Case Study 002

SimplyReport

The report that tells your client what it can't see.

Consultants spend their Mondays rebuilding the same slide deck. We set out to remove that. Then the thing being reported on changed underneath everyone, and the harder problem turned out to be honesty: half of what clients now ask about cannot be measured accurately by anyone, at any price. Most tools answer anyway. We decided the answer is the product.

1.6%

Average click-through rate for the top-ranking page on keywords where an AI Overview appears, measured December 2025. The same keywords returned 7.3% in December 2023.

Source: Ahrefs, 300,000 keywords
25%

The drop in traditional search engine volume Gartner forecast for 2026 — published February 2024. That window has now closed and whether it landed is disputed. We cite it as a forecast, which is all it ever was.

Source: Gartner, February 2024 press release

“Open GA4, screenshot the charts, retype the numbers, repeat for every client.”

Before a line of code, we ran roughly twenty interviews with independent SEO consultants and very small agencies. We asked what their week actually looks like, not what features they want. The same Monday came up again and again. Hours of it. Not analysis — transcription.

The client never logs in.

Consultants had all tried giving clients dashboard access. Clients don't use dashboards. They open a link, or they open an attachment, and that is the whole relationship with the data.

The paragraph is the product.

Nobody was paying for the charts. They were paying for the sentence that says what changed and what to do about it. The charts were evidence for the sentence.

That is a narrow, well-understood, boring problem, and there are competent tools that solve it. If nothing had changed, we would not have built this.

The deck still
measures clicks.

Search stopped being a list of links for a growing share of queries. Answers are assembled on the results page or inside an assistant, and the click that used to follow no longer does.

So the deck now reports a shrinking surface with total confidence, while the client asks a question the deck cannot answer: why doesn't ChatGPT mention us?

Consultants told us they get asked. They also told us they answer from instinct, because there is nothing on the screen in front of them that addresses it.

That is the gap. Not “reporting is tedious” — reporting is tedious and now measures the wrong thing.

Two changes in 2026 put AI data inside the exact connectors a reporting tool already uses. No new integration, no scraping, no vendor to depend on.

Search Console3 June 2026

Dedicated generative-AI performance reporting, isolating impressions from AI Overviews, AI Mode, and Discover generative features. Five dimensions: impressions, pages, countries, devices, dates.

The catch

Impressions only. No clicks, no click-through rate, no queries. Anyone selling you an “AI click rate” from this data is deriving it. Rollout also began with a subset of properties rather than all of them, so absence of the report is not absence of the traffic.

Source: Google Search Central
Google Analytics 42026

A native AI Assistant channel in the Default Channel Group, matching traffic where the medium is ai-assistant.

The catch

The assistant list is Google’s, and Google states it is proprietary and unpublished. Perplexity is not on it and lands in Referral. Traffic from AI Overviews and AI Mode stays inside Organic Search, so it never appears in the AI channel at all.

Both catches are why we think there is room here. The data is now available to everyone; the willingness to publish its limits next to it is not.

Connect once. Send a link. The client needs no account.

Connect Google Analytics 4 and Search Console once. Get a branded report with written analysis, delivered by link or by email. No login, no software.

One report, both surfaces

Classic search performance and AI-assistant visibility in the same document, for the same period, with the same caveats attached to each. Not two tools stapled together.

The analysis is written, not templated

Not “sessions grew 27%” — the reader can already see that in the table. The generated commentary leads with movement: which page climbed, for which query, and what to do about it. Where the data does not support a cause, it says so instead of inventing one.

Native multilingual, not translation

Analysis is generated in the target language from a prompt authored in that language, not written in English and passed through a translator. We could not find a competitor offering this. For a consultant serving clients outside English, the alternative today is rewriting the summary by hand.

Honest limits are printed in the report

Every section states what it cannot measure. That is a deliberate commercial bet, described below.

Published pricing

$0Free
$29Solo
$59Pro
$129Agency

Per month.

Crowded
Market.

Case Study 001 described an empty market. This is the opposite, and pretending otherwise would be the first dishonest thing on this page.

Established client reporting

Mature, integration-rich, and priced per client. These tools are good at what they were designed for. Their templates were designed before June 2026.

AgencyAnalytics

Roughly $12–20 per client per month. 85+ integrations.

DashThis

From roughly $33. AI-written insights on every plan, including the cheapest.

Whatagraph

From roughly €199.

Octoboard · Zite · Looker Studio

Looker Studio at zero, and two more competent options in between.

AI visibility platforms

New, well funded, and aimed elsewhere. These tools track prompts across engines far more deeply than we intend to. Most have thin white-label and thin multi-client reporting, because agencies are not their primary buyer.

Profound

Raised at a $1B valuation. Sells to enterprises.

Peec

Reached meaningful ARR inside a year. From roughly €89.

Otterly

Starts at roughly $29. Ships an API.

Where that leaves the gap: nobody ships one client-ready, white-labelled report that covers classic search and AI visibility together, states the measurement limits of each, and costs less than the AI-visibility tools do on their own. That gap is narrow, and it will not stay open indefinitely. It is a position, not a moat.

