Measuring what a website does
Most website reporting measures activity, not effect. A measurement stack that answers whether the site changed anything, and admits when it cannot.

Open the monthly report of most small companies and you will find a chart going up and to the right, sitting above a paragraph that says something worked. Sessions rose 12%. Pageviews rose 9%. Nobody asks the obvious next question, which is: up from what, compared to what, and would it have moved anyway. The report exists because reporting is expected, not because anyone downstream can act on it, and the two most common numbers in it — sessions and pageviews — are the two least likely to tell you whether the site changed anything.
The honest counter-argument deserves saying first, because it's the one most measurement critiques skip past. More data is not, in itself, a bad idea. Instrumenting everything you can and deciding later what matters is a defensible approach for a company running enough traffic to make the noise average out. The failure is not tracking too much. It is reading small numbers as if they were large ones. A company converting 40 enquiries a month that watches its conversion rate move from 2.1% to 2.4% and calls it an improvement has usually just watched two enquiries happen instead of one, in a month that had one more Tuesday in it. The number is real. The story attached to it is invented.
That is the actual argument of this piece: for the overwhelming majority of small and mid-sized companies, the constraint on measurement is not tooling, dashboards, or attribution sophistication. It's sample size. Below roughly a hundred conversions a month, most of what looks like analysis is arithmetic performed on too few events to support it, and the fix is not a better tool — it's a smaller, more honest stack, plus the discipline to say when the data cannot decide something.
The four numbers worth a monthly report
Start from what a business actually needs to know, not from what a tracking script happens to collect by default. A monthly report earns its place if it answers one of these: did we get more of the thing that matters, did the mix of who's asking change, did anything break, and is there a reason to believe next month will look different. Four categories of number answer those questions. Nearly everything else is decoration.
Conversions, counted, not estimated. Enquiry form submissions, calls booked, quotes requested, demo sign-ups — whatever the site's one job is, count the actual completions of that job. Not clicks toward it, the completions.
Conversion rate by source, not overall. The overall rate tells you almost nothing on its own; the same number split by where the visitor came from tells you where quality and quantity disagree, which is usually the more interesting fact.
Time to first response and time to close, for whatever the enquiry turns into. These aren't website metrics in the traditional sense, but they're the numbers that connect the site to revenue, and most companies keep them somewhere else entirely — a CRM, a spreadsheet, a salesperson's memory — disconnected from the report that's supposed to explain performance.
Self-reported source, which the next section covers on its own, because it deserves to.
Sessions, pageviews, average time on page, and bounce rate don't make this list, and the omission is deliberate rather than an oversight. Sessions go up when a bot crawls the site, when someone bookmarks it and revisits out of habit, when a single visitor's session gets split across a device switch. None of that is the business doing better. We've made the fuller case for a metrics list built this way in the only website metrics that mean anything, and the underlying logic there is the same one running through this piece: a number belongs on a report only if a plausible change in it would change what someone does next.
Worth saying here, because it changes shape entirely at the small end: a one-person site built to do one job — a freelancer's page, a consultant's CV turned into a URL — often doesn't need any of the above. Tools like reach exist for exactly that case: you upload a CV and a photo, the page is generated in about twenty seconds, and you can be live at a free subdomain in under two minutes. But reach also has no visitor analytics built in and no custom code field to paste a tracking script into, so the measurement stack this article describes largely doesn't apply to a site built this way — there's nowhere to hang the instrumentation. What's left, for a page like that, is the crudest and often the most honest signal available: what a person tells you when they email you, because the contact section is a mail link rather than a form with fields to capture anything else. That's a real constraint, not a workaround, and it happens to be a preview of the argument this whole piece is making about bigger sites too — that the fallback, when instrumentation runs out, is asking directly.
How many conversions before a change is even detectable
This is the part most reporting skips, and it's the part that would change most companies' behaviour if they actually did it once.
Whether a change in a rate is real or noise is a statistics question with a standard answer: a two-proportion test, comparing this month's conversion rate to last month's (or to a baseline period) at a stated confidence level. You don't need to run the test by hand — any basic A/B calculator does it — but you do need to feed it your actual numbers, and the numbers most small companies have are smaller than they think.
