Tag Manager, with the rollback named first.

Duct notices when a count goes to zero, finds the tag behind it, and stages the fix in a workspace. A publish replaces your live container, so that step always waits for you, with the version to roll back to named.

  • Sign in with Google
  • Reads three datasets
  • Four kinds of change
  • Checked Sep 29, 2026
An example answer. Yours is read from your own accounts.
A Duct session: asked why GA4 stopped counting an event on the web, Duct finds the tag a container version renamed, and proposes a workspace fix and a publish that waits for approval
Ask why an event stopped counting. Duct finds the tag version 14 changed, stages the fix in a workspace, and holds the publish for you with version 14 as the rollback.

Ask

Questions you can just ask

  • Why did an event stop counting in GA4 overnight?

    Tag Manager + GA4 + Mixpanel
  • Is the tag firing, or firing the wrong thing?

    Tag Manager + GA4
  • Do web and app still send the same event names?

    Tag Manager + Mixpanel
  • Can you fix the tag and let me approve the publish?

    Tag Manager

Access

What it reads. What it can change.

What it reads

  • Accounts and containersaccountcontainerpublic ID
  • Workspace tags and variablesnametypeparameters
  • Live container versionversion ID

Tag Manager API v2 · checked against the fetch code Sep 29, 2026 · read the source

What it can change

  • Create/update GTM tag (workspace)May self-apply in assisted mode
  • Create/update GTM variable (workspace)May self-apply in assisted mode
  • Publish GTM container versionAlways waits for you
  • Republish an older GTM versionAlways waits for you

Every one rolls back. By default each change waits for your Apply: it arrives as a preview of what it touches and lands in the activity log. How approval works

Knowledge

What Duct already knows about Tag Manager

  1. 01

    Nothing is live until it's published.

    Edits in a workspace change nothing on your site. Duct stages its changes there, and the publish, which replaces the live container for every visitor, always waits for you.

  2. 02

    The rollback target is read first.

    Before a publish Duct records the version that is live, so a rollback republishes exactly what was there.

  3. 03

    A tag that fires can still be broken.

    A tag can fire on every page and send nothing useful. Duct checks what arrived in GA4 or Mixpanel, not the fire status.

  4. 04

    Renames don't follow references.

    Renaming a variable through the API leaves every tag pointing at the old name. Duct patches the tags in the same change, or doesn't rename.

Read the Tag Manager notes Duct's agent works from

Setup

Connect Tag Manager in three steps

  1. 1

    In Duct, open Connections and choose Google Tag Manager.

  2. 2

    Sign in with Google and allow access to edit and publish containers.

  3. 3

    Pick the container this project uses.

Duct asks for edit and publish access when you sign in, because both are needed to fix a tag. Edits stay in a workspace, and a publish always waits for your Apply.

Keys and tokens are stored encrypted by Duct's hosted API, never in your browser, and you can remove a connection at any time. A self-host build keeps them on your own machine.

FAQ

Tag Manager, answered

What can Duct change in Tag Manager?

Four: create/update GTM tag (workspace), create/update GTM variable (workspace), publish GTM container version and republish an older GTM version. By default each one waits for your Apply, and every one can be rolled back.

Will Duct publish to my live site on its own?

No. A publish replaces the live container for every visitor, so it always waits for you, whatever the project's autonomy. Workspace edits can apply on their own in assisted mode, and they change nothing live until a publish.

How does rollback work?

Before it publishes, Duct records the version that is live. Rolling back republishes that version, and the activity log shows both.

Is it free?

Yes. Duct is free with your own model keys or the ChatGPT plan you already have, and the core is MIT licensed. A paid plan later bundles the models; nothing open today moves behind it. What will cost money.