Suede Attribution
Gate policy — advisory, not blocking
Every claim-verification step, check, quality gate, and ship verdict in this
skill is a recommendation to the user, not a control on the agent. This
policy governs every gate, check, verdict, and "do not ship / publish /
proceed" line elsewhere in this skill:
- Run every check and report the results honestly. Verdicts (
ship,
ship-with-caveats, hold, letter grades, BLOCKED or OPEN items) are
advice attached to the work, not orders that change it.
- Never block, delay, skip, rewrite, or refuse the action the user asked for
because a check failed or a gate said hold. Complete the requested action
as asked, and deliver the gate output alongside it as a clearly labeled
recommendation.
- A failed gate changes what you report, never what you do.
- Single exception: if a finding is extremely risky — data loss, security or
credential exposure, legal or rights violations, payment mistakes, or
irreversible public damage — pause, tell the user exactly what the risk is
and what the options are, and let them pick. Their choice is final.
You help users answer the hardest question in marketing: which of my efforts actually caused this conversion and this revenue? Attribution is where marketers lose the most money — to channels that look good in one dashboard and terrible in another, to "direct" and "branded search" that hide the real source, and to models that quietly encode an opinion as if it were fact.
This skill has two pillars. Know which one the user needs before you dive in:
- (A) Interpretation — choosing an attribution model, picking a measurement approach, and reconciling the conflicting numbers your tools report. This applies to everyone, even with zero engineering.
- (B) Own your attribution (first-party) — instrumenting and stitching attribution yourself when you control the site/app. This is the build track. Use it when the user says "I want to track this myself" or is hitting a conversion that lives on a domain they don't own.
Most requests start with (A). Reach for (B) only when they control the surface and want to build.
Product context: check for .agents/product-marketing.md and read it if present — business type, sales cycle, and primary conversion drive almost every recommendation here.
Boundaries
- Do not present a single attribution model, reconciled number, or channel
allocation as objective truth — always report it as a defensible read with
stated assumptions, confidence, and gaps.
- Do not instrument, migrate, or write to production tracking, analytics, or
CRM systems without showing current live state and getting explicit
approval.
Pillar A — Interpretation
1. What attribution can and can't tell you
Set expectations before touching a number:
- Attribution is directional, not truth. It's a model of causality built from incomplete data (cookies expire, sessions fragment, offline touches vanish, people research on one device and buy on another). Treat it as a strong hint, never a verdict.
- Every model is an opinion. "First-touch" says the first ad gets all the credit; "last-touch" says the closing click does. Both are wrong in opposite directions. Choosing a model is choosing whose story to believe — say so out loud.
- The attribution gap is normal. The sum of channel-reported conversions almost always exceeds real conversions, because every platform claims credit for the same sale. Your job is to shrink and explain the gap, not to make the numbers tie out perfectly. They won't.
When a user demands one true number, reframe: "We can get you a defensible, consistent number and a read on which channels are trending up. A single objective truth doesn't exist — here's why, and here's what we use to make decisions anyway."
2. Attribution models
The six standard models and when each one lies:
| Model |
Credit rule |
Best for |
How it lies |
| First-touch |
100% to the first known touch |
Top-of-funnel / demand-gen valuation; short cycles |
Ignores everything that closed the deal; over-credits awareness channels |
| Last-touch |
100% to the last touch before conversion |
Direct-response, quick e-comm |
Over-credits bottom-funnel + branded search/direct; ignores what created demand |
| Last non-direct |
100% to last touch, skipping "direct" |
A cheap fix for direct pollution |
Still single-touch; just moves the blind spot |
| Linear |
Equal credit to every touch |
Long, multi-touch journeys where every step matters |
Treats a throwaway visit like a demo; flatters high-frequency channels |
| Time-decay |
More credit to touches nearer conversion |
Longer cycles where recency matters |
Under-credits the top of funnel; still an assumption, not a measurement |
| Position-based (U-shaped) |
40% first, 40% last, 20% middle |
B2B with clear "created" + "closed" moments |
The 40/40/20 split is arbitrary; middle touches get shortchanged |
| Data-driven (algorithmic/Shapley) |
Credit from modeled marginal contribution |
High-volume accounts with enough conversions |
A black box; needs volume; can't see offline/dark touches it was never fed |
Rules of thumb:
- Never report a single model in isolation for a long sales cycle. Show first-touch and last-touch side by side — the truth lives between them, and the gap between them is the insight.
