How to Audit Your AI Citations: The 6-Step Method Security Marketers Use to Find Out Why AI Skips Their Brand
When a CISO asks ChatGPT for "best SSO solutions for mid-market," the answer names five vendors. This guide shows you exactly how to find out which sources put those five vendors there, and why you weren't one of them.
B2B buyers are shifting where they start vendor research. G2's research found 51% of B2B software buyers now start their research with an AI chatbot more often than with Google — up from 29% just eleven months earlier (G2 Research, April 2026, retrieved 2026-09-18). Security buyers researching inside ChatGPT, Perplexity, or Claude don't get ten blue links. They get a shortlist.
Here's what most marketing teams miss: that shortlist isn't random. Every AI engine builds its answer from a specific set of citations, and those citations follow patterns you can map, measure, and change. If your brand keeps getting skipped, the reason is sitting in a handful of specific URLs. You just haven't audited them yet.
This guide gives you the full audit method. It takes a few hours to run manually. By the end, you'll know exactly which sources decide the shortlist in your category, whether your problem is presence or citability, and which one or two pages are carrying your competitors into every answer. GrackerAI's AI visibility platform automates most of what follows — more on that at the end, once you know what you're looking for. This citation audit is one specific layer — it assumes your technical and organizational security posture is already sound. If you have not run a traditional audit recently, the blind spots in cybersecurity audits is worth doing first.
Understand the Two Filters Your Brand Has to Survive
When an AI engine answers "top SSO solutions," your brand gets filtered twice.
Filter 1: Retrieval and extraction. The engine searches the web and pulls roughly 10 sources. But it doesn't read full pages. It extracts snippets and chunks. If you're mentioned in paragraph 14 of a listicle, below the fold, outside any table or heading, you may not exist in what the model actually reads. The page cited you. The model never saw you.
Filter 2: Synthesis. From what survives extraction, the model decides who makes the answer. The biggest signal is cross-source consensus: a vendor appearing in 8 of 10 retrieved sources is the "agreed answer." A vendor appearing in 1 is noise. The model also favors brands it already recognizes from training data, brands described with the exact category language in the prompt, and brands framed strongly (comparison tables, "best overall" labels, dedicated sections) rather than mentioned in passing.
Every visibility problem lives in one of these two filters. The audit tells you which. For more on how each engine's retrieval and synthesis steps actually work, see our breakdown of how AI engines decide which sources to cite.
Step 1: Build a Prompt Set, Not a Single Prompt
One prompt tells you almost nothing. Retrieval changes with phrasing, so you need 15 to 30 prompt variants written the way real security buyers actually ask:
"top SSO solutions" / "best SSO for mid-market" / "Okta alternatives for a 200-person company" / "SSO tools comparison 2026" / "which identity provider should a Series B startup use"
Don't invent these from a conference room. Pull them from your Google Search Console and Bing Webmaster data. The queries your real buyers type retrieve different sources than the queries marketers imagine, and the real ones are the only ones that matter for pipeline.
Step 2: Run Every Prompt Across Every Engine and Log the Citations
Run each prompt on ChatGPT (with browsing), Perplexity, Gemini, Copilot, and Google AI Overviews. All of them expose their sources.
For every run, capture four things:
- The cited URLs
- The domain behind each URL
- Which brands appeared in the answer
- Where each brand appeared: first third of the response, middle, or tail
Position matters more than most teams realize. A brand named in the opening lines is the engine's confident pick. A brand squeezed into the last sentence is barely on the list.
One more rule: run each prompt 3 to 5 times across a few days. AI retrieval is non-deterministic. A source cited in 4 of 5 runs is load-bearing. A source cited once is noise. You cannot tell them apart from a single run.
Step 3: Build Your Citation Frequency Table
Now aggregate. Across all prompts, all engines, all runs: which domains get cited most in your category?
In cybersecurity categories the pattern is usually some mix of G2 and Gartner Peer Insights, Reddit threads (r/sysadmin, r/cybersecurity, r/netsec), a handful of "best X tools" listicles from security publications, vendor comparison pages, and occasionally Wikipedia or analyst summaries.
Your top 10 to 15 domains by citation frequency are the target surface. These specific pages decide who makes the shortlist. This single table is the most valuable output of the entire audit — it's the same diagnostic our study of attack surface management vendors builds at scale across 240,000 AI responses; here you're building the same thing by hand, for your own category.
GrackerAI's Top Citing Domains view builds this table automatically and refreshes it daily across the AI engines it tracks, once you're ready to stop doing it by hand.
