Google has published new guidance on the use of corporate email addresses for sensitive actions in Google Ads. The change is being introduced as a pilot, but it is a useful prompt for every business to check who can control its advertising account and which email addresses those people use.
For businesses in Bath and across the South West, this is less about a technical Google Ads feature and more about ownership. An advertising account can contain billing details, customer data, campaign history and access to substantial budgets. If access depends on a former employee’s personal inbox or an agency address the business does not control, a routine staff or supplier change can become a serious problem.
What Google is changing
According to Google’s new help guidance, some sensitive Google Ads actions may require an eligible corporate email address during the pilot. Google describes a corporate address as one using an organisation’s domain, rather than a free consumer email service.
The extra check is intended to make it harder for an unauthorised person to carry out important account changes. The precise prompts will depend on the action and the account included in the pilot, so businesses should not assume that every user will see the same request immediately.
The practical message is straightforward: Google increasingly expects the people making high-impact changes to have an identity that can be connected to the organisation they represent.
Why a company email address matters
A company-controlled email address gives a business a clearer way to grant and withdraw access. When someone joins, an address can be created under the business domain. When they leave, the account can be disabled without needing their cooperation.
That is much harder when an important Google Ads login belongs to an individual’s Gmail, Outlook or other personal account. The business may know the address but not control its password, recovery options or passkeys. The same risk applies when the only administrator is attached to a supplier rather than the advertiser itself.
This does not mean every external specialist needs an inbox on the client’s domain. Agencies and freelancers can use their own properly managed business identities and manager accounts. The advertiser should, however, retain at least one secure administrator identity that it controls directly.
Check account ownership before the prompt appears
Do not wait until an urgent billing, access or campaign change triggers a new security requirement. Open the Google Ads access settings and identify every administrator, standard user and read-only user.
For each one, ask whether the person still needs access, whether the email belongs to the correct organisation, and whether somebody can remove that access promptly. Old employees, dormant agency logins and unexplained addresses should be investigated rather than left in place “just in case”.
Businesses using Google Ads to generate local leads should also document the account’s customer ID, billing owner, primary administrator and recovery route. Keep that record somewhere controlled by the organisation, not solely in one person’s inbox.
Domain email is only one part of security
A corporate address proves little if the underlying mailbox is poorly protected. Administrators should use multi-factor authentication, preferably with passkeys or security keys where available, and should have separate user identities rather than sharing one login.
Shared credentials make it difficult to tell who changed a budget, added a user or altered tracking. They also make offboarding risky because changing a shared password can disrupt several people at once. Named access is cleaner, safer and easier to audit.
It is also worth reviewing the security of the business domain itself. If the domain expires, the email service is compromised or only one person controls the registrar, the apparent corporate identity may not provide much protection. Website, email and advertising ownership should form part of the same basic digital continuity plan.
What Bath and South West advertisers should do now
- Confirm that the business has at least one current Google Ads administrator using an address it controls.
- Remove users who no longer need access and reduce administrator permissions where standard access is sufficient.
- Check that external partners use named, professionally managed identities and that the client retains direct ownership.
- Turn on strong multi-factor authentication and avoid shared passwords.
- Record the account ID, billing contact, administrators and recovery process in a secure internal document.
If your advertising is managed externally, ask who would still be able to access and operate the account if the relationship ended tomorrow. A good supplier should be able to answer clearly. This is part of sensible search marketing management, not a sign of mistrust.
A small rule with a useful warning
Google’s corporate email pilot may affect only selected accounts and sensitive actions at first. Even so, it exposes a common weakness: businesses often spend heavily through advertising platforms without maintaining clear control of the identities that administer them.
The best response is not to create extra inboxes hurriedly when Google asks. It is to establish durable ownership now, give each person the access they need, and make sure the business can recover its account when staff, agencies or technology change.
Source: Search Engine Land’s report on Google Ads corporate email requirements.

