Signature Framework · #3

The Audit-Proof Funnel

The standard I hold a funnel to: for any contact, prove the consent basis, the acquisition source, and the measurement lineage from the same stored records.

Here is the standard I hold a marketing funnel to: for any contact and any number in it, I can prove three things at once. The basis on which we were allowed to message that contact. The source that acquired them. And the measurement lineage behind whatever figure we reported about them. When all three resolve to a stored record instead of a belief, the funnel is audit-proof. It survives the two audits that come for every marketing program, and almost never at the same time.

The first audit is a compliance audit. A regulator, a carrier, or opposing counsel asks a narrow question: show me the consent basis for every message this contact received. The second is an ROI audit. A CFO, a board, or a new CMO asks a different one: show me how this campaign's spend produced this reported conversion. Most programs can answer one of these well and improvise the other, because the two answers live in different tools owned by different teams. The audit-proof funnel is the one where the same underlying records answer both, and don't contradict each other when you lay them side by side.

This is the capstone of a set. I've written before about the Consent Ledger, the register that makes the consent basis provable, and about the UTM naming convention that makes the acquisition source provable. Each stands on its own. This piece is about the spine that joins them, plus the third ledger most teams don't keep at all: the one that makes the number provable. The framework, the integration model, and the table below are my synthesis. The facts they're built on are Google's and the law's, and I've cited each to its primary source and kept my judgment marked as opinion, separate from the statute and the vendor documentation.

The three provable facts

A funnel is a pipe with three governed properties, not one. Each property is provable by a different record, keyed on a different thing, and owned, in most orgs, by a different team.

Consent basis: keyed on the contact. Can you name the legal basis to message this person on this channel, and produce the proof? Marketing texts run on the TCPA, which requires prior express written consent: a signed, number-specific, clearly-disclosed authorization (47 CFR § 64.1200(f)). Commercial email runs on CAN-SPAM (15 U.S.C. § 7704). For EU subjects, GDPR asks you not whether you believe you had consent but to demonstrate it (Art. 7). The Consent Ledger is the artifact that answers this column; I won't re-derive it here.

Acquisition source: keyed on the campaign. Can you say which campaign and channel brought this contact in, and will the analytics agree with you? GA4 doesn't report your medium string to stakeholders. It runs every session through a fixed rule set and assigns a channel, and traffic whose parameters match no rule falls to "Unassigned," which Google defines as "the value Analytics uses when there are no other channel rules that match the event data" (GA4 Help, Default channel group, accessed 2026-08-27). Governed UTM naming is what keeps a contact's origin reconstructable instead of silently miscredited. That's the UTM convention's column.

Measurement integrity: keyed on the number. Can you reconstruct the reported figure: how much of it was directly observed, how credit was assigned, and whether the underlying data still exists to defend it? This is the column almost no one keeps a record for, and it's the one an ROI audit lives in. The rest of this paper is mostly about it, because it's the newest of the three and the least owned.

What the measurement layer actually requires

This is the evidence section. Everything here is , cited to Google's own documentation and dated, because the platform behavior moves and a reader deserves to know how fresh the claim is. Current as of 2026-08-27.

Consent state changes what gets measured. Google Consent Mode adjusts how tags behave based on a user's consent, communicated through four signals: ad_storage and analytics_storage gate whether identifiers such as cookies or device IDs may be read or written; ad_user_data and ad_personalization, both added in Consent Mode v2, instruct Google on how already-collected data may be used (Google for Developers, Consent mode overview, accessed 2026-08-27). When storage consent is denied, tags "send measurements without cookies" for modeling rather than reading or writing identifiers (same, accessed 2026-08-27).

Denied consent forces modeling. When users grant analytics consent, GA4 records observed data tied to an identifier. When they decline, events "are not associated with a persistent user identifier," and GA4 fills the gap with modeled data. It "applies machine learning to estimate the behavior of those users based on the behavior of similar users who do accept analytics cookies" (GA4 Help, Behavioral modeling for consent mode, accessed 2026-08-27). This is the causal link that makes the whole funnel one system rather than three: a decision at the consent layer changes the composition of the number at the measurement layer.

The modeling has thresholds, and they're Google's. Behavioral modeling isn't automatic. A property must collect at least 1,000 events per day with analytics_storage='denied' for at least 7 days, and have at least 1,000 daily users sending events with analytics_storage='granted' for at least 7 of the previous 28 days, and meeting the thresholds "doesn't guarantee eligibility" (GA4 Help, Behavioral modeling for consent mode, accessed 2026-08-27). On the ads side, consent mode conversion modeling needs "a daily ad click threshold of 700 ad clicks over a 7 day period, per country and domain grouping," and Google notes consented users "are typically 2–5x more likely to convert than unconsented users" (Google Ads Help, About consent mode modeling, accessed 2026-08-27). These numbers are Google-set and have changed historically; treat them as current-as-dated, not permanent.

