Verify behavior, not just the banner.

A successful install is the beginning. Prove which requests and storage each consent choice permits on the actual site.

The acceptance sequence

  1. Before a choice: start with cleared site storage. Optional scripts, pixels and media must remain inert under an opt-in profile. Necessary services stay available.
  2. Reject optional: confirm no optional loader starts. Reopen preferences; Necessary stays on, and all optional choices remain off.
  3. Accept all: confirm each configured service loads once. Refresh and check that the choice is remembered.
  4. Customized choices: allow Analytics only. Marketing, Media, Functional and every custom purpose stay off. Repeat for Media and a custom purpose separately.
  5. Withdraw: first allow, then reject in the same page. Check vendor revoke signals, blocked media and locally saved restrictions. Generic scripts and script-based widgets reload the page because removing an element cannot undo executed JavaScript.
  6. Regrant: allow Media again. The original content must load again, without a duplicate placeholder. Test a service outage: new grants remain blocked and an error is announced; withdrawals still restrict local choices.

Read and review scanner evidence

The scanner tests one public page in five isolated scenarios: before choice, rejected, accepted, Analytics-only, and withdrawal. Withdrawal includes acceptance and rejection in the same browser context. The report preserves the consent-state label for requests made during setup.

Inventory includes network observations and visible or inert scripts, images/pixels, and frames in the main document. Open a resource in Technology inventory, select a reviewed category and record a reason. In managed workspaces, assigned specialists save classifications; ordinary customer owners cannot approve them. Legacy workspace owners and administrators retain their existing review access. Review records are audited and scoped to that property.

Reviewing a resource does not silently activate it. Compare explicit category markers and managed IDs with your configuration; add or correct a technology, then review and publish its consent configuration separately. Download JSON or CSV from the report for requests, cookie names/domains, storage keys, inventory, findings and tested states. Cookie values and query strings are intentionally excluded.

Limits of automated verification

A clean report is not a compliance certificate. Classification is heuristic; server-side tracking, consent behind login, delayed events, other pages, regional variations, ad blockers and browser privacy restrictions require manual testing. GTM tags must be audited individually. Older reports contain only their original three scenarios; rerun a scan for the new ones.

Keyboard and accessibility acceptance

  • Open preferences from both the banner and a footer button. Tab and Shift+Tab remain in the modal; the page behind it cannot receive focus.
  • Escape and Close work without forcing a choice, including on a first visit. Focus returns to the opener or a visible persistent control.
  • All controls have useful names, descriptions and visible focus. Errors are announced without granting optional access.
  • Check 320px layouts, 200%/400% zoom, enlarged text, translated copy, forced colors, keyboard-only use and screen readers on each supported browser.
  • Publishing validates text, secondary text, link/focus colors and primary-button contrast. Those checks do not replace a full WCAG 2.2 AA audit of the host site.

Production sign-off

Repeat these checks on a real Shopify theme, WordPress installation and custom site, including caches and duplicate app/plugin/GTM installs. Test vendor accounts, trusted geolocation, CSP, consent duration and policy updates. Have the site's privacy reviewer approve purposes, notices and regional choices.

Open the technology reference →