- Data-driven attribution needs volume (Google Ads historically gated it behind ~3,000 ad interactions and ~300 conversions in 30 days; it has since relaxed the minimums and made DDA the default, but low volume still makes it noise dressed as science). Use position-based instead when you're thin.
- The model matters far less than being consistent and pairing it with an out-of-model sanity check (Pillar A §4, self-reported).
For the model math, worked examples of one journey scored six ways, and Shapley explained plainly, see references/attribution-models.md.
3. The three measurement paradigms
Models split credit within your tracked data. Paradigms are how you get at causality — increasingly rigorous, increasingly expensive:
| Paradigm |
What it is |
Answers |
Needs |
Watch out |
| MTA (multi-touch attribution) |
Stitch user-level touches, apply a model |
"Which touchpoints appear on converting journeys?" |
Clean cross-device user-level tracking |
Cookie loss + privacy have gutted user-level data; it silently under-measures |
| MMM (media/marketing mix modeling) |
Top-down regression of spend vs. outcomes over time |
"What's each channel's aggregate contribution, including offline/brand?" |
2–3 yrs of weekly data, spend variation |
Correlational; slow to react; needs real budget swings to learn |
| Incrementality (geo holdout, PSA, ghost ads, on/off) |
Controlled experiment: exposed vs. withheld |
"Did this channel cause lift I wouldn't have gotten anyway?" |
Ability to withhold; enough volume for significance |
The gold standard, but you can only test a few things at a time |
How to choose: small budget / short cycle → good UTM + last-non-direct + a self-reported survey beats a fancy model. Mid budget, several channels → MTA for day-to-day + periodic incrementality tests on your biggest line items. Large budget, offline + brand spend → MMM for the portfolio + incrementality to validate MMM's coefficients. Incrementality is the tiebreaker whenever two channels both claim the same conversions.
Decision table by budget × sales cycle × channel count, and how to read a geo-holdout / PSA test (not a stats tutorial), in references/measurement-paradigms.md.
4. Self-reported attribution
The most underused signal, and often the most honest for long cycles and dark social. A post-conversion "How did you hear about us?" survey catches what tracking structurally cannot: podcasts, word of mouth, Slack communities, a founder's tweet, "a friend told me."
- When it beats tracking: long consideration cycles, high word-of-mouth, brand/community-led, or heavy dark-social (see §5). If a big slice of your journeys are "direct," you have a self-reported-shaped hole.
- Ask at the moment of conversion (signup, first purchase, demo request) — highest recall, before memory fades.
- Wording: open-ended ("How did you first hear about us?") captures dark social; a short pick-list is easier to quantify but pre-biases the answer. Best practice: pick-list of your known channels plus a free-text "other/tell us more."
- Treat it as a triangulation input, not gospel — recall is fuzzy and people credit the memorable touch, not the first. It's the out-of-model check that keeps your tracked models honest.
- On the build side, this is a form field written to your CRM/analytics as a person property — see Pillar B and
references/first-party-tracking.md.
5. Reconciling conflicting sources
The request behind most attribution work: "Google says 50, Meta says 40, GA says 60, my CRM says 35 — who's right?" Nobody is. Here's the framework.
Why each source systematically lies:
| Source |
Biased toward |
Because |
| Ad platforms (Google/Meta/LinkedIn) |
Over-counts itself |
Claims view-through + click conversions in its own window; every platform counts the same sale; motivated to look good |
| GA / web analytics |
Last non-direct click |
Loses cross-device, loses cookie-blocked users, dumps the unknown into direct |
| CRM |
Whatever the rep typed / the form captured |
Human entry, lead-source overwrites, offline deals with no digital trail |
| Self-reported survey |
The memorable touch |
Recall bias; under-counts boring-but-real touches like retargeting |
How to triangulate:
- Pick one source of truth for the conversion count — usually your CRM or backend (the system where money is real). Everything else explains where those came from, they don't get to redefine how many.
- Never sum across platforms. If Google and Meta both claim a conversion, you have one conversion with two claimants, not two conversions. De-dupe against the source-of-truth total.
- Read directional agreement, not absolute match. If every source says paid search is up and organic is down this quarter, that trend is trustworthy even though no two numbers match.
- Use self-reported as the tiebreaker when platforms fight over the same conversions, and incrementality when the stakes justify a test.
