Governing the UTMs Your Agencies Build
Last updated
Hold every agency to one tagging standard, and keep the standard and the links when an agency leaves.
Agencies tag inconsistently because each one brings its own habits and nobody on the brand side checks before launch. Fix it in four moves: put the standard in the contract, give each agency a workspace that only offers your approved values, approve links before they go live, and make sure the links and their history live in your account, not the agency’s.
TL;DR
- Every agency tags in its own dialect. A PDF of rules does not change that; a builder that refuses bad values does.
- Write the standard into the contract or brief as a deliverable, with who owns the links and the history when the work ends.
- Give each agency its own workspace with only the values it should use. Your team keeps the definitions.
- Approve before launch. Review after the report arrives is an argument about data you cannot fix.
- Record who built each link inside the link itself, with an agency field, so a mistake traces back in one filter.
- When an agency is replaced, remove its people and keep everything they built: the records, the short links, and the click history your plan retains.
Every Agency Speaks Its Own Dialect
Brands that run most of their paid media through agencies tell us the same story on sales calls. It is especially common in pharma, healthcare and financial services, where one brand often has several agencies at once: one for search, one for social, one for display, a specialist for a single brand or market.
Each agency arrives with its own way of tagging. Call it the agency dialect: the casing, separators, source names and campaign patterns that agency uses for every client, because that is what its templates and its people already do.
An analytics lead managing URLs across several agencies summed up the problem for us: each of those agencies has its own habits, and none of them match. Someone puts an ID in utm_content. Someone else puts the creative name. A third agency puts the call-to-action text. All three are defensible. None of them join.
Their templates. An agency running dozens of clients does not rebuild its spreadsheet for yours. It fills its own columns and maps them onto your parameters as best it can. One marketing team we spoke with found its reports littered with plus signs. They were encoded spaces, left over from a pipe-and-space format inherited from agency work.
Their platform settings. Paid social teams love dynamic tokens. A token like {{campaign.name}} in Meta copies whatever the agency typed in Ads Manager straight into your analytics, spaces and capitals included. The guide to UTM codes for Facebook ads shows how those parameters work. Meta’s dynamic URL parameters include ID tokens such as {{campaign.id}} alongside the name tokens. An ID gives you a stable key to join on. A name gives you whatever was typed. An agency optimizing campaigns does not care which one you prefer unless someone tells it.
Their staffing. Agency teams turn over. The person who learned your convention in March is on another account by September, and the new person learned a different client’s convention first.
None of this is bad faith. Agencies are paid to launch and optimize campaigns, and your reporting taxonomy is invisible to them until it breaks a report someone cares about.
A stern email will not change any of it. So fix it with structure.
Write the Standard Into the Contract
Most brands hand the agency a convention document at kickoff and never mention it again. The agency reads it once. Then launch week happens.
Treat the tagging standard as a deliverable instead, with the same weight as the media plan. A financial services brand we spoke with did the first half of this well: it handed its agency a defined code structure, and the agency generated codes to that structure across many placements in a single run. The second half, checking what came back, was still a person reading a file.
Put these in the contract, the statement of work, or at minimum the campaign brief. Your legal or procurement team owns the wording; bring them this list.
- Where links are built. Name the tool or sheet. “Follow our convention” is unenforceable. “Build every tracked link in our builder” is a checkbox.
- Which fields are governed. Source, medium and campaign almost always. Content and term are where agencies want freedom. Decide per field, and write the decision down.
- The version in force. Conventions change. Say which version applies and how the agency hears about a new one.
- Dynamic tokens. List the tokens the agency may use and where. ID tokens are always fine as join keys, and GA4 accepts a
utm_idparameter for a campaign ID. A name token belongs in a grouped field only if the name in the ad platform was built from your standard; otherwise the governed value goes in that field. - Review before launch. State the turnaround you commit to, so approval never becomes the excuse for a late launch.
- Ownership. The ad accounts, the short link domains, the tracked links and their click history belong to the brand. Say so in writing before anyone needs it. Then write down the exit: at the end of the engagement, the agency hands over admin access to anything it set up for you, plus exports of its link sheets.
That last bullet is the one teams skip. It is also the one that costs the most, which is why it gets its own section below.
One rule to carry into every negotiation: the brand owns the standard, the links and the history. The agency borrows all three for the length of the contract.
If you are writing the convention itself for the first time, start with UTM naming conventions. Agencies follow a standard far more reliably when it reads like a picklist than when it reads like an essay.
Give Agencies a Workspace, Not a PDF
A PDF describes the rules. A builder enforces them. Only one of those survives launch week.
The usual workaround is a copy of the spreadsheet for each agency. A healthcare brand’s digital team walked us through exactly this: the internal team had one sheet, and the advertising agency worked from its own duplicate because it created far more UTMs, sometimes dozens at a time before a big launch. Two sheets means two sets of dropdowns drifting apart, and someone on the brand side updating both whenever a value changes.
