Why Is It So Hard to Govern Many Websites at Once?

Governing many websites is hard because the answers to basic questions live in different places: a spreadsheet, several hosting vendors, code repositories, and a stack of monitoring tools. Nothing connects them into one view.

Picture a head of digital responsible for a few hundred websites. The inventory is a spreadsheet of names, URLs, hosts, CMSs, and business owners. The code sits in GitHub, monitoring is in place, and several vendors host parts of the portfolio. The day-to-day questions are still slow to answer:

  • A major WordPress vulnerability is announced. Which sites are affected, so the team can update them before a deadline?
  • A move away from one hosting vendor is planned for next year. Which sites does that vendor host?
  • Are the sites cookie compliant, and is Google Analytics implemented properly?
  • Is every domain renewing on time, including one a business unit bought on its own that the digital team later inherited?

Each question has an answer somewhere. Collecting it by hand means asking developers to check site after site.

Why Did Vardot Build Auditray?

Vardot built Auditray to solve its own governance problem. We run hundreds of websites for our clients, some of whom run hundreds of sites each, and we kept needing to know which of them were outdated or exposed.

The Drupal Security Team uses Wednesday security release windows: every Wednesday for contributed projects, and one Wednesday a month, usually the third, for Drupal core. When an advisory lands for a contributed module, which of our sites run the affected version? 

Without Auditray, answering that took hours of developer time. With Auditray, it is a direct query with a specific answer, for example: six sites run the affected version; the rest are fine, so the team focuses on those six. 

A policy, a set of controls with thresholds you choose, sets the priority too. A team can tolerate a moderately critical advisory but not a critical one, and Auditray flags only the sites that break that rule.

We tried spreadsheets first, then Drupal modules. As an agency, we promise clients that their websites stay updated and compliant, and keeping that promise at this scale took more manual effort than it should. Auditray came out of that experience.

Why Is There No Single Standard for a Compliant Website?

There is no single standard for a compliant website because website standards are thematic, and each theme is governed differently:

  • Accessibility has WCAG.
  • Privacy has rules for how a site collects personal information.
  • Security has several frameworks, such as SOC 2 and PCI DSS for sites that take payments. 
  • SEO has best practices but no governing body that defines them.

In practice, a well-governed site passes checks drawn from several frameworks: a favicon is in place, page titles are descriptive, the accessibility score from your accessibility platform clears 80 or 90 percent, and there are no known security vulnerabilities. Universities and enterprises then add internal standards for how their sites behave and what they say.

Regulations apply only in part. Most of GDPR's obligations cover people and processes, such as appointing a data protection officer where required, so a website governance platform should monitor the website-relevant part and leave the rest to the wider compliance program.

What Should a Website Governance Platform Do?

Website governance is the practice of setting standards for your websites, checking whether each site meets them, and giving the responsible teams a clear way to act on what fails. We believe a platform should make that practice continuous, and four principles follow.

Governance should read from the ecosystem, not replace it. Every site sits within an ecosystem: Google Analytics, Microsoft Clarity, Semrush, Cloudflare, and more. Auditray integrates with those tools and reads what each policy needs. For example, one policy we recommend flags any site that loads Google Analytics without Google Consent Mode v2.

 Accessibility works the same way: Auditray reads what platforms such as Acquia Web Governance report and holds the result to your threshold.

Governance should cover the code, not only the live site. Connect a repository, and Auditray checks code health and builds a software bill of materials (SBOM): the packages the site depends on, drawn from manifests such as Composer and package.json, with pending security updates. You can export it as CycloneDX or SPDX.

The standard has to be yours. Our default policies come from our experience running websites. Organizations that disagree can change any threshold themselves.

Governance should not depend on one CMS. A portfolio can mix Drupal with other CMS-based, managed, and custom-built sites, so governance has to sit outside any one platform. Community tools such as the Drupal Remote Dashboard (DRD) module cover Drupal sites only. Auditray is a standalone application (Python backend, JavaScript frontend) that governs Drupal, WordPress, and other websites through one policy model. Built by Vardot, a Drupal Certified Diamond Partner, it carries especially deep Drupal controls. 

