The consent handover pack: what agencies should give clients before go-live
The agency project ends. The consent setup lives on. And six months later the client emails, frustrated: the banner disappeared after a theme update, the reject button stopped working, or nobody knows what the CMP dashboard login is. The setup was fine. The handover was not.
A handover pack is the documentation and training bundle that lets the client's team operate a consent setup without breaking it. It takes a few hours to assemble, and it is the difference between a consent build that survives contact with the client and one that quietly decays.
What goes in the pack
Start with the consent inventory as a living document, not a PDF. A shared spreadsheet or doc listing every tracked script, its category, its consent gate, and who owns it. Mark which scripts the client's team must never add without review, and give them the exact process for adding a new one: notify the agency contact or follow the documented approval flow.
Include the login inventory. CMP account, tag manager access, the consent log location, and who holds admin rights. Agencies routinely retain admin access the client does not know about, or worse, the only person with admin access leaves the agency. List every account and name a successor.
Document the update procedure for the three things that break consent: theme or template updates, CMS plugin updates, and new scripts added by marketing tools. For each, spell out the check: verify the banner still fires, run a reject-all test, confirm the blocked scripts stay blocked. One page each. Clients will follow a checklist; they will not reverse-engineer intent.
The training nobody wants but everybody needs
A 30-minute recorded walkthrough beats twenty pages of prose. Record yourself opening the CMP, changing a vendor, and running a reject-all test in dev tools. The client watches it once and keeps it. When someone new inherits the site, the video is the onboarding.
The one slide worth making is the 'do not touch' slide. Which settings revert consent changes. Which tag fires everything. Which dashboard button publishes to production. Clients break consent setups most often through the interface, not through code, so name the dangerous controls explicitly.
How to price and position it
The handover pack is billable work, not a courtesy. Fold it into the project scope as a named deliverable, not as free documentation. Clients who see 'handover pack' as a line item understand it has a purpose; clients who receive documentation they did not pay for treat it as optional reading.
The pack is also the foundation of a retainer. Quarterly consent reviews, post-update verification, and a standing slot for new-script reviews are natural follow-on services. The handover pack documents the baseline; the retainer protects it. Agencies that hand over cleanly and offer to stay involved keep more clients than agencies that vanish.
The bottom line
Consent setups do not fail at launch. They fail in month three when the client's team makes a routine change with no idea what it touches. A handover pack, a login list, three checklists, and a recorded walkthrough keep your good work intact. Build it into every project, charge for it, and use it to sell the retainer that protects it.
Common questions
What is the most common post-handover failure?
Theme and CMS updates that silently revert consent configurations or drop the consent script from templates. A post-update verification checklist in the handover pack catches this before visitors do.
Should the agency keep admin access after handover?
It depends on the retainer arrangement. If the agency will run quarterly reviews, keep access with the client's knowledge and a documented list of who holds it. If not, transfer everything and name the client's successor explicitly.
How long should the handover walkthrough be?
About 30 minutes recorded, covering the CMP interface, changing a vendor, and running a reject-all test. Short enough to actually be watched, long enough to cover the dangerous controls.