O2.05.3Queryable tracking scopedesignresearch

Tracking scope needs to be queryable

Aliases: tracking inventory · tracking-scope query · identity-linkage status

What it is

Queryable tracking scope lets a person inspect which applications, sites, devices, identifiers, data classes, and participants are currently included in linkage. It is not a copy of first-use disclosure: disclosure explains an impending flow, whereas a scope query is a continuously updated, traceable ledger of present state.

Why it happens

Tracking relationships change with sign-in, device replacement, new SDKs, partners, and retention. A one-time prompt quickly becomes stale. A single “allow tracking” switch also cannot reveal which identities and downstream processes it covers. Projecting runtime configuration and event lineage into a readable inventory supports review, challenge, and targeted adjustment.

Studying it

With accounts whose tracking graphs are known, vary signed-in devices, sites, preference state, and partners. Ask participants where one activity is being linked and what disabling one item would affect. Reconcile answers and interface entries bidirectionally with network requests, identifier maps, and processor records. A long inventory is not proof of completeness: vague aggregation can still hide gaps.

Where it stops holding

Exact fraud-detection features and linkage rules may be restricted, while their data classes, purpose, and scope remain visible. Delayed downstream revocation should not immediately appear as fully stopped; current, pending, and historical states need separation. Anonymous tracking cannot always be attributed completely to one person, so the interface should state the limits of device- or browser-level visibility.

Applying it

  • Organize around “what is being linked,” layering context, data class, identifier, purpose, recipient, and last activity.
  • Connect each entry to its governing choice and explanation, naming whether scope is account, device, or browser.
  • Keep an intelligible change record for additions, removals, and pending propagation while masking raw identifiers from shoulder surfers.
  • Generate expected graphs from a configuration matrix and reconcile them with requests, SDKs, and processor logs; treat either-sided omissions as transparency failures.

Related

  • Same group: O2.05.1 Cross-application and cross-site tracking needs explicit disclosure · O2.05.2 Opting out needs to be as easy as opting in
  • Adjacent: O2.04 Privacy Dashboard · O2.08 Disclosure of third-party data sharing
  • Search terms: queryable tracking scope · tracking inventory · identity linkage status

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O2.05.3