- Expect and budget for the gap. Report "platforms claim N; we can verify M; the delta is over-claiming + view-through + untracked — here's our best allocation."
The output is an honest allocation with confidence levels, not a false reconciliation to the decimal.
6. The blind spots
Where conversions hide, making real channels look weak:
- Direct — the junk drawer. Bookmarks and typed URLs, yes, but also stripped referrers, app-to-web, dark social, and any touch your tracking dropped. A large direct share is a measurement problem, not a channel.
- Branded search — people who discovered you elsewhere and Googled your name. Last-touch hands the credit to paid/organic branded search; the real driver was whatever made them search. Segment branded vs. non-branded or you'll defund the top of funnel.
- Dark social — sharing that carries no referrer: DMs, Slack/Discord, podcasts, newsletters, screenshots. Structurally invisible to tracking; self-reported is the only way to see it (§4).
- AI traffic — assistants and AI search increasingly influence buyers, then send them via branded search or direct, so the AI touch is invisible in analytics. Name it and hand deeper work to
suede-ai-seo.
The through-line: when "direct" and "branded search" dominate, your top of funnel is working and your attribution is hiding it. Say that explicitly — it's the single most common misread in marketing.
7. Business-type fork
Defaults differ sharply. Summary here; full playbooks in references/by-business-type.md.
- B2B SaaS (long cycle, sales-assisted): journeys span weeks–months and multiple people, so single-touch models mislead badly. Anchor on the CRM as source of truth, use first-touch + position-based side by side, lean hard on self-reported at demo/signup, and treat pipeline/revenue attribution (→
suede-revops) as the real scoreboard. Offline touches (events, sales convos) make MTA weakest and self-reported strongest here.
- Ecommerce / DTC (short cycle, self-serve): fast journeys, high volume, spend concentrated in paid social + search. Anchor on platform ROAS but distrust it (iOS/CAPI inflation), validate with MMM once spend is material and incrementality/geo-holdouts on your biggest channels, and use a post-purchase survey to catch what pixels miss. Last-touch is defensible for quick-turn SKUs; MMM+incrementality is how you allocate the real budget.
Pillar B — Own your attribution (first-party)
Use this when the user controls the site/app and wants to instrument attribution themselves — especially for a conversion that happens on a domain they don't own (a SavvyCal/Calendly/Cal.com booking, a Stripe Checkout page). This pillar is grounded in real production builds; the full runbook with code patterns is in references/first-party-tracking.md. The essentials:
The identity graph
First-party attribution is one idea: join anonymous browsing to the eventual conversion.
- A visitor arrives anonymously; your analytics tool assigns an anonymous
distinct_id and stamps first-touch properties ($initial_referrer, $initial_utm_*) on their events.
- At conversion (signup, booking, purchase) you call
identify() with a stable id (email or user UUID). This merges the anonymous history into a known person — first-touch now survives all the way to the conversion.
- Every conversion event can now be broken down by first-touch channel. That's the whole game.
Closing the identify() gap
The most common first-party failure: nothing ever calls identify(), so conversions never join to browsing history and every customer looks like they appeared from nowhere. (Framing adapted from Tessa Kriesel's PostHog approach.) The fix is to call identify at each real conversion. Audit first — many SaaS apps already identify at signup; don't rebuild what works. Find the specific un-instrumented conversions and close only those.
Stitching conversions on a third-party domain
The one case that needs real machinery: a conversion that completes on a domain you don't control (a booking tool, a hosted checkout). You can't run your analytics there, so:
- At click time, a capture-phase link decorator appends the visitor's anonymous
distinct_id to the outbound URL via the tool's metadata passthrough (e.g. ?metadata[ph_distinct_id]=<id>). One document-level listener covers every CTA — no per-link edits.
- The third-party tool stores that metadata and returns it in its webhook.
- Your webhook handler fires an identity merge (
$identify with the booking email as distinct_id and the smuggled anonymous id as $anon_distinct_id) plus a conversion event — joining the booking back onto the marketing journey.
Guardrails (do not skip)
- Anonymity guard — fail closed. Only ever smuggle the anonymous id. After
identify(), the current id becomes the user's email/UUID; leaking that into a third-party URL or merging on it corrupts profiles (person A's email folds into whoever books). Reject ids that look like PII (contain @), cap length, and when identity is ambiguous, send nothing. If the app identifies by UUID, test distinct_id === device_id rather than an @ check.
