Attribution didn't get harder because the channels multiplied. It got harder because the same user is now three identities (web, iOS, Android), measured by three systems that never agree, under privacy rules that keep moving. Here's the stack that holds it together.
Many noisy inputs on the left, refined stage by stage into one decision on the right. Tap a stage to see what it does, and what breaks if you skip it.
Most teams optimize layer 5 on top of a broken layer 1. Identity first, then collection, then attribution. Validation and decisions are only ever as good as what's underneath them.
user_id set; you stop double-counting, but it's last-click.Most cross-platform apps live at Level 1, believe they're at Level 3, and budget like Level 0. The self-check below tells you the truth.
user_id shared across web, iOS, and Android) or every number downstream is fiction.A combined mobile + desktop app is the hardest measurement problem in consumer growth, and most teams are quietly getting it wrong. Not because they lack tools, but because they wired the tools up in the wrong order.
The instinct is to start with channels: connect Meta, connect Google, connect the App Store, read the dashboards, and sum it up. That sum is the number that's wrong. Each platform reports on its own window, with its own modeled fill, counting a user your other systems also counted, so the totals overlap and disagree, and the more channels you add the worse it gets. The dashboards aren't measurement. They're each channel's marketing for itself.
The fix is to think in layers, not channels. You just saw the five above. Now let's pressure-test where your stack actually stands, then go layer by layer (with the channel reality, the privacy mechanics, and the deeper plumbing for whoever has to build it).
Tick what you genuinely have in place. The score updates live and points you at your weakest layer (and the next fix). It saves to this browser.
The color is the honest signal quality, not the vendor's pitch. Filter by surface or type, and tap any channel for the mechanism, the constraint, and what to do about it.
Read the colors honestly: web is mostly green because you control the server; iOS is mostly amber-to-red because Apple aggregates everything; Android sits in between only because Google retired the Privacy Sandbox in October 2025, so the advertising ID still works (for now). The two cells everyone gets wrong: Apple Search Ads vs. organic App Store (blended in App Store Connect, so pull ASA reporting separately and subtract), and GEO (no real attribution exists yet; you'll see chatgpt.com as a referrer and little else).
Same 100 real conversions. Here's what each system tells you it drove. Illustrative, but the shape is real on every cross-platform app.
Sum the dashboards and you over-count by ~40% (everyone claims the same conversion). Trust analytics alone and you under-count the privacy-hidden ones. None of them is lying; they're answering different questions. The job isn't to make them agree. It's to pick the right one for each decision.
iOS, App Tracking Transparency and SKAN. Since iOS 14.5, device-level tracking requires explicit opt-in, and only 15–25% of users globally grant it (higher among those actually shown a well-timed prompt). The rest are measured through SKAdNetwork, now version 4, which returns aggregated, delayed conversions: coarse or fine values, postback windows stretching to 35 days, and crowd-anonymity tiers that strip the source app when volume is low. AdAttributionKit, Apple's stated successor, adds re-engagement and configurable windows, but ecosystem adoption is near zero, because every publisher, network, and MMP has to upgrade in lockstep and they haven't. In practice, SKAN 4 is the workhorse, and only about one in five iOS marketers say they trust their attribution.
The web, the "cookiepocalypse" that wasn't. Google reversed Chrome's third-party-cookie deprecation in 2024 and abandoned the choice-prompt plan in 2025, then retired the Android Privacy Sandbox attribution APIs in October 2025. So the apocalypse everyone re-platformed for never arrived in Chrome. But Safari and Firefox have blocked third-party cookies by default for years, so roughly a third of web traffic is cookie-constrained no matter what Chrome does. The durable takeaway isn't a date; it's a posture: assume signal loss, and move conversion collection server-side.
Android, in limbo. The advertising ID (GAID) survived the Privacy Sandbox retirement and still works today, with no confirmed deprecation date. That makes Android your most measurable mobile surface right now, but it's a reprieve, not a guarantee, so don't hard-wire your stack to it.
Layer 1 — Identity. The only durable cross-platform key is an authenticated user_id you set in both the web tag and the mobile SDK. GA4 and Firebase don't share an identity space, and a logged-out user is three separate people across three browsers. Deterministic stitching (hashed email or phone at login) is the floor; probabilistic stitching (IP plus user-agent) is a fragile fallback that degrades further under Apple's Private Relay. The honest implication: your join rate is capped by your login rate, so the product decision of when to ask users to authenticate is also your single biggest measurement decision.
