SEO Tool Access and Tracking Setup
Set up SEO access, tracking and data sources before an audit, verify every permission, test data integrity, and hand over a reliable measurement baseline.
Access, tracking and data sources setup is the measurement gate for the SEO engagement. It proves the team can retrieve audit evidence, distinguish reliable data from contaminated data and repeat the baseline later.
Phase: P1 · Stage A — Understand. Timebox: two to five business days, with requests sent before kickoff wherever possible. Owner: the SEO lead is accountable; the client project owner coordinates invitations, while analytics, engineering, ecommerce and CRM owners verify their systems.
Why this phase comes here
The preceding discovery and goals phase establishes the site, markets, business outcomes, stakeholders and questions the engagement must answer. This phase converts that scope into observable systems. If discovery says qualified demo requests matter, the tracking setup must identify the event and the CRM stage that represent one. If discovery names the United Kingdom and United States as separate markets, the data setup must preserve country, timezone and currency context rather than blending them.
It comes before the audit because you cannot audit what you cannot measure. A crawler can reveal status codes and links, but not which queries lost impressions, which pages generated qualified revenue or whether a conversion fired twice. Those facts live in the client’s search, analytics, log and business systems.
Starting the audit while access is still “in progress” creates delay at the point where first-party evidence should confirm early hypotheses. Analysts may fill the gap with assumptions and preserve those assumptions in the baseline.
Running this phase later also corrupts comparison. If tracking is repaired halfway through, “before” and “after” use different measurement systems. Fix integrity, mark the discontinuity, then capture the baseline.
Inputs and outputs
Inputs tell the owner what must be available before verification. Outputs are the contract with the technical baseline audit: the next owner should not need to chase credentials or guess whether a zero means “none” or “not measured.”
Phase inputs and outputs
| Direction | Item | Owner | Acceptance condition |
|---|---|---|---|
| Input | Discovery record | SEO lead | Names canonical domains, subdomains, markets, business outcomes, key conversions, known migrations and stakeholders. |
| Input | System owner map | Client project owner | Names an administrator for search consoles, analytics, tag manager, CMS, hosting/CDN, logs, ecommerce or CRM, and existing SEO tools. |
| Input | Approved access model | Security or IT owner | Specifies named accounts, least-privilege roles, expiry rules, credential-sharing policy and approval path. |
| Output | Verified access register | SEO lead | Every required system has property, role, holder, verifier, verification date, evidence and status recorded. |
| Output | Data integrity report | Analytics owner | Duplicate tags, bots, cross-domain journeys, conversions, timezone, currency and sampling are passed, failed or qualified with evidence. |
| Output | AmICited configuration | SEO lead | Correct domain, organic sources, countries, prompt set, schedules, tags and competitors are connected and return real data. |
| Output | Baseline pack | SEO lead | Contains 28 complete days where available, comparison window, exclusions, known breaks and capture timestamp. |
| Output | Exception log | Client project owner | Every unresolved gap has impact, workaround, named owner and due date; blocking gaps are clearly marked. |
The access and tracking checklist
Every item below states what to do, why it matters, how to do it, which tool is involved and the evidence that closes it. “Requested” is a workflow state, never a done-when condition.
1. Establish the canonical scope and access register
What to do: Create one row for every property and system in scope. Include the domain property and all relevant URL-prefix variants in Google Search Console; Bing Webmaster Tools; analytics; tag manager; CMS; hosting and CDN; raw or processed server logs; ecommerce or CRM backend; consent platform; and existing rank, crawl or reporting tools.
Why it matters: A vague row labeled “GSC access” can hide a missing protocol, host, shop or international subdomain.
How and tool: Start from discovery’s domain and market map. Record system, account/property identifier, required role, administrator, intended user, request date and reason. Use named company accounts and the least privilege that can retrieve the required evidence; do not exchange shared passwords in the register.
Done when: Every in-scope system has an administrator and verifier, every property is named exactly, and no critical row remains merely “to be identified.”
2. Verify Google Search Console property coverage
What to do: Confirm the verified domain property and inspect every operationally relevant URL-prefix property.
Why it matters: Access to https://www.example.com/ does not prove visibility into https://example.com/ or a shop subdomain. The wrong variant can make pages and queries appear absent.
