Testing and troubleshooting
Acceptance layers
- Schema and migration idempotency.
- Tenant/access invariants.
- Service health, readiness, capabilities and domain contracts.
- Authorized and unauthorized API behavior.
- Worker cycles and queue/dead-letter behavior.
- Authenticated dashboard route rendering.
- Provider sandbox observation with evidence.
- Dry-run activation and rollback.
- Tracking consent, deduplication, retention and privacy requests.
- Export, report delivery and expiring share links.
Acceptance matrix
| Layer | Positive path | Required negative/failure path | Evidence |
|---|---|---|---|
| Migration | Fresh apply and existing-volume upgrade | Repeat/idempotency or reviewed failure | Applied version and integrity query |
| Access | Authorized workspace read/write | Cross-workspace, expired key and missing permission | Status plus audit event where required |
| Service | Health, readiness, capability and representative domain call | Misconfiguration and dependency failure | Response schema and logs/metrics |
| Observation | Provider answer/evidence stored | Rate limit, timeout, partial run and retry | Run manifest, snapshots and failure counts |
| Usage | Provider event and pricing provenance stored in the same workspace | Cross-workspace provider, missing rate, mixed currency and metering persistence failure | Usage record, pricing source and operator signal |
| Intelligence | Versioned metric with sample/confidence | Low sample, unresolved entity and definition change | Metric snapshot and evidence links |
| Action | Approval, dry run, execute and verify | Rejection, duplicate, policy block, failure and rollback | Immutable action events |
| Publication | Preview, publish and read-after-write verify | Dead letter, unknown external state and rollback | Publication attempts/external reference |
| Tracking | Allowed-origin consented event | Invalid token/origin, denied consent and duplicate | Acceptance/deduplication counters |
| Attribution | Eligible touchpoints and outcomes | Low coverage and unattributed outcome | Model, window and confidence |
| Reporting | Generate, deliver and download | Delivery retry/dead letter and expired share | Immutable report and delivery attempts |
Reference end-to-end journey
- Create or select a Tenant and Workspace.
- Add brand, website and competitor targets.
- Configure and test a provider.
- Create topics, prompts and a prompt set.
- Run observations and inspect evidence.
- Validate metrics, sample gates and competitive denominator.
- Convert one finding to a recommendation and proposed action.
- Preview and approve a content/channel change in staging.
- Verify publication and send tracking events.
- Re-run monitoring and inspect attribution/experiment limitations.
- Generate export/report and test an expiring share.
- Confirm audit, retention and privacy flows.
Common problems
No default provider
Select an active provider as workspace default. AI operations without an explicit provider fail intentionally when no default exists.
Provider is degraded
Check endpoint, model, encrypted credential/secret reference, provider capabilities, API version, rate limits and egress policy. Do not expose the secret in screenshots or logs.
Usage record is unpriced
The provider returned no total cost and the workspace provider has no applicable input, output, or web-search rate. Enter the rates from the provider contract and use the correct three-letter currency. Historical events retain the pricing result recorded at execution time; changing a provider rate does not silently rewrite them.
Web search usage is zero
Confirm that an eligible direct provider profile has web search enabled and that the provider response exposes a search-request count. Generic OpenAI-compatible/custom providers cannot assert native-search support. Some providers charge for search without returning a separate request counter; do not invent a count from citations.
Usage estimate differs from the provider invoice
Confirm model, token units, search fees, currency, negotiated rates and effective date. GEO estimates do not apply free tiers, discounts, tax or undocumented provider charges. Treat the provider invoice as authoritative.
Provider succeeded but no usage event appears
Contact your GEO Platform administrator to check for a usage-persistence error and verify that the Organization, Tenant, Workspace, and provider ownership match. A metering failure does not convert a valid provider response into a failed observation, so a successful provider call can still require a usage-ledger investigation.
Share of voice is 100%
Verify that competitor targets exist, are classified as competitors, use the same project/market/language scope and have representative prompts. Inspect sample size and confidence.
Score contains commerce concepts
Current GEO scoring must not use checkout, cart, Masterpass or Mastercard. Determine whether the term occurs only in raw discovered endpoints or in score/signals/tasks/AI recommendations. Historical reports are immutable and may retain output from an older engine version.
Tracking has no events
Check token, site status, allowed origin, HTTPS collector, consent state, event name, browser blocking and retention. A platform API key cannot replace a tracking site token.
Publication does not execute
Check connection status, secret reference, allowlist, approval, policy result, schedule, idempotency state and dead-letter reason. Preview or simulation status is not publication.
API returns 403
Confirm product access, Tenant, Workspace scope, and required permission. Resource UUIDs do not grant access.
Release evidence
A production claim should identify whether validation covered source/type checks, production build, local containers, provider sandbox, real external publication, tracking traffic and post-action attribution. These are separate milestones.
Evidence labels
Use precise release language:
- Source verified: static/source contract inspection only.
- Build verified: production build completed; no runtime claim.
- Local runtime verified: local database/services and safe e2e completed.
- Sandbox verified: real third-party sandbox credential and API exercised.
- Production verified: approved production account/destination exercised.
- Outcome verified: post-action observation/tracking data collected and interpreted with limitations.