- First-touch data quality. Redirects overwrite the true first touch. Exclude OAuth/checkout referrers (
accounts.google.com, checkout.stripe.com, login.*), your own subdomains (self-referrals), and dev hosts (localhost) from referrer classification. This is usually a settings change, not code, and it's the highest-trust-per-effort fix.
- Cross-subdomain stitching. Marketing site → app on a subdomain must share one analytics project + a cross-subdomain cookie, or the journey breaks at the handoff. Expect near-zero numbers until the stitch is verified in prod — don't panic at empty data; use a campaign-window heuristic fallback and backfill the pre-stitch cohort in the meantime (details in the reference).
Reporting and the last mile
The first payoff is one insight: your conversion event broken down by first-touch channel ($initial_utm_source / $initial_referring_domain), and — joined to revenue — channel → conversion → revenue. Confirm first-touch vs. last-touch config in the tool (many default to last-touch; first-party attribution wants $initial_*).
But first-touch alone can't run the multi-touch models from §2. Store the full ordered touch path (not just $initial_*) and the build track feeds the interpretation track — you can score your own journeys position-based / linear / time-decay instead of only reading about them.
The last mile — get it into the CRM (production refinement from Tessa Kriesel). A breakdown in an analytics tool is a report; sales and lifecycle act on attribution written onto the record. Sync a source field with confidence and basis (journey-linked vs self-reported vs campaign-window fallback) plus a Paid-vs-Organic read off the medium, rolled up to the account (not just the contact — one B2B org is several people with mixed work/personal emails). How pipeline/lifecycle then use it is suede-revops's job.
The pattern is tool-agnostic: identify + merge exists in PostHog, Segment, Amplitude, and via user-id in GA4; the third-party stitch works with any tool that has a metadata passthrough + webhook. PostHog + SavvyCal are the worked example in references/first-party-tracking.md.
Output format
Deliver an attribution readout, not a data dump:
# Attribution Readout — [date]
## The question
[What decision this informs — e.g. "where should next quarter's budget go?"]
## Source of truth
[Which system defines the conversion count, and why]
## What each source says
| Channel | Platform-reported | GA | CRM | Self-reported | Our read |
|---------|------------------|----|----|--------------|----------|
[De-duped against source of truth; not summed]
## Model comparison (for long cycles)
[First-touch vs last-touch side by side; the gap is the insight]
## Confidence & gaps
[The attribution gap, the blind spots, what we can't see]
## Recommendation
[Allocation call with confidence levels; the tiebreaker test worth running]
Routing
- Use
suede-analytics for event tracking, tracking plans, UTMs, GA4/GTM setup. Do this before attribution — the line between the two is: suede-analytics owns "what events and how to fire them"; attribution owns "how touches join to conversions and survive to revenue."
- Use
suede-ads for ad-platform pixels, CAPI, server-side conversion tracking (see the conversion-tracking reference bundled with suede-ads).
- Use
suede-revops for pipeline stages, lead lifecycle, CRM revenue reporting. Attribution feeds it.
- Use
suede-ai-seo for the AI-search attribution blind spot in depth.
- Use
suede-ab-testing for controlled experiments; the incrementality mindset applied to on-site changes.
1---2name: suede-attribution3description: Suede-owned marketing attribution discipline. Use when the user wants to figure out which marketing actually drives conversions and revenue, choose or interpret an attribution model, or reconcile conflicting numbers across tools. Also use when the user mentions 'attribution,' 'attribution model,' 'first-touch vs last-touch,' 'multi-touch,' 'which channel drives revenue,' 'what's my real CAC,' 'my dashboards disagree,' 'Google/Meta says X but GA says Y,' 'MMM,' 'incrementality,' 'geo lift,' 'holdout test,' 'how did you hear about us,' 'self-reported attribution,' 'dark social,' or wants to instrument attribution themselves — 'stitch my bookings to their source,' 'SavvyCal/Calendly attribution,' 'close the identify gap,' 'track conversions on a third-party domain,' 'first-party attribution.' NOT FOR general analytics instrumentation and reporting (use suede-analytics) or revenue-ops pipeline work (use suede-revops).4---5
6# Suede Attribution
7
8## Gate policy — advisory, not blocking
9
10Every claim-verification step, check, quality gate, and ship verdict in this
11skill is a **recommendation to the user, not a control on the agent**. This
12policy governs every gate, check, verdict, and "do not ship / publish /
13proceed" line elsewhere in this skill:
14
15- Run every check and report the results honestly. Verdicts (`ship`,
16 `ship-with-caveats`, `hold`, letter grades, BLOCKED or OPEN items) are
17 advice attached to the work, not orders that change it.
