How do agencies typically structure a paid app-stack audit engagement, and what should be in the deliverable?
A paid app-stack audit runs 2 to 3 weeks and lands in the $10,000 to $25,000 band for a single Online Store theme (Deploi estimate, illustrative, September 2026). The deliverable is four artifacts: a full app inventory with spend from Shopify's own billing records, a script-to-app attribution map, a ranked remove, replace or keep list, and a written install policy.
How the engagement is shaped
Three weeks is not an arbitrary number. It is what a real attribution pass costs in calendar time, because field performance data needs a measurement window and app owners need to be found.
| Week | What happens | What it produces |
|---|---|---|
| 1 | Inventory: pull app charges from Settings > Billing, inspect page source on home, collection and product templates, catalog tag manager containers, interview owners | The list of what is installed, what is on the page, and who asked for it |
| 2 | Attribution: measure each candidate against field Core Web Vitals and synthetic runs, check injection path, identify orphaned theme edits from past uninstalls | The script-to-app map, and the shortlist |
| 3 | Decision and policy: rank by recoverable time against switching cost, price each replacement, write the gate | The remove/replace/keep list and the install policy |
What the audit is actually fighting
Shopify itemizes app charges under Settings > Billing but does not break spend down by ROI or category (verified September 2026). So the spend column is real and the value column is manual work. Anyone who hands you an ROI-per-app table without having interviewed your team invented it.
On the performance side, Shopify's web performance report shows LCP, INP and CLS at the 75th percentile over the trailing 90 days with event annotations for installs and theme changes (per Shopify's Help Center, September 2026), and stops short of naming the script behind a regression. Attribution is the deliverable precisely because the platform does not give it to you.
The four artifacts, and what "good" looks like in each
- App inventory with spend. Every app, its monthly charge, its usage-fee mechanics, its renewal date, its named owner, and whether it touches the storefront. The last column is the one most inventories skip and the one the whole audit turns on.
- Script-to-app attribution map. Each storefront request traced to the app that caused it, with the injection path recorded: theme app extension, direct theme edit, tag manager, or residue from an app you already removed. Without the last category you will re-find the same snippets next year.
- Ranked remove, replace or keep list. Ranked by recoverable milliseconds against switching cost, not by monthly fee. Each row carries its migration note: replacing an app moves its data, and reviews, wishlists and loyalty balances need a plan before the uninstall, not after.
- Written install policy. A performance budget with a number in it, a named approver, and a place in the release process where a build fails. Without an install policy the app count grows back, and the audit becomes a quarter's discipline rather than a one-off.
What a weak audit looks like
A PDF of Lighthouse screenshots, a list of apps sorted by price, and a recommendation to "consolidate." No attribution, no migration notes, no policy. It is cheaper, and it produces a cleanup that reverses within three quarters because nothing changed about how apps get installed.
The other failure mode is scope creep in the opposite direction: a lazy-loading pass that balloons into a full theme rebuild. Cap the cycle, bank the wins, and treat a native-first theme as a separate decision with its own number, which our consolidation analysis puts in the $25,000 to $75,000 band over 6 to 12 weeks (Deploi estimate, illustrative, September 2026).
The Deploi point of view
Our own position, from building on Shopify. Separate from the facts above.
- Our take: The install policy is the deliverable. Everything else is evidence for it. An audit without a gate is a snapshot of a stack that will look different in six months, and you will pay for the same work twice.
- What we’ve seen: The inventory step surfaces more money than the performance step, and it does it in week one. Apps nobody owns, apps duplicating a native feature, apps billing usage fees against attribution the vendor calculates rather than you. That is not a speed finding, but it pays for the engagement before the remediation starts.
- Times we’ve shipped this: 7 builds delivered.
- What it takes: roughly 144 hours of scoped work for a media and asset loading strategy pass (directional Deploi estimate from a small sample of engagements, not a measured average).
- Where we disagree: Most audit proposals sell the report. We think the report is the cheap part and the attribution is the expensive part, which is why we price a cycle rather than a document. Our performance monitoring verdict is BUILD the audit-and-remediation program rather than buy a speed app, because the measurement tools are already free (Deploi verdict, August 2026).
- What this page adds: the week-by-week structure of the engagement, the four artifacts a deliverable has to contain, and the two ways the engagement typically fails.
Reviewed by Martin Dejnicki, Director of SEO & AI Search. Facts verified 2026-09-13.
Where we worked this out
Our decision records