How Does Auditray Work?

Auditray works in four stages: connect the portfolio, run consistent checks, organize findings, and support follow-through. 

How Do You Build a Site Inventory in Auditray?

Start from the list you already keep: paste URLs or upload an Excel or CSV file. Auditray maps columns such as name and URL to site fields, creates new fields, such as hosting, from columns it does not recognize, checks each field's type, and keeps an import history.

Custom fields let the inventory reflect how you govern: owning team, host, or vendor. If one vendor maintains a handful of your 40 sites and another maintains the rest, a vendor field shows who is responsible for each. Roles (viewer, site admin, organization admin) can be scoped to specific sites. 

Which Tools Does Auditray Integrate With?

Auditray integrates with the tools teams already run around their websites. Current integrations cover:

  • Version control: GitHub, GitLab, and Bitbucket
  • Monitoring: New Relic
  • CDN and DNS: Cloudflare
  • Error tracking: Sentry
  • Analytics: Google Analytics, Google Tag Manager, and Microsoft Clarity
  • SEO and search: Google Search Console and Semrush
  •  Accessibility and governance: Acquia Web Governance

How Do Policies and Controls Work in Auditray?

A policy is a collection of controls, and each control is a single check with a threshold and a criticality level, such as warning or critical. Policies come in three kinds:

  • Generic, such as Site Hygiene: page cache enabled, error reporting hidden from visitors, a valid SSL certificate, enforced HTTPS redirects, and a domain registration that is not about to expire.
  • Platform-specific, such as WordPress security best practices and a consolidated set of Drupal controls.
  • Framework-based, such as a PCI DSS 4.0.1 policy for sites that process payments. It does not replace a formal PCI DSS assessment. 

Defaults are a starting point. A stricter organization can clone a policy, tighten its thresholds, and disable the original. Auditray also publishes its own policy updates, which you can review and apply.

Example thresholds: Auditray default vs. a stricter organization

Control

Example default

Example stricter setting

Low-risk security vulnerabilities on a Drupal site

Up to 5

0

Domain expiry warning

45 days before expiry

6 months before expiry

What Happens When Auditray Finds an Issue?

When Auditray finds an issue, it reports it rather than fixing it. It shows which policies and controls each site passes or fails, and you can rerun any individual check manually to confirm a fix.

Agencies use the same view with their clients. Technical users work with the code-level views, which appear once a repository is connected, and account managers can see a client site's open issues, such as performance problems, and raise them with the client. 

What Does Agentic Website Governance Mean?

Agentic website governance means replacing occasional manual reviews with continuous, organized checks that show the responsible teams what needs attention across every site they run. Auditray uses AI to help assess the health of each site against its standards. People still decide what to fix and when.

Where Does Auditray Host Customer Data?

Auditray hosts customer data on Google Cloud. Scans run on background workers, which clone each connected codebase, scan it, store the results, and cache the codebase.

Do You Need a Website Governance Platform? Five Questions to Answer

You need a website governance platform if you cannot answer these questions quickly, from facts you already hold:

  1. Do you know how many websites you are responsible for, who owns each one, and which vendor hosts or maintains it?
  2. When a critical security advisory lands on a Wednesday, can you name the affected sites the same day without asking developers?
  3. Do you know which domains and SSL certificates are close to expiring, including those a business unit bought on its own?
  4. Is every site held to one written standard, with thresholds you chose?
  5. Can you see, for every site, which controls it passes and fails today?

How to read your answers:

  • No to 1 or 2: you have the problem Auditray was built to solve. Start with the inventory.
  • No to 3 or 4: you know what you run, but not whether it meets your standard. Policies close that gap.
  • No to 5: the work may be happening, but no one can see where each site stands.
  • Yes to all five: your process is working. Keep it, and revisit as the portfolio grows.

How Can You Try Auditray?

Start with the spreadsheet you already keep. Create a workspace in Auditray, import your site list, connect one integration, and see what fails.