Article

How do you read a cookie audit report?

Start a free audit

Read a cookie audit report in this order: scope, scenarios, findings, evidence IDs, then the next action. Findings are technical observations for review.

In brief

Read a cookie audit report in this order: scope, scenarios, findings, the evidence behind each finding, then the next action. Scope names the region and the consent states the visit actually ran. Findings describe cookies, requests, or scripts from those states. A free US-baseline file does not by itself support an EU or California conclusion. If your file uses different headings, follow this order with the labels you see.

Not legal advice

This page explains how to read a ConsentProbe-shaped technical report. It is not legal advice, and it is not a changelog of every label in the product UI. If a heading in your file uses a different name, follow the same order with the label you see. Severity in the report is a review priority. It is not a determination that a statute was violated, and it is not a statement that the shop passed one.

Short answer

Start with scope. Then read the scenarios that were actually run. Then read each finding as an observation tied to an evidence ID. Then decide the next action and the re-test.

A public sample report uses fictional data so you can learn the layout. Do not attribute those findings to a real shop. When you need a file for your domain, run that URL.

Start with scope

Scope names the product and the region path. A free US-baseline visit is one browser pass outside California. It records cookies, requests, and screenshots for that path. It does not run an EU fresh, reject, and accept set, and it does not run a California GPC pair.

An EU regional report covers fresh, reject, and accept scenarios in an EU context. A California report covers a GPC-off visit and a GPC-on visit. Read the free versus paid guide before you paste a US-baseline line into an EU or California note.

Also note the URL and the time window. One homepage visit is a sample of that URL. A product page, cart, or account template can load different apps. Say which URLs are in the file before you describe the theme as a whole.

Scenarios, then findings

Each scenario should carry a label. Fresh means no banner click. Reject All means the click was verified, then the page was observed again. Accept All is the baseline for what expected vendors look like after a choice. GPC-off and GPC-on are a pair, and only a California-context pair supports a GPC comparison.

If the file has one scenario, limit your sentences to that scenario. A fresh-only file does not document a reject result.

A finding has a title, a priority, and evidence IDs. The title should say what was observed: a host, a cookie name, a storage key, or a script, and the scenario it appeared in. Priority tells engineering what to open first. Keep the line as a technical observation queued for review.

If you cannot point from the finding to a cookie, request, or screenshot ID, ask for that link before you forward the finding. The pre-consent audit checklist says what a complete pack contains when a layer is missing.

Reading order for a ConsentProbe-shaped report. Match the labels in your file.
OrderSectionWhat to take from it
1ScopeRegion path, product, URLs, and the time window
2ScenariosWhich of fresh, reject, accept, or GPC actually ran
3FindingsObserved host, cookie, or script, plus a review priority
4Evidence IDsThe cookie row, request, or screenshot behind each finding
5Next actionWhat to change, then which scenario to re-run

How to open an evidence link

Open the evidence before you rewrite the finding in your own words. A cookie row should show the name and the domain. A request row should show the host, the path, and the scenario timestamp. A screenshot should show the banner or the DevTools panel for that same scenario.

A banner-only screenshot leaves the finding thin. Add the cookie table and the request list for the same scenario, or re-run. Strip query values that carry identifiers before you forward the file.

Consent Mode text inside a finding is still a tag signal. Confirm the request list before you describe pixels as blocked. The consent-mode checklist shows the raw-request comparison.

What to send engineering

Send the scope line, the scenario list, and the findings that include evidence IDs. Include the URL and whether reject or accept was verified.

A useful handoff names the re-test: the same URL, the same scenarios, and the hosts you expect to disappear or appear after the change. Re-run after a material CMP, pixel, theme, or privacy-control change, and after you finish the remediation step you care about.

A free US-baseline file described as an EU audit goes past the scope line. A finding pasted into a legal memo as a violation, or as a clean result, still needs its evidence ID on the sentence. One URL described as the whole theme needs the template names, plus the product URL on the next run if that template loads extra apps.

FAQ

Is every finding a violation?

Treat each finding as a technical observation prioritized for review. It is not a legal determination.

Why does scope matter?

The region and the scenarios set the limit of what the file can support. A US-baseline file does not answer an EU reject question.

What if I only have screenshots of the banner?

The pack is incomplete. Add the cookie table and the request list for the same scenario, or re-run and keep those layers.

Is one URL enough?

It is a visit sample of that URL. Critical templates may need their own URLs on a later run.

When should I re-run?

After a material CMP, pixel, theme, or privacy-control change, and after you finish the remediation step you care about.

Can I paste the public sample into a customer deck?

The sample is fictional. Use it to learn the layout. Run the real shop when you need findings for that domain.

Related guides

Use the free versus paid page before you quote a regional line, the pre-consent checklist when the evidence section is thin, and the CMP claims page when marketing text disagrees with a finding.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

How to read a cookie audit report | ConsentProbe