Reported conversions can be a blend. GA4 uses modeling to "estimate online key events that can't be observed directly," and in consent-mode markets "key events are modeled for unconsented users." Reports "attribute key event events across channels based on a mix of observed data where possible and modeled data where necessary" (GA4 Help, About modeled key events, accessed 2026-08-27). In the standard GA4 interface you generally can't separate the observed portion of a number from the modeled portion; the report hands you the blend. The BigQuery export exposes some modeling flags, but the everyday dashboard a stakeholder reads does not, which is exactly why a lineage record has to carry that composition itself rather than expecting the UI to surface it.

The data has an expiry. GA4 retention controls set how long user-level and event-level data is kept before automatic deletion: user-level data is held 2 or 14 months; Google-signals data is capped at 26 months regardless of settings (GA4 Help, Data retention, accessed 2026-08-27). A number you can't reconstruct because the underlying data aged out is not a defensible number, whatever it said the day you screenshotted it.

Credit assignment is a chosen model, not a fact of nature. GA4 attribution is "assigning credit for important user actions to different ads, clicks, and factors along the user's path," across models including data-driven attribution and last-click variants; data-driven attribution can reattribute conversions "for up to 7 days after the conversion," and direct visits are excluded from credit unless the whole path is direct (GA4 Help, Get started with attribution, accessed 2026-08-27). Two teams running the same funnel under different attribution models will report different numbers and both be correct. The lineage is what tells you which one you were looking at.

Measurement you can audit is not a novel idea I'm importing. The industry already has named requirements for it: the Media Rating Council, a non-profit set up in 1963 at the request of Congress, accredits measurement products only when a service discloses its methodology, meets minimum standards, and submits to independent audit (MRC, Audit and Accreditation Process, accessed 2026-08-27). I'm not claiming any funnel is MRC-accredited. I'm pointing out that disclose the method and prove the number is an established professional posture, and the audit-proof funnel applies it to the operator's own pipe, one contact and one number at a time.

The seam where funnels fail

The failure is almost never inside one of these systems. Each one, run by competent people, is usually fine on its own terms. The failure is at the seam, and the seam has no owner.

Consent lives with legal, compliance, or the lifecycle team. They can prove the basis to message, but they don't administer the analytics property or the ad accounts. Attribution lives with analytics or growth. They own the UTMs and the GA4 configuration, but they tend to treat consent as someone else's checkbox and rarely reconcile the modeled portion of their numbers back to consent state. And measurement integrity (the retention windows, the attribution model, the observed-versus-modeled mix) lives with whoever administers GA4 and Ads, which is often no one senior, running on defaults nobody signed off on.

So you get three internally tidy systems that cannot corroborate each other. That's not a smaller version of an audit-proof funnel. It's the same as having none, because the moment an auditor of either kind walks from a dollar of spend toward a consented, sourced, measured outcome, the walk breaks at a handoff no one is accountable for. The consent state and the attribution number are causally linked (denied consent produces modeled conversions, per the fact above), yet they're governed by different people, in different tools, with no shared record between them. A demand letter tests one side of that seam. A CFO's ROI review tests the other. The program that survives both is the one where a single spine reconciles them.

The integration model

The three ledgers reconcile on one join. Framework #1 keys on the contact. Framework #2 keys on the campaign. Measurement integrity keys on the number. The claim of this whole piece is that these three keys have to join: the same contact whose consent sits in the ledger is the contact whose acquisition source is UTM-governed and whose conversion is (observed or modeled) in the attribution report. When the join holds, either auditor can walk from spend to a consented, sourced, measured outcome and back. When it doesn't, you have three systems that can't vouch for each other.

Measurement lineage is the third ledger, and it's built on the same discipline as the first. The Consent Ledger's insight was to turn an obligation into a maintainable record with an audit reference, a pointer to the stored proof, so the row is provable rather than asserted. Measurement lineage extends that pattern to the number. One record per reported metric, naming its retention window (can the underlying data still be produced?), its attribution model and lookback (how was credit assigned?), and its observed-versus-modeled composition (how much of this is machine-estimated because consent was absent?). The audit-reference discipline that made consent provable makes the number provable too.

The design consequence follows, and it's the governance-first thesis of everything I write, pointed at measurement: you cannot buy back observability with worse privacy. Because denied consent forces modeling, the tempting move is to weaken consent capture to reduce the modeled portion of your numbers. Don't. The honest funnel records that a share of the number is modeled, keeps the consent record clean, and reports the composition. The trustworthy number isn't the one with the smallest modeled portion. It's the one whose modeled portion is disclosed instead of hidden.

