Container audits · conversion monitoring · governed changes

Your tag manager, on speaking terms.

For marketing leaders whose Google Tag Manager container is a black box run through someone else’s ticket queue. Project5 audits what is in there, tells you the morning a conversion tag stops firing, and makes every change reversible.

The interface is a sentence — audit this container, did checkout events drop last week? — and 38 governed tools do the work, every write fenced to containers you name.

Surface
GTM + GA4
Tools
38, governed
Audit
7 categories, scored
Writes
Allowlist-fenced
Rollback
One sentence

The problem

The container nobody owns is charging you rent.

GTM is where marketing intent meets engineering reality, and in most companies nobody owns that seam. The CMO can’t read the container, the devs don’t care what’s in it, and the agency that set it up left eighteen months ago. Five bills arrive in the post.

Container rot
Zombie pixels from dead campaigns and departed agencies. Nobody deletes them, because nobody knows what’s safe to delete. Your page speed pays the tax on every visit.
Silent data death
A form redesign breaks the conversion tag. Nobody notices for six weeks. A quarter of decisions get made on the corpse of that data. This is the expensive one.
Zero change visibility
Someone publishes, something breaks, and there is no journal anyone can read to find out what happened or when.
Compliance exposure
Pixels firing before consent, and a disclosure list that stopped matching what the container actually loads two agencies ago.
The ticket queue
“Add the LinkedIn tag” takes a sprint. The first and most expensive week of campaign spend goes out unmeasured.

What you get

Three things nobody’s GTM setup has today.

Not a dashboard to log into. Three deliverables that land where you already work, each one aimed at a bill above.

01 / The Audit

A scored report, in seconds.

Seven categories against any live container — zombie tags, duplicate triggers, consent posture, performance weight, naming rot, version hygiene, orphaned entities. Client-ready, ranked fixes first, written for the person who approves the work rather than the person who built it.


KillsContainer rot, and the page-speed tax it has been quietly charging you.

02 / The Health Check

Proof your conversions still fire.

Daily verification, backed by the GA4 API, that your key events are still breathing. A flatline or a step-change surfaces as a finding the next morning — not as a gap somebody notices at quarter close.


KillsSilent data death, in a day instead of a quarter.

03 / Drift Watch

The changelog you never had.

Every readable container snapshotted on a schedule and diffed against the last known good. Changes arrive in plain English — tag modified: firing triggers changed — so “who changed what, and when” stops being archaeology.


KillsZero change visibility, including the changes you made yourself.

Request an audit

Read-only. Name a container, get the scored report back.

How it works

You ask. Claude drives.

Project5 is an MCP server, so there is no dashboard to learn and no console to log into. The interface is the conversation you are already having.

  1. You ask, in a sentence.

    • Audit this container.
    • Add the LinkedIn conversion tag and publish.
    • Did checkout events drop last week?

    No syntax to get right, no permissions dance, no ticket.

  2. Claude drives the tools.

    Claude Code holds Project5’s 38 governed tools and picks the ones the job needs — reading the container, writing the entity, publishing the version, reading GA4 back. You see the reasoning as it goes.

  3. Every change is versioned.

    Mutations land as container versions with a journal entry attached. There is finally an answer to “who changed what, and when” that isn’t archaeology.

  4. Rollback is a sentence.

    Roll back to the version before that. The publish reverses, and the reversal is journaled too. That insurance is what makes delegating the container safe in the first place.

  5. Writes are fenced.

    An allowlist names the containers automation may touch. Anything outside it fails closed — not a warning to click past, a refusal. Read access and write access are not the same grant.

Proof

We point it at ourselves first.

We don’t sell tag hygiene we haven’t lived. Everything on this list is visible from where you are standing:

  • This site is instrumented by Project5 itself. Its GTM container was created by the product, not by hand in the GTM console.
  • The consent stack you just met is the one we’d ship you. Consent Mode v2 denied by default in the document head, zero off-origin requests before you say yes, Global Privacy Control honoured, Accept and Decline given equal weight, and a withdrawal that purges the cookies rather than merely remembering you asked.
  • Drift watch runs on our own containers on a daily schedule — the same routine, on the same code path, that we would point at yours.

The product caught its owner

On 2026-08-08, drift watch read a GA4 tag we had created hours earlier and reported it back to us: added — fires on all pages, no consent settings declared. We declared them and republished. The next run narrated that fix too. We would rather show you that than a testimonial.

The loop is verified live, end to end:

tag authored published fired in a real browser numbers read back via API

87 /100 B

7 categories
15 findings
GTM-W44B54PP

The deliverable

See what lands in your inbox.

A scored report with the ranked fixes first, written for the person who has to approve the work rather than the person who built the container. The one below is real output from the audit tool, run against a demonstration container we seeded with the rot we typically find — not a mock-up, and not a client’s data.

See a sample audit

Start here

Start with the audit.

Send one email naming the container you want read. You get the scored report back — the same one linked above, against your own tags. Read-only: nothing is written to your container unless you later name it on the allowlist yourself.

No form to fill in, no call to book, and no third-party processor collecting your details on the way — an email is the whole funnel.