◀ All articles

Playbooks

How to run an AEO audit in one afternoon

September 11, 2026 · 5 min read

Access, identity, evidence, then measurement — a four-hour sequence with a table for what to capture and what to ignore.


You do not need a six-week "AI transformation" project to find out why assistants ignore your brand. You need one afternoon, a browser, curl, and a ruthless order of operations.

This is an AEO audit you can finish in about four hours: access → identity → evidence → measurement. Skip ahead and you will polish schema on a site the bots cannot fetch.

What you are auditing

Answer engine optimization here means: can retrieval systems reach your pages, resolve who you are, and find facts worth citing? It is not a synonym for "rank #1 in ChatGPT." See also what answer engine optimization is if you need the framing; this post is the field procedure.

Afternoon timeline

BlockTimeFocusOutput
1. Access60–75 minrobots, WAF, HTML fetchPass/fail for key bots + URLs
2. Identity60–75 minName, About, Organization schema, sameAsEntity consistency notes
3. Evidence45–60 minCitable pages, third-party profilesGap list ranked by effort
4. Measurement30–45 minBaselines onlyWhat you will track next month

Total: roughly four hours for one primary domain. Multi-brand sites need more — do not fake depth by skimming.

Step 1 — Access (can machines fetch you?)

  1. Open https://yoursite.com/robots.txt. Note Disallow rules for GPTBot, ChatGPT-User, PerplexityBot, Google-Extended, and any blanket * rules that hide / or key paths.
  2. Fetch the homepage and one money page with a plain HTTP client (no JS):
    curl -sI https://www.example.com/
    curl -sL -A "Mozilla/5.0" https://www.example.com/ | head
    
  3. Repeat with AI-ish user-agents you care about (exact strings change; confirm current ones in vendor docs). You want 200 and real body text, not a challenge page.
  4. If you get 403/429 with bots but 200 in Chrome, read when your WAF blocks the bots — robots.txt lying "Allowed" while Cloudflare Bot Fight Mode kills the request is a classic trap.
  5. Spot-check whether brand copy exists in initial HTML. If the company name only appears after hydration, treat that as an access problem for non-JS fetchers (JavaScript rendering and AI crawlers).

Capture: URL, status, user-agent, whether brand name appears in raw HTML. Ignore: pretty Lighthouse scores, font loading, animation jank.

Step 2 — Identity (one brand, one entity)

  1. Write down the canonical brand string exactly as you want machines to store it (for example, Northstar Analytics).
  2. Compare homepage <title>, visible H1, meta description, and Organization name in JSON-LD. Mismatches like "Northstar" vs "Northstar Analytics Inc." vs "northstar.ai" split the entity (brand name mismatch).
  3. Open the About page. A human should learn what you do in the first screen; a machine should see the same facts without scrolling through lifestyle photography. (About pages machines can read).
  4. Validate Organization schema: @type, name, url, logo, sameAs. Use Organization schema as the field checklist.
  5. Confirm sameAs targets are real profile URLs you control or claim (LinkedIn, Crunchbase, Wikidata when eligible) — see sameAs profile links.

Capture: side-by-side name strings + schema snippet. Ignore: tagline cleverness, brand color hex codes.

Step 3 — Evidence (what could an answer cite?)

Assistants cite pages that look like answers: definitions, comparisons, docs, pricing clarity, reputable third-party profiles. They rarely cite a homepage hero with three adjectives.

  1. List 5–10 URLs you would be proud to see cited (docs, pricing, integration pages, research posts).
  2. For each, check: clear title, definition-like opening, updated date that is honest, no soft 404 behavior.
  3. Check off-site: G2/Capterra (if SaaS), Crunchbase, Wikipedia/Wikidata only if notability is real (Wikidata, Crunchbase, Wikipedia).
  4. Skim competitor entity setup once for contrast (reading a competitor entity setup) — steal structure, not claims.
Evidence typeWorth auditing today?Common failure
Pricing / plans pageYesVague tiers; AI invents features
Docs / how-toYesGated entirely; crawler sees login wall
Blog "thought leadership"SelectiveNo definition, no table, no author
Press mentionsLight passWrong company name spelling
Review sitesYes for SaaSUnclaimed profile, wrong category

Capture: URL + "citable? yes/no + why". Ignore: social vanity metrics.

Step 4 — Measurement (baselines, not theater)

You will not prove AEO ROI in four hours. You can leave with baselines:

  1. Note current AI referral traffic if any (even if near zero). Similarweb Gen AI Landscape 2025 (US desktop, Sep 2025) reported ChatGPT referrals averaging about 15 minutes on site versus about 8 for Google, with roughly 12 pages per session versus about 9, and about 7% conversion on transactional sites versus about 5% for Google — useful context when samples are small, not a promise for your niche.
  2. Save today's readiness findings (or a BrandKnown scan) so next month's re-scan is comparable.
  3. Pick 10–20 prompts you care about and record, manually, whether you are named this week. Label it a snapshot, not a rank tracker.
  4. Schedule the next audit or re-scan after fixes — not after "content sprints" that never touched robots.

Gartner (Feb 2024 forecast) suggested traditional search volume may drop 25% by 2026 due to AI agents — treat that as a forecast, not a measured fact, and do not put it in the audit as if you observed it on your domain.

What to ignore on purpose

  • Keyword density rituals
  • Inventing twenty FAQs for schema theater (FAQ schema for answer engines covers when FAQ markup helps)
  • Promising leadership "we will dominate AI search"
  • Comparing your readiness score to a competitor's citation count (different instruments)

End-of-day deliverable

One page is enough:

  1. Access: pass/fail table for bots and key URLs
  2. Identity: name consistency + schema gaps
  3. Evidence: top five fixes ranked by effort
  4. Measurement: what you will re-check in 30 days

If you want the access and identity pass automated, a BrandKnown scan (~60 seconds, free first scan) maps cleanly onto blocks 1–2. The afternoon still needs a human for evidence judgment and for refusing fake precision.

Ship the access fixes first. Identity second. New content third. That order is the audit.

See how your own site scores

One scan checks your homepage, robots.txt, llms.txt, About page and JSON-LD, then hands you the copy-paste fixes. Free, no account needed for the first run.

Keep reading