Checklist
How should an agency hand a cookie audit to the client?
What belongs in an agency cookie audit client packet versus an eng ticket. Fresh and Reject evidence, with one sentence per finding. Not legal advice.
In brief
An agency hands a merchant a client packet: labeled Fresh and Reject findings, the hosts or cookies that mismatched the claim, screenshots, and one expected-versus-observed sentence per finding. An eng ticket is a different file, and so is a walkthrough of report controls. Keep the sentences observational. The testing hub stays the hub. A free US-baseline scan is not an EU or California legal conclusion. This page is not a second cookie-audit hub and not legal advice.
Not legal advice
This guide explains how an agency packages cookie audit observations for a merchant client handoff: what the client packet includes, and what it does not claim. It is not legal advice, not a compliance certificate, not a counsel memo, and not a guarantee that any finding or fix meets GDPR, ePrivacy, CPRA, or other rules. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 29, 2026. The testing hub stays the hub. The report-reading page stays the guide to report controls. The eng-ticket page stays the developer handoff. This page does not rewrite those three, and it does not open a second cookie-audit hub.
Short answer
An agency cookie audit handoff to a merchant client is a client-facing packet. Put labeled Fresh and Reject findings in it, name the hosts or cookies that mismatched the claim, attach screenshots, and write one plain expected-versus-observed sentence per finding.
That packet is a different artifact from an eng ticket. The eng-ticket page owns repro steps and fix ownership for developers. It is also different from teaching the client how to read every report control. The report-reading page owns that walkthrough. Start from the evidence pack pattern. Keep claims observational, such as host X on Fresh before Accept, rather than a legal conclusion.
Send the client to the testing hub when they ask which test to run next, and to the before-Accept audit when they want the protocol. Do not invent a second cookie-audit hub. This page is not legal advice. Observation is not counsel permission.
Three artifacts
Agencies blur these files when one PDF tries to be the stakeholder summary, the developer ticket, and the report manual. Split them. Prefer client packet contents over a stamp that the deliverable is done.
| Artifact | Audience | What it owns |
|---|---|---|
| Client packet, this page | Merchant, marketing, and ops stakeholders | Summary findings, screenshots, and a pointer to the next test |
| Eng ticket | Developers | Repro, expected versus observed, and linked artifacts. The eng-ticket page owns the field list. |
| Report literacy | Anyone opening a scan UI | How to read a cookie audit report. That page owns the controls. |
Client packet checklist
Use this list to wrap a pack. It does not replace the evidence pack fields, and it does not paste the report-reading tutorial or a second hub outline.
- Write a scope sentence: URL, date, time zone, and which regions the client claimed. Say whether the file is a US-baseline format check or an EU or California scenario. The free versus paid guide is the honesty line.
- Name the states you ran. Include Fresh and Reject when Reject claims matter. Note Accept or GPC only when they were in scope.
- For each finding, name the host or cookie, the consent state label, one expected-versus-observed sentence, and a link to the request, cookie, or screenshot.
- State the non-claims in the packet: not legal advice, not a CMP certificate, and observation is not counsel permission.
- Point next actions at the eng-ticket page for fixes, the testing hub for which test to run next, and the retest pages after a fix or a CMP switch.
- Link the report-reading page when the client asks what a control means. Do not paste that tutorial into the packet.
What the client should not receive instead
A raw export with unlabeled rows makes the merchant guess which state produced the host. Label Fresh and Reject on the row, or the packet fails the handoff even when the capture was careful.
An eng ticket buried in the same document hides fix ownership. Keep repro steps on the ticket. Keep the stakeholder sentence in the packet. Example of a packet sentence, not a customer capture: Fresh, before Accept, request to a marketing host; expected no marketing host before a choice; observed the host on the first load. Screenshot attached.
If the client asks for legal clearance, the packet stays technical. Point them to their counsel. Privacy-policy comparisons and re-run cadence live on their own pages.
When assembling packets gets slow
Assembling client packets across many storefront templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the client URL. Each finding stays tied to a request, a cookie, or a screenshot. Wrap that pack in the checklist above.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when the client's claims are those regions. ConsentProbe does not write counsel memos, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.
FAQ
How should an agency hand a cookie audit to the client?
Deliver a labeled Fresh and Reject packet with hosts, screenshots, and one expected-versus-observed sentence per finding. Link eng tickets separately. The eng-ticket page is the developer file.
Is the client packet the same as an eng ticket?
No. The client packet is the stakeholder summary. The eng ticket is fix ownership. Keep repro steps on the ticket page's field list, not in the client summary.
Is this a guide to what a cookie audit report is?
No. The report-reading page covers how to read a report. This page covers the agency to client handoff. It does not rewrite that report page.
Do we need a second cookie-audit hub?
No. Use the testing hub. This page reinforces cookie audit through the handoff. It is not a second cookie-audit hub.
What if the client asks for legal clearance?
Observation is not counsel permission. Point them to their counsel and keep the packet technical. ConsentProbe does not replace counsel.
Is this legal advice?
No. This is a technical handoff. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP, and it does not issue a certificate.
Limits of this page
This page tells an agency what belongs in a client packet and which published page owns the eng ticket, the report walkthrough, and the testing hub. It is not legal advice, not a second cookie-audit hub, and not a rewrite of the report-reading page or the eng-ticket page. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the evidence pack for the fields, the report-reading page for the controls, the eng-ticket page for developer ownership, the testing hub for which test is next, and the before-Accept audit for the protocol.
- Cookie consent evidence pack
- How do you read a cookie audit report?
- Cookie audit finding to an eng ticket
- Cookie audit hub
- How to run a cookie audit before Accept
- Pre-consent audit checklist
- Cookie audit vs privacy policy claims
- How often to re-run a cookie consent audit
- CMP claims vs runtime evidence
- Free US-baseline vs paid EU and California
- Re-test after a GPC or Reject All fix
- Retest after switching CMP vendors
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.