Audit and consented funnel reporting
Audit and consented funnel reporting
Last verified: 2026-07-13
Awthy separates public-site analytics from plugin-managed WooCommerce reporting.
Search Console and privacy-friendly marketing analytics are not configured in the repository. They require owner account setup and tool approval before collection starts.
Optional consented WooCommerce funnel summaries are implemented in the plugin. The WordPress admin view is local to the site and does not require Awthy Hub or managed reporting. Visitor-facing capture requires both local gates:
commerce_analytics_enabledis enabled for the site,- analytics consent is satisfied for visitor-facing events.
Awthy Hub and managed reporting may show longer-lived and richer hosted reports, but they are a superset of the local WordPress view. Turning off Hub must not break the local WordPress panel.
Approved dimensions
Managed WooCommerce reports may use only safe dimensions:
- hashed product, variation, cart, order, and coupon references,
- product type,
- checkout step name,
- authentication factor type,
- authentication assurance level,
- trusted-device flag,
- coarse occurred-at time buckets.
Awthy does not collect raw cart contents, order keys, payment details, addresses, full behavioral replay, raw coupon codes, product names, or customer PII for these reports.
Awthy product copy may describe audit reporting, managed audit reporting, WooCommerce evidence summaries, consented funnel summaries, and server-side performance diagnostics where those features exist. It must not describe these reports as fraud scoring, chargeback protection, bank reconciliation, accounting automation, payment decisioning, or session replay.
Report summaries
Managed reports may summarize:
- product views,
- add-to-cart counts,
- checkout starts and step references,
- checkout failures from existing security evidence events,
- order conversions,
- coupon usage references,
- cart-abandonment references,
- strong-auth-at-checkout counts.
Reading hosted report status
Hosted reports show only stores owned by the signed-in Hub account. Choose a 7-, 14-, 30-, or 90-day preset, or enter a custom start and end date. Store, event, outcome, severity, stream, and flow filters scope the Custd queries, summaries, and managed reports. Display-safe text search is narrower: it filters connected-store rows by host or connection status, and you can sort those rows by activity, items needing review, or store name.
The selected range, filters, sort, expanded report detail, and page are encoded in the URL. You can reload, use browser back and forward, or share the URL with another authorized member of the same account without losing that view. A shared URL never grants access: signed-out users and members of another account cannot use it to read the account's rows.
The store table is paginated. Investigate this report narrows the URL to a managed report section while keeping the active filters. Store, event, outcome, severity, stream, and flow filters apply to the on-screen summaries, store table, managed report details, and CSV or JSON download. Text search applies only to connected-store rows and their corresponding export rows; it does not change summary totals or managed report details. An export is not a broader unfiltered data dump.
Treat the report status as part of the result:
- Complete means Custd has coverage for the requested window. A complete report may still contain zero matching events.
- Partial means some requested coverage is missing. Existing rows remain useful, but absence is not proof that no activity occurred.
- Stale means the newest observed source is older than expected. Check the store connection before relying on recent totals.
- Truncated means a configured row or bucket limit was reached. Narrow the window or filters; truncation does not silently become a complete result.
- Unavailable means the report could not run safely. Retry later or follow the visible support guidance rather than treating it as an empty report.
Partial, stale, and truncated results remain visible with their warning. Awthy reserves the unavailable message for a report that could not run safely; it does not hide usable rows behind outage copy. Loading is announced after you apply filters while Hub navigates to the validated URL.
Unknown capture, consent, schema, or export state stays unknown until Awthy has observed evidence. The interface must not turn missing evidence into a reassuring claim.
CSV and JSON exports contain only display-safe reporting fields for the active validated view. Their connected-store rows respect host/status text search, while their summaries and managed details retain the Custd query scope. Spreadsheet formulas are neutralized in CSV cells. Raw customer data, credentials, Custd tenant identifiers, SQL, storage locations, and provider payloads do not belong in reports or support screenshots.
If an export or report fails, keep the current URL, note the visible result state and non-secret error text, and retry once. If it remains unavailable, follow Hub Connection and provide support only the safe evidence listed there.
WooCommerce funnel panel
The WordPress admin WooCommerce funnel panel shows consented, minimized funnel summaries for the selected local window. It offers 24-hour and 7-day views, and the server enforces a 7-day maximum even when the site's audit log is retained longer. Use it to understand whether security and checkout events are being recorded, not to reconstruct a visitor journey.
The panel reads from local WordPress data. Hub-managed reporting can add broader retention, account-level aggregation, and hosted reporting workflows, but local free functionality should continue to work without HaakCo servers.
Do not interpret the panel as fraud scoring, payment decisioning, chargeback protection, bank reconciliation, accounting automation, or session replay.
UTM convention
Use these fields for launch links:
utm_source: channel or partner, for examplewordpress_org,email,community, oragency,utm_medium:listing,post,email,referral, ordirect,utm_campaign:awthy_launch_2026,utm_content: optional CTA or page variant.
Do not promote a product expansion candidate from analytics alone. Pair analytics with support, setup, discovery, or pilot evidence.