Learn
The agency playbook for continuous cookie compliance
Agencies don't fail cookie compliance at launch — they fail it three months later, when a campaign pixel or a tag manager edit quietly starts firing before consent on a site nobody was watching. Continuous monitoring is how an agency turns that risk into a service line.
This playbook covers the full loop: onboarding a client portfolio, choosing a monitoring cadence, scanning around launches, triaging alerts, and turning the scan history into client reporting.
Step 1 — Onboard the portfolio with a baseline scan
Start by listing every domain your agency is responsible for — sites you built, sites you host, and sites where you only run campaigns but installed the tags. Then run a baseline scan on each one. The scan needs no client credentials or code changes, so onboarding 20 sites is an afternoon, not a project.
The baseline does two things: it surfaces the sites with pre-consent trackers or broken banners right now (triage those first), and it gives every client relationship a dated starting point you can measure drift against. On the Agency plan you get 25 monitored sites, 500 scans a month, and 5 seats — enough to give account managers their own logins instead of a shared inbox.
Step 2 — Set a monitoring cadence per site tier
Not every site deserves the same frequency. A practical tiering: weekly for sites with active campaigns, frequent deploys, or e-commerce checkout flows; biweekly for sites with a steady publishing rhythm; monthly for brochure sites that rarely change.
Compliance Monitor supports all three cadences with email alerts on every change it finds. The rule of thumb: match the scan frequency to the deploy frequency, because regressions ship with changes — a new landing page, a tag manager edit, a pixel added for a campaign.
Step 3 — Scan around launches, not just on schedule
Scheduled scans catch drift; launch-day scans prevent it. Make an ad-hoc scan part of your go-live checklist for every campaign and site release: run it on the new landing page before traffic starts, and confirm the new pixels sit behind the consent gate.
This is where most agency-caused violations happen — the site was compliant at handoff, then a campaign added a Meta or TikTok pixel that fires pre-consent. Catching it before spend starts costs one scan; catching it after a demand letter costs a client relationship. The pre-consent tracking guide explains why this specific failure drives most claims.
Step 4 — Triage alerts with a simple severity ladder
When an alert email arrives, classify it before assigning it:
- Fix now: a tracker started firing pre-consent, the banner stopped appearing, or declining no longer blocks trackers. These are the findings claims are built on.
- Fix this sprint: a new post-consent tracker appeared that the cookie policy doesn't mention, or a vendor domain changed.
- Log and review: cosmetic changes — expiration shifts, renamed cookies — that go into the next client report.
Route alerts to the account owner for each site, and use the private Zapier integration if you want findings pushed into the ticketing tool your team already lives in.
Step 5 — Turn the scan history into client reporting
The monitoring history is a deliverable in its own right. Attach the PDF report to your monthly client reporting, export findings to Notion or Confluence where the client keeps their documentation, or send a public share link when the client just needs to see the current state.
Frame it as risk management, not tooling: "your site was scanned four times this month, one issue was found and fixed within 48 hours." Clients who see that line every month understand what the retainer buys — and clients with a verified badge on their site get to show it to their own visitors.
Step 6 — Package compliance monitoring as a service line
Once the workflow runs, the economics are straightforward: the Agency plan costs $39.99/month across 25 sites, and agencies typically bill compliance monitoring per client as part of a maintenance or media retainer. The margin is real because the marginal effort per site is a few minutes of alert triage.
It also protects the agency itself — when tags you installed are questioned, a documented history of scans, alerts, and fixes is the record you want to produce. Whether liability can reach the agency is a contract and jurisdiction question for your lawyer, not a scanner; what the scanner provides is the evidence that you were watching. Full plan details are on the cookie compliance for agencies page.
Related guides
More insightsGuide
Protecting your clients from privacy lawsuits
The practical checklist for CIPA and session-recording claims — audit the trackers that trigger demand letters.
Guide
How law firms run cookie audits for clients
The counsel-side playbook: intake, scanning, remediation letters, and monitoring retainers for client sites.
Guide
Cookie compliance for digital agencies
Monitor every client site from one dashboard — 25 monitored sites, team seats, alerts, and client-ready reports.
Ready to prove your compliance?
Start with a scan so you can show regulators and stakeholders the evidence you followed cookie compliance checker best practices.
Run a free scan