How and tool: In Google Search Console, open Performance, select the agreed recent date range, retrieve query and page rows, inspect Indexing and Sitemaps, and note the property identifier. Compare the property’s scope with the discovery domain map. In AmICited, connect the matching source from Data Sources and confirm that Google Search Queries returns recent rows.
Done when: The register contains the domain property, all useful variants, role, report tested, row/date evidence and verification date. A report with no rows is investigated rather than accepted as proof.
3. Verify Bing Webmaster Tools independently
What to do: Confirm the correct site in Bing Webmaster Tools and retrieve search and crawl data.
Why it matters: Seeing a site in an account does not prove the connected identity can read current Bing search and crawl data.
How and tool: Open the selected site, retrieve a recent search-performance report and inspect crawl information. Connect Bing in AmICited Data Sources, then open Bing Search Performance and check that clicks, impressions, click-through rate and average position have a real reporting period.
Done when: The expected site is named in the register and both the provider report and AmICited report return plausible dates or a documented legitimate no-data state.
4. Validate analytics and tag-manager collection
What to do: Test pageviews, consent behavior, key events, duplicate firing, referral attribution and cross-domain journeys.
Why it matters: Two container installations can double events; a payment domain can restart sessions; consent changes can create a step change unrelated to SEO.
How and tool: Use the analytics real-time or debug view and the tag manager’s preview mode. Run a controlled session with a unique campaign marker through one key journey. Record each expected event once, its parameters, source/medium, landing page, session continuity and consent state. Compare tag-manager installation with hard-coded tags and plugins in the CMS.
Done when: One controlled action produces one expected event, no critical tag fires twice, cross-domain navigation retains the session, and consent behavior matches the approved policy. Save the test timestamp and event evidence.
5. Reconcile conversions with the system of record
What to do: Map analytics conversions to orders, leads or qualified stages in the ecommerce platform or CRM. A system of record is the authoritative backend used to confirm that the business event actually occurred.
Why it matters: A thank-you-page view is not automatically an order, nor a form submission a qualified lead. Silent event failure can reverse apparent landing-page performance.
How and tool: Select at least three known test or recent records where permitted, trace their identifiers and timestamps through analytics and the backend, and document cancellations, refunds, spam and offline changes. Store only the minimum identifier needed.
Done when: Every primary conversion has an owner, trigger, backend counterpart and reconciliation result. Any unexplained count difference beyond the thresholds below blocks use of conversion rates as a baseline.
6. Confirm CMS, hosting, CDN and log access
What to do: Verify read access to publishing configuration, redirects, caching, deployments, edge rules and server request logs. Server logs are records produced when clients—including search and AI crawlers—request resources from the infrastructure.
Why it matters: The audit may need to distinguish a content defect from a template, redirect, firewall or edge-cache rule. Crawl analysis cannot show what Googlebot requested historically if logs become necessary later.
How and tool: In each administrative system, open one harmless configuration screen without changing it. For logs, retrieve a bounded 24-hour sample containing timestamp, requested path, response status and user agent; document retention, timezone and redaction. Confirm whether origin and CDN logs overlap or represent different request layers.
Done when: The team can locate the active deployment and redirect/caching controls, and can retrieve a parseable log sample—or the exception log records why logs do not exist, the analytical limitation and the approved alternative.
7. Inventory existing SEO tools and historical breaks
What to do: List rank trackers, crawlers, dashboards, warehouses and previous agency workspaces, including their configured domains, markets and data retention.
Why it matters: Existing tools may contain useful history, but combining unlike “visibility,” “rank” or “conversion” definitions manufactures a trend no single system measured.
How and tool: Pull one representative report from each tool. Record metric definition, country/device, keyword or prompt set, frequency, ownership, export capability and known migration or tracking dates.
Done when: Each retained source has a documented use and definition; redundant or inaccessible sources are marked as such, and known discontinuities appear in the baseline notes.
8. Connect and prove AmICited data sources
What to do: Add the canonical domain, connect Google Search Console and Bing Webmaster Tools, and configure every applicable organic, paid and ecommerce source.
