Catalogue every activity that sells or shares personal information for cross-context behavioural advertising, assess each one before it starts under § 7150, and hold the summary a named executive attests to.
2Activity context assembledThe activity, whether it sells or shares, the purpose it serves and the day it went live
3Assessment evidence draftedThe activity, its purpose, the negative impacts, the safeguards and completeness
4Controls appliedTrigger checks, pre-processing date checks, re-review clock checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is attested at any of them — the agent is assembling, and the privacy lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the attesting executive to approve.
Anything thin
Adds a privacy counsel read first.
Privacy review
The assessment is held with its activity, its purpose and the safeguards behind it.
Attest · Append evidence · Send to privacy review
Attested — by a named executive▼
6Register and activity records updatedOnly where write access and records policy allow it
7Outcome evaluatedTrigger accuracy, assessment coverage, reviewer corrections and what the read found
Corrections
Each privacy correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Attesting to the § 7157 summary.
Deciding an activity needs no assessment.
Certifying the cybersecurity audit under § 7124.
Telling the CPPA an activity was lawful.
Automation boundaryAgent acts unaided
✓Maintain the register of every sell-or-share activity.
✓Run the § 7150 assessment before processing begins.
✓Track the re-review clock that a material change starts running.
✓Flag the activity whose stated purpose the record cannot evidence.
Nothing is attested or filed except by a named person, inside the agreed boundaries.
Judging whether an assessment may be attested.
Telling the CPPA the register is complete.
Setting the lawful purpose an activity runs on.
Changes to tags, audiences or destination records.
Example output
One activity, annotated
A marketing department with a direct relationship to its customers is not a data broker, and a sale is still a sale; this record is what one activity carried into the register.
Register entry · single activityIllustrative example
Activity
Recorded as
Trigger
Evidence of record
Confidence
Held for
Audience export, § 7150
Assessed before launch, safeguards recorded
Sell or share
Register entry, 3 August 2026
Held unattested
The attesting executive, by name
As receivedTaken from the tag manager export and the destination record — it reaches as far as those sources do.
What the record holdsTag manager exportDestination recordOpt-out signal log
Why no attestation hereWhether an assessment may be attested is reserved to a named executive.
ActionAttestAppend evidenceSend to privacy review
What the score decidesBelow the configured threshold an entry picks up a privacy read before the executive sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every activityFrom the system that runs it
03Evidence
Where the evidence is used
Our audience targeting copilot yields an audience — internal, continuous and per-segment; this one yields a dated external filing with a named signer, working on processing activities rather than people.
01Approved path
The register is the assessment
An assessment attaches to a processing activity, not to a segment, and § 7150 wants it settled before that activity begins.
02Human review
What was checked, and not found
The verbatim § 7157 wording and the title it demands of its signer, the revenue thresholds deciding who is caught, a retention period put at five years by some sources and three by others, the tally of comprehensive state privacy laws, the states whose statutes compel a browser opt-out signal and the per-day penalty sums were each checked against the CPPA consolidated text, which truncated on every fetch, and none was confirmed.
04Build an evidence trail
The activity, the purpose it serves and the executive who attested stay on the record.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Tag and pixel sourcesTag manager · containers Site and app SDKs
Ad platforms and destinationsConversions APIs · CTV Audience export records
Consent and opt-outConsent platform · GPC log Preference and signal records
Agent
Marketing risk assessment
Reads the activities Assembles the register Holds for the executive
Records and case systemsPrivacy tooling · ticketing Assessment and review records
Integration availability depends on the client's existing systems and API access.
Agent controls
Six gates between the model and the executive
Six gates set in order, the narrowest last. Whatever clears them all is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and trigger rules; on 3 December 2025 the CPPA fined ROR Partners for selling custom audiences while unregistered, which is why every destination is named.Track
L4TraceabilityRecord each activity, the assessment behind it, the register it feeds and every read of the file.Record
L3Executive releaseHold the summary for the attesting executive; the hold governs release, not whether an activity should ever have started.Gate
L2Scope guardrailsTest the register against 11 CCR §§ 7150–7157 as configured; behavioural advertising was cut from the final ADMT scope, which reaches significant decisions in finance, housing, education, employment and healthcare alone.Restrict
L1Confidence thresholdsRoute a thin assessment to a privacy read first; the PlayOn order of 3 March 2026 shows liability arising out of a single targeted campaign.Require review
Model coreEvidence assembled — the activities, their purposes, the safeguards and completeness
L1 – L2Test whether an assessment may stand
L3Puts the attestation in a person's hands
L4 – L5Keep the activity and the purpose behind it
L6Holds the assessment undrafted when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the register entry that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the summary a regulator reads
Depth of coverage ▼
E1Final-output evaluationDid the entry record what the activity actually does?
