Skip to content
19 min readByBob Thordarson

Person-Level vs Company-Level Identification: What You Can Actually Know About a B2B Visitor

B2B website visitor identification resolves anonymous traffic at one of two levels, and the gap between them decides what you can do with the result. Company-level returns an organization from an IP address. Person-level returns a named individual with a work email. This guide covers what each one delivers, what the published match rates actually mean, why one vendor can publish four different numbers for the same product, and the compliance difference that changed on January 1, 2023.

Isometric diagram of two resolution paths from one anonymous visitor, one returning an office building and one returning a named person card.

Key benchmarks at a glance

B2B visitor identification match rates by resolution level, 2026 · 2026

MetricFigures
Person-level match rate, realistic US B2B17.5%Midpoint of the 15-20% range compiled from vendor documentation, July 2026
Person-level match rate, independent testing12.5%Midpoint of MarketBetter's 5-20% across 12 platforms, 2026
Person-level match rate, highest published claim55%Happierleads, published claim
Company-level match rate, typical47.5%Midpoint of the 30-65% range compiled July 2026
Company-level match rate, highest published claim80%Happierleads, published claim

Last updated: September 7, 2026

B2B website visitor identification is the practice of resolving anonymous website traffic into known organizations or known individuals using first-party signals and an identity graph. It operates at two levels. Company-level identification returns the organization a visitor is browsing from. Person-level identification returns a named individual, usually with a work email address attached.

KEY STATS

  • Around 98% of website visitors are anonymous and never identify themselves (Twilio Segment, 2026)
  • Only about 3% of B2B website visitors fill out a form (6sense, 2022)
  • Company-level identification resolves a visitor's IP address to an organization and typically matches 30-65% of B2B traffic, with the highest published claim in the category at 80% (compiled July 2026; Happierleads)
  • Person-level identification returns a named individual and a work email, and realistically lands at 15-20% of US B2B traffic against a highest published claim of 55% (compiled July 2026; Happierleads)
  • Independent testing across 12 person-level platforms returned a range of 5-20%, where the low end falls short of every advertised figure in the category (MarketBetter, 2026)
  • One person-level product carries four separately published match rates spanning 8% to 45%, sourced from Warmly, MarketBetter, Bullseye and the vendor's own documentation (compiled July 2026)
  • LiveRamp reports a 99.5% match rate on full-PII consumer data, measured independently by Comscore. It is a B2C ceiling with no B2B equivalent (LiveRamp/Comscore CustomIQ, Q1 2026)
  • California's business-to-business exemption under the CCPA expired on January 1, 2023, making a work email address personal information (IAPP)
  • Data sourced from vendor documentation, independent platform testing and published privacy guidance, compiled July 2026

I've watched this one distinction derail more evaluations than any other question in the category. A buyer books three demos, sees three dashboards that all look roughly the same, and only discovers on day nine of a trial that one of them was never going to return a name.

The pricing pages rarely say which level they run at. The word nearly all of them use is "identify," and it covers both. When we compiled the vendor table for the match-rate post in this series, I had to open the technical documentation of all 15 tools to work out which level each one operated at, because the marketing pages simply didn't say.

The useful question is which level your next action must support, and that single decision eliminates most of the market before you reach a price.

What's in this guide:

What is B2B website visitor identification?

The category exists because of a gap between two numbers. Twilio Segment reports that around 98% of visitors stay anonymous, and 6sense found that about 3% of B2B visitors fill in a form. Every tool in this market is an attempt to recover some part of that difference, and the pillar guide covers the whole category.

We got the first of those figures wrong ourselves. An early draft of ours rendered Twilio Segment's number as "up to 98%," which turns their floor into a ceiling and makes the anonymous share sound smaller than they actually measured it. I corrected it across three posts.

Both levels start from the same raw material. A visitor arrives, and their session produces a small set of signals — an IP address, a user agent, a set of page views, sometimes a cookie, occasionally a hashed email if they have clicked through from a marketing email. Post 2 walks through the five methods that read those signals. What separates the two levels is which of those signals the vendor leans on, and what the graph on the other side can do with it.

We treat that as the first question on any evaluation call now. The mechanics of the graph itself are the subject of a companion post in this series, what is an identity graph. This one covers the output, and specifically which output can support the thing you intend to do next.

