Guide
Person-Level vs Company-Level Visitor Identification
Every visitor identification vendor sells one of two answers. Company-level tools tell you an account is on your site. Person-level tools tell you a buyer is. They are built on different techniques, cover different shares of your traffic, and carry different privacy obligations, which is why "which one should I buy" is the wrong first question. This guide gives you the decision rule, then shows how both signals get routed into pipeline. For ranked tool picks, start with our best website visitor identification tools flagship; for the mechanics behind each method, see how visitor identification works.
What is the difference between person-level and company-level identification?
Company-level identification resolves an anonymous visit to the organization behind it. Person-level identification resolves the same visit to a named individual. The first is mostly reverse-IP lookup plus firmographic enrichment. The second is an identity graph: device, cookie, and account signals collected across a network of partner sites, matched to a professional profile.
That difference in method is why the two behave so differently. Reverse-IP reads an address range that belongs to a company, so it works for office traffic, never needed cookies, and is unaffected by cookie deprecation. An identity graph only resolves visitors who have already been seen somewhere in that network, so its coverage is capped by the network, not by your site. Warmly leads with company-level and layers person-level on top; RB2B is person-level first. For a vendor-by-vendor breakdown, see Warmly vs RB2B.
Which identifies more visitors?
Company-level usually resolves more of your B2B traffic, because it only needs the visitor's network to belong to a company. Person-level coverage is capped by the vendor's identity network, is strongest on US traffic, and is materially lower outside the US. Published match rates for both methods are vendor-reported and vary widely; your rate depends on how much of your traffic comes from corporate networks rather than home broadband, VPNs, and mobile carriers.
Two cautions. First, a company-level match on a large enterprise may be one of thousands of employees, so a "hit" is an account signal, not a buyer signal. Second, any vendor quoting a single guaranteed match rate is overselling. Expect coverage, not completeness, from either method, and size the upside with the de-anonymization ROI benchmark before you buy.
Which is more actionable for outreach?
Person-level is more actionable per match, because a name, title, and email can go straight into a sequence. Company-level is more actionable per dollar, because it feeds account-based plays: intent scoring, ABM ad audiences, and a rep alert that says "a target account is reading pricing" without needing to know which employee it was.
| Factor | Company-level | Person-level |
|---|---|---|
| Primary method | Reverse-IP plus firmographic enrichment | Identity graph, increasingly cookieless |
| What you learn | The visiting organization | The named individual |
| Coverage | Broadest on office and enterprise traffic | Capped by the identity network; strongest on US traffic |
| Best downstream play | Account alerts, intent scoring, ABM audiences | Direct sequence enrollment, LinkedIn touch |
| Works outside the US | Yes, wherever office traffic exists | Weakly, and restricted in the EU |
| Personal data under GDPR | Output usually not; the IP lookup can be | Yes |
| Cookie dependence | None | Low and falling, but coverage drops with it |
Whichever you choose, the person or account still needs to reach a rep inside five minutes to matter. That is a routing problem, covered in our speed-to-lead implementation guide, and it is where most identification budgets are wasted.
Which carries more privacy risk?
Person-level carries more privacy risk, because it processes personal data. Company-level output names an organization, not a person: "someone from Acme Corp visited." That lowers the risk, but it does not remove it, because in the EU the IP address used to resolve the visit can itself be personal data. That distinction drives most of the regional differences you will see in vendor coverage.
Person-level identification names an individual and is personal data under GDPR, so it needs a lawful basis, transparency, and data-subject rights handling. Company-level output names an organization, which generally lowers privacy risk, but in the EU the IP address used to resolve it can itself be personal data, so neither method is exempt. Nothing here is legal advice. This is why person-level tools identify US traffic far more aggressively than EU traffic, and why the same tool can be a fit for a US-only team and a poor fit for an EU-first one.
Court of Justice of the EU, Breyer v Bundesrepublik Deutschland (C-582/14, 2016)
Practical consequences: confirm where your traffic comes from before buying person-level, check the provider's lawful-basis and opt-out posture, and keep person-level alerts out of any workflow that would embarrass you if the visitor asked how you knew. Nothing here is legal advice; consult counsel for your jurisdiction.