Layer 2 — Collection. On web, move tags to a server container (server-side GTM, or Google's newer Tag Gateway) so conversions survive ad-blockers and short-lived cookies, then fan out from one server to GA4, Meta CAPI, TikTok Events API, and Google Enhanced Conversions with consistent IDs. On app, decide the MMP question early: skip it if you run a single Google App Campaign; adopt one (AppsFlyer, Adjust, Singular, Branch) the moment you run two or more networks, need fraud filtering, or need web-to-app deep linking, which became non-optional when Firebase Dynamic Links shut down in August 2025.
Layer 3 — Attribution, and the reconciliation playbook. You saw the three numbers. Here's how to actually live with them:
The MMP owns cross-channel paid app spend. Server-side analytics owns web. The platform owns only its own in-channel creative and bid optimization. Write it down once; stop re-litigating it weekly.
Averaging three differently-biased numbers makes a fourth, more confident, wrong number. Convert the others into ratios against your system of record and watch the ratios, not the raw counts.
When two sources move apart by more than about a fifth, something changed (a tag broke, a window shifted, a channel started cannibalizing). The gap is a signal, not a rounding error.
Layer 4 — Validation. This is where truth actually lives, because attribution in a privacy world can only see a shrinking fraction of touches. Three instruments, three jobs, in this order of authority:
MTA coverage, the share of touches it can still see. Down by roughly half since pre-ATT. This is why validation, not attribution, became the truth layer.
Pick the decision you're trying to make.
Don't let organic disappear into "direct." Web SEO is measurable at query level in Search Console (with last-click bias and "(not provided)" keywords); GEO and AI search have no standard attribution yet and show up only as referrer hosts. On the app side, the stores aren't symmetric: Google Play's Search and Explore exclude paid traffic (clean organic since late 2022), while Apple's App Store Connect blends organic and Apple Search Ads, so you must pull ASA reporting separately and subtract to see true organic. Two more rules: organic store-search users tend to be your highest-LTV cohort, so measure their value, not just their volume; and treat referral and affiliate as performance, not organic, because they feel earned but most MMPs bucket them with paid, which matters the moment you compare against an organic baseline.
The halo, and its evil twin. Paid spend manufactures incremental organic. Published app data puts it near three extra organic installs per hundred paid, an ~7–8% undercount of paid's true effect. The flip side is branded-search cannibalization, where paid eats clicks organic would have won for free. You can only see either one with an experiment: pause the channel in a holdout geo and watch what organic does. If you've never run that test, you don't know your channel mix; you know your dashboards.
The dashboards say 1,380. Meta claims 420, Google 510, Apple Search Ads 230, TikTok 220. Summed, that's already more signups than Streak actually got. Every network counted the users it touched, and many were touched twice.
The MMP says 1,000, split differently. Deduplicated on one window, it hands ~38% to Google, 31% to Meta, 19% to ASA, 12% to TikTok. Cleaner, but still last-touch, and blind to the upper-funnel TikTok views that seeded the branded Google searches.
Analytics says 1,000, but only 700 are joined. 30% never logged in on the surface they converted on, so their web→app journey is broken and lands in "direct / organic". Streak's "organic" looks bigger than it is.
A geo holdout settles it. Pause TikTok in three matched metros: total signups drop 9%, not the 12% the MMP credited it, and branded Google searches dip too. TikTok is real but over-credited downstream and under-credited upstream. Now you can move budget with a straight face.
If your "total conversions" is the sum of what each ad account claims, it's inflated by every user two networks both touched. Fix: one system of record; dashboards are for in-channel tuning only.
Trying to recover user-level paths post-ATT burns months for noise. Fix: accept aggregation; judge iOS channels on incrementality, not click logs.
Chrome kept cookies; the Android Sandbox is dead. Fix: build for graceful signal loss generally, not for one vendor's cancelled deadline.
It still includes Apple Search Ads. Fix: pull ASA reporting and subtract before you celebrate an "organic" win.
Without one experiment, you have correlations dressed as causes. Fix: one clean geo test a quarter beats a year of dashboard staring.
The triangulation thesis in full: give each method a job, and the decision rules for when to trust which.
Read the pillar →How to prioritize the holdout tests that settle attribution arguments. The validation layer, operationalized.
Read it →The newest organic channel in the matrix, and the one with no attribution standard yet. How to show up in AI answers.
Read it →Figures here are vendor- and study-sourced and best treated as directional; opt-in rates, lift medians, and spillover estimates vary widely by category, geo, and method. The "Streak" walkthrough and the three-numbers chart are illustrative, not real data. The framework is the durable part; re-verify the numbers against your own data before you bet a budget on them.