toolkit

Scenario · The bigger jobs

A prospect wants a free audit — with granted data access

A prospect who already granted GSC + GBP access asks for a free audit before any agreement.

When a prospect has already handed over real access to their search and business-listing data before signing anything, a sales audit can say something much stronger than the outside-only version — an actual number, with a real decline or opportunity attached, rather than just a handful of surface findings. This pulls that real performance data, works out what's actually driving a change rather than just noting that one happened, and is explicit in the final document about exactly what could and couldn't be proven from what was granted — because overclaiming a cause is the risk once real numbers are in hand.

What to ask for

Site audit (all-in-one)Site-level audit orchestrator — point it at a domain and it audits the whole site in one run.Search Console seriesOptional integration — reads Search Console's Search Analytics API and writes the data series nothing else has.Google Business Profile clientOptional integration — pulls a GBP location's profile, reviews, daily performance metrics and monthly search keywords via the Business Profile and Performance APIs, then grades them to PASS / REVIEW / FAIL.GBP public listing auditAudit the public surface of every Google Business Profile listing without an API — what Search and Maps actually show: practitioner, acquired-brand and competitor baselines.GSC decline decompositionGSC traffic-drop triage with mechanism attribution — decompose a click decline into worse ranking, weaker demand, falling click-through, a mix of the three, the page dropping out of results, or a decline that turns out to be growth, with an ordered rule set, grain-coverage gate, URL-migration clustering, stable-position cohort CTR test, equal-window + YoY cross-check and hedged verdict.AI search visibilityAI Search Visibility report — measures how visible a business is inside AI search answers (ChatGPT, Gemini and other engines) and builds a client-ready report.Hosting & DNSHosting & DNS infra fingerprint — reads a domain's DNS, TLS, headers and RDAP and reports the backend stack: web host, nameservers, CDN/edge, email provider, SSL issuer, CMS, registrar and last-changed date.Client report (PDF)Rolls up a site's tool runs into one branded, client-ready report plus PDF.

See it work

A real run of Hosting & DNS:

example.com
  hosting:    Cloudflare (origin hidden)
  platform:   —
  CDN/edge:   Cloudflare
  nameserver: Cloudflare
  IP:         <ip>  CLOUDFLARENET - Cloudflare, Inc., US
  email:
  SSL:        SSL Corporation
  registrar:  RESERVED-Internet Assigned Numbers Authority
  registered: <date>
  last change:<date>
  account:    active — SEO (Active)
  expects:    seo, analytics, content
  CS:         Jordan Casey
  specialist: Priya Nandan
  tech SEO:   Sam Okafor
  writer:     Morgan Reyes
  editor:     Alex Chen
  content dev:Jamie Park

HOSTING PLAYBOOK
  wiki disabled (--no-wiki)
wrote ./out/hosting-and-dns.json
report: ./out/hosting-and-dns-hosting-and-dns.html

The captured report, exactly as a run hands it to a client —open the full report ↗

The other prospect shape: real granted access (GSC, GBP) before any agreement. The outside-only audit is built on “no analytics, no Search Console, no logins” and is cut to three findings because nothing unverifiable from outside belongs in it. With granted data the calculus inverts: traffic, rankings and GBP performance are verifiable, the deliverable can carry quantified decline/opportunity numbers, and the discipline shifts from “three findings, all verifiable” to hedged attribution and grain/coverage honesty.

  1. Confirm scope and window in writing. Which property (GSC domain vs URL prefix), which GBP location, and the comparison windows — equal-window plus YoY where seasonality matters. Pull the grains you need: search-console-series --grain date_page (and date_query_page where query decline matters) and google-business-profile-client for the same period. Without an agreed window the “decline” is just a choice of dates.
  2. Read the infrastructure first — same as the outside-only audit. Hosting, DNS, SSL, expiry. It is the one finding that is verifiable in ten seconds, has an obvious consequence, and buys credibility for the numbers that follow.
  3. Run the site-level audit (Site audit (all-in-one)) and the GBP public audit. The Site audit (all-in-one) pass discovers URLs, routes by stack and fans out QA/redirects/images/WordPress — the shape of the site today. gbp-public-listing-audit enumerates the public listing per viewport and checks NAP/utm/link health independent of API data.
  4. Pull and decompose the numbers. search-console-series gives clicks/impressions/CTR/position per page and query; feed date_page (and date_query_page where available) into gsc-decline-decomposition for the ordered decomposition — RANK_LOSS / DEMAND_LOSS / CTR_EROSION / MIXED plus DISAPPEARED/GREW — with grain-coverage gate, URL-migration clustering, stable-position cohort CTR test, and hedged verdict. google-business-profile-client gives monthly search/maps×desktop/mobile rollup, review velocity/reply-latency (unanswered-negative FAIL gate), threshold vs exact keyword values, branded/unbranded split with collision exclusions, and edge-month partial handling. No number ships without its cohort, window and coverage.
  5. Check AI search visibility. Whether the engines name them for their own procedures and city, and who takes share of voice instead. With granted data this sits beside the GSC/GBP numbers rather than in place of them.
  6. [manual] Cut it down, then add one quantified headline. Keep the three most credible outside findings, but add a single quantified headline from the granted data — e.g. “18K clicks → 11K (−39%) in 90 days, 72% of the loss on 6 URLs (positions 3→11) with no demand drop” — stated with its window, grain, and what it does not prove. The Synergy run was exactly this shape and had no doctrine page to follow; this is that page.
  7. Assemble the document and state what access did and did not cover. The roll-up builds the branded deliverable. Add an explicit “What we could / could not see” box: GSC page+query grains, GBP location scope, branded/unbranded caveats, threshold vs exact keyword note, edge-month partial flag, and the three blind spots (competitor moves, ranking-system change, intent shift) that no site-side data can prove. That box is the difference between a quantified audit and an over-claimed one.

Hedged attribution is the discipline

With outside-only data the risk is including something you cannot verify. With granted data the risk is over-attributing something you can measure. gsc-decline-decomposition’s hedged verdict template is the model: mechanism, ordered rules, what was excluded, what remains unknown. Every claim in the deliverable carries its grain, window, coverage and blind-spot footnote — or it is removed.

What this does not cover

Certainty about why the numbers moved. With granted data the audit can report what happened — clicks, impressions, position, maps/search volume, review velocity, reply latency — and how big the movement was, but attribution stays hedged (rank loss vs demand vs CTR erosion, grain and coverage honesty per GSC decline decomposition). Nothing here proves a competitor, an algorithm update, or intent shift caused the drop; those are named as blind spots, not ranked.

← All scenarios