Should you buy company-level or person-level first?
Buy company-level first for most B2B teams between 1 and 50 million dollars in ARR. Buy person-level first only if you are small, US-only, and can work a feed of names by hand. Here is the decision matrix, with the verdict for each situation.
| Your situation | Start with | Verdict |
|---|---|---|
| Mid-market or enterprise ICP, any international traffic, 5 or more reps | Company-level: Warmly | Best default. Broad account coverage, lower privacy exposure, intent scoring and CRM routing in the same tool. |
| US-only traffic, under roughly 5 million dollars ARR, fewer than 5 reps, manual follow-up is manageable | Person-level: RB2B | Best on a budget. Free tier, names go straight to Slack, but you own routing and the privacy posture. |
| Follow-up already under 5 minutes, want maximum coverage on US traffic | Both, Warmly first then RB2B | Right only once routing works. Two feeds into a rep who ignores one is worse than one feed they act on. |
| EU-first audience | Company-level only | Person-level coverage is thin and the compliance burden is real. Spend the budget on routing instead. |
Where person-level-first wins
To be fair to the other side: a US-only founder-led team with a few hundred visits a week and no RevOps does better starting with RB2B. The free tier removes the budget decision, a name in Slack is easier to act on than an account, and there is no routing system to build yet because the founder is the routing system. The moment that team adds a second rep or a European customer, the calculus flips to company-level.
How do you route both signals into pipeline?
You route both the same way: filter on ICP first, then push the fit signal to a named owner with a time-boxed SLA. The technique that produced the signal changes the alert, not the process.
- Filter before you alert. Company size, industry, and page intent for company-level; title and seniority added for person-level. Skip this and reps stop trusting the feed within a week.
- Route to an owner in seconds, not minutes. Company-level hits go to the account owner if one exists, otherwise round-robin. Person-level hits go straight into a sequence in Amplemarket or your engagement platform, with the rep alerted in parallel.
- Hold a 5-minute SLA on high-intent pages. Pricing, integrations, and repeat visits inside seven days are instant alerts. A single blog read goes to nurture. The speed-to-lead guide has the escalation rules.
- Measure by signal type. Track time-to-first-touch and meeting rate separately for company-level and person-level alerts. One of them will earn its budget and the other will tell you what to cut.
Tools produce the signal; the system turns it into pipeline. The Visitor Deanonymization agent ($349) picks company-level, person-level, or a hybrid for your traffic profile, installs Warmly or RB2B, tunes the ICP filters, and wires the Slack alert and CRM routing with you inside your own Claude, then confirms an identified visit reaches a rep in minutes before it is called done. For where your pipeline is leaking first, see your leaks priced in dollars.
Frequently asked questions
What is the difference between person-level and company-level visitor identification?
Which identifies more website visitors, company-level or person-level?
Is person-level visitor identification legal under GDPR?
Should I buy company-level or person-level identification first?
Can I use both company-level and person-level identification together?
What is the fastest way to turn identified visitors into pipeline?
Sources and references
Identification rates on this page are vendor-reported or commonly reported industry figures, and are directional, not a controlled study. Outcomes vary by traffic mix, geography, and follow-up process.
- EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive: the regulator's guidance on which tracking technologies fall within the ePrivacy consent rules.
- Court of Justice of the EU, Breyer v Bundesrepublik Deutschland (C-582/14, 2016): held that a dynamic IP address can be personal data for a website operator, which is why company-level identification lowers privacy risk without removing it.
- Oldroyd, McElheran, Elkington, "The Short Life of Online Sales Leads," Harvard Business Review (2011): why an identified visit has to reach a rep within minutes to be worth the identification.
Run this play in your own stack
Read the guide, then install the engine.
The Artemis AI GTM Engineer prices this leak in dollars before it recommends anything, then builds the fix with you inside your own Claude. See how an agent installs and buys, or start with the free audit that prices all seven leaks.