Documentation

Everything you need to get ConsentMonitor working for your sites.

Getting started

Four steps from sign-up to your first automated check.

1

Sign up

Create your account at consentmonitor.com. Magic link or Google — no password needed.

2

Create an organization

An organization is your workspace — it groups your domains, team members, and billing. You can belong to multiple organizations, which is useful if you manage several clients.

3

Add a domain

Add the root domain you want to monitor (e.g. example.com). If you signed up with a business email, ConsentMonitor may suggest it automatically. You can always add it manually.

4

Add a page

A page is a specific URL to check — a homepage, a checkout, a product listing. Give it a name and paste the full URL (https://example.com/checkout). That's what gets monitored.

How it works

ConsentMonitor visits your pages using a headless browser — no cookies, no session, exactly like a first-time visitor. Nothing is installed on your site. Checks run automatically at your plan's frequency.

Each check follows five steps, in order:

1
CMP detected and loaded — We check whether a Consent Management Platform is present and initialized before any user interaction.
2
Consent banner was visible — The banner must appear before the user has done anything. Hidden or delayed banners fail here.
3
Tracker requests before consent — We capture all third-party network requests fired before the user made any consent decision. Any non-essential tracker firing here is a violation.
4
Cookies set before consent — Non-functional cookies dropped before consent was granted are flagged. This includes HttpOnly cookies set server-side — your CMP can't remove those, which is an extra risk.
5
Rejection was respected — We click "Reject" in the banner, then check whether any tracking requests or cookies appear afterwards. If they do, that's a direct violation.

Check results

Each check produces a pass or fail verdict, with a breakdown of what was found.

The six summary cards at the top give you a quick read:

CMP Which Consent Management Platform was detected. "Unknown" means something was found but not matched to our vendor library — it's still detected, just unclassified.
Consent banner Whether the banner was visible before any user interaction. If it wasn't shown, all the steps below are moot.
Requests before consent Count of non-essential third-party network requests that fired before the user chose. These are your tracker violations.
Cookies before consent Non-functional cookies dropped before consent. Includes server-set HttpOnly cookies, flagged separately because your CMP can't touch them.
Cookies after reject Cookies that were set or persisted after the user clicked Reject. Direct violations — these are what regulators look for.
Requests after reject Third-party requests that continued after rejection. These indicate trackers that aren't properly gated behind your CMP.

Below the cards, violations are grouped by vendor — requests and cookies in separate sections. Expand a vendor to see which exact hostnames fired and when. At the bottom of a failed check, ConsentMonitor generates a suggested remediation your analytics or dev team can act on directly.

A screenshot is taken at check time so you can confirm the banner was actually visible when the check ran.

Cookie inventory

The Cookies tab (per domain) aggregates every cookie seen across all checks — deduplicated, so each unique cookie name appears once regardless of how many times it was observed.

You can filter by vendor, category, or state (before consent / after reject / clean). Advertising and measurement cookies set before consent are your highest-priority items — the ones regulators focus on.

Use the Download list button to export as CSV. The export includes name, vendor, category, state, typical duration, and whether it's HttpOnly. That's enough to include in a compliance report, share with your CMP vendor, or drop into a DPIA.

Alerts & pausing checks

When a check finds violations, organization members receive an email alert with a direct link to the check result.

To stop receiving alerts for a specific page, pause it from the Pages list. Pausing stops both the automated checks and the alerts — the page won't be monitored until you resume it. Useful during a deployment when you know things are temporarily broken and don't want noise.

You can resume a page at any time. Historical check data is preserved either way.

How many pages do you need?

You don't need to track every URL on your site. Consent issues surface most on landing pages — the URLs where visitors arrive for the first time and see the consent banner. Those are the pages that matter for compliance.

The quickest way to get that list: open Google Analytics 4 → Reports → Engagement → Landing page, sort by sessions. The top 10–20 typically cover the vast majority of your traffic and give you solid coverage without going overboard.

Not sure where to start? Email [email protected] and we'll help you put the list together.

Custom volumes & frequencies

Standard plans run checks weekly (Free), daily (paid tiers), or hourly (Enterprise). Page limits follow the same tiers — Free comes with a handful, paid plans scale up from there.

If you're managing a large number of pages across multiple client domains, or need a frequency that doesn't fit the standard options, we can put together something custom. Agencies monitoring dozens of sites tend to need this kind of arrangement.

Get a quote

Check errors

A check error means ConsentMonitor couldn't complete the check at all — not that a violation was found. These are infrastructure-level failures, not compliance results.

Page load failed

The page was unreachable or timed out. Common causes: the URL changed, the page requires authentication, or a firewall is blocking our checker's IP range.

If you suspect a firewall issue, contact [email protected] — we can provide the IP range to allowlist so checks go through cleanly.

Browser crashed

An internal error occurred during the check. This is usually transient — the next scheduled check will likely succeed on its own.

If it keeps failing on the same page, send the check ID (visible at the top of the check detail page) to [email protected] and we'll dig in.