Step 4: Diagnose Presence vs. Citability
Here's where the audit turns into an action plan. For each high-frequency source, check two things separately:
A. Are you mentioned on that page at all?
B. When that page gets cited, do you survive the answer?
These are completely different problems with completely different fixes:
What you find | Your problem | Your fix |
Not on the page | Presence | Earned media: get included in the listicle, comparison, or review site |
On the page, never in the answer | Citability | You're mentioned too late, outside tables and headings, or described with language that doesn't match buyer prompts |
On the page, sometimes in the answer | Weak consensus | You need presence on more of the top sources so the model sees agreement |
In the answer without strong citations | Brand prior | The model already knows you; protect this by keeping sources fresh |
Most security vendors assume they have a presence problem. The audit frequently reveals a citability problem instead: they're already on the right pages, buried in paragraph 12, described as "workforce access management" while every buyer prompt says "SSO." Our guide on how to track AI citations, mentions, and sources covers the ongoing monitoring version of this diagnostic once you've run it once by hand.
Step 5: Trace Your Competitors' Citation Paths
For each competitor that consistently makes the shortlist, work backwards: which specific citations carried them in?
You'll usually find one or two kingmaker sources. A single well-structured comparison table on a high-authority domain often drives the majority of a competitor's inclusions across every engine.
Those kingmaker pages become your priority list. Two moves: get placed on the same page, or publish a stronger, better-structured asset that engines start pulling instead. Both work. The second one compounds. Closing the gap from here usually comes down to the same distribution and validation work covered in our ChatGPT citation playbook. It also helps to know what category those kingmaker sources tend to fall into — how AI search engines surface brand reputation signals breaks down why regulatory, legal, and journalism sources so often outrank owned content in these citation paths.
Step 6: Re-Run Monthly and Track the Deltas
Citation sources rotate. A domain that engines stop citing is an early warning your visibility is about to drop, weeks before any score reflects it. A newly cited domain is a window: get placed while the source is fresh, before the shortlist calcifies around it.
Re-run the full audit monthly at minimum. Quarterly is too slow. The engines move faster than that.
The Output: One Matrix That Tells You Everything
When you're done, you have a simple grid. Prompts down the side. Top citing domains across the top. Each cell marked one of three ways: brand present on page, brand cited in answer, or neither.
That one matrix answers the question every security CMO is asking right now: is our gap a presence problem or a citability problem? Get that diagnosis wrong and you'll spend two quarters producing content when you needed placements, or chasing placements when your existing pages just needed restructuring. That matrix is also exactly the kind of artifact lean marketing teams need to turn into a stakeholder deck — see the content-to-deck pipeline for B2B marketing teams for a repeatable way to do that without losing a week.
Two Things the Manual Audit Will Teach You Fast
Engines behave differently, so never blend the data. Perplexity leans on recent high-authority pages and Reddit. ChatGPT browsing favors a smaller set of established domains. Google AI Overviews largely mirrors existing Google rankings. A blended visibility number hides which engine is actually costing you deals. Keep every metric per-engine.
Incumbents get a head start you have to out-cite. For brands the model already knows from training data, engines sometimes include them even on thin citation support. Challengers don't get that courtesy. If you're the newer vendor, you need overwhelming cross-source presence to displace a familiar name. That's not unfair. It's just the consensus math, and now you know how to work it.
Frequently Asked Questions
How long does a manual AI citation audit take?
A single pass — 15 to 30 prompts across five or more AI engines, three to five runs each — takes a few hours of hands-on work. Re-running it monthly to track deltas takes less time once the prompt set and domain list already exist.
Is my problem presence or citability?
Presence means your brand isn't mentioned at all on the pages AI engines cite most. Citability means you're on those pages but described too late, outside a table or heading, or in language that doesn't match how buyers phrase their prompts. Step 4's diagnostic separates the two, because they need different fixes.
Do AI engines cite the same sources every time you run a prompt?
Not exactly the same set, and not always the same sources over time. Citations rotate as engines re-crawl and re-rank the web, which is why a single audit run is a snapshot, not a permanent map. Re-running monthly catches a newly cited domain while it's still fresh and flags a domain that stopped being cited before it shows up as a visibility drop.
Should I track AI citations the same way across every engine?
No. Perplexity, ChatGPT, and the Google AI surfaces pull from different source mixes and behave differently, so a blended visibility number hides which engine is actually costing you deals. Keep every metric per-engine.
What's the difference between this audit and an AI visibility score?
The manual audit tells you which specific URLs are carrying your competitors into AI answers, and why. A visibility score summarizes citation frequency over time without necessarily naming the pages behind it. Run the manual audit first to understand your category, then use a score to track the trend.
Run It Manually Once. Then Never Again.
Do the manual audit at least once. Nothing builds conviction like watching a competitor ride one comparison table into every answer in your category.
But 15 to 30 prompts, five or more engines, three to five runs each, logged over days, with position tracking and source deltas? That's thousands of data points a month. It's the kind of tracking GrackerAI automates for security teams: daily prompt tracking across the AI engines it monitors, per-engine citation frequency, position distribution, alerts when a source starts or stops being cited, and a recommendation engine that turns the gaps into a prioritized fix list.
See how AI sees your brand. GrackerAI offers a free trial (a credit card is required to start it) that generates an AI visibility score in about a minute — a faster starting point once you've run the manual audit once and know what you're looking for.