Technical guide

Runtime Audit vs CMP: What Each One Measures

Separate the consent banner and preference layer from a browser runtime audit of cookies, requests, and scripts on a Shopify storefront.

In brief

A CMP shows the banner and stores a preference. A runtime audit records cookies, storage, network requests, scripts, and screenshots from a real browser visit. Shopify can gate app and custom pixels through Customer Privacy settings. Theme scripts and request-only pixels still need a storefront check. A US-baseline audit is not a regional result and is not legal advice.

Hard boundary

US-baseline means one non-California United States visit profile. Locale, timezone, and Shopify market settings do not replace regional IP evidence. A CMP admin export is not runtime evidence. This page describes measurement boundaries. It is not legal advice and does not name a preferred CMP.

What the CMP measures

The consent management platform is the banner, preference center, and the storage or API that records Accept, Reject, or a purpose-level choice. Shopify Customer Privacy settings can delay app and custom pixel callbacks until a recorded state allows them.

A CMP admin screen can show that a category is off. That screen does not show whether a theme script, a hardcoded pixel, or a tag manager still sent a request.

  • Visible controls and whether reject is as available as accept.
  • Stored preference keys or CMP cookies after a verified click.
  • Documented APIs such as Shopify customerPrivacy or a vendor consent API.
  • Which pixel callbacks the platform claims to gate.

What a runtime audit measures

A runtime audit opens the public storefront in a controlled browser and records what that visit actually set and sent. ConsentProbe methodology lists cookies, storage, requests, CMP actions, screenshots, and vendor detections as evidence layers.

The audit can verify that a reject control produced an observable state change. It cannot see private admin toggles, contracts, or server-to-server Conversion API traffic.

Shopify storefront boundaries

App pixels and custom pixels that honor Customer Privacy can stay quiet until the recorded consent state changes. Theme.liquid scripts, app embeds that inject tags outside that gate, and third-party chat or review widgets often sit outside that path.

Treat each installation source separately: Shopify app, Customer Events, theme code, tag manager, or embedded service. After a CMP or pixel change, rerun the same fresh, reject, and accept sessions.

How the two fit together

Use the CMP to set and store the choice. Use the runtime audit to test whether marketing and ads traffic waited, stopped, or continued, including cookieless pings. The sample report shows how findings attach to screenshots and request records. Listed regional products on pricing add EU or California scenarios when you need those visit profiles.

Related guides

The first-load checklist and the Consent Mode network checklist sit on the audit side of this split.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Runtime Audit vs CMP: What Each One Measures | ConsentProbe