Agency operations

Which questions should you ask before hiring a tracking specialist?

Which questions should you ask before hiring a tracking specialist?

Rhobin

July 30, 2026

7 min read

Ask how the cookie is actually set and how long it survives in Safari, what still gets sent when a visitor refuses consent, what the baseline is before any change, where the data lives after 14 months, and who the data processor is. Good answers are specific, quote a range rather than a single number, and say what the answer depends on.

The symptom

The call goes well. They talk about server-side tracking, first-party cookies, setups that hold up against ad blockers, Consent Mode, and all of it lines up with what you have read. You come away fairly convinced and slightly uneasy, because you could not have caught a wrong answer if you had been given one. Judging the answer takes the expertise you are trying to buy.

So the decision gets made on the things you can judge instead. Price, references, how fast they replied, whether they seem pleasant to work with. Those are real signals about working with someone. None of them tell you whether the tracking will still hold up in Safari in four months.

At Archon Labs we get pulled into this decision from both sides, sometimes as the candidate and sometimes as the second opinion after a setup did not deliver what was promised. The pattern is the same either way. The agency asked reasonable questions, got reasonable answers, and nothing in that exchange could have separated a specialist from someone fluent in the vocabulary.

Why it happens

Three things make this harder to buy than almost anything else an agency buys.

The vocabulary is free. "First-party cookie" and "server-side" describe an intention, not a result. Two setups can both be described that way, honestly, and still produce cookie lifetimes that differ by a factor of nearly sixty. The words survive the difference, which is exactly why they cannot be used to evaluate it.

There is nothing to inspect. Commission a landing page and you can look at the landing page. Here the deliverable is a number that is supposed to be more correct than the number you had before, and you have no correct version to hold it against.

The failure is quiet and slow. A typical account has 15 to 30% of its conversions consistently uncaptured, and ad blockers strip 30 to 40% of events before they arrive anywhere. A setup that recovers a thin slice of that still makes the dashboard move, so a mediocre implementation and a strong one look alike for the first few weeks. The gap shows up a quarter later, in bidding decisions nobody traces back to a tag.

Which tells you what the questions need to do: produce answers you can check afterwards, against documentation you did not have to write.

What good looks like

Five questions, each one anchored to something a browser vendor, Google, or the regulator publishes itself. For each, what a good answer contains and what a weak one sounds like.

How will the cookie be set, and how long will it survive in Safari?

A good answer separates a cookie written by JavaScript from one set in the server's response, because Safari treats them differently. WebKit's own documentation states that persistent cookies created through document.cookie are capped to a seven day expiry. A better answer volunteers the trap underneath it: WebKit also caps cookies set in third-party CNAME-cloaked responses at seven days, so a subdomain that resolves to somebody else's domain gets the short lifetime even though the cookie is technically set server-side. The weak answer is "we use first-party cookies, so 400 days". That number is a ceiling Chrome puts on any cookie, not something a vendor hands you, and quoting it as a feature is a tell.

What still gets sent when a visitor refuses consent?

Listen for whether the answer knows the two modes apart. Google's documentation says that in advanced consent mode a denied visitor still produces consent state and measurements without cookies, while in basic mode nothing is sent before the visitor consents and the modelling applied is a general one rather than one built on your own advertiser data. Google also notes that when advertising consent is denied, new advertising cookies stop, but the data sent still includes the full page URL with any ad click information in its parameters unless redaction is switched on. Someone who says a refusal means you get nothing has not read this. Someone who says they recover it anyway is worse.

What is the baseline, and how will you prove the recovery?

This is the question most candidates have not prepared for. A good answer starts by measuring the current state before touching anything, and names which events, which platforms and which date range will be compared afterwards. It also commits to a range instead of a promise, because 15 to 40% is what a server-side implementation typically recovers and the honest version of that stays a range. A weak answer offers one confident percentage, or proposes to demonstrate the improvement inside the same dashboard that was wrong to begin with. The baseline work itself is what a tracking audit covers.

Where will the data live, and what happens to it after 14 months?

A standard Analytics property keeps event-level data for two or 14 months, and the longer retention options are reserved for Analytics 360. So "it is all in GA4" is an answer with an expiry date attached. A good candidate knows that, and can tell you where raw data goes if you want a year-on-year comparison later, who has access to it, and what you keep if the relationship ends. If everything lives in their account, you are renting your own history.

Who is the data processor, and what does the contract say?

Server-side tracking moves personal data through infrastructure that somebody has to be accountable for. Article 28 of the GDPR requires a controller to use only processors that provide sufficient guarantees, expert knowledge and reliability among them, and requires the processing to be governed by a contract setting out its subject matter, duration, nature and purpose. A specialist expects this question and already has the paperwork. Someone who treats it as procurement friction has told you where compliance sits on their list.

These are the questions we would rather be asked than walked through a portfolio, because they can be checked. Choosing a supplier does not answer any of them. Archon Signal is the server-side setup we run on agency accounts, and how it is configured is what decides the outcome, which is also why the platform underneath matters less than most comparisons suggest, something we went into in does the server-side tool matter.

For one performance agency, the configured version meant 38% of client traffic affected by tracking prevention recovered, 26% more measured conversions, and 14 hours saved per project. One last tell to listen for: the ceiling on any setup is roughly 95% of events, never more. Consent refusals, blockers and plain network failures take the rest. A candidate who promises you more than that has failed the evaluation on the way in.

Frequently asked

We are hiring an employee, not a vendor. Do these still work?

Yes, with one adjustment. Someone interviewing for a seat cannot arrive with a baseline plan for accounts they have never seen, so the third question becomes a conversation about method rather than a deliverable. The other four work unchanged, and they reveal more in an interview than a technical test does, because they cannot be crammed the night before.

What if the honest answer to most of this is "it depends"?

Then they are right, and it depends is only half an answer. What follows it is the test. "It depends on whether the cookie comes from the response or the tag, and on whether that subdomain resolves to your own domain" is expertise. "It depends, each setup is different" is a way of closing the question down. Reward the first, notice the second.

We already run Stape. Does that change what we should ask?

It shifts the emphasis. You are no longer asking whether someone can build it, you are asking whether what you already have is configured tightly: whether it holds up against ad blockers and Safari, whether click IDs and UTM parameters survive the trip, whether consent is wired into the setup rather than bolted beside it. Most agencies we audit already own the tool. Having it is not the same as having it right.

Is this level of detail going to put good candidates off?

It does the opposite to the ones you want. A specialist finds these questions a relief, because they are finally being judged on the part they are good at instead of on a day rate. The reaction is data in itself: mild irritation at the first question tells you more than any reference call will.

If you would rather see the answers on your own accounts before you hire anybody, request a free tracking audit and we will show you where the conversions are going missing today.

© 2026 Archon LabsPrivacyTermsBuilt on unsampled data.