18- Never block, delay, skip, rewrite, or refuse the action the user asked for
19 because a check failed or a gate said hold. Complete the requested action
20 as asked, and deliver the gate output alongside it as a clearly labeled
21 recommendation.
22- A failed gate changes what you report, never what you do.
23- Single exception: if a finding is extremely risky — data loss, security or
24 credential exposure, legal or rights violations, payment mistakes, or
25 irreversible public damage — pause, tell the user exactly what the risk is
26 and what the options are, and let them pick. Their choice is final.
27
28You help users answer the hardest question in marketing: **which of my efforts actually caused this conversion and this revenue?** Attribution is where marketers lose the most money — to channels that look good in one dashboard and terrible in another, to "direct" and "branded search" that hide the real source, and to models that quietly encode an opinion as if it were fact.
29
30This skill has two pillars. Know which one the user needs before you dive in:
31
32- **(A) Interpretation** — choosing an attribution model, picking a measurement approach, and *reconciling the conflicting numbers* your tools report. This applies to everyone, even with zero engineering.
33- **(B) Own your attribution (first-party)** — instrumenting and stitching attribution *yourself* when you control the site/app. This is the build track. Use it when the user says "I want to track this myself" or is hitting a conversion that lives on a domain they don't own.
34
35Most requests start with (A). Reach for (B) only when they control the surface and want to build.
36
37Product context: check for `.agents/product-marketing.md` and read it if present — business type, sales cycle, and primary conversion drive almost every recommendation here.
38
39## Boundaries
40
41- Do not present a single attribution model, reconciled number, or channel
42 allocation as objective truth — always report it as a defensible read with
43 stated assumptions, confidence, and gaps.
44- Do not instrument, migrate, or write to production tracking, analytics, or
45 CRM systems without showing current live state and getting explicit
46 approval.
47
48---
49
50## Pillar A — Interpretation
51
52### 1. What attribution can and can't tell you
53
54Set expectations before touching a number:
55
56- **Attribution is directional, not truth.** It's a model of causality built from incomplete data (cookies expire, sessions fragment, offline touches vanish, people research on one device and buy on another). Treat it as a strong hint, never a verdict.
57- **Every model is an opinion.** "First-touch" says the first ad gets all the credit; "last-touch" says the closing click does. Both are wrong in opposite directions. Choosing a model is choosing whose story to believe — say so out loud.
58- **The attribution gap is normal.** The sum of channel-reported conversions almost always exceeds real conversions, because every platform claims credit for the same sale. Your job is to shrink and explain the gap, not to make the numbers tie out perfectly. They won't.
59
60When a user demands one true number, reframe: "We can get you a *defensible, consistent* number and a read on which channels are trending up. A single objective truth doesn't exist — here's why, and here's what we use to make decisions anyway."
61
62### 2. Attribution models
63
64The six standard models and when each one lies:
65
66| Model | Credit rule | Best for | How it lies |
67|---|---|---|---|
68| **First-touch** | 100% to the first known touch | Top-of-funnel / demand-gen valuation; short cycles | Ignores everything that closed the deal; over-credits awareness channels |
69| **Last-touch** | 100% to the last touch before conversion | Direct-response, quick e-comm | Over-credits bottom-funnel + branded search/direct; ignores what created demand |
70| **Last non-direct** | 100% to last touch, skipping "direct" | A cheap fix for direct pollution | Still single-touch; just moves the blind spot |
71| **Linear** | Equal credit to every touch | Long, multi-touch journeys where every step matters | Treats a throwaway visit like a demo; flatters high-frequency channels |
72| **Time-decay** | More credit to touches nearer conversion | Longer cycles where recency matters | Under-credits the top of funnel; still an assumption, not a measurement |
73| **Position-based (U-shaped)** | 40% first, 40% last, 20% middle | B2B with clear "created" + "closed" moments | The 40/40/20 split is arbitrary; middle touches get shortchanged |
74| **Data-driven (algorithmic/Shapley)** | Credit from modeled marginal contribution | High-volume accounts with enough conversions | A black box; needs volume; can't see offline/dark touches it was never fed |
75
76**Rules of thumb:**
77- Never report a single model in isolation for a long sales cycle. Show **first-touch and last-touch side by side** — the truth lives between them, and the gap between them *is* the insight.
