Consent purposes
Configure the actual purposes required by scripts, connections, and browser storage in each regional experience.
Open a banner, choose Consent → Purposes, and enable Enforce purposes per resource. Configure regional settings first. Saving creates a draft; use Review and publish to apply it to your site.
Define purposes and regional policies
The catalog includes Essential, Analytics, Advertising, Functional, and separate US privacy rights. Add custom purposes when your resources have other uses. A purpose's identifier remains stable when its name or translations change. Only Essential is always allowed. Hiding a purpose from visitors does not grant it.
Choose an existing regional experience in Consent → Purposes to edit its policy. Region matching uses the same countries, subdivisions, exclusions, and priorities as the banner's regional settings. State rules take precedence over country rules; higher priority wins within the same specificity. Catalog editing and integration settings are available in the advanced controls.
For each purpose, select its treatment:
- Opt-in: wait for the visitor's permission.
- Opt-out: allow until the visitor denies the purpose, subject to respected privacy signals.
- Not applicable: this policy does not require permission for that purpose.
The fallback protects visitors whose location is unavailable. It cannot default to an opt-out grant. Global Privacy Control applies to the US sale/sharing and targeted-advertising rights.
Assign scripts, connections, cookies, and storage
Open Scripts & Connections or Cookies and expand the resource's row. Its Consent requirements control lets you keep the category default or assign every actual purpose of that resource. A resource runs only when all its required purposes allow it. The Requires column summarizes its current draft requirements.
Without an explicit assignment, the resource uses its existing category purpose. Unknown purposes and invalid assignments remain blocked. The inventory's Labels are documentation and do not control enforcement.
Categorize unclassified resources or give them explicit consent requirements before publishing an enabled purpose policy. Publication rejects unresolved resources so enabling the policy cannot silently leave them permanently blocked.
A script used only for analytics can be assigned Analytics. A resource that also performs sale/sharing requires both Analytics and Sale or sharing. Classification depends on how you actually configure and use the resource, not just its product name.
In a configured US opt-out experience, an analytics-only resource may continue after a sale/sharing-only opt-out. The mixed-use resource is blocked. In an opt-in experience, analytics waits for permission. To make a sale/sharing opt-out also restrict the entire Analytics or Advertising category, select that mapping in the regional policy. These additional mappings are off initially; disabling one never removes an explicit resource assignment.
Assignments remain enforced when a resource disappears from a scan. Retired assignments appear in the editor and can be removed deliberately, then published.
HTTP-only cookies require control by the server that sets them. The browser cannot directly prevent or remove them. The editor identifies them as server-controlled. Network purpose assignments support fetch, XMLHttpRequest, sendBeacon, WebSocket, and EventSource. Other observed transport types are identified in the editor rather than offered unsupported assignments.
Preview and publish
The visitor test in the advanced controls evaluates the draft for a country, subdivision, privacy signals, and visitor choice. Compare analytics-only and mixed-use resources before publishing. The preview uses the runtime's shared evaluator; its decision table does not execute third-party scripts.
Google signals maps purposes to the seven supported Consent Mode keys. These signals govern supporting Google tags; they do not determine location or replace resource blocking. Custom purpose names do not become new Google or IAB keys.
Saving rejects conflicting edits rather than overwriting another editor's changes. Policy changes invalidate earlier grants for the changed policy; label and translation edits keep the consent revision. Publishing snapshots the catalog, policies, and assignments together. Rollback restores that configuration with a distinct consent revision.