A marketing ops lead at another multi-agency brand described the same maintenance loop from the other end: re-saving the file to several places every time a value was added, and wondering what to do once more agencies joined. What that lead wanted most was to stop maintaining the file at all.
Replace the copies with this structure.
One definition, owned by the brand. Mediums, sources, campaign components and the rules on each field live in one place. The agency does not get a copy to edit. It gets access to build against the one you maintain.
One workspace per agency. The agency’s people see their own workspace and the links built in it. They do not see your internal team’s work or another agency’s.
A slice of the values, not all of them. Your social agency has no business picking cpc from the medium list. Your search agency should not see TikTok as a source. Narrow each workspace to the values that agency should use, and the agency’s dialect is not on the menu.
In Terminus, the marketing taxonomy governance platform, that is the pattern built into governance models. You define fields, picklists and taxonomies once, with validation attached: casing corrected on the way in, spaces replaced, required fields enforced, patterns and uniqueness checked. Each agency works in its own workspace. On the Business plan, scoped workspaces let you choose which dropdown values each workspace can use, without duplicating the model.
It holds whichever way the agency works. One-off links in the Quick or Form builder, hundreds of rows in the Grid (on Business), a CSV round trip through Excel, or the API from the agency’s own tooling: every route runs the same validation, so a script cannot create what the form would refuse.
And when the convention changes, you edit a draft of the model while every agency keeps building against the published version. Publish, and every workspace moves at once. Nobody emails a v7 of the PDF.
If you want to see what a governed builder feels like from the agency’s seat, the no-signup playground runs in the browser. The template library has starting models if you would rather not begin from a blank page.
Approve Before Launch, Not After the Report
Validation catches malformed values. It does not catch a well-formed wrong answer.
An agency picks lead-nurture as the campaign goal when the brief said awareness. Both are valid picklist values. The analytics lead we mentioned earlier raised exactly this case, and the question behind it: can we reject a link while it is being created, rather than downloading everything, checking it, and sending it back? With so many people building links, a manual check on every batch does not scale.
That download-check-send loop is what most brands run today. A marketing ops lead at a multi-agency brand described an older version of the same process: agencies filled in a spreadsheet, the lead checked it, then signed off before they could use the links.
The trouble with review after the fact is timing. By the time someone notices, the ads have been live for a week and the clicks are already recorded under the wrong label. You cannot re-tag a click.
So move the review in front of launch:
- The agency builds and submits. Validation has already refused anything malformed.
- Someone on the brand side reviews the batch. They check the judgment calls: the right campaign and the right goal.
- Approve or reject, with a reason. A rejected batch goes back with a comment instead of an email thread.
- Only approved links go live.
In Terminus, approval workflows are on the Business plan and you switch them on per taxonomy, per workspace. That lets you require review for a new agency’s paid social links while your internal email team builds without a review step. A submission sits as a draft until the agency submits it for review. A workspace admin approves or rejects it, the thread keeps comments on the submission itself, and email notifications tell each side what happened. A batch with any invalid row cannot be approved. Once approved, the record is locked.
Do not require review for everything. Review is a cost, and a reviewer approving two hundred routine links a week stops reading them. Require it where the judgment calls live: new agencies, new markets, high-spend launches. Relax it for agencies that have earned trust, and say in the contract what earning it looks like.
Know Who Built What
When a bad value shows up in a report, the first question is always whose it is. Without an answer, the fix becomes a meeting.
One brand we spoke with had solved this inside its campaign ID. Each ID carried a short code for whoever created the link: the agency’s code or the internal team’s. The point was that any mistake could be traced to its origin, the brand or the agency, without an investigation.
That instinct is right, and the lesson is to put it in the data.
Add an agency field to the model. Make it a governed dropdown with one value per agency and one for internal teams. It is usually worth putting in the campaign name too, so it survives into every analytics tool that only sees the UTM string.
Lock it per workspace. If the social agency’s workspace can only pick agency-social, nobody can claim someone else built the link, and nobody forgets to fill it in. In Terminus, make it required and scope each workspace to its one value with a scoped workspace filter on the agency dropdown (Business plan). Without scoped workspaces, keep it required and check it at review.
Keep the workspace as a second answer. Every submission and record in Terminus belongs to the workspace it was built in, and a submission knows who created it. The agency field is the version of that answer that travels with the link.
The field pays off twice. It answers “whose mistake?” in one filter. And it lets you compare agencies by results. Terminus click analytics group clicks on its short links by the governed fields each link was built from, recorded at click time, so “clicks by agency” is a grouping in the report.
One caution. Use the field to find and fix problems, not to run a league table in the quarterly business review. Agencies that feel graded on tagging errors start routing links around the process, and then you have no data at all.