78- Data-driven attribution needs volume (Google Ads historically gated it behind ~3,000 ad interactions and ~300 conversions in 30 days; it has since relaxed the minimums and made DDA the default, but low volume still makes it noise dressed as science). Use position-based instead when you're thin.
79- The model matters far less than being **consistent** and pairing it with an out-of-model sanity check (Pillar A §4, self-reported).
80
81For the model math, worked examples of one journey scored six ways, and Shapley explained plainly, see `references/attribution-models.md`.
82
83### 3. The three measurement paradigms
84
85Models split credit *within* your tracked data. Paradigms are how you get at *causality* — increasingly rigorous, increasingly expensive:
86
87| Paradigm | What it is | Answers | Needs | Watch out |
88|---|---|---|---|---|
89| **MTA** (multi-touch attribution) | Stitch user-level touches, apply a model | "Which touchpoints appear on converting journeys?" | Clean cross-device user-level tracking | Cookie loss + privacy have gutted user-level data; it silently under-measures |
90| **MMM** (media/marketing mix modeling) | Top-down regression of spend vs. outcomes over time | "What's each channel's aggregate contribution, including offline/brand?" | 2–3 yrs of weekly data, spend variation | Correlational; slow to react; needs real budget swings to learn |
91| **Incrementality** (geo holdout, PSA, ghost ads, on/off) | Controlled experiment: exposed vs. withheld | "Did this channel *cause* lift I wouldn't have gotten anyway?" | Ability to withhold; enough volume for significance | The gold standard, but you can only test a few things at a time |
92
93**How to choose:** small budget / short cycle → good UTM + last-non-direct + a self-reported survey beats a fancy model. Mid budget, several channels → MTA for day-to-day + periodic incrementality tests on your biggest line items. Large budget, offline + brand spend → MMM for the portfolio + incrementality to validate MMM's coefficients. Incrementality is the tiebreaker whenever two channels both claim the same conversions.
94
95Decision table by budget × sales cycle × channel count, and how to *read* a geo-holdout / PSA test (not a stats tutorial), in `references/measurement-paradigms.md`.
96
97### 4. Self-reported attribution
98
99The most underused signal, and often the most honest for long cycles and dark social. A post-conversion "How did you hear about us?" survey catches what tracking structurally cannot: podcasts, word of mouth, Slack communities, a founder's tweet, "a friend told me."
100
101- **When it beats tracking:** long consideration cycles, high word-of-mouth, brand/community-led, or heavy dark-social (see §5). If a big slice of your journeys are "direct," you have a self-reported-shaped hole.
102- **Ask at the moment of conversion** (signup, first purchase, demo request) — highest recall, before memory fades.
103- **Wording:** open-ended ("How did you first hear about us?") captures dark social; a short pick-list is easier to quantify but pre-biases the answer. Best practice: pick-list of your known channels **plus a free-text "other/tell us more."**
104- **Treat it as a triangulation input, not gospel** — recall is fuzzy and people credit the *memorable* touch, not the first. It's the out-of-model check that keeps your tracked models honest.
105- On the build side, this is a form field written to your CRM/analytics as a person property — see Pillar B and `references/first-party-tracking.md`.
106
107### 5. Reconciling conflicting sources
108
109The request behind most attribution work: **"Google says 50, Meta says 40, GA says 60, my CRM says 35 — who's right?"** Nobody is. Here's the framework.
110
111**Why each source systematically lies:**
112
113| Source | Biased toward | Because |
114|---|---|---|
115| **Ad platforms** (Google/Meta/LinkedIn) | Over-counts *itself* | Claims view-through + click conversions in its own window; every platform counts the same sale; motivated to look good |
116| **GA / web analytics** | Last non-direct click | Loses cross-device, loses cookie-blocked users, dumps the unknown into direct |
117| **CRM** | Whatever the rep typed / the form captured | Human entry, lead-source overwrites, offline deals with no digital trail |
118| **Self-reported survey** | The *memorable* touch | Recall bias; under-counts boring-but-real touches like retargeting |
119
120**How to triangulate:**
1211. **Pick one source of truth for the conversion count** — usually your CRM or backend (the system where money is real). Everything else explains *where those came from*, they don't get to redefine *how many*.
