Two ways to watch a client roster

Both work. They answer different questions, and one of them needs permission from every client before it answers anything.

The choice

Installed monitoring, or monitoring that installs nothing

Most tracking monitoring works by putting a script on the site it watches. That buys depth: once you are inside the page, you can see every event, every property, and every value it sends.

The cost is that it only watches sites where the script actually landed. For an agency, that means a conversation, a developer ticket, and a client's approval for every account you want covered. In practice the rollout stops after the first few clients who said yes.

We scan from the outside, the way a visitor does. That gives up depth and gains something an agency needs more: it works on every client, today, without asking any of them for anything.

 
Installed on each site
RiskSignal
Setup
A script added to every client site, through a tag manager or the code itself.
You send a list of domains. Nothing is installed anywhere.
Coverage
The clients who agreed to the install. The rest are dark.
Every client on your roster, including the ones who would never approve a script.
Time to cover
However long it takes each client to deploy it.
The next morning's scan.
New client
Another install before they are covered.
Add the domain to the list.
Depth
Every event and value the page sends, including things we cannot see.
Whether the tracking is present and transmitting. That is the boundary.
Access
Client approval for a third party on their site.
None. No credentials, no code, no account access.
Who it suits
A team that owns one property and wants everything about it.
An agency answering for twenty sites it does not control.
Alerts
Automated.
A person checks every one before it reaches you.
Priced by
The property, and usually its traffic.
How many client sites are on your roster.
Both

You can run both

These are not mutually exclusive, and for most agencies the sensible answer is both. Keep deep, installed monitoring on the flagship accounts that justified the rollout. Use us for the long tail you will never get a script onto.

That tail is usually most of the roster, and it is the part where a break goes unnoticed longest, because nobody is looking at those dashboards every week.

Honesty

What we give up

Scanning from outside means real limits, and they are worth knowing before you buy rather than after.

We detect a tag that has gone missing, and a tag that is present but transmitting nothing. We do not see conversion values, deduplication, consent configuration, or anything that only fails behind a checkout or a login. Server-side tracking is invisible to us, and where we can tell a site is using it we stay quiet rather than report a failure we cannot confirm.

The full boundary is on the Scope & Limitations page. If the failures you are worried about are in that list, installed monitoring is the right tool and we will say so.

Watching client sites you do not control?