Work through what that means concretely. A site converting at 3% needs roughly a few hundred visitors on each side of a comparison before a move of a couple of percentage points clears the bar of "probably real" rather than "probably noise" — and that threshold gets sharply worse, not better, the closer the true rate is to the one you started with, because small absolute differences between small rates are exactly what statistical noise looks like. A company with 3,000 monthly visitors converting at 3% gets about 90 conversions a month. Two consecutive months of that company, compared against each other, will usually not clear significance even with a real, if modest, underlying improvement. A company with 300 visitors a month at the same rate gets 9 conversions, and at that volume nothing short of the rate roughly doubling will read as anything other than chance.
The practical floor, stated plainly rather than derived to three decimal places: under about a hundred conversions a month, treat month-to-month rate comparisons as description, not diagnosis. You can still watch the count. You can still watch the source mix. What you can't honestly do is tell a client or a boss that last month's dip or bump means something, because at that volume it usually doesn't, and saying otherwise trains everyone in the room to make decisions off noise.
This is also where most of the tooling debate becomes beside the point. Whether the platform underneath is GA4, Plausible, or raw server logs changes what you can measure and how privacy-respecting the collection is, not whether nine conversions in a month are a trend — that's a sample-size problem no platform solves. We go through the tooling trade-offs specifically in GA4 versus Plausible versus server logs, and the short version is that the choice of tool matters far less than most teams assume it does, right up until the point where compliance or data ownership makes it matter a great deal.
Self-reported attribution is the cheapest fix available
Platform attribution — the reports inside GA4 or an ad platform that assign a conversion to a channel — has gotten worse over the past several years for reasons outside any one company's control: cookie restrictions, in-app browsers that strip referrer data, ad blockers, multi- device journeys that no cookie can stitch back together. None of that is a conspiracy against small businesses. It's the consequence of browsers and platforms making privacy trade-offs that happen to break a measurement technique built for an earlier web. The result is that the attribution report inside most ad platforms tells you the platform's version of events, and that version is structurally biased toward crediting the platform.
The cheapest correction available to almost any company is not a better attribution model. It's a single field, added to the enquiry form, that asks the person how they found you — a dropdown with five or six options and an "other" free-text field, not a mandatory essay. It costs nothing to build, it isn't blocked by any browser setting, and it captures something a cookie-based system increasingly cannot: the visitor's own account of what actually made them act, as opposed to which channel happened to fire the last tracked click before the form submitted.
The two sources disagree more often than people expect, and the disagreement is informative rather than annoying. A platform report showing organic search as the top converting channel, next to a self-reported field showing half those same people typed "recommended by a colleague," is not a measurement error to be reconciled — it's two different true facts. The click that converted and the reason the person clicked are not the same event, and conflating them is most of what goes wrong when a company reads attribution reports as if they were causal explanations. We've written the fuller argument for why platform attribution should be read as a story rather than a ledger in attribution is mostly a story; the self-reported field is the practical antidote, not a replacement for the platform data but a check against trusting it more than it deserves.
One caution worth stating plainly: self-reported data has its own bias. People report the channel that's easiest to name, which tends to overweight anything with a brand name attached — "Google" covers organic search, paid search, and Google Maps in most respondents' heads — and underweight anything word-of-mouth or forgotten. Treat it as a second, imperfect signal that corrects the first, imperfect signal in a different direction, not as ground truth on its own.
A metric that diagnoses is not a metric that scores
The distinction worth keeping in your head through all of this: some numbers exist to score performance, and some exist to diagnose a problem, and they get used interchangeably far too often.
A scoring metric answers "is this good." A diagnostic metric answers "what's happening, and where." Conversion rate is closer to a scoring metric — it compresses a lot of behaviour into one number that goes up or down. Conversion rate broken out by source, by device, by landing page, or by time of day is diagnostic — it doesn't tell you if you're doing well, it tells you where to look next.
The mistake most reporting makes is treating scoring metrics as if they were self-explanatory and skipping the diagnostic layer entirely. A report that says "conversion rate dropped from 3.1% to 2.6%" and stops there has scored the month. It hasn't explained anything, and without the source-level, page-level breakdown sitting underneath it, nobody reading the report can act on it — they can only feel bad about it, which is not the same as knowing what to change.
