Change one visitor notice and update every site
Runner writes, versions, serves and records the visitor notice itself, and checks each listed site's main address on a schedule for what is actually running. Change the organization policy once and every property follows, while a site can still set its own collection level and notice, marked as an override.
Built into Runner
- One update reaches every site through the embed already in place
- A scheduled check of each listed site's main address, with a review queue for what is running but not declared
- A preference centre visitors can return to
- Every choice kept with the version they saw
Worth knowing
The scheduled check reads a site's markup and headers on a few pages — it does not run the page, so a tag a tag manager loads at runtime is only governed once you declare it, and a site you have not listed is not checked at all. The ad industry's TCF string is built in but stays off until Runner's own CMP registration with IAB Europe is complete.
Your team stops shipping releases to change a banner
Each site carries the same one line of script, and the notice it draws is assembled from your organization's policy whenever that file is served. Reword the notice, restyle it, or switch it from informing to asking, once, and every site running the embed follows within minutes. Nobody opens a pull request in the product site, the docs or the blog.
Settings has a page called Who asks the visitor: every product in the workspace, how its notice is set, and the services the visitor's answer governs there. A site that collects while Runner draws no notice is listed first, because that's the row worth confirming. And one switch turns collection off on every site at once.
The scheduled check finds what got added, and a person decides what it is
Once a day Runner reads a few pages of each listed site and compares the third-party addresses and cookie names it finds with the services that site declares. It reads a cookie's name, never its value. When it recognises a service it suggests a category, but nothing reaches the notice until someone on your team picks one and confirms it — and from then on that site's visitors are asked about it.
Something new raises an in-app notification with a count and a link to the review queue, never the vendor's name, and email stays off until you turn it on. Setting a finding aside says it needs no declaration; it doesn't stop it running. A site that doesn't answer produces no findings, so a failed check never passes for an empty queue.
Each visitor gets the stricter answer, and every answer is kept
You set each site to ask before collecting or to collect and inform. Each visitor is shown whichever is stricter, that setting or the rule where they are, worked out as the page loads and never cached, and a region nobody has written a rule for gets the strict answer. A Global Privacy Control signal means no category is switched on for that visitor by default, on any site.
Every choice is recorded against the site it was made on: the categories, when and how the decision arrived, the copy variant on screen and the embed's version. The record holds no visitor identifier, a refusal is kept exactly like an acceptance, and your own scripts can read the same answer from window.runnerConsent instead of running a banner of their own.
The short version
Change it once and every site follows. The check runs itself. A person decides what each finding is.
Questions buyers ask
Do we have to redeploy every site to change the cookie banner?
No. The notice comes from the one line of script each site already carries, assembled from your organization's policy and cached for five minutes, so a change reaches every site running the embed within minutes without a release on any of them.
Can one site's notice be different from the others?
Yes, where the difference belongs to that site: its languages, its privacy link, its look, the services it declares, and whether it asks or informs. The site's settings page marks each override and says a later organization change won't reach it. The collection switch, data retention, the declared privacy regime and the registered domains stay organization-wide.
Does it find trackers we forgot to declare?
Yes, the ones a site's markup and headers name. Once a day it reads a few pages of each listed site and queues anything undeclared for review. It doesn't run the page, so a tag a tag manager loads at runtime is governed once you declare it, and a site you haven't listed isn't checked.
What does a consent record contain?
The choice, never the person. Each record holds the categories, when and how the decision arrived, how the site's notice was set, the copy variant on screen and the embed's version, against the site it was made on. There is no visitor identifier in it, and a refusal is kept exactly like an acceptance.
Does it produce an IAB TCF string?
Not today. The TCF string is built in and stays off until Runner's own CMP registration with IAB Europe is complete, and until then no TC string or vendor id leaves the notice.
Can we keep our existing analytics and tag manager?
Yes, they stay in place. Your page's own scripts can gate on the visitor's answer through window.runnerConsent, and where a site uses Consent Mode, the embed sends each decision as an update to the default your page sets first.
Use what already works
List the services already running on each site so the visitor's choice can govern Runner's collector and the processors you declare. The scheduled check shows what it found beside that list; a person confirms a finding before the notice changes. Existing tag and analytics tools can stay in place.
How teams often buy this job
Usually bought as Cookiebot, OneTrust or Osano.
CookiebotOneTrustOsanoTrademarks of their owners. No affiliation or endorsement.