Why it matters: A connected badge proves authorization, not a complete import. Reports should reveal whether the source is current, importing, empty, failed or requires reconnection before anyone interprets its numbers.
How and tool: Open https://app.amicited.com/data-sources, connect the correct accounts, read each status ribbon and open its report. The Data Sources
guide explains which reports each group powers. For ecommerce reporting, review Data Health
so measured purchase costs are not confused with assumed margin.
Done when: Every required card shows the intended property and a healthy current state, and one real downstream report has been opened per connection. Where a provider legitimately has no data, record why and what report proved the empty state.
9. Configure prompt tracking, countries, tags and competitors
What to do: Establish a small, representative baseline of buyer questions, markets and competitive brands before scaling the library.
Why it matters: Prompt results vary by engine and country. An unlabeled mixture of brand, category and use-case prompts produces an average nobody can interpret, while the wrong competitors distort strategic comparisons.
How and tool: Open https://app.amicited.com/prompts. Follow the tutorials to add prompts by pasting a list
, choose which AI engines to track
and schedule prompt tracking
. Assign one country and at least one purpose tag to every prompt. Then open https://app.amicited.com/competitors and manage your tracked competitors list
, separating commercial rivals from publishers, marketplaces and other cited sources.
Done when: Every baseline prompt has a country, tag, provider set and schedule; at least one run completes; each competitor has a reason for inclusion; and the owner can filter data by AI model, country, tag and date without producing an unexplained empty view.
10. Freeze the baseline and sign the handoff
What to do: Capture the agreed measurement window, exclusions, integrity results and access status in one dated package.
Why it matters: Live dashboards change. Without a frozen definition, later teams cannot reproduce the baseline or tell whether a movement reflects performance, configuration or repaired tracking.
How and tool: Use 28 complete days where the system supports it, add the preceding 28 complete days for context, and exclude partial current days. Export or capture source summaries, record timezone/currency, and link each number to its source and filter state.
Done when: The SEO lead and analytics owner approve the same baseline pack, all critical checks are green, and every exception has an impact, workaround, owner and due date.
Tools in AmICited
These product steps verify the connections and establish the monitored market. The tutorials hold interface-level instructions; this phase records why each action belongs in the engagement and what evidence must return.
- Open
https://app.amicited.com/data-sourcesto add and verify connections. Use Data Sources to interpret groups and sync states. - Open
https://app.amicited.com/reports/google-search/queriesand retrieve real query rows. Use Google Search Queries to interpret clicks, impressions, click-through rate and position. - Open
https://app.amicited.com/reports/bing-webmastersand verify the second search source. Use Bing Search Performance for the report contract. - Open
https://app.amicited.com/promptsto configure countries, tags, providers and schedules. Use Prompt Tracking for the capability overview and the academy tutorials for the exact controls. - Open
https://app.amicited.com/competitorsto review detected and manually tracked brands. Use Competitor Analysis to understand how the competitive set feeds comparisons. - Open
https://app.amicited.com/reports/data-healthfor commerce engagements and use Data Health to qualify measured versus assumed purchase-cost coverage. This does not replace the analytics integrity tests above; it answers a narrower margin-quality question.
Decision rules
Thresholds are operational gates, not universal laws. They tell this engagement when a number is safe to baseline, when it needs a qualification and when work must stop.