This same confusion shows up one layer downstream, in what a "conversion" is actually worth. A form submission and a closed deal are not the same event, and a company that reports only the former is scoring lead volume while implicitly claiming to have scored business results. Two months with identical conversion counts can produce wildly different revenue if the sales-readiness of the leads differs, and a report that never asks whether the leads were any good is, in effect, incentivising more volume of a worse mix. The full argument for tracking lead quality as its own dimension, separate from lead count, is in the lead quality problem — it's the diagnostic layer that a pure conversion count is structurally unable to provide.
Writing a report that can say "we do not know yet"
The test of whether a measurement stack is honest is whether the report it produces is allowed to contain a sentence admitting the data can't decide something. Almost none can, currently, because the format of a monthly report — a chart, a number, a one-line interpretation — has no slot for uncertainty. Every number gets a story whether or not it earned one, because leaving a chart uncommented on reads as an omission rather than as intellectual honesty.
Building a report structure that tolerates "we don't know yet" is mostly a matter of changing what each section is allowed to claim. Put the counted numbers first — enquiries, calls booked, whatever the real conversions are — with no adjective attached, because a count needs no interpretation to be useful. Put the source mix, both platform-reported and self-reported, next to each other rather than reconciled into one number, because the gap between them is itself the finding some months. Then, before any narrative paragraph, run the significance check described earlier and state its result as plainly as the count: "this month's change is within the range we'd expect from chance" is a complete, useful sentence, and it should appear in reports as often as the data actually supports it — which, for most small companies, most months, is often.
What this produces in practice is a shorter report that says less and means more of what it does say. A year of monthly reports built this way will contain several months that essentially say nothing changed and we can't tell if anything is coming. That's not a failure of the reporting. A business genuinely does not move every month, and a report that pretends otherwise twelve times a year is training everyone who reads it to distrust the one month the data actually does show something real.
The alternative — reporting activity because activity is what's available, and narrating it as if it were effect — is not a measurement failure exactly. It's a failure to admit that measurement, done honestly at a small scale, mostly tells you what you already suspected, and occasionally tells you that you don't know yet. Both of those are more useful than a chart that goes up.
Questions people ask
- How many conversions a month do I need before analytics tells me anything?
- As a rough working floor, well under a hundred conversions a month means most month-to-month changes in your numbers are noise, not signal. Below that, treat the dashboard as a log of what happened, not as a verdict on what worked.
- Is Google Analytics wrong, or just the way most people read it?
- The tool is not the problem. The habit of reading a chart that went up as proof something worked, without asking whether the move is bigger than the normal month-to-month wobble, is the problem — and it happens on every platform, not just GA4.
- What should a small company track if not sessions and pageviews?
- A short list of things a human actually did that cost the business something to ignore — an enquiry submitted, a call booked, a quote requested — plus one field asking how they found you. Everything else is optional colour.
- Do I need a full analytics setup for a one-page personal site?
- Usually not. A one-page site has one job, and the honest way to learn whether it's working is to ask the people who contact you how they found it, rather than instrumenting a page that gets a handful of visits a month.
Everything in this series
- The lead quality problemMarketing reports leads, sales says they are rubbish, and both are right. How to define a qualified enquiry so the argument becomes an empirical one.
- Core Web Vitals and what they are actually worthSpeed metrics became a compliance exercise. What the numbers do for rankings, what they do for conversion, and which sites can safely ignore them.
- How to run an A/B test when you do not have the trafficMost business sites cannot detect the effects they are testing for. How to know when a test is pointless, and what to do instead.
- How long before SEO shows up in the numbersRealistic timelines by starting position, with the leading indicators worth watching in the meantime and the point at which to call it.
- Conversion rate: what good actually looks likeBenchmarks are mostly unusable because nobody defines the numerator. How to set a realistic target from your own traffic mix and sales cycle.
- Attribution is mostly a story you tell yourselfMulti-touch models look rigorous and are largely assumption. What attribution can support, what it cannot, and the cheap correction worth running.
- GA4 versus Plausible versus server logsThree ways to count visitors, three different numbers. What each one actually measures, what consent banners do to them, and which to trust.
- The only website metrics that mean anythingA short list of numbers worth tracking for a business site, each with what it diagnoses, what it cannot tell you, and how often to look.