How company-level identification works

Company-level identification resolves the visitor's IP address against a database mapping IP ranges to organizations. Corporate networks announce themselves. A block of addresses registered to a company, used from that company's offices or its VPN, resolves to that company with reasonable confidence.

The output is an organization. You learn that someone at a named company read three pricing pages on Tuesday. You don't learn who, and no amount of enrichment on top changes that, because the underlying signal never carried a person.

This is the older and more widely deployed of the two approaches, and its limits are structural rather than technical. Reverse IP resolution degrades exactly where modern work happens. A visitor on home broadband resolves to a residential ISP. A visitor on a phone resolves to a mobile carrier. A visitor behind a cloud security gateway resolves to the gateway's provider, which is why a large enterprise can look like it's browsing from Cloudflare.

I wouldn't call any of that a vendor defect, and I've stopped treating a low company-level rate as evidence that a tool is weak. It's simply what the internet looks like now. It's also the reason we see company-level rates vary by twenty points or more between two customers running precisely the same tool.

How person-level identification works

Person-level identification needs a stable identifier that belongs to an individual, not to a network. In practice that means a hashed email address, captured either when the visitor clicked in from an email or matched through a third-party identity graph built on US consumer data.

The graph does the rest. It holds edges between identifiers that have been observed together, and a lookup asks whether this device, this hashed email, or this combination has been seen alongside a known person before. When the answer is confident, the tool returns a name, a work email, and often a LinkedIn profile.

The property I most often have to explain on a call is that person-level identification isn't company-level identification with extra effort applied. It's a completely different mechanism running on different data, and it fails in different places.

A visitor whose IP resolves cleanly to a Fortune 500 office may return nothing at the person level, because nobody in the graph has ever linked that particular device to a particular human. The reverse happens just as often. Remote workers on residential connections are invisible to reverse IP and perfectly resolvable person-level, which is why I never assume the two rates move together on the same site.

The numbers, side by side

Once you put the published figures next to the tested ones, the two levels sit precisely like this.

Range chart comparing company-level and person-level B2B match rates against the highest published claim at each level.

LevelRealistic rangeHighest published claimIndependent testing
Company-level30-65%80% (Happierleads)not systematically tested
Person-level (US)15-20%55% (Happierleads)5-20% (MarketBetter, 12 platforms)
Consumer, full PII99.5% (LiveRamp, via Comscore CustomIQ)

The takeaway: Company-level identification resolves roughly two to three times more traffic than person-level, typically 30-65% against 15-20%. MarketBetter's testing of 12 person-level platforms in 2026 returned 5-20%, with the bottom of that range well below what any vendor advertises. The 99.5% consumer figure belongs to a different problem on denser data and is not a benchmark any B2B tool can be measured against.

When we compiled that vendor table, I took every figure from the source itself rather than from somebody else's roundup. It's slower. It also caught things a copied table would have carried straight through, and two rows had moved by the time I re-checked the set in late July, RB2B's among them.

The consumer number is the one I flag hardest. LiveRamp reports 99.5%, Comscore CustomIQ measured it rather than the vendor self-reporting it, and it describes matching on full personally identifiable information inside a consumer graph far denser than anything available in B2B.

I've seen it quoted three rows above a B2B tool in comparison posts that were careful about everything else. Nobody intends the implication. The reader still walks away with it, which is why we keep it in a separate band on our own chart and label what measured it.

Why one vendor publishes four different person-level rates

RB2B is the clearest example in the category. I'm not accusing anyone of misrepresentation. I'm showing you that a match rate quoted without its denominator can vary by a factor of five with all four figures still arithmetically correct.

SourceRB2B person-level figure
Warmly8-15%
MarketBetter10-20%
Bullseye~30%
RB2B's own documentation40-45%

The takeaway: Four published figures for one product span 8% to 45%, a five-fold spread. The differences come from what sits in the denominator — all traffic, US traffic only, or traffic the tool considers matchable — and from who was doing the measuring. RB2B's own support documentation puts the company-level figure at 30-35%, which is far less contested than any of these.

Every one of those numbers can be defensible at once. A rate calculated against matchable US traffic will always be larger than one calculated against all sessions, and neither party has to be misrepresenting anything for the two to differ this much.

