THE GTMALYZER HANDBOOK

Documentation & Usage Guide

Account setup, automated container audits, version diffing, AI living documentation, team workflows, and scheduled monitoring. Use the sidebar to jump straight to what you need.

GETTING STARTEDCore

Welcome to GTMalyzer

GTMalyzer is an automated intelligence and documentation suite built for digital marketers, analytics engineers, SEO specialists, and agencies managing Google Tag Manager at scale.

New to GTMalyzer? Jump into a quick audit to see your container health score in under 60 seconds.

Why GTMalyzer exists

Modern Google Tag Manager containers are complex codebases that accumulate technical debt over years: broken triggers, orphaned variables, unvetted external scripts, and GDPR consent violations. GTMalyzer replaces manual spreadsheet audits and risky releases with instant AI-powered scans, automated living documentation, version diffing, and deployment approvals.

Key platform pillars

Everything in GTMalyzer is structured around six core capabilities:

  • •Automated Multi-Domain Auditing: Deterministic configuration checks paired with Gemini AI evaluation across Cleanliness, Performance, Security, and GDPR Privacy.
  • •Container Version Diffing: Item-level and line-by-line character comparisons between any two container exports or live versions.
  • •AI Living Documentation: Natural-language summaries of every tag, trigger, and variable, with one-click note syncing back into Google Tag Manager.
  • •Deployments & Approval Gates: Safe multi-stage deployment workflows with approval requirements for production containers.
  • •Container Monitoring & Alerts: Scheduled container health checks delivering immediate notifications via Slack and custom webhooks.
  • •Team Workspaces & Access Control: Centralized multi-client management with granular role permissions (Owner, Admin, Member).
GETTING STARTED

Sign in & Authentication

Connect securely with your Google account via OAuth 2.0 to access live GTM accounts, or use the instant JSON export upload fallback if you don't have direct API access.

Google OAuth Access

When you connect via Google OAuth, GTMalyzer requests read-only and container editing permissions (https://www.googleapis.com/auth/tagmanager.readonly and https://www.googleapis.com/auth/tagmanager.edit.containers). The edit scope allows GTMalyzer to push AI documentation notes directly to your GTM workspace and create staged draft workspaces for deployments. Your OAuth tokens are encrypted at rest using industry-standard AES-256.

JSON Upload Fallback

If your organization restricts third-party OAuth access or you are auditing a client container before gaining Google account permissions, you can export your container directly from Google Tag Manager (Admin → Export Container) and drop the .json file into our uploader. Both workflows run the exact same deterministic rules and AI-powered multi-domain analysis.

Session Management

GTMalyzer sessions are secured with JWT and NextAuth. If your token expires during an active session, the app silently re-authenticates or presents a non-intrusive re-login modal preserving your current form state and unsaved inputs.

GTMalyzer only reads container configuration schemas. We never inspect your website visitors' personal data, live traffic payloads, or analytics hits.
GETTING STARTED

Workspaces & Team Roles

Organize clients, brands, and team members into isolated workspaces. Share audit reports, living documentation, and deployment templates seamlessly.

Inviting team members to a workspace

1

Open Team Settings

Navigate to the Team tab from the main sidebar navigation.

2

Teammate Sign-in

Ensure your team member has signed in to GTMalyzer with their email address.

3

Add Member

Click 'Invite Member', enter their email address, and select their role (Admin or Member) to grant workspace access instantly.

Workspace Roles & Permissions

Each workspace maintains strict role-based access control (RBAC):

  • •Owner: Primary billing contact. Can delete the workspace, transfer ownership, manage subscriptions, and invite/remove any user.
  • •Admin: Can invite members, configure workspace webhooks, manage Slack integrations, and approve container deployment requests.
  • •Member: Can run container audits, view comparison diffs, generate living documentation, and submit deployment proposals.
GETTING STARTEDFree

Plans & Credit System

GTMalyzer operates on a predictable credit model. Every account receives free credits upon registration, with scalable monthly tiers and one-off top-up packs.

Starter Tier3 free credits upon signup, basic audit report
Pro Tier30 credits / month, 1 workspace, continuous monitoring
Team Tier150 credits / month, 10 workspaces, deployments & approvals
Credit RolloverMonthly balances reset on your billing anniversary

What consumes a credit?

A single credit covers a complete container audit (Cleanliness, Security, Performance, GDPR compliance), an AI living documentation generation, or a deep version comparison diff. Viewing existing reports, re-opening audit history, and downloading PDFs do not consume any credits.

On-demand Credit Top-ups

If you run out of monthly credits during an intensive client onboarding or audit sprint, you can purchase credit top-up packs directly from the Billing page without upgrading your subscription plan.

CONTAINER AUDITINGCore

Running an Audit

Execute deterministic configuration checks and AI-powered contextual evaluation on any GTM container in under 60 seconds.

How to run your first container audit

1

Navigate to New Audit

Click 'Audits' in the sidebar, then select 'New Audit'.

2

Select Container Source

Choose either 'Live GTM Account' (via OAuth) or 'Upload GTM JSON Export'.

