← Blog

Buyer's guidePrivacy

Why teams don't put Google Analytics on internal tools

Google Analytics is very good at one thing: measuring how strangers arrive. Which campaign brought them, which page converted them, which audience to buy more of. An internal HR portal has no strangers, no campaigns, and nothing to convert — and the questions its owner actually has, GA was never built to answer.

July 24, 2026 · 6 min read

Illustration of a marketing funnel chart next to a flat internal dashboard

GA answers acquisition questions. Internal tools ask adoption questions.

None of this is a knock on Google Analytics. It's the standard for a reason — on a public marketing site, "where did this traffic come from and did it convert" is exactly the question, and GA answers it better than almost anything. But look at what an internal-tool owner needs to know: Who still uses this? Which functions do they use — and which do they route around? Is adoption up since the redesign? Do people quietly hate it? Those are portfolio questions about a known, finite population, and GA's core vocabulary — sessions, sources, mediums, conversions, audiences — simply doesn't speak them. There is no channel to attribute when everyone arrives from the same intranet link. There's no funnel to optimize when the "purchase" is submitting a leave request.

You can bend GA4 toward these questions with custom events, custom dimensions, and exploration reports — people do. But a tool nobody on a stretched product team has time to learn, reconfigured to approximate answers it wasn't designed for, tends to produce one outcome: a property somebody set up in a sprint two years ago that nobody has logged into since. If the question is "is adoption up," the answer should not require a query language. (What the adoption question actually needs: measuring internal tool adoption.)

Consent gets strange when your users are your employees

On a public site, GA comes with a consent banner and a cookie-management platform, and that's just the cost of doing business. Point the same stack at employees and the ground shifts. GDPR treats workplace data with special suspicion, because consent given inside an employment power relationship is hard to call "freely given" — an employee clicking "accept" on their own payroll portal is not making a free choice in any meaningful sense. Several European data-protection authorities have also found the data transfers behind Google Analytics problematic at various points, which means your DPO has read those findings even if you haven't. Frameworks like Turkey's KVKK add their own national layers on top. None of this makes GA on an internal tool "illegal," and none of this is legal advice — but it reliably converts a simple wish ("I'd like a usage graph") into a legal project with a DPIA, an opinion, and a quarter of elapsed time.

The way out isn't better consent tooling. It's not needing identity in the first place. For fix-or-retire decisions you need volumes, trends, and sentiment — never who. Measurement that is anonymous by design — random locally-generated visitor IDs, no fingerprinting, cohort views withheld below a k-anonymity floor, DNT and GPC honored — gives your privacy team a short risk section instead of a long negotiation.

Your telemetry becomes someone else's data

Here's the objection that ends the conversation in most security reviews, and it has nothing to do with cookies. GA works by sending page URLs and titles to Google's servers. On a marketing site, fine — those pages are public. On internal tools, URLs and page titles are a map of your organization: team names, project codenames, tool inventories, the sudden appearance of a page called "Integration Planning — Project Falcon." Routing that stream to an advertising company's infrastructure is exactly the kind of thing security architecture reviews exist to say no to. Not because Google is doing anything nefarious with it — because "internal operational metadata leaves the trust boundary as a side effect of a usage graph" is a trade nobody signed up for.

The numbers would be wrong anyway

Even if legal and security waved it through, there's a practical problem: GA's scripts are among the most-blocked resources on the internet. Ad blockers block them by default, several browsers restrict them out of the box, and — the part that matters here — corporate networks and managed-browser policies frequently block ad-tech domains wholesale. On an internal tool, that's not a small skew in a big public sample; it can be a large, systematic hole in a small population, concentrated in exactly the departments with the strictest device policies. You'd be making retire-or-invest decisions on a graph missing an unknowable fraction of your own company. First-party telemetry served from a non-ad-tech domain doesn't carry that handicap.

Usage without sentiment is half a dashboard

Suppose all of the above were solved. GA would still only give you the quantitative half. There's no in-context rating widget, no way for a user to say "this screen is broken" with a screenshot attached, no NPS, and no path from what users say to what your team ships. For internal tools that half is the decisive one: usage tells you what already happened, sentiment tells you what's coming, and the feedback itself is the backlog trying to write itself. A stack for internal products should put pageviews, function-level usage, ratings, and feedback themes on one screen — and then close the loop, turning recurring complaints into drafted backlog items a human can accept or reject and push to Jira or Azure DevOps. GA doesn't do any of that, because it was never supposed to.

The honest comparison

You needBest fit
Campaign attribution, conversions, and audiences on a public marketing siteGoogle Analytics — genuinely the right tool
Session replay and heatmaps to debug UXMicrosoft Clarity, FullStory (see Morvero vs Clarity)
Anonymous usage + ratings + feedback across a portfolio of internal tools, flat-priced, feeding the backlogMorvero

Same shape of conclusion as our Pendo and Amplitude piece: this isn't "GA bad," it's altitude and audience. GA measures acquisition of strangers; internal portfolios need adoption and satisfaction among colleagues. Plenty of companies run GA on morvero.com-style public sites and something else behind the SSO wall — and pay for that something on terms that don't punish rollout, which is why we price flat per product, never per-MAU.

Where Morvero fits: one script tag per internal product gives you anonymous pageview and function-level usage (one HTML attribute per feature), an in-context rating widget with consent-first feedback and screenshots, NPS microsurveys, and AI theme summaries that draft backlog suggestions for a human to accept or reject and push to Jira or Azure DevOps — with anomaly alerts when a product's usage or rating slides. No consent banner engineering, no ad-tech domains, no per-MAU meter. Setup details in the docs, and the first two products are free: start free.