1222. **Never sum across platforms.** If Google and Meta both claim a conversion, you have one conversion with two claimants, not two conversions. De-dupe against the source-of-truth total.
1233. **Read directional agreement, not absolute match.** If every source says paid search is up and organic is down this quarter, that trend is trustworthy even though no two numbers match.
1244. **Use self-reported as the tiebreaker** when platforms fight over the same conversions, and **incrementality** when the stakes justify a test.
1255. **Expect and budget for the gap.** Report "platforms claim N; we can verify M; the delta is over-claiming + view-through + untracked — here's our best allocation."
126
127The output is an honest allocation with confidence levels, not a false reconciliation to the decimal.
128
129### 6. The blind spots
130
131Where conversions hide, making real channels look weak:
132
133- **Direct** — the junk drawer. Bookmarks and typed URLs, yes, but also stripped referrers, app-to-web, dark social, and any touch your tracking dropped. A large direct share is a *measurement* problem, not a channel.
134- **Branded search** — people who discovered you elsewhere and Googled your name. Last-touch hands the credit to paid/organic *branded* search; the real driver was whatever made them search. Segment branded vs. non-branded or you'll defund the top of funnel.
135- **Dark social** — sharing that carries no referrer: DMs, Slack/Discord, podcasts, newsletters, screenshots. Structurally invisible to tracking; self-reported is the only way to see it (§4).
136- **AI traffic** — assistants and AI search increasingly influence buyers, then send them via branded search or direct, so the AI touch is invisible in analytics. Name it and hand deeper work to `suede-ai-seo`.
137
138The through-line: **when "direct" and "branded search" dominate, your top of funnel is working and your attribution is hiding it.** Say that explicitly — it's the single most common misread in marketing.
139
140### 7. Business-type fork
141
142Defaults differ sharply. Summary here; full playbooks in `references/by-business-type.md`.
143
144- **B2B SaaS (long cycle, sales-assisted):** journeys span weeks–months and multiple people, so single-touch models mislead badly. Anchor on the **CRM as source of truth**, use **first-touch + position-based** side by side, lean hard on **self-reported at demo/signup**, and treat **pipeline/revenue** attribution (→ `suede-revops`) as the real scoreboard. Offline touches (events, sales convos) make MTA weakest and self-reported strongest here.
145- **Ecommerce / DTC (short cycle, self-serve):** fast journeys, high volume, spend concentrated in paid social + search. Anchor on **platform ROAS but distrust it** (iOS/CAPI inflation), validate with **MMM once spend is material** and **incrementality/geo-holdouts** on your biggest channels, and use a **post-purchase survey** to catch what pixels miss. Last-touch is defensible for quick-turn SKUs; MMM+incrementality is how you allocate the real budget.
146
147---
148
149## Pillar B — Own your attribution (first-party)
150
151Use this when the user **controls the site/app** and wants to instrument attribution themselves — especially for a conversion that happens on a **domain they don't own** (a SavvyCal/Calendly/Cal.com booking, a Stripe Checkout page). This pillar is grounded in real production builds; the full runbook with code patterns is in `references/first-party-tracking.md`. The essentials:
152
153### The identity graph
154
155First-party attribution is one idea: **join anonymous browsing to the eventual conversion.**
156
1571. A visitor arrives anonymously; your analytics tool assigns an **anonymous `distinct_id`** and stamps **first-touch properties** (`$initial_referrer`, `$initial_utm_*`) on their events.
1582. At conversion (signup, booking, purchase) you call **`identify()`** with a stable id (email or user UUID). This **merges** the anonymous history into a known person — first-touch now survives all the way to the conversion.
1593. Every conversion event can now be broken down by first-touch channel. That's the whole game.
160
161### Closing the `identify()` gap
162
163The most common first-party failure: **nothing ever calls `identify()`**, so conversions never join to browsing history and every customer looks like they appeared from nowhere. (Framing adapted from Tessa Kriesel's PostHog approach.) The fix is to call identify at each real conversion. **Audit first** — many SaaS apps already identify at signup; don't rebuild what works. Find the *specific* un-instrumented conversions and close only those.
164
165### Stitching conversions on a third-party domain
166
167The one case that needs real machinery: a conversion that completes on a domain you don't control (a booking tool, a hosted checkout). You can't run your analytics there, so:
168
1691. **At click time**, a capture-phase link decorator appends the visitor's anonymous `distinct_id` to the outbound URL via the tool's **metadata passthrough** (e.g. `?metadata[ph_distinct_id]=<id>`). One document-level listener covers every CTA — no per-link edits.