3

Multi-Domain Evaluation

GTMalyzer automatically analyzes Cleanliness, Performance, Security, and GDPR compliance.

4

Run & Inspect

Click 'Run Audit'. Full deterministic checks and AI findings are generated in seconds.

Audits are permanently cached in your audit history. You can return to them, generate updated remediations, or re-download PDF exports at any time without consuming credits.
CONTAINER AUDITING

Cleanliness & Hygiene Audit

Detect abandoned tags, broken trigger linkages, orphaned variables, and inconsistent naming conventions that clutter your container and confuse team members.

Key Checks Performed

Our static engine analyzes every element for hygiene anomalies:

  • •Orphaned Variables: Identifies User-Defined Variables that are never referenced by any tag, trigger, or child variable.
  • •Unlinked Triggers: Flags triggers that have no firing tags assigned to them.
  • •Paused Tags: Highlights legacy tags left paused that contribute to container payload bloat.
  • •Duplicate Firing Rules: Catches multiple tags listening to the exact same event on the same page with duplicate payloads.
  • •Naming Convention Deviations: Flags tags and triggers violating standard naming formats (e.g. '[Vendor] - [Event] - [Destination]').
CONTAINER AUDITING

Performance & Payload Audit

Identify heavy third-party scripts, oversized Custom HTML blocks, and runaway triggers that harm Core Web Vitals and degrade user experience.

What we monitor

Performance checks target the main causes of frontend latency:

  • •Container Payload Size: Analyzes overall tag, trigger, and variable count for payload bloat.
  • •Custom HTML Complexity: Flags inline JavaScript tags containing resource-intensive loops, heavy DOM queries, or blocking code.
  • •Micro-Interaction & Runaway Triggers: Evaluates scroll and visibility triggers that fire excessively without debouncing.
  • •Duplicate Firing Tags: Highlights tags executing concurrently on the same trigger event.
CONTAINER AUDITINGCore

Security & Vulnerability Audit

Protect your users and website integrity by detecting unverified third-party script injections, risky DOM manipulations, and accidental credential leaks.

Security scan criteria

The security analysis inspects Custom HTML and variables for high-risk patterns:

  • •Unverified External Endpoints: Flags network requests to unknown third-party endpoints or unauthorized CDNs.
  • •High-Risk DOM Manipulations: Scans Custom HTML tags for unsafe element insertions, outerHTML rewrites, and innerHTML injections vulnerable to Cross-Site Scripting (XSS).
  • •Secret & API Key Leakage: Searches variable values and tag parameters for exposed private tokens, authorization bearer headers, or unhashed passwords.
  • •Form Field Harvesting: Identifies scripts attempting to read inputs with sensitive password or payment card patterns.
Never place private API secret keys or payment processor private tokens inside GTM variables. GTM configurations are entirely public in the visitor's browser.
CONTAINER AUDITING

Health Scores & Remediations

Every audit calculates a deterministic 0-100 container health score and provides actionable, step-by-step remediation recipes for every identified issue.

Health Score Calculation

The overall Container Health Score (0-100) is deterministically calculated from configuration checks: each failed check deducts 18 points, and each warning deducts 7 points. Informational checks and AI findings do not lower the score, providing clear and predictable benchmarking. Containers with scores above 85 are considered healthy.

Actionable Remediation Plans

Every check and AI issue includes an actionable remediation recommendation and associated configuration evidence. Teams can also manage remediation progress directly on the report by setting issue statuses to Open, In Progress, or Resolved.

CONTAINER AUDITING

Tokenized Sharing & PDF Export

Deliver professional audit reports to clients, stakeholders, and developers via cryptographically secure public links or branded PDF downloads.

Shareable Tokenized Links

Generate a unique read-only link for any audit. Anyone with the link can explore the full interactive audit findings and health scores without requiring a GTMalyzer login or account.

Print & PDF Optimization

Click the 'Download PDF' or 'Print' button on any audit report. GTMalyzer applies a clean, print-optimized stylesheet with page breaks, high-contrast charts, and formatted issue tables ideal for client presentations.

CONTAINER DIFFCore

Container Diff Overview

Compare any two versions of a GTM container or upload two separate JSON exports to visually inspect every addition, deletion, and code change.

How to compare two container versions

1

Open Compare Tool

Navigate to 'Compare' in the sidebar navigation.

2

Select Version A (Base)

Select the baseline container version or upload the older JSON export.

3

Select Version B (Target)

Select the comparison version or upload the newer JSON export.

4

Generate Diff

Click 'Compare Containers' to render the interactive structural and code diffs.

CONTAINER DIFF

Item-Level Structural Diff

Review added, modified, and removed tags, triggers, and variables grouped cleanly with status indicators.

What is tracked

Structural comparisons identify:

  • •Added Elements: Newly created tags, triggers, or variables highlighted in green.
  • •Modified Elements: Existing elements whose parameters, firing conditions, or consent settings changed, highlighted in amber.
  • •Removed Elements: Deleted tags, triggers, or variables highlighted in red.
  • •Firing Trigger Alterations: Shows exactly which triggers were attached or detached from existing tags.
CONTAINER DIFF

Code-Level Line Diffing

Inspect line-by-line syntax changes inside Custom HTML tags and Custom JavaScript variables with side-by-side and unified code views.