Competitor prices researched August 2026 and stated as approximations. They move.

The strongest product decisions on this project were subtractions.

We are not building prompt-level AI visibility tracking

Asking hundreds of prompts across several engines, daily, and diffing the answers is a real product with real infrastructure cost, and several well-capitalised companies are already building it. If our customers eventually need that depth, the right move is to integrate a provider by API and treat them as a supplier, not to spend a year losing to them.

We stopped leading with “AI-powered analysis”

In 2024 that was a differentiator. In 2026 the cheapest plan of an incumbent includes AI-written insights. A feature everybody ships is a checkbox, not a reason to switch.

We killed a feature that measured the wrong thing

An early build asked a language model to simulate how ChatGPT would answer a question about a brand, and reported the result as visibility data. It produced convincing output. It was not a measurement of anything — a model’s guess about another model’s behaviour is a guess. It is switched off at the route boundary rather than left running behind a flag.

Not a dashboard. Not rank tracking. Not a site auditor

And not more integrations. Each of those is a request we have heard, and each of them turns this into a worse version of a tool that already exists with eighty-five integrations and a decade of head start.

The disclaimer is the feature.

Every competing tool has a commercial incentive to present its numbers as ground truth. We are betting the opposite is worth more, because of what happens after the report is sent.

The consultant forwards a report. The client Googles one of the numbers, or asks their nephew, or asks ChatGPT. If the report said something confident and wrong, the consultant is the one who looks careless. If the report already said this figure counts impressions only, and here is why no tool can give you AI clicks today, the consultant looks like the person who knows the terrain.

AI impressions have no click data

Google does not provide it. Nobody has it.

AI Overviews traffic is counted as organic search

It does not appear in any AI channel, in our report or anyone else’s.

Many AI referrals arrive with no referrer at all

Assistant traffic is systematically undercounted, everywhere, by everyone.

An API response is not the consumer app

What a model returns to a developer is not necessarily what a person sees in the product.

We hold ourselves to the same rule on this page. Where a number comes from someone else's research, the source is named next to it. Where we have not verified something ourselves, we say so rather than rounding it up into a claim.

AI Crawler Access Check

Before the reporting app is finished, one piece of it runs in public, free, with no signup and no account: a check that tells any site owner which AI systems can actually reach their pages. It takes about two seconds.

Reads robots.txt the way the specification says to

Not the way most checkers do. Longest matching user-agent group rather than the first one. Most specific path wins. Allow beats Disallow on an equal-length tie. An empty Disallow means allow everything. A 5xx response means cannot determine, never blocked.

Probes the homepage with each bot’s own user-agent

Because a CDN or WAF rule can block a crawler that robots.txt welcomes. A file check alone would report the opposite of the truth.

Checks what an assistant finds once it arrives

Whether content is in the HTML or waits for JavaScript, whether there is structured data, a heading, a visible date, an llms.txt.

Generates a fix

Built from what is actually wrong on that site, carrying over the site’s existing rules instead of pasting a generic block.

24

Agents tracked, in four groups — retrieval and user-triggered, training crawlers, control tokens that are not crawlers at all, and social link-preview bots. Each carries a recorded verification date and an automated check that fails the build when an entry goes stale.

The part we are most pleased with is what the tool refuses to report.

Four commonly listed social crawlers are not included. Every source we found for their user-agent strings was a bot directory citing another bot directory, with no vendor documentation behind any of them. Shipping them would have made the list longer and the tool less honest. Their absence is rendered on the results page with the reason, and a test keeps them out.

Three agents are documented by their own vendors as not honouring robots.txt. The tool shows the rule and declines to count it as a block, because a rule that is not obeyed is not a control.

Also live A second free tool that outputs the exact GA4 custom channel group definition for AI assistant traffic, plus a plain list of what the native channel still misses.

Run the check on your domain →

Reporting App

  • Next.js 16 · App Router
  • Turbopack
  • React 19 · TypeScript, strict
  • CSS Modules — no utility framework
  • Supabase Postgres
  • Recharts (web)
  • Hand-drawn SVG charts (PDF)
  • @react-pdf/renderer · Resend · Zustand

Marketing & Tools

  • Next.js · TypeScript
  • CSS Modules
  • MDX with a static import registry
  • Zero third-party trackers beyond one analytics script
  • No cookies, no local storage
  • Asserted by end-to-end test, not by policy page

Data Layer

  • One OAuth flow covering Analytics and Search Console
  • Refresh with an expiry buffer
  • Disconnect revokes at Google
  • Graceful degradation per data source
  • Prior-period joins with a deadband
  • Climbers, droppers, new and disappeared queries

Reliability

  • Freshness gates in CI on every dated claim
  • Tests that assert served HTML contains no invented figures
  • Design rules enforced against computed styles, not source

We audited our own live tool.

The crawler tool takes a domain from an anonymous stranger, makes about a dozen server-side requests to it, follows redirects, and renders part of what comes back onto a public page. That last property is what makes it interesting to attack. We audited it before promoting it anywhere, and it did not come back clean.