E2Step-level evaluationDid the agent read the right activity, the right purpose and the live destination?
E3Tool evaluationDid it read and write the correct activity and the correct assessment?
E4Confidence calibrationDo low-confidence assessments actually attract more privacy corrections?
E5Slice evaluationHow does performance change across specific activity types?
E6Business outcomeHow many entries needed a correction before the executive attested?
Floor — the register the business answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each placed at the stage where it first shows.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KD-03
Stale activity read
The destination read is not the one now in service.
Stage gathersThe tags, the purpose, the dates and the register
02 · Reasoning2 modes
KD-04
Trigger missed on launch
An activity starts before its assessment exists.
KD-06
ADMT scope read too widely
Ad targeting is worked as a significant decision.
Stage proposesActivities, their purposes and completeness
03 · Tool / write2 modes
KD-02
Thin assessment passed forward
An entry moves on without the privacy read.
KD-05
Bound to the wrong activity
An assessment is filed against the wrong tag.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KD-01
Attested, evidence unrecorded
The record shows an attestation but not what supported it.
Stage returnsThe summary an executive attests and a regulator reads
05 · Change / Version1 mode
KD-07
Silent trigger regression
A configuration change moves the trigger, not the register.
Stage tracksModel, prompt, trigger rules and register fields
Sev-1 · an activity live with no assessmentSev-2 · wrong evidence reaches the registerSev-3 · source degrades, entry held unattested
An activity-level assessment-coverage figure can read clean while third-party tags and SDKs carry most of the rework. Nestack reports the correction rate by activity type, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Third-party tags and SDKs
10.4%
3.6×
Review
CTV and in-app integrations
7.4%
2.6×
Review
Conversions APIs and server feeds
4.6%
1.6×
Watch
First-party owned channels
2.2%
0.8×
Normal
Bar: correction-rate lift vs. first-party channel baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unassessed activity costs
A cycle shuts when the unassessed pixel is a regression case. That suite is what the next register built is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on third-party tags and SDKs.
02Diagnose
The pixel a campaign team added in an afternoon, three years before anyone had to describe it, is read back until one cause remains.
03Improve
The change ships numbered, and the activities that forced it ride with it.
04Verify
Nothing releases while one touched activity case is still red.
05Learn
It is retained for good, and the assessment rules are amended in that same commit.
Learn → DetectThe return edge. The next cycle is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, register assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Sell-or-share trigger discovery and boundary work.
02Tag, SDK and destination sources.
03Activity-to-assessment and re-review clock mapping.
04Activity and assessment ingestion.
05Activity, purpose and record binding.
06Completeness scoring and review routing.
07Executive attestation workflow.
08Tag and destination-system integration.
09Trigger and materiality cases.
10Guardrails and attestation controls.
11Activity-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne activity type, one cycleProductionProduction assessment workflowAdvancedMultiple brands / entities
Introduced at Pilot
Register assembly to your activities✓✓✓
Attesting executive release✓✓✓
Sell-and-share inventory baseline✓✓✓
Introduced at Production
Reporting by processing activity—✓✓
Attestation workflow in your systems—✓✓
Approved write-back—✓✓
Tag-and-SDK integration—✓✓
Introduced at Advanced
Multi-brand registers——✓
Cross-period evidence packs——✓
Large tag estates——✓
Multi-clock retention controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, activity volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your activities and the destinations each one feeds→Activity inventory mapping and evidence captureWeek 1
02Representative tag, SDK and destination records→Record binding, trigger logic and the register baselineWeek 2
03Your purposes and the safeguards behind them→Activity mapping, trigger binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Tag, SDK and destination-source assessment, then integration setupWeek 2
05Registers you would not want examined→Trigger cases and failure-mode testingWeek 4
06What no risk assessment may establish→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named executive to attest→Attestation workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Every band below is worked time rather than drawn space, which is why the fifth of them holds two.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Privacy workflow discovery, activity mapping and the automation boundaryW2Source integration and the assessment-coverage baselineW3Register assembly, trigger logic and release controlsW4Evaluation suite, trigger cases and failure-mode testingW5Destination integration, pilot activities and targeted correctionsW6One assessment cycle run under the privacy lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth takes a second because the work does.
At the end of W6Validation closes on live registers, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Marketing AI agent
Build a risk assessment agent around the activity running today that a 1 April 2028 filing has to count.
Show us one activity and the record behind it. If your opt-out is honoured per device rather than per account, then that is the fact pattern the Disney settlement of 11 February 2026 turned on. Cybersecurity audits sit with the CISO and are a different lane.