Data and access decision rules
| Test | Green | Bad looks like | Decision |
|---|---|---|---|
| Critical access | Real report retrieved from every critical system | Still requested, wrong property, login-only proof, or report cannot be exported/read | Escalate after 1 business day; block dependent audit conclusions. |
| Tag duplication | Each controlled action fires once | Any duplicate primary conversion or more than 5% duplicate page/event identifiers in the test sample | Repair and retest before baselining analytics. |
| Conversion coverage | Every primary conversion appears in analytics and its backend | A primary conversion is absent, or analytics-to-backend variance exceeds 10% without an explained cause | Do not use conversion rate as a baseline; reconcile or qualify. |
| Cross-domain continuity | One test journey remains one session with the expected source | Payment, booking, login or app domain becomes a self-referral or starts a new session | Correct domain/linker configuration and repeat the test. |
| Bots and internal traffic | Known bots, monitors, staff and test traffic are identifiable and excluded from decision views | Any known automated test appears as a user conversion, or suspicious traffic exceeds 10% of sessions in a material segment | Segment and investigate; never delete raw evidence to make the report look clean. |
| Timezone and currency | Reporting timezone and currency are recorded and compatible with the business close | Any unexplained mismatch between analytics, ads, ecommerce or CRM | Normalize in the baseline or keep sources separate with explicit labels. |
| Sampling and thresholds | Report declares no sampling/thresholding, or limitation is recorded | A sampled or thresholded view is treated as an exact total | Reduce range, use an export/API/warehouse where available, or label the figure directional. |
| Source freshness | Latest complete date matches the provider's expected delay | Unexpected gap of 3 or more complete days, failed import or reconnect-required state | Diagnose connection before using trend data. |
| Prompt configuration | 100% of baseline prompts have country, tag, providers and schedule | Any unscoped prompt or mixed-market group used for the headline baseline | Fix metadata before first baseline export. |
| Commerce cost coverage | 100% measured for revenue included in margin decisions | Any material revenue relies on an assumed purchase cost without disclosure | Complete costs or label profit and margin as assumption-based. |
Zero traffic is not automatically bad. A new property, a low-volume market or a genuinely unused channel can produce zero. The failure is an unexplained zero: a number accepted without checking scope, collection, date range and source status.
Deliverable: the access and data-readiness pack
Hand over a spreadsheet or controlled table plus a short baseline memo. The access register needs these columns: system; account/property; scope; required role; access holder; administrator; requested date; verified date; report tested; evidence location; status; expiry; and notes. Use Not requested, Requested, Granted, Verified, Failed and Not applicable as distinct states.
The data-integrity tab records each test, expected and observed behavior, sample window, result, owner and remediation date. The baseline memo names the windows, timezone, currency, filters, conversion definitions, exclusions, discontinuities and reports used. Do not include passwords, recovery codes, personal data or reusable access tokens.
The package is accepted when another analyst can reproduce the reports, understand every qualification and begin without requesting critical access.
What goes wrong
- The wrong Search Console variant is verified. The analyst receives a URL-prefix property, sees plausible data and misses a subdomain or protocol. Prevent it by reconciling every property with the discovery domain map and preferring the domain property for complete coverage.
- Conversion tracking has been silently broken for months. A dashboard still shows sessions, so nobody tests the business event. Catch it with a controlled conversion and backend reconciliation before computing any conversion baseline.
- Server logs are requested only when crawl analysis needs them. Retention may have already removed the useful window, or infrastructure may require a security review. Identify the owner, fields and retention now, even if log analysis occurs in the next phase.
- Half-granted access is treated as complete. A login works, but the required property, report, export or container does not. Close only against a real report.
- A connection badge substitutes for a data check. OAuth succeeds while the wrong property, expired scope or stalled import feeds the report. Open the downstream report and record its latest complete date.
- Markets and currencies are blended. Revenue is summed across currencies or country-specific prompt answers are averaged together. Preserve the source units and label every baseline slice.
- Historical dashboards are trusted without definitions. A previous agency’s “visibility” score may use different keywords, devices or competitors. Preserve useful history, but do not splice incomparable series.
- Permissions are broader than the task requires. Administrator access is handed out because it is convenient. Begin with report-reading permissions and elevate only for an approved implementation step.
Handoff to the technical baseline audit
The next owner receives the verified access register, data-integrity report, AmICited source status, baseline memo, system owner map, log sample and exception log. The technical baseline audit can then compare crawl and indexation evidence with search demand, crawler requests and business outcomes.
The handoff is green when all critical systems are verified, primary conversions pass controlled tests, source freshness is understood and the baseline filters can be reproduced. A non-critical exception may travel forward only when its impact, workaround, owner and due date are explicit. Missing server logs make crawler-history conclusions provisional. A wrong Search Console property, broken primary conversion or unexplained duplicate tracking blocks the dependent part of the audit.
FAQ
Frequently asked questions
How long should access and tracking setup take?
Is read-only access enough for an SEO audit?
What if analytics has been broken for months?
Can the audit start without server logs?
Which Google Search Console property should be connected?
More tutorials in this section
Ready to put it into practice?
Free check · 7-day trial · no credit card