Checklist
How do you turn a cookie audit finding into an eng ticket?
Write one engineering ticket per cookie audit finding: consent state, URL, repro steps, expected versus observed, and the cookie, request, and screenshot.
In brief
Turn one cookie audit finding into an engineering ticket by naming the consent state, the storefront URL, and the repro steps, then attaching the cookie row, the network request, and the screenshot. Put expected versus observed on two lines. A line that only says tracking still happens cannot be replayed. ConsentProbe links those three surfaces on a labeled run. A free US-baseline scan does not prove EU or California behavior. This page is handoff guidance, not legal advice.
Not legal advice
This article explains how to turn a cookie audit finding into an engineering ticket with reproducible artifacts. It is not legal advice, not a compliance certificate, and not a guarantee that closing a ticket meets GDPR, CPRA, ePrivacy, or any other rule. ConsentProbe reports are technical observations. They do not replace counsel.
Last updated September 24, 2026. The evidence pack guide owns the file list. The report reading guide owns the report screens. This page owns the ticket fields and the handoff order.
Short answer
Turn a cookie audit finding into an eng ticket with one sentence that says what broke which expectation, the consent-state label you tested, the storefront URL, and the repro steps. Attach the cookie row, the network request, and the screenshot that show it. Add expected versus observed as two short lines.
Engineering needs a host, a state label, and a way to replay the run. A ticket that only says tracking still happens has none of those. ConsentProbe findings already point at the request, the cookie, and the screenshot when the run used a labeled scenario such as Fresh, Reject, Accept, or GPC-on. A free US-baseline scan does not prove EU or California behavior. ConsentProbe does not install a CMP. This page is handoff guidance, not legal advice and not a compliance certificate.
Why vague tickets stall
Banner broken and still tracking do not name a consent state or a host. Engineering cannot replay a run from those words. A banner screenshot shows the buttons. The network after Reject lives in a different file. The audit-versus-banner guide and the CMP claims guide cover that split.
Keep one finding to one fixable surface: a script, a pixel, an app embed, or a server Set-Cookie. When two hosts need two different changes, write two tickets. A single ticket that lists ten hosts forces one owner to sort work that does not share a fix.
Ticket fields
Copy the row, fill it from one labeled finding, and leave the cells you cannot support empty rather than guessing a vendor story.
| Field | What to write |
|---|---|
| Title | Consent state, symptom, and host. Example: Reject All: example-pixel.example still requests on /. |
| Consent state | Fresh, Reject All, Accept All, or GPC-on. Record the exact button text when the click path matters. |
| URL | Storefront URL and path. Note the theme or app when you know it. |
| Repro | Clean profile, the steps, one navigation, then Network and Application. |
| Expected | The behavior the claim implied. Example: the marketing pixel is absent after Reject. |
| Observed | Host, cookie name or class, and timing relative to the banner. |
| Artifacts | Cookie table excerpt, request URL, and screenshot. Optional HAR with query values and secrets removed. |
| Owner hint | Theme, app, CMP, customer events, or server. A best guess so the ticket has an owner. |
The sentence engineering reads first
Example sentence, using a public hostname as a stand-in rather than a measured shop: After Reject All on /collections/all, connect.facebook.net still requested and a cookie in the _fbp class was set. Screenshot S1, request R12, cookie C4.
A weak line is Meta still tracks users. It names a brand and skips the URL, the consent state, and the three files. The evidence pack guide holds the rules for those files.
From the file to a re-test
Keep the after file comparable with the before file. Same URL, same button text, same surfaces.
- Capture labeled evidence. The evidence pack guide is the file list: cookie, request, and screenshot under one URL and one consent state.
- Fill the ticket once per distinct host or failure mode. Split the ticket when the fixes differ.
- Engineering changes the gate or removes the tag.
- Re-run the same consent state and attach the before and after request diff. The re-test guide is that loop.
- When the original claim was regional, re-test in that scenario, EU or GPC, and not only on a free US-baseline scan. The free versus paid guide states that split.
Re-run Network under the same label
Closing the ticket because the CMP dashboard says blocked leaves the host untested. Require Network and cookies under the same consent-state label. The CMP claims guide is the longer comparison of banner text and runtime.
On a ConsentProbe re-scan, the finding stays linked to the request, the cookie, and the screenshot, so the after file can sit next to the before file. The report reading guide is the screen tour for those links.
When assembling the pack by hand is slow
After you have filled the ticket once by hand, paste the storefront URL when you want Fresh, Reject, Accept, or GPC scenarios with the request, the cookie, and the screenshot stored on the finding.
Use the free US-baseline visit for the report format. Use paid EU or California scenarios when those regions are the claim on the ticket. ConsentProbe does not install a CMP, and the report is not a compliance certificate.
FAQ
What belongs in a cookie audit eng ticket?
The consent-state label, the URL, the repro steps, expected versus observed, and linked cookie, request, and screenshot artifacts.
Is still tracking enough for engineering?
No. Name the host and the consent state, and attach a way to replay the run.
Does ConsentProbe replace the ticket?
No. It supplies labeled evidence you attach or link. Engineering still owns the fix. ConsentProbe does not install a CMP.
Is closing the ticket a compliance certificate?
No. Closing the ticket updates a technical file. It is not legal advice and not a compliance certificate.
Does a free US re-scan prove an EU Reject fix?
No. A free US-baseline visit is not an EU or California conclusion. Re-test in the scenario that matched the original claim. See the free versus paid guide.
Where is the full evidence checklist?
The evidence pack guide lists the files. The report reading guide walks the report screens. This page is the ticket shape.
Limits of this page
This page explains how to turn one cookie audit finding into an engineering ticket. It is not legal advice, not a compliance certificate, and not a guarantee that a closed ticket meets GDPR, CPRA, ePrivacy, or any other rule. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California conclusion. ConsentProbe does not install a CMP.
Related guides
Open the evidence pack for the file list, the report guide for the screens, and the CMP claims guide before you close a ticket from a dashboard badge.
- What belongs in a cookie consent audit evidence pack?
- How do you read a cookie audit report?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Pre-consent audit checklist: what to verify before Accept
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- What is the difference between a cookie consent audit and a cookie banner?
- Does Reject All stop marketing pixels?
- How do you re-test after a GPC or Reject All fix?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.