演示真实运行记录 · claude-sonnet-5-5 · 2026年10月
Create a lean tracking plan for a global SaaS product whose primary funnel is landing-page visit, demo request, workspace signup, first project created, and paid subscription. Include event names, essential properties, triggers, validation steps, and privacy safeguards. Do not put personal data in events. Use the analytics skill.
Skill: analytics
Lean Tracking Plan: Global SaaS Funnel
Tool-agnostic. It works with GA4, Mixpanel, Amplitude, PostHog or Segment. I didn't find a product-marketing context file, so I assumed no existing tracking and no chosen tool. Last updated: 2026-10-04.
1. Decisions this plan informs
| Question | Decision |
|---|---|
| Which channels and regions drive demos and signups? | Budget and localization |
| Where is the biggest drop-off between funnel steps? | CRO and onboarding priorities |
| How long does signup take to reach first project? | Activation fixes |
| Which plans convert to paid, and how fast? | Pricing and packaging |
2. Conventions
- Event names:
object_action, lowercase snake_case, past tense. There are 5 funnel events plus 1 optional. - Properties: snake_case with enumerated values. Don't send free text.
- Identity: use an anonymous
anonymous_id(first-party, random) before signup. After signup, use an opaqueaccount_id(internal UUID). Never use email, name, or phone as an ID. - Server-side events: fire
workspace_signed_up,first_project_createdandsubscription_startedfrom the backend. This is more reliable and ad-blocker-proof, and it ensures the event fires only once.
3. Events
Funnel events
| # | Event | Trigger | Source |
|---|---|---|---|
| 1 | landing_page_viewed |
First pageview of a session on a marketing landing page (not every page view) | Client |
| 2 | demo_requested |
Demo form submitted and server returns 2xx (not on button click) | Server/Client |
| 3 | workspace_signed_up |
Workspace record created successfully | Server |
| 4 | first_project_created |
First project created in a workspace (is_first enforced server-side, once per workspace) |
Server |
| 5 | subscription_started |
Payment provider confirms first paid subscription (webhook) | Server |
Optional (add only if needed)
| Event | Why |
|---|---|
cta_clicked (cta_id, page_group) |
Diagnose the landing page → demo/signup step. Skip it if page-level conversion is enough. |
Properties
Common properties (attach to every event):
| Property | Type / values | Notes |
|---|---|---|
anonymous_id |
random UUID | First-party, rotates on consent withdrawal |
account_id |
opaque UUID | From event 3 onward |
region |
amer, emea, apac, latam |
Derived from country, no IP stored |
country |
ISO 3166-1 alpha-2 | Derived server-side, then IP discarded |
locale |
e.g. en-US, de-DE |
Browser or site locale |
device_category |
desktop, mobile, tablet |
|
app_version |
semver string | Helps debug releases |
Event-specific properties:
| Event | Properties |
|---|---|
landing_page_viewed |
page_group (home, pricing, solution, campaign), utm_source, utm_medium, utm_campaign, utm_content, referrer_domain (domain only) |
demo_requested |
form_id, company_size_band (1-10, 11-50, 51-200, 201-1000, 1000+), use_case (enumerated), utm_* carried from first touch |
workspace_signed_up |
signup_method (email, google, sso), plan_type (free, trial), utm_* carried from first touch, days_since_first_touch |
first_project_created |
project_type (enumerated template), minutes_since_signup, creation_method (template, blank, import) |
subscription_started |
plan_id, billing_interval (monthly, annual), value (number), currency (ISO 4217), seats_band, days_since_signup, is_trial_conversion (bool) |
4. Funnel and conversions
landing_page_viewed → demo_requested (branch, not a required step) → workspace_signed_up → first_project_created → subscription_started
- Primary conversions:
workspace_signed_up,first_project_created(activation),subscription_started. - Secondary conversion:
demo_requested. - Funnel window: 30 days from first touch to signup, 90 days to paid. Report by
region,utm_mediumandplan_id. - Counting: once per workspace, except
subscription_started, which counts once per subscription.
