Scenario · The bigger jobs
A prospect wants a free audit — with granted data access
A prospect who already granted GSC + GBP access asks for a free audit before any agreement.
When a prospect has already handed over real access to their search and business-listing data before signing anything, a sales audit can say something much stronger than the outside-only version — an actual number, with a real decline or opportunity attached, rather than just a handful of surface findings. This pulls that real performance data, works out what's actually driving a change rather than just noting that one happened, and is explicit in the final document about exactly what could and couldn't be proven from what was granted — because overclaiming a cause is the risk once real numbers are in hand.
What to ask for
See it work
A real run of Hosting & DNS:
example.com
hosting: Cloudflare (origin hidden)
platform: —
CDN/edge: Cloudflare
nameserver: Cloudflare
IP: <ip> CLOUDFLARENET - Cloudflare, Inc., US
email:
SSL: SSL Corporation
registrar: RESERVED-Internet Assigned Numbers Authority
registered: <date>
last change:<date>
account: active — SEO (Active)
expects: seo, analytics, content
CS: Jordan Casey
specialist: Priya Nandan
tech SEO: Sam Okafor
writer: Morgan Reyes
editor: Alex Chen
content dev:Jamie Park
HOSTING PLAYBOOK
wiki disabled (--no-wiki)
wrote ./out/hosting-and-dns.json
report: ./out/hosting-and-dns-hosting-and-dns.htmlThe captured report, exactly as a run hands it to a client —open the full report ↗
The other prospect shape: real granted access (GSC, GBP) before any agreement. The outside-only audit is built on “no analytics, no Search Console, no logins” and is cut to three findings because nothing unverifiable from outside belongs in it. With granted data the calculus inverts: traffic, rankings and GBP performance are verifiable, the deliverable can carry quantified decline/opportunity numbers, and the discipline shifts from “three findings, all verifiable” to hedged attribution and grain/coverage honesty.
- Confirm scope and window in writing. Which property (GSC domain vs URL prefix), which GBP location, and the comparison windows — equal-window plus YoY where seasonality matters. Pull the grains you need:
search-console-series --grain date_page(anddate_query_pagewhere query decline matters) andgoogle-business-profile-clientfor the same period. Without an agreed window the “decline” is just a choice of dates. - Read the infrastructure first — same as the outside-only audit. Hosting, DNS, SSL, expiry. It is the one finding that is verifiable in ten seconds, has an obvious consequence, and buys credibility for the numbers that follow.
- Run the site-level audit (Site audit (all-in-one)) and the GBP public audit. The Site audit (all-in-one) pass discovers URLs, routes by stack and fans out QA/redirects/images/WordPress — the shape of the site today.
gbp-public-listing-auditenumerates the public listing per viewport and checks NAP/utm/link health independent of API data. - Pull and decompose the numbers.
search-console-seriesgives clicks/impressions/CTR/position per page and query; feeddate_page(anddate_query_pagewhere available) intogsc-decline-decompositionfor the ordered decomposition — RANK_LOSS / DEMAND_LOSS / CTR_EROSION / MIXED plus DISAPPEARED/GREW — with grain-coverage gate, URL-migration clustering, stable-position cohort CTR test, and hedged verdict.google-business-profile-clientgives monthly search/maps×desktop/mobile rollup, review velocity/reply-latency (unanswered-negative FAIL gate), threshold vs exact keyword values, branded/unbranded split with collision exclusions, and edge-month partial handling. No number ships without its cohort, window and coverage. - Check AI search visibility. Whether the engines name them for their own procedures and city, and who takes share of voice instead. With granted data this sits beside the GSC/GBP numbers rather than in place of them.
- [manual] Cut it down, then add one quantified headline. Keep the three most credible outside findings, but add a single quantified headline from the granted data — e.g. “18K clicks → 11K (−39%) in 90 days, 72% of the loss on 6 URLs (positions 3→11) with no demand drop” — stated with its window, grain, and what it does not prove. The Synergy run was exactly this shape and had no doctrine page to follow; this is that page.
- Assemble the document and state what access did and did not cover. The roll-up builds the branded deliverable. Add an explicit “What we could / could not see” box: GSC page+query grains, GBP location scope, branded/unbranded caveats, threshold vs exact keyword note, edge-month partial flag, and the three blind spots (competitor moves, ranking-system change, intent shift) that no site-side data can prove. That box is the difference between a quantified audit and an over-claimed one.
Hedged attribution is the discipline
With outside-only data the risk is including something you cannot verify. With granted data the risk is over-attributing something you can measure. gsc-decline-decomposition’s hedged verdict template is the model: mechanism, ordered rules, what was excluded, what remains unknown. Every claim in the deliverable carries its grain, window, coverage and blind-spot footnote — or it is removed.
What this does not cover
Certainty about why the numbers moved. With granted data the audit can report what happened — clicks, impressions, position, maps/search volume, review velocity, reply latency — and how big the movement was, but attribution stays hedged (rank loss vs demand vs CTR erosion, grain and coverage honesty per GSC decline decomposition). Nothing here proves a competitor, an algorithm update, or intent shift caused the drop; those are named as blind spots, not ranked.