A competitor names the same split, and blames the marketing rather than the buyer:

"But buried under all the marketing jargon and inflated match rate claims, there's a fundamental split that most buyers miss entirely. Some tools identify companies. Others identify people." — George Gogidze, Leadpipe (Leadpipe)

This is why I stopped treating a published match rate as a specification, and why Post 4 takes the whole category apart on that point. The only version of the number that truly means anything to you is the one produced on your own traffic.

We haven't published a match rate for Signal and we won't publish one until a customer test validates it. I made that call when the series started and I'd defend it now, even though it costs us the single number every competitor leads with. The flagship post in this series names Signal exactly zero times.

If I put a percentage on our pricing page tomorrow, I'd be adding a fifth unverifiable figure to a category that already carries four of them for a single competitor's product, and I'd be asking you to trust mine on precisely the grounds this post argues you shouldn't trust theirs.

What each level actually tells you

CapabilityCompany-levelPerson-level
Names the organizationyesyes
Names the individualnoyes
Returns a work emailnousually
Survives remote and mobile trafficpoorlyyes
Works outside the USyesrate falls sharply
Supports an ad audienceyesyes
Supports one-to-one follow-upnoyes
Carries CCPA personal-information dutieslimitedyes

The takeaway: The dividing line is whether the output can support a message addressed to a specific human. Company-level identification supports audiences, alerts and account prioritisation. Person-level identification supports those and one-to-one follow-up, at roughly a third of the coverage and with materially heavier compliance obligations attached to every record.

Read that table by row rather than by column and the trade becomes clear. Person-level wins seven of the eight rows, which is precisely why the category markets it so hard.

It also loses the one row that decides how much data you get at all. I've sat in evaluations where a team picked person-level on the strength of those seven rows, then spent a quarter wondering why their alert channel was quiet.

When person-level is real, and when it is not

It is real when your traffic is US-weighted

The graphs underneath every person-level tool in this market are built predominantly on US consumer data. That is a fact about where the data came from, not a limitation anyone chose.

If most of your traffic is European or Asian, person-level resolution will return a fraction of what the same tool returns for a US-focused competitor, and the published rate you were shown during the demo will have been calculated on a population you don't sell to. I pull the geography split before the first call now. It takes a minute.

It is real when a hashed email is already in play

The highest-confidence person-level matches are deterministic, and deterministic matching needs an exact identifier. Traffic arriving from your own email campaigns carries one. Traffic arriving cold from organic search usually doesn't, which is why the same tool can post very different numbers across two channels on the same site.

It is vaporware when nobody will name the denominator

I treat one specific answer as disqualifying. Ask a vendor what their match rate is measured against, and if the reply stays at "our proprietary methodology" through two follow-ups, the number isn't a number.

Every vendor I've asked directly has eventually given me a straight answer, which took one follow-up email in most cases and a scheduled call with a solutions engineer in two of them. Not one of them treated the question as hostile.

The compliance difference vendors skip

The two levels don't carry the same legal weight, and the gap widened on a specific date.

California's business-to-business exemption under the CCPA, which had kept employee and business-contact data outside much of the law's reach, expired on January 1, 2023, and since that date a work email address belonging to a Californian has been personal information in exactly the way a personal address is. The IAPP notes that the sunset wasn't extended.

Privacy counsel state the scope of that change plainly:

"As of January 1, 2023, the personal information of personnel (including job applicants, employees, officers, directors and contractors), and of business to business contacts, is subject to the California Consumer Privacy Act ("CCPA"). This is because of the January 1 sunset of the prior exemption for personnel and B2B data." — Theodore P. Augustinos and Nick Elwell-Sutton, Troutman Pepper Locke (Troutman Pepper Locke)

Company-level identification mostly sits outside that problem. An organization isn't a natural person, and knowing that somebody at a company visited your pricing page doesn't by itself create a record about an individual.

Person-level identification creates exactly such a record, on every match, usually without the individual having filled in anything at all. That doesn't make it unlawful. It does mean a person-level deployment is a decision your counsel should see before it ships, not after, and I'm not qualified to make it for you.

It does mean the two levels belong in different rows of your privacy documentation. A person-level deployment needs your counsel involved in a way a company-level one may not. The consent architecture for the tracking layer is covered separately in this series, under is it legal to track and identify website visitors.

A second consequence catches people later. A person-level record invites a follow-up email, and that email is governed by a completely different set of rules from the identification that produced it.