5. Validation steps
- Spec review: Check every event and property against this document. Reject undocumented properties through a schema/allowlist in the tag or SDK layer.
- Staging test: Run the full funnel on staging with debug tools (GA4 DebugView, GTM Preview or the vendor's live event view). Confirm that each event fires once, in order, with the right property types.
- Duplicates: Reload the thank-you page, double-click submit and use the back button. Event 2–5 must not re-fire.
- Server vs. client parity: Compare backend records (demos, workspaces, projects, subscriptions) with analytics counts for a day. Aim for a gap under 2–3%, and investigate anything beyond that.
- Identity stitching: Confirm
anonymous_idlinks the landing page to signup, andaccount_idpersists after signup. Check that UTMs on the first touch carry to events 2–5. - Cross-region and cross-device: Test in at least one EU, US and APAC locale, on mobile and desktop, with an ad blocker on and off.
- Consent test: With consent denied, confirm no analytics cookies or client events fire (see section 6). Verify that essential server-side counts follow your legal basis.
- PII scan: Search sample payloads and warehouse columns for
@, phone patterns and name-like strings. Run it automatically each week. - Post-launch monitoring: Set alerts for a >30% day-over-day drop in any event, a sudden spike in duplicates, or a new unexpected property.
6. Privacy safeguards
- No personal data in events: No email, name, phone, IP address, free-text fields, company name, or payment details. Use bands (
company_size_band) and enumerations instead of raw values. Form fields stay in the CRM, not in analytics. - Identifiers: Opaque, random, first-party IDs only. Don't use hashed email as a user ID (it's still personal data under GDPR). Don't pass IDs to ad platforms without consent.
- Consent: Use a consent management platform with region-aware defaults: opt-in for the EU/UK, Brazil and similar, and opt-out where law allows (for example, parts of the US). Use consent mode or equivalent, and block client-side tracking until consent is granted. Respect Global Privacy Control signals.
- Geo: Resolve country at ingestion, then discard the IP. Turn on IP anonymization or "don't store IP" in your tool.
- URLs and referrers: Strip query strings except an allowlist of
utm_*. Logreferrer_domainonly. This prevents tokens, emails or invite codes in URLs from leaking. - Data residency and transfers: Choose an EU-hosted region for EU traffic, or use SCCs/DPA with the vendor. Record vendors in your processor list.
- Retention and deletion: Set event retention to 14 months or less (or per your policy). Support deletion by
account_idandanonymous_id, and propagate deletions to downstream tools. - Access: Restrict raw event access to named roles. Use aggregates in dashboards.
- Governance: Any new event or property needs a plan update and privacy sign-off. Keep a change log.
7. Implementation notes
- Use a single data layer or SDK wrapper (
track(name, props)) that enforces the schema and strips unknown keys. This is the main defense against accidental PII. - Persist first-touch UTMs in a first-party cookie or local storage (with consent), and send them to the backend at signup so server-side events can carry them.
- Send
subscription_startedfrom the payment webhook with an idempotency key (the subscription ID) to prevent duplicates. - Choose the tool based on need. Marketing-site attribution suits GA4. Funnel and cohort analysis suits Mixpanel, Amplitude or PostHog. Segment is worth it only if you need routing to several tools.
8. Open questions
- Which analytics tool or tools are you using or planning?
- Is
demo_requesteda separate path, or can a demo requester also sign up directly? This changes how to read the funnel. - Is there a free trial or freemium plan? This affects
plan_typeand thesubscription_starteddefinition. - Which regions need strict opt-in consent (EU/UK, others)?
I can turn this into a spreadsheet or JSON schema (for runtime validation), or draft the data layer code for your stack, if that would help.
Real run recorded with claude-code / claude-sonnet-5-5. Output is shown verbatim, unmodified.
规划、审计和排查 GA4、GTM、UTM、转化与产品事件追踪。
说明与风险
使用前请审查数据来源、适用的隐私义务和任何外部服务行为。