For agencies · studios · fractional teams

Twenty-five containers. One short list.

You are accountable for tag managers you do not own, that clients edit behind your back, and that nobody has a history of. You get one digest across the lot, and a write boundary the client controls.

Same service as everywhere else on this site, at fleet scale: $1,500 a month for up to 25 client containers, checked daily, with a change report per client you can forward without an editing pass. One person runs it — me — and the reports go out under your name.

Agency tier
$1,500/mo
Containers
Up to 25
Reports
White-label
Delivery
Run for you
Beyond 25
Fleet, custom

The problem, at your scale

You carry the blame for containers you don’t control.

A single-site team has one container to lose track of. You have one per client, each with its own history of departed contractors, and the client’s own marketing hire has edit access to every one of them.

Changes you didn’t make
A client’s in-house marketer publishes something on a Friday. Attribution goes strange on Monday. GTM logged it — in their console, as raw config, with no alert to either of you — so the first hour of the call goes on establishing that it was not you.
Breakage found by the client
A conversion tag dies on the client’s site and the client is the one who notices. Whatever the cause, that is a renewal conversation you are now having from behind.
Onboarding archaeology
Every new client starts with a week of reading someone else’s container by hand, and you quote the engagement before you know what is in there.
Nothing to show in a quiet month
The retainer line item for “analytics maintenance” is the easiest one on your invoice for a client to question, precisely when it has been working.
The delegation problem
You want automation touching client containers. Your client’s answer to “can an LLM edit our GTM?” is no, and a confirmation dialog is not an answer that changes it.

What you get

Four things that only matter above one client.

Everything in the Monitoring service applies to every container on the account. These are the parts that only start to mean something once there is more than one.

01 / Fleet digest

Exceptions, not a stack of reports.

One run across every container the account can read, one block each. A container with nothing to say is a single line; the one that changed since the last run carries its changelog underneath it.

Twenty-five clients should cost you the thirty seconds it takes to read the exceptions, not twenty-five inboxes to check.


KillsChanges you didn’t make, found before the client finds them.

02 / Forwardable reports

A deliverable you can bill for.

The monthly change report and the audit are written for the person who approves the work, not the person who built the container — which means they leave your hands and go to the client without an editing pass.

An outage arrives priced, against a weekday-adjusted baseline with the assumptions printed. That is the artifact that answers “what did we pay you for this month.”


KillsHaving nothing to show in a quiet month.

03 / Fenced per client

A grant boundary, not a dialog.

An allowlist names exactly which containers automation may write to. Anything outside it fails closed — a refusal, not a warning to click past — and read access is a different grant from write access.

That is the answer that lets a client principal say yes: their container is not on the list until they put it there, and taking it off is one line.


KillsThe delegation problem, at the only layer where it can actually be solved.

The exceptions digest

Most rows are one line. That is the point.

A container with nothing to report gets a heading and nothing else, so the one that changed is the only thing with body text under it. You read the exceptions and close the tab.

The run below is real output over the three containers this service account can read — the site you are on, a demonstration container, and one other. One drifted since the previous run; the other two are quiet, and being quiet takes one line each.

  • It reads every field, not a watchlist. Both sides of the comparison are compared in full, so an edit to a field nobody thought to monitor still appears.
  • Trigger ids come back as names. Names are resolved from both sides, so a trigger deleted in the same change is still named in the line about the tag that used to fire on it.
  • It writes nothing. A drift check is a read, a comparison, and a file it keeps for you.
Drift run · all readable containers 3 containers
  • GTM-WJSNBN47 project5.ai DRIFT

    • Container version: 5 → 6 (published by unknown — GTM exposes no author).
    • Version 6 is named “Lead conversion (ad-ready)”.
    • Tag “GA4 event — generate_lead” ADDED — GA4 event, fires on generate_lead, requires analytics_storage.
    • Trigger “generate_lead” ADDED — custom event.
    • Variable “dlv - product” ADDED — data layer variable.
  • GTM-W44B54PP Project5 Demo CLEAN

  • GTM-N9HGRC5Z Rustfish.com CLEAN

Real output from the drift check over this account’s own three containers. At twenty-five the shape is the same and the reading time barely moves, because quiet containers stay one line.

The part nobody says out loud

Audit the prospect before the pitch.

The container audit is free and it is read-only, which makes it the cheapest piece of pre-pitch research available to you. Walk into the room already knowing what is broken in their measurement, and open with the finding instead of the credentials slide.

  • Seven scored categories, ranked fixes first. Zombie tags, consent posture, duplicate triggers, performance weight, naming, version hygiene, orphaned entities — with a score and a grade at the top.
  • Written for the person who signs. The report is already in the register a prospect’s marketing director reads. It is a leave-behind as it stands.
  • Read-only, always. Nothing is written to any container that is not on the allowlist, so an audit cannot change anything in a container you were given access to look at.
  • The container audit needs their access. It reads the GTM API rather than the public web, so it takes the read grant the prospect gives you; a container cannot be audited from the outside. My pre-consent scanner is a separate tool that does read a public page without a grant, and what fences it is publication rather than capability: I scan any public page for its own owner, or for myself, and I do not publish findings about a site whose owner did not ask me to. How the scanner behaves.
See what the report looks like

Real output from the audit tool, run against a demonstration container.

Straight answers

What is built, and what isn’t yet.

You are about to put client containers on a single-founder service. Here is the part of the pitch that usually gets left out.

Built, running daily
Multi-container drift checking across every container the account can read, plain-English changelogs, GA4-backed conversion-health checking with priced outages, the scored audit, measurement-plan reconciliation, allowlist-fenced writes, and one-sentence rollback.
White-label reporting
Included in this tier as part of the engagement — reports go out under your name. It is not a self-serve branding toggle you configure, and it would be dishonest to show you a settings screen that does not exist yet.
No dashboard, on purpose
There is no console to log into. The report, the alert and the git history are the interface. If a dashboard is a hard requirement, I am the wrong vendor and would rather you knew now.
Nothing on this site is self-serve yet
The pre-consent scanner is built and running, but it is a tool I run, not a box on this page — there is nowhere here to type a URL and get a result back. The free container audit is the same: requested through the form and run for you. Instant self-serve is planned; it is not shipped, and nothing on this site should read as though it is.
No case studies yet
I have no named client logos and am not going to borrow any. What I have instead is the tooling pointed at my own containers, with the findings published.

Pricing

What it costs, against what it replaces.

$1,500 a month covers up to 25 client containers. Against that: one broken checkout tag on one client, caught a month late, costs more than the annual bill — and the reports come back to you as something you can bill for.

Where the Agency tier sits

Studio

$600/mo

Up to 10 containers

Agency

$1,500/mo

Up to 25 containers, white-label

Fleet

Custom

25+ containers

  • You’ll never pay per alert, per report or per request. Charging for those would make you ration the one thing you’re buying.
  • The retainer covers daily monitoring, the monthly change report, the quarterly re-audit and the small changes that come up. A rebuild is a project, quoted separately.
  • Annual prepay is ten months for twelve on every retainer tier.
  • The audit stays free — for your prospects as well as your clients.
Talk about a fleet

Goes to the request form on the home page. No sales call to book, no third-party processor.