When the Agency Leaves, the Links Stay
Agencies get replaced. A review goes to another agency, or a new CMO brings a preferred partner. It is routine, and it is the moment a tagging program can lose years of work.
The failure looks like this. The agency built links in its own spreadsheet. It shortened them on its own link shortener account. Its people knew what q3_hcp_retarget_v2 meant. When the contract ends, the spreadsheet stays on the agency’s drive, the short links live in an account you do not control, and the only people who could explain the naming are gone.
The system walks out the door with the agency.
Check these before the transition, not during it.
Ad accounts. Make sure the ad accounts sit in your business, with the agency given access. Meta lets you give a partner access to assets in your business portfolio, and removing that partner revokes the access you granted. In Google Ads, an agency usually links its manager account to yours; if you unlink it, Google states that your account keeps its own campaign history. If the ad account was created inside the agency’s business portfolio, or your team has no admin user on the account itself, you are negotiating, not unlinking.
The links and their history. If agencies built in your account, their records stay when their people go. In Terminus, you suspend and then remove the agency’s members. The records they created stay in the workspace, with every field value intact, and a CSV export of the records takes one click if the new agency wants the history in a spreadsheet.
Short links. Links on your own custom domain keep redirecting after the people who made them are gone. Destinations stay editable, so a landing page that retires with the old campaign can point somewhere current. Terminus monitors the domain, and a fallback page catches any slug that does not exist, instead of a dead end.
Click history. Clicks stay attached to the links, grouped by the same governed fields, for as long as your plan keeps click history. Last year’s performance by campaign and agency is still there when the new agency asks for a baseline.
The next agency’s setup. Give the new agency its own workspace. Cloning a workspace copies its configuration, the taxonomies and the value filters, without members or records. The new team starts with your standard on day one instead of its own dialect, and the old agency’s work stays separate for comparison. That old workspace keeps its records, so it keeps counting toward your plan’s workspace limit; budget one workspace per agency, past and present.
This is why the ownership bullet belongs in the contract. Tooling can keep your links and history in your account. Only the contract settles who owns the ad accounts and the domains.
Start With the Agency That Builds the Most
You do not need every agency moved in the same quarter. Sequence it.
Start with the agency that builds the most links, usually paid social or search. Write the standard into its next statement of work, give it a workspace narrowed to its values, and require review for the first month. Watch what gets rejected; those rejections are your convention’s unclear spots, and fixing them makes the second agency easier than the first.
Then bring in the next agency. Then the internal teams that have been copying the agency’s spreadsheet.
If you are the one who will have to justify the change internally, the ROI of marketing taxonomy governance lays out how to make that case. And if you want to understand how a well-run agency thinks about this from its own side of the relationship, read the agency playbook in the Marketing Taxonomy Guide. It is written for agencies governing many clients, and knowing what a good agency expects makes you a better client to govern.
FAQ
Should agencies build UTMs, or should the brand build them?
Whoever launches the ad should build the link, because they know the placements. Brands that build every link themselves become the launch bottleneck. Let agencies build, inside a builder the brand controls, and review the judgment calls before launch.
What should an agency contract say about UTM tracking?
Where links are built, which fields are governed, which version of the standard applies, which dynamic tokens are allowed, the review turnaround, and that the ad accounts, short link domains, tracked links and click history belong to the brand.
Should agencies use dynamic tokens like {{campaign.name}}?
Only where the token resolves to a governed value. Build the campaign name from your standard first, have the agency paste that name into Ads Manager, and the name token then carries a value your reports can group on. ID tokens are always fine as join keys. Once the ad is live, don’t rename the campaign in Ads Manager; a renamed campaign can leave name-based values that no longer match what you reported before. The builder cannot see Meta’s separate URL parameters box, so spot-check the URL parameters on live ads.
Can each agency see only its own links?
Yes, if each agency works in its own workspace, as long as agency people are workspace members, not account admins. In Terminus, members see only the workspaces they belong to, and on the Business plan you can also narrow which dropdown values each workspace offers.
Do agency users need their own seats in Terminus?
Agency members are active members of your account, so each one counts as a seat while active, like anyone on your team. Suspending or removing a member takes them off the seat count, so an agency’s people only use seats while they have access. See pricing for current seat rates.
How do I trace a bad UTM back to the agency that built it?
Add a governed agency field to your model, include it in the campaign name, and lock each agency’s workspace to its own value. A mistake then traces back with one filter, in your builder or in analytics.
What happens to our tracking links when we change agencies?
If the links were built in your account on your own short link domain, the links keep working, and you remove the agency’s people while the records, short links and click history stay. If the agency built them in its own tools, those links and that history leave with it.
Does approving every agency link slow down launches?
It can, so match the review to the risk. New agencies and big launches get a reviewer; an agency whose submissions stopped coming back rejected gets a lighter touch. Put the turnaround in the contract either way.
Every account starts with a 21-day trial, no credit card required.