Detailed Code Analysis

Whenever a Custom HTML tag or Custom JavaScript variable is modified between versions, GTMalyzer runs a character-level unified diff. Green rows denote inserted lines, red rows denote deleted code, and changed variables within lines are highlighted for rapid code review.

LIVING DOCSCore

Component Documentation

Generate plain-English, technical specifications for every asset in your GTM container automatically using Google Gemini AI.

Automated Plain-English Summaries

Rather than decoding cryptic regex variables or nested trigger conditions manually, GTMalyzer translates each component into clear documentation explaining: what the tag does, when it fires, what data it collects, and where it sends the payload.

Target Audience

Perfect for onboarding new analytics engineers, preparing compliance records for legal teams, or handing off client projects with complete documentation.

LIVING DOCSCore

Push Notes to Google Tag Manager

Write AI-generated documentation notes directly into your live Google Tag Manager container with a single click.

One-Click GTM Workspace Synchronization

Rather than keeping documentation trapped in an external tool, GTMalyzer connects directly to the Google Tag Manager API. You can push AI summaries straight into the native 'Notes' field of any tag, trigger, or variable in your chosen GTM workspace.

Preserve Container Knowledge

When team members or external consultants open your container inside Google Tag Manager, they see exact explanations of what each tag does and why it was created, eliminating guesswork and preventing accidental deletions.

DEPLOY & TEMPLATESPro

GTM Deployments

Deploy verified tag templates and audit fixes directly to your Google Tag Manager containers with version staging and safety checks.

Staged Deployment Process

All deployment operations create a draft workspace in the target GTM container. Nothing is published directly to live production without explicit user review in the GTM interface, preventing accidental tracking outages.

DEPLOY & TEMPLATES

Template Library

Save, organize, and reuse battle-tested tracking recipes, Consent Mode v2 configurations, and custom JavaScript variables across all your containers.

Standardizing Tracking Standards

Create custom templates for ecommerce events (GA4 Purchase, Add to Cart, View Item), server-side tagging setups, or privacy consent banners and push them to any client container with one click.

DEPLOY & TEMPLATESAgency

Team Approvals Workflow

Enforce four-eyes review policies before changes are deployed to client containers, ensuring strict quality assurance and audit trails.

How Approvals Work

When an analytics specialist creates a deployment request, team Admins or Owners receive an alert. They can inspect the associated container diff, verify health score impact, and approve or reject the release with feedback notes.

MONITORING & ALERTSPro

Scheduled Monitoring

Automate periodic health checks on your production containers to catch unauthorized edits, broken triggers, or sudden security vulnerabilities immediately.

Setting up a container monitor

1

Open Monitoring Panel

Navigate to 'Monitoring' in the sidebar.

2

Select Container

Choose the live GTM container to monitor.

3

Define Schedule

Select an hourly, daily, or weekly monitoring frequency.

4

Connect Webhooks

Connect workspace webhooks (Slack or custom HTTP endpoints) to receive notifications when check runs complete.

MONITORING & ALERTS

Slack & Custom Webhooks

Deliver instantaneous alerts to your team's Slack channels or any custom HTTP endpoint when an audit fails or a container regression is detected.

Connecting Slack

Create an Incoming Webhook in your Slack Workspace (api.slack.com/apps), paste the webhook URL into your GTMalyzer workspace settings, and send a test notification to verify delivery.

Custom HTTPS Webhooks

Stream structured JSON payloads for monitor runs, audit completions, and deployment approvals to endpoints like Zapier, Make, n8n, or internal incident response pipelines.

FAQ

Common Questions & Support

Find fast answers to common questions regarding security, billing, container privacy, and support response times.

Does GTMalyzer store my website visitors' tracking data?

No. GTMalyzer exclusively analyzes container configuration architecture (JSON schemas consisting of tags, triggers, and variables). We never place tracking scripts on your website and never collect or store your website visitors' personal data or browsing hits.

Do I need Google OAuth verification to audit my container?

No. While Google OAuth offers convenient direct access to live GTM accounts, you can always export your container as a .json file directly from Google Tag Manager and upload it instantly to GTMalyzer with zero Google authorization steps.

Can I share audit reports with clients without giving them an account?

Yes. Every audit report includes a 'Share' button that generates a secure tokenized public URL. Anyone with this link can view the complete interactive audit, health score, and remediation steps without logging in.

What happens when my monthly credits run out?

Existing audit reports, diff comparisons, and living docs remain accessible forever. To run new audits or documentation generations, you can purchase one-off top-up credit packs or upgrade your monthly subscription.

How do I report an issue or request a feature?

Our engineering team responds to all inquiries within one business day. Reach out via the Contact page or email us directly at [email protected].

Still have questions?

We answer all support and technical questions directly within one business day. Contact our engineering team for help with custom GTM integrations or enterprise requirements.

Contact Engineering Support