The primary finding was a class of server-side request forgery: the code validated one hostname and connected to another, because a normalisation helper written for form input had been reused as a security check. Two names that differ by a prefix are two different DNS records, and an attacker controls both. A second finding was the classic version of the same mistake — validating an address and then letting the HTTP client resolve the name again independently.

The fixes, in order

  1. Validate the hostname that will actually be connected to, at the connection site.
  2. Resolve names through a single validating resolver that hands the socket only the addresses it approved, so checking and connecting are one step that cannot disagree.
  3. Allow-list schemes and ports on the initial request and on every redirect hop.

How we know they work. Every test targeting these findings was confirmed failing against the unfixed code before the fix landed. A hostile fixture server sits in the suite with assertions that it is never contacted, each preceded by a positive control so that “zero hits” cannot pass on a server that failed to start. A coverage test asserts every outbound request in a full check carries the guarded resolver, and it was verified to fail when that resolver is removed from a single call site.

A test that has never failed is not evidence. That is the whole method.

A reporting tool that looks like a template implies template output.

The visual system exists to say the opposite before a single number is read.

Seven colours. No others, anywhere.

A near-white ground, white reserved exclusively for the artifact under review, two levels of ink, one hairline rule, one accent used only for the primary action, one flag colour used only for a revealed error.

Three typefaces, three jobs.

A grotesque for interface, a serif for content under review, a mono with tabular figures for timings and trace data. No display face.

Rules enforced by build scripts and end-to-end assertions, not by convention.

  • No coloured top bars
  • No elevation shadows, focus rings only
  • No border radius above 2px
  • No white fill outside the artifact class
  • No scroll-triggered or entrance animation of any kind

Three motions are permitted, all opacity, all inside a reduced-motion guard: a state replacement in the tools, a copy confirmation, and the crawler check's pending phases.

The distinction that took longest: a card versus a panel.

A card announces itself with elevation and colour — that is the tell that says “template.” A panel is a tonal surface with a hairline that groups related things — that is layout. Removing all containment made the pricing page read as four unrelated lists. Panels fixed it without reintroducing the tell.

No audience, no advertising budget, no launch event.

The sequence is built so each step earns the right to the next one.

Be useful before asking for anything

Free tools with no signup, no account, no email gate. They answer a question consultants are being asked by clients right now, in seconds. If a tool is genuinely useful, it gets forwarded; that is the only distribution we can afford.

Ten people, one question

The free tool goes to a small number of practitioners who actually run agents or do SEO for a living, with a single question: run it on your domain — did it tell you anything you didn’t know? Ten honest answers decide whether this deserves a wider launch. A launch to strangers before that question is answered is a coin flip with one flip.

Write only from primary sources

Short posts on things we verified ourselves, with every claim linked to the vendor’s own documentation. The first is about a change to default AI-bot behaviour at a major CDN and the part of it that could affect ordinary search rankings. The second is a correction: our own tool reported six blocked bots for a domain, and was right — about a parked page at a domain that was not the company’s real site. That produced a genuine finding about how parking pages redirect, and it shipped as a feature.

Go back to the twenty

The consultants who described the Monday problem have not yet been asked the AI question. Three questions: has a client asked about AI mentions in the last six months; how do you answer today and how long does it take; have you tried an AI visibility tool and what happened. Those answers set the roadmap and the pricing page, not a market report.

Charge

Free, then $29, $59, $129. The paid tiers exist to be enforced from the first paying customer, not retrofitted.

What we are explicitly not doing: paid acquisition, cold outreach at volume, launch-day theatre, or writing a single thing we have not verified.

Publishing these is part of the same bet as printing the limits inside the report.

We depend on two Google connectors

Both changed in our favour this year. They can change again, and the generative-AI reporting is still rolling out — whether the API exposes it on the same terms as the interface is not something we take on trust.

The measurement gaps may close

If Google ships AI click data tomorrow, honesty about its absence stops being a differentiator. Then the differentiator has to be the report itself.

The category is funded and we are not

Our answer is scope: we are not trying to be an AI visibility platform. We are trying to be the report a consultant sends on Monday.

Solo capacity is the hard constraint

Every feature is measured against it. That is why the list of what we did not build is longer than the list of what we did.

A tool that says “I don’t know” is more valuable than one that guesses

The temptation on every screen was to fill the gap with an estimate. The estimates would have been plausible and unfalsifiable. Refusing to produce them cost us features and gave us the only position on this page that a better-funded competitor cannot copy without contradicting their own marketing.

Verify the thing, not the shape of the thing

A large test suite proved our data layer had the right shape. It proved nothing about whether the numbers were right, because it had never met a real property. The same lesson arrived twice from the other direction: our own published advice about a vendor’s change was wrong twice, and both times the correction came from reading the vendor’s own documentation instead of the summaries of it.

Subtraction is the product decision

Four earlier product ideas at this lab were derived from market reports rather than from talking to a buyer, and each collapsed on the first concrete detail. This is the one with twenty interviews behind it, and its best decisions have all been about what to leave out.

Reporting that admits
what it can't see.

SimplyReport is in build. The free tools are live now, and they answer the question your clients are already asking.

← Back to Work