Here is the spine as one table.

Provable factGoverning frameworkKeyed onPrimary evidence it producesFails at the seam when…
Consent basisConsent Ledger (#1)Contact × channelSigned, number-specific consent record + opt-out logThe analytics or ads team treats consent as someone else's checkbox
Acquisition sourceUTM Naming Convention (#2)Campaign / sourceGA4 channel assignment derived from governed UTMsAn off-spec utm_medium routes spend to Unassigned
Measurement integrityMeasurement lineage (#3, new)The reported numberRetention window + attribution model + observed/modeled mixThe settings are defaults nobody signed off on and the modeled portion goes undisclosed

The rows corroborate each other or they don't. A contact with a clean consent record whose acquisition source landed in Unassigned is not audit-proof: the compliance side holds, the ROI side breaks. A fully sourced campaign whose reported conversions are 60% modeled, on an attribution model no one chose, with the underlying data aged out, is not audit-proof either: the ROI side has a number, but not one you can defend. Audit-proof is all three rows joining on the same contact and the same dollar.

Where to start

You don't buy a platform for this. You reconstruct the join from what you already have: the consent flow, the UTM taxonomy, and the GA4 settings that are already running whether you chose them or not. Pick one live campaign. Pull the consent basis for the contacts it messaged, the channel GA4 assigned its traffic, and the retention, attribution model, and modeled composition behind its reported conversions. Then try to walk the three together for a single contact and a single number.

The reconstruction is the audit. The rows that won't join are the exposure, and they're far cheaper to find now, on a campaign of your choosing, than under a demand letter or in a budget review where someone else picks the campaign.

The spine outlasts the rules

Every fact in this paper is dated because every one of them moves. Consent Mode went from v1 to v2 and added two signals. The FCC's one-to-one consent rule was adopted, rebuilt for across an industry, and vacated inside about thirteen months. Retention defaults and modeling thresholds are Google's to change, and they have. A funnel tuned to any one of these ages as fast as the rule it was tuned to. A funnel built to keep the records (the consent basis, the acquisition source, and the measurement lineage, joined on one spine) survives the churn, because whatever the rule turns out to be, both auditors are still asking the same two questions. Show me the consent. Show me the number. The audit-proof funnel is the one that can open the file and show its work for both.


This is an operational framework and my professional opinion, not legal advice, and reading it does not create a lawyer-client relationship between us. Platform behavior, retention defaults, and modeling thresholds described here are Google's and change over time; the law varies by jurisdiction and by your own facts. Verify anything time-sensitive against the primary sources below before you rely on it, and take questions about your own program to a qualified attorney.

Drafted with AI assistance; researched, edited, and verified by Jennifer Gallo LeBlanc.


Sources

Measurement layer, primary sources, accessed 2026-08-27:

  1. Google for Developers, Consent mode overview (four signals; measurements without cookies). https://developers.google.com/tag-platform/security/concepts/consent-mode
  2. GA4 Help, Behavioral modeling for consent mode (observed vs. modeled; 1,000-event / 1,000-user / 7-day thresholds). https://support.google.com/analytics/answer/11161109
  3. GA4 Help, About modeled key events (modeled conversions; observed-plus-modeled blend). https://support.google.com/analytics/answer/10710245
  4. Google Ads Help, About consent mode modeling (700 ad clicks / 7 days; 2–5x consented conversion rate). https://support.google.com/google-ads/answer/10548233
  5. GA4 Help, [GA4] Data retention (2/14-month user-level; 26-month Google-signals cap). https://support.google.com/analytics/answer/7667196
  6. GA4 Help, Get started with attribution (data-driven and last-click models; 7-day DDA reattribution; direct exclusion). https://support.google.com/analytics/answer/10596866
  7. GA4 Help, [GA4] Default channel group (UTM→channel rules; Unassigned fallback). https://support.google.com/analytics/answer/9756891
  8. Media Rating Council, Audit and Accreditation Process (disclose method; minimum standards; independent audit). https://mediaratingcouncil.org/about-mrc/audit-and-accreditation-process

Consent-basis layer, inherited by reference from The Consent Ledger; primaries cited here:

  1. TCPA implementing rule, prior express written consent (47 CFR § 64.1200(f)). https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200
  2. CAN-SPAM Act, 15 U.S.C. § 7704. https://www.law.cornell.edu/uscode/text/15/7704
  3. GDPR, Article 7 (conditions for consent; the duty to demonstrate). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504

← Back to Insights