The acceptance sequence
- Before a choice: start with cleared site storage. Optional scripts, pixels and media must remain inert under an opt-in profile. Necessary services stay available.
- Reject optional: confirm no optional loader starts. Reopen preferences; Necessary stays on, and all optional choices remain off.
- Accept all: confirm each configured service loads once. Refresh and check that the choice is remembered.
- Customized choices: allow Analytics only. Marketing, Media, Functional and every custom purpose stay off. Repeat for Media and a custom purpose separately.
- Withdraw: first allow, then reject in the same page. Check vendor revoke signals, blocked media and locally saved restrictions. Generic scripts and script-based widgets reload the page because removing an element cannot undo executed JavaScript.
- Regrant: allow Media again. The original content must load again, without a duplicate placeholder. Test a service outage: new grants remain blocked and an error is announced; withdrawals still restrict local choices.
Read and review scanner evidence
The scanner tests one public page in five isolated scenarios: before choice, rejected, accepted, Analytics-only, and withdrawal. Withdrawal includes acceptance and rejection in the same browser context. The report preserves the consent-state label for requests made during setup.
Inventory includes network observations and visible or inert scripts, images/pixels, and frames in the main document. Open a resource in Technology inventory, select a reviewed category and record a reason. In managed workspaces, assigned specialists save classifications; ordinary customer owners cannot approve them. Legacy workspace owners and administrators retain their existing review access. Review records are audited and scoped to that property.
Reviewing a resource does not silently activate it. Compare explicit category markers and managed IDs with your configuration; add or correct a technology, then review and publish its consent configuration separately. Download JSON or CSV from the report for requests, cookie names/domains, storage keys, inventory, findings and tested states. Cookie values and query strings are intentionally excluded.
Limits of automated verification
Keyboard and accessibility acceptance
- Open preferences from both the banner and a footer button. Tab and Shift+Tab remain in the modal; the page behind it cannot receive focus.
- Escape and Close work without forcing a choice, including on a first visit. Focus returns to the opener or a visible persistent control.
- All controls have useful names, descriptions and visible focus. Errors are announced without granting optional access.
- Check 320px layouts, 200%/400% zoom, enlarged text, translated copy, forced colors, keyboard-only use and screen readers on each supported browser.
- Publishing validates text, secondary text, link/focus colors and primary-button contrast. Those checks do not replace a full WCAG 2.2 AA audit of the host site.
Production sign-off
Repeat these checks on a real Shopify theme, WordPress installation and custom site, including caches and duplicate app/plugin/GTM installs. Test vendor accounts, trusted geolocation, CSP, consent duration and policy updates. Have the site's privacy reviewer approve purposes, notices and regional choices.
Open the technology reference →