The first week with a new client is usually spent waiting: for tag-manager access, for the analytics property, for the ad accounts, for someone to find the login. You do not need any of it to start. Everything the client's visitors' browsers receive is visible to yours, and that is most of what decides whether their measurement is trustworthy. This is the outside-in audit we run on day one, and often before the contract.
What can you learn without a login?
From a fresh browser and a public URL you can establish, for every page template that matters:
- Which analytics, advertising, replay, testing and consent tools are present, with their account or container ids.
- Which of them actually fire, and which are dead weight left by a previous agency.
- What fires before the visitor answers the cookie banner, and what still fires after Reject.
- Whether the basics are wired: one copy of each tag, the same ids across templates and domains, and — by hand — whether links to a checkout or booking domain carry the cross-domain linker.
- Which visitor actions produce a measurement at all: page views, scroll, clicks on key links, typing in forms. If nothing leaves the browser when a visitor starts a form, the lead funnel is not being measured, whatever the reports say.
That is enough to write the first findings memo, to size the work, and to know which questions to ask when access arrives.
What do you need from the client on day one?
Nothing. Later, three things in this order, each cheap for them and each unlocking something specific:
- A list of the pages that matter — the money pages, the lead forms, the checkout or booking flow, any sub-domains. Five minutes of their time; it turns a homepage check into a site audit.
- A firewall allowlist rule, if the site sits behind bot protection that blocks automated visitors. One rule, scoped to your scanner's address.
- Written permission for anything beyond observation — before you submit a form or complete a purchase on their site in your own testing. (TagAudit itself submits nothing, on any site, in its current configuration.)
Access to the tag manager and the analytics property comes after, and by then you know exactly what to look for in them.
The day-one method, step by step
- Fresh profile, EU conditions. Use a browser profile that has never seen the site. If the client sells in Europe, test as a European visitor; banners and defaults often differ by region.
- Inventory on load. DevTools → Network, Preserve log on. Load the homepage and note every third-party request: analytics, ads, replay, chat, testing, consent. Record the ids.
- Answer the banner both ways. Reload fresh and click Accept; reload fresh and click Reject. Record what fires in each case. The difference between the two lists is the part of the stack the banner actually controls.
- Repeat on the templates that matter: a content page, a product or service page, the lead form, the first step of checkout. Tags go missing per template, not per site.
- Interact. Scroll to the end, click one internal link, start typing in a form without submitting. Note which actions produced a request and which produced nothing.
- Follow the money across domains. If a link leaves for a checkout, booking or payment domain, check that the same analytics id is used on the other side and, by hand, that the outbound link carries the cross-domain linker.
- Write the table. One row per tag: present · fired on load · fired before consent · fired after Reject · id · templates seen on. One row per action: scroll · click · form start · what fired.
The whole pass takes under an hour by hand. TagAudit's free scan runs a version of steps 2, 3 and 5 on a public URL — the inventory, a visit with the banner declined, or left unanswered where there is no reject control, and the interaction test — and ranks what it finds; the Pro Scan adds a funnel crawl and unlocks the fixes.
What goes in the first memo?
Three sections, in this order, and short:
- What is measured today. The inventory, with ids, and which tags are live. This is the part the client usually does not have.
- What is not measured or is measured wrong. Missing tags per template, duplicates, actions that produce nothing, consent that only gates part of the stack, a broken cross-domain step. Each with the evidence: the request you saw or did not see, on which page, under which consent choice.
- What to do first. Ordered by impact on the decisions the client makes: a purchase or lead event that never fires outranks a duplicate page view, which outranks a stale pixel.
Keep the legal reading out of it. Say what fires and when; do not say what is compliant. That is a conversation for the client and their advisers, and you have given them the facts it needs.
What should you never say about a prospect?
Do not accuse. An outside-in audit sees requests, not intent, and it sees one visit under one set of conditions. A tag that fired after Reject in your test may be gated on the next template, or may be an intended cookieless ping. Report the observation with its conditions — the page, the consent choice, the date — and let the finding speak. Never publish a finding about a company that is not your client, and never name a third party as non-compliant on the strength of a scan. We hold ourselves to the same rule.
What you can't see from outside
- Server-to-server integrations — Conversions API, offline conversion uploads, warehouse syncs. Flag where they probably exist and verify in the accounts later.
- Anything a submitted form or a completed purchase would send. Actions that would send something to the site are switched off in our current configuration, on every site, so tags that fire only after them stay unobserved.
- Reporting configuration — filters, attribution settings, retention, sampling, unpublished tag-manager workspaces. That is the day-two audit, once access arrives, and it is a different audit.
- The pages you did not load. An outside-in audit is only as complete as the list of templates you tested.
FAQ
Can I do this before the contract is signed? Yes, on public pages, the same way any visitor's browser would. Keep it to observation: do not submit forms or complete purchases on a site whose owner has not given you permission.
Is this the same as a technology-detection tool? Detection says a tool is present. This audit says whether it fired, under which consent choice, and for which visitor actions. Presence is the easy part.
Do I still need the analytics and tag-manager access? Yes, for the reporting-side audit. The outside-in audit tells you what the browser sends; the inside audit tells you what the property does with it. Both, in that order.
How long does it take? Under an hour by hand for a handful of templates; a few minutes with a scan.