ask | How It Works |
|---|---|
| "Which keywords am I ranking for?" | Reads GSC search analytics data |
| "Where is my traffic coming from?" | Reads GA4 traffic source data |
| "Is this page indexed?" | Uses GSC URL Inspection API (read-only) |
| "Audit my homepage" | Crawls the URL and cross-references with GSC/GA4 data |
| "What should I work on first?" | Analyzes GSC and GA4 data to prioritize by impact |
| "Show me my striking-distance keywords" | Filters GSC data for keywords near page 1 |
The AI reads your data, analyzes it, and tells you what to do. You make the changes yourself — which means you stay in control.
For a full walkthrough of what Brass-SEO can do with your data, see how Brass-SEO works or start with your first SEO analysis.
The Broader Privacy Architecture
Read-only access is one piece of a larger privacy design. Every layer of Brass-SEO is built to minimize what we can access:
- Your conversations are private. Database-level security means each user can only see their own chats. Our team cannot read your messages. See the full Data Privacy Guide for details.
- The AI does not train on your data. Your conversations are processed and discarded — not stored, not trained on, not remembered between sessions.
- Your tokens are encrypted. Google access tokens are stored with AES-256-GCM encryption at rest.
- You can delete everything. Full account deletion removes all data immediately — no retention period, no waiting.
Read-only Google access is the first layer. But it is backed by the same principle throughout the entire system: access the minimum, store the minimum, and give you full control.
Frequently Asked Questions
Does read-only access limit the reports Brass-SEO can generate?
No. Every report and AI analysis in Brass-SEO works with read-only data. The GSC and GA4 APIs provide full access to your search performance, traffic, and engagement data through read-only scopes. You can see everything — keywords, positions, clicks, impressions, landing pages, traffic sources, and engagement metrics.
Can Brass-SEO submit my sitemap to Google?
No, and we chose not to include this feature specifically because it would require write access to your GSC property. You can submit your sitemap directly in Google Search Console, which takes about 30 seconds. We did not think that convenience justified requesting broader permissions.
What if I want a tool that can make changes to my Google accounts?
Some SEO tools offer management features — like automated sitemap submission or URL removal requests — that may require write access to your Google accounts. If you need those capabilities, check what permissions the tool requests on the consent screen. You can use Brass-SEO for analysis alongside other tools — connecting Brass-SEO does not affect other tools' access.
Can I verify what scopes Brass-SEO has?
Yes. Go to myaccount.google.com/permissions and find Brass-SEO in the list. Google shows exactly which permissions are granted. You will see "View Search Console data" and "View your Google Analytics data" — nothing else.
Is read-only access common among SEO tools?
It varies. Analysis-focused tools typically use read-only access. Tools that offer management features (submitting sitemaps, managing properties, requesting URL removals) require write access. When evaluating any tool, check the consent screen — Google tells you exactly what you are granting.