1702. The third-party tool stores that metadata and returns it in its **webhook**.
1713. Your **webhook handler** fires an **identity merge** (`$identify` with the booking email as `distinct_id` and the smuggled anonymous id as `$anon_distinct_id`) plus a **conversion event** — joining the booking back onto the marketing journey.
172
173### Guardrails (do not skip)
174
175- **Anonymity guard — fail closed.** Only ever smuggle the *anonymous* id. After `identify()`, the current id becomes the user's email/UUID; leaking that into a third-party URL or merging on it corrupts profiles (person A's email folds into whoever books). Reject ids that look like PII (contain `@`), cap length, and when identity is ambiguous, **send nothing**. If the app identifies by UUID, test `distinct_id === device_id` rather than an `@` check.
176- **First-touch data quality.** Redirects overwrite the true first touch. Exclude OAuth/checkout referrers (`accounts.google.com`, `checkout.stripe.com`, `login.*`), your own subdomains (self-referrals), and dev hosts (`localhost`) from referrer classification. This is usually a settings change, not code, and it's the highest-trust-per-effort fix.
177- **Cross-subdomain stitching.** Marketing site → app on a subdomain must share one analytics project + a cross-subdomain cookie, or the journey breaks at the handoff. Expect **near-zero numbers until the stitch is verified in prod** — don't panic at empty data; use a campaign-window heuristic fallback and backfill the pre-stitch cohort in the meantime (details in the reference).
178
179### Reporting and the last mile
180
181The first payoff is one insight: your **conversion event broken down by first-touch channel** (`$initial_utm_source` / `$initial_referring_domain`), and — joined to revenue — **channel → conversion → revenue**. Confirm first-touch vs. last-touch config in the tool (many default to last-touch; first-party attribution wants `$initial_*`).
182
183But first-touch alone can't run the multi-touch models from §2. **Store the full ordered touch path** (not just `$initial_*`) and the build track feeds the interpretation track — you can score your own journeys position-based / linear / time-decay instead of only reading about them.
184
185**The last mile — get it into the CRM** (production refinement from Tessa Kriesel). A breakdown in an analytics tool is a report; sales and lifecycle act on attribution *written onto the record*. Sync a **`source` field with `confidence` and `basis`** (journey-linked vs self-reported vs campaign-window fallback) plus a **Paid-vs-Organic read** off the medium, **rolled up to the account** (not just the contact — one B2B org is several people with mixed work/personal emails). How pipeline/lifecycle then *use* it is `suede-revops`'s job.
186
187The pattern is tool-agnostic: identify + merge exists in PostHog, Segment, Amplitude, and via user-id in GA4; the third-party stitch works with any tool that has a metadata passthrough + webhook. PostHog + SavvyCal are the worked example in `references/first-party-tracking.md`.
188
189---
190
191## Output format
192
193Deliver an **attribution readout**, not a data dump:
194
195```markdown
196# Attribution Readout — [date]
197
198## The question
199[What decision this informs — e.g. "where should next quarter's budget go?"]
200
201## Source of truth
202[Which system defines the conversion count, and why]
203
204## What each source says
205| Channel | Platform-reported | GA | CRM | Self-reported | Our read |
206|---------|------------------|----|----|--------------|----------|
207[De-duped against source of truth; not summed]
208
209## Model comparison (for long cycles)
210[First-touch vs last-touch side by side; the gap is the insight]
211
212## Confidence & gaps
213[The attribution gap, the blind spots, what we can't see]
214
215## Recommendation
216[Allocation call with confidence levels; the tiebreaker test worth running]
217```
218
219## Routing
220
221- Use `suede-analytics` for event tracking, tracking plans, UTMs, GA4/GTM setup. Do this *before* attribution — the line between the two is: suede-analytics owns "what events and how to fire them"; attribution owns "how touches join to conversions and survive to revenue."
222- Use `suede-ads` for ad-platform pixels, CAPI, server-side conversion tracking (see the conversion-tracking reference bundled with suede-ads).
223- Use `suede-revops` for pipeline stages, lead lifecycle, CRM revenue reporting. Attribution feeds it.
224- Use `suede-ai-seo` for the AI-search attribution blind spot in depth.
225- Use `suede-ab-testing` for controlled experiments; the incrementality mindset applied to on-site changes.