The symptom
Somewhere in the last two years, someone on the marketing team got Google Tag Manager access "because it made sense at the time." Maybe the developer was busy, maybe the agency was between retainers, maybe it just felt wasteful to bring in a specialist for what looked like a few clicks. Now that person maintains the container between campaign briefs, client calls and reporting deadlines, and tracking has become the thing that gets touched last and checked never.
You notice it in the usual places. A conversion count that does not match between Google Ads and GA4 for a week before anyone asks why. A consent banner update that quietly stopped a tag nobody remembers adding. A container with three admins who no longer work on the account and one who does, and nobody sure who can actually approve a change if that last person is on holiday.
None of this is a skills problem. The interface is genuinely built for someone without a developer background. The problem is what happens to a system that needs ongoing attention when the person responsible for it treats it as a side task, because for them, correctly, it is one. It is the same pattern covered from the marketer's side in what happens when marketers are asked to do your tracking, this piece looks at why, specifically, from the platform's own rules.
Why it happens
Three specific failure modes explain most of what goes wrong, and each one is documented by Google itself, not inferred from how tracking usually breaks.
The account has no real owner, only an admin who can be one role change away from losing it. Tag Manager has no domain-style ownership. Access is admin and user permissions, full stop, and Google's own guidance names the exact risk of a single-admin setup: "If a team member who is the sole administrator of your Tag Manager account changes roles, you can get locked out of your account." The recommended fix is to keep at least two active administrators at all times. Skip that, and the container is worse off than locked, Google states plainly that an account or container with no admin at all "will be automatically deleted," leaving anyone with read access a 30 day window to export what they can before it is gone (Managing users and permissions, Tag Manager Help). A container set up by one marketer under their personal login, with nobody added as a second admin because nobody thought to, is exactly this setup.
Consent has a required firing order, and nothing in the product enforces it for you. Every web container ships a default trigger built for exactly one job. Google's documentation is specific: "The Consent Initialization trigger will always fire before all other tags, including any Initialization triggers," and it exists so that "consent settings are honored before any other triggers fire" (Page view triggers, Tag Manager Help). Get that trigger wrong, or leave a tag out of its consent settings, and the failure runs in one of two directions depending on which mode is configured: basic consent mode sends nothing at all until a visitor actively consents, or advanced mode defaults to a consented state everywhere except the regions Google requires a stricter default for (About consent mode, Tag Manager Help). One direction quietly under-measures. The other sends data before consent exists, which stops being a measurement question and becomes a compliance one. Neither shows up as an error message. Both need someone checking the container against this specific rule on a recurring basis, not once during the original setup.
The step built to catch mistakes before they go live is optional, and it is the first thing to get skipped. Preview mode exists so that anyone can "test a container configuration before it is published" and confirm every tag fires as expected, connected live to Tag Assistant so the fire status of each tag is visible before the change is real (Preview and debug containers, Tag Manager Help). Nothing in Tag Manager requires this step before publishing. It takes real time against a live site to run properly, checking every page the change touches, not just the one it was built for. Fitting a tracking change between two campaign tasks is precisely the condition where that time does not get spent, and a change ships that looks fine until a conversion number moves for reasons nobody can explain three weeks later.

None of these three failures need a bad marketer. They need a good one, doing a job that was never structured to be anyone's main responsibility, on a system that Google itself documents as requiring ongoing, deliberate attention to avoid each of them. Even a container that avoids all three still sits on top of the industry-wide baseline: 15-30% of conversions go consistently uncaptured across setups that are technically working as intended. A side-task container adds its own losses on top of that number, it does not start from zero.
What good looks like
The fix is not a better GTM course. It is moving tracking off the list of things a marketer fits in around their real job and onto someone whose actual job is exactly this: watching admin access, verifying consent order after every banner or region change, and running Preview on every change before it ships, as a matter of routine rather than memory.
That is what Archon Signal is built to do for an agency: a specialist who owns the container the way the setup itself demands, rather than one more task queued behind the next campaign brief. The agency keeps the account, the client relationship, and the reporting. The specific, sourced failure modes above stop being background risk. It is a different decision than hiring a full-time data person in-house, and a cheaper one for most agencies.

FAQ
Isn't Google Tag Manager built for marketers to use without a developer?
Yes, and that part works. The interface does not require code for most tag types. What it does not solve is ownership: who is the second admin, who checks consent order after a banner update, who runs Preview before every publish. Those are process questions, not interface ones, and they are the three places setups documented above actually fail.
We already have someone who set up GTM, why change anything?
Ask who the second admin is. If the honest answer is nobody, or "I'd have to check," that is the exact scenario Google's own account management guidance warns creates lockout risk. It costs nothing to check today and a lot to discover it after that person has left.
Doesn't this just mean hiring a full-time tracking person?
No. It means the container has a specialist attached to it, not that the agency needs a headcount. An external specialist covers the ongoing checks (admin access, consent order, pre-publish testing) without becoming a fixed cost on top of what marketing already spends its time on.
What actually breaks first when nobody owns the container?
In practice it is consent ordering. It fails silently in both directions, so a banner update or a new region requirement can sit wrong for months before a conversion count drop or a compliance question forces someone to look.
Is this only a problem for agencies managing many client accounts?
It shows up faster there, because more containers means more single points of failure across more admins who rotate off accounts. A single in-house team hits the same three failure modes, just on a longer timeline.
If any of these three failure modes sound familiar in your own containers, a free tracking audit will tell you exactly which ones apply. Request a free tracking audit.