Bulk senders now operate against a spam-complaint ceiling of under 0.3%, with a target under 0.1%, under the Google, Yahoo and Microsoft requirements. A list assembled from people who never opted in generates complaints at a rate that clears 0.3% quickly, and the reputation cost falls on the domain you send everything else from.

We feed identified contacts into the systems you already run rather than sending on your behalf, which forgoes the sending revenue and leaves your domain reputation where it belongs, with you. Whether a given record should be emailed at all is a question for you and your counsel, and routing it into a CRM is covered separately in this series under routing anonymous visitors into your CRM and ATS.

How to pick a level

Five-step procedure for choosing between company-level and person-level identification, ending in a validation on your own traffic.

  1. Decide what you'll do with the record. If the next step is an ad audience, an account-prioritisation score, or a Slack alert to an owner, company-level is sufficient and will cover far more of your traffic. If the next step is a message addressed to a named human, only person-level will do. This decides the question; the remaining steps confirm you can live with the answer.
  2. Check how much of your traffic is US. Pull the geography split you already have in analytics before a single demo. A person-level tool evaluated on 30% US traffic will disappoint you for reasons that have nothing to do with the tool.
  3. Ask which denominator the rate uses. All sessions, or matchable sessions. I ask this in the first ten minutes now, and the answer reorders the shortlist more often than the price does.
  4. Treat person-level output as personal information. It is personal information in California, and it needs to be documented as such before it lands anywhere.
  5. Run it on your own traffic before you sign. Two weeks of a live pixel measured against a denominator you control settles every published claim in this post. Any vendor confident in their number will help you produce it.

We built Signal around that last step, which is why the compound claim we make is validated, routed and under $100 rather than a headline percentage.

Two weeks of a live pixel on your own traffic, measured against a denominator you set, settles every published claim in this post, ours very much included. Run it on us.

Frequently asked questions

What is the difference between person-level and company-level visitor identification?

Company-level identification resolves a visitor's IP address to the organization they are browsing from, returning a company name and no individual. Person-level identification uses an identity graph and a stable identifier such as a hashed email to return a named individual, usually with a work email attached. Company-level covers more traffic; person-level supports one-to-one follow-up.

What is a realistic B2B website visitor identification match rate?

Person-level match rates realistically land at 15-20% of US B2B traffic based on vendor documentation compiled in July 2026, and independent testing of 12 platforms by MarketBetter in 2026 returned 5-20%. Company-level typically runs 30-65%. Published claims reach 55% for person-level and 80% for company-level, both from Happierleads.

Why do vendors publish such different match rates for the same tool?

Because the denominator is rarely stated. A rate measured against matchable US traffic is much larger than one measured against all sessions. Four published person-level figures for RB2B span 8-15%, 10-20%, around 30%, and 40-45%, sourced from Warmly, MarketBetter, Bullseye and RB2B's own documentation. All four can be defensible measurements of different quantities.

It is not prohibited, but it carries obligations that company-level identification largely avoids. California's business-to-business exemption under the CCPA expired on January 1, 2023, so a work email belonging to a Californian is personal information. A person-level deployment needs privacy counsel involved and proper documentation. This is not legal advice.

Does person-level identification work outside the United States?

The match rate falls sharply. The identity graphs underpinning person-level tools in this market are built predominantly on US consumer data, so coverage outside the US is materially lower and published rates will usually have been calculated on US traffic. Company-level identification, which relies on IP-to-organization mapping, travels better internationally.

Should I use company-level or person-level identification?

Decide by naming the action that follows the match. Ad audiences, account scoring and owner alerts need only a company, and company-level covers two to three times more traffic. A message to a named individual requires person-level. Then validate the vendor's rate on two weeks of your own traffic before signing anything.

Continue the Series

This is Post 6 in Geysera's 13-part series on B2B anonymous visitor identification.

Sources

Bob Thordarson

Co-Founder and CEO

Bob Thordarson is CEO and Co-Founder of Geysera, a serial entrepreneur with 25+ years and five co-founded ventures, including Cequint (acquired by TNS in 2010 for $112.5M) and Consumerware (acquired by ParkerVision). A graduate of the University of Washington and MIT Entrepreneurial Masters Program, based in Seattle, he serves on the boards of DRY Soda Co. and the Entrepreneurs' Organization Seattle chapter. He is an expert in retention marketing email systems and methodology for ecommerce and B2B brands — measured by incremental revenue, not vanity metrics.