Permissions
Telescope registers exactly one permission. Analytics are read-only, so there is nothing else to gate.
View analytics reports
Under Users → Groups → (a group) → Permissions, look for the Telescope heading and tick View analytics reports.
Without it, a user sees none of the following:
- The Analytics field, even where it is in the field layout
- The compact panel in the entry sidebar
- The Telescope item in the control panel navigation, and the Overview page behind it
- The print view
Admins have it implicitly, as with every Craft permission. Plugin settings remain admin-only.
Your editors do not need Google accounts
This is the part worth saying out loud, because it is the usual reason for reaching for a plugin like this in the first place. The only Google identity involved is the service account. Editors authenticate to Craft and nothing else — you never have to add them to the GA4 property, hand out logins, or explain the GA4 interface to somebody who just wants to know whether their blog post did well.
What the service account can do
Add the service account to your GA4 property as a Viewer. Telescope only reads: it makes runReport calls against the Data API and never writes, so no higher role is needed and none should be granted.