Learn · Visitors and identity · Updated 2026-08-14

Person-level vs company-level visitor identification

Company-level identification matches a website visitor's IP address to the business it belongs to. Person-level identification tries to match that visitor to a named individual, a harder claim. Company-level is more reliable since it only identifies an organization, not a person.

The two get sold as points on the same spectrum, one product tier away from each other. But they rest on different evidence. Confusing them is how a business ends up paying for "who visited your site" and getting a list of companies, or paying for a list of companies and being quietly upsold on named contacts that are guesses dressed up as facts.

What each one is actually claiming

Company-level identification, sometimes called firmographic identification, takes a visitor's IP address and checks it against a database of IP ranges registered to businesses, internet service providers, and hosting companies. The output is an organization. A name, a domain, sometimes an industry and headcount. It never claims to know which specific employee was browsing.

Person-level identification goes a step further. It tries to attach a named individual to that same visit. That requires a different kind of data entirely, usually a match against a data broker's file, a cookie or device graph, or hashed contact data the visitor already gave someone else. It is a fundamentally harder problem, because a business network, a home wifi router, or a shared IP behind a VPN can sit between dozens of people and a single IP address, and nothing about the IP itself says which one of them clicked.

How company-level identification actually works

Most business internet connections route through IP ranges that an internet registry has recorded as belonging to that company, its ISP, or a cloud provider it rents infrastructure from. A company-level tool reverse-looks-up the visiting IP against exactly that kind of registry, cross-referenced with firmographic data providers that maintain company-to-IP-range mappings. When the match lands on a real office network, it tends to be reasonably solid, because a business's registered IP block does not change often and does not get casually shared outside the organization.

How person-level identification actually works

Since an IP address alone cannot narrow down to one person, person-level tools lean on the same three signals covered on what is de-anonymization: cookie and device graphs bought or synced from data brokers, IP intelligence stretched past its reliable use case into a guess about a specific resident, or hashed contact data matched against a business's own list. None of these were designed to identify a stranger with certainty, and all three inherit the shared-IP and stale-graph problems described there.

Company-level identificationPerson-level identification
What it resolves toAn organization: name, domain, industryA named individual
Primary data sourceIP-to-business range registries, firmographic databasesData broker cookie graphs, device fingerprinting, or hashed contact matching
Reliability profileReasonably stable; business IP ranges change infrequentlyMuch less stable; depends on cookie persistence and broker file freshness
Main failure modeRemote and hybrid workers on home connections don't route through the office IP rangeShared IPs, cleared cookies, and stale broker data produce false or expired matches
Privacy exposureLower; a business name is not personal data in most frameworksHigher; a named individual is personal data under GDPR, CCPA, and similar laws
Best suited toB2B lead qualification, account-based marketing, sales prioritizationRarely defensible for anonymous strangers; more legitimate when reuniting a business with its own known contacts

Why remote work broke company-level identification's core assumption

This is the part most explanations of B2B visitor identification skip. Company-level matching was built on an assumption that held up reasonably well through the 2010s: employees mostly browse the internet from an office network with a registered, stable IP range. Widespread remote and hybrid work broke that assumption. An employee working from a home connection, a co-working space, or a mobile hotspot is routing through their home ISP's or carrier's IP range, not their employer's. Database freshness does not fix that, because the information a company-level tool needs (which business this connection belongs to) simply is not present in a residential IP block. The practical result is that company-level identification tools now systematically undercount or miss remote employees, while still confidently matching whoever happens to be in the physical office that day. A B2B visitor identification report from any vendor should be read with that skew in mind, not as a complete account of who visited.

What "which company visited" can and can't tell you

A solid company-level match can tell a sales or marketing team that a specific organization looked at their pricing page three times this week, which is a genuinely useful signal for prioritizing outreach. It cannot tell them which person at that company did the looking, what that person's role is, or whether it was one person or five different employees across three visits. Those gaps get filled in, often, by guesswork dressed as insight: a tool infers a likely contact from the company's org chart on a professional network and presents it next to the visit as if both were observed together. They weren't. Only the visit was; the name came from a separate database entirely.

How to tell which one a vendor is actually selling you

Vendor pages in this category tend to use "visitor identification" as a single umbrella term, which makes it hard to know what you would actually receive before signing up. A few direct questions cut through most of the marketing copy. What does the output field actually contain, a company name and domain, or a first and last name? Then there's the network question: what happens when the same visitor returns on a different connection, a phone on a carrier network instead of office wifi? A company-level tool will often lose that visitor entirely, while a person-level tool built on cookies might still catch them. And ask how the tool handles a shared office. Do ten employees at the same company on the same IP range get reported as ten separate matches, or one company-level record? The honest answer is the latter. A vendor implying otherwise is overselling resolution it doesn't have. None of these questions require technical expertise, and a vendor that can't answer them plainly is telling you something about the product on its own.

The privacy line between the two

A company name is not personal data under most privacy frameworks, which is a meaningful part of why company-level identification is the safer default. A named individual is personal data under GDPR, CCPA, and similar laws, and matching a stranger to one without their knowledge sits in genuinely contested legal territory that shifts by jurisdiction and by exactly how the match was produced. This is not a claim that person-level identification is always unlawful. It is a claim that the compliance burden is real, specific to the method used, and worth resolving before a sales team starts reaching out to names a tool inferred rather than names a visitor actually gave.

Which one to actually use

For B2B use cases, company-level identification is the more defensible default. It answers a question, which organization is showing interest, using evidence that is genuinely tied to the visit itself, and it carries a lighter privacy footprint because an organization's name is not personal data under most frameworks. Person-level identification of an anonymous stranger is the part of this market most prone to overclaiming, because the underlying evidence, a cookie graph or an IP stretched past its reliable use, is inherently weaker than a business IP registry, no matter how confidently a vendor's dashboard presents it. The one place person-level matching holds up is when it is reuniting a business with someone already in its own contact list, which is a fundamentally different and better-supported claim than identifying a true stranger.

Where Raydar sits

Raydar's visitor identification sits at the level of a hashed IP address, not a device fingerprint and not a person-level data broker lookup, tagged with an explicit high-confidence or low-confidence label. It doesn't claim to name an individual visitor. It also won't catch every remote worker's home connection, for the same structural reasons described above. Coverage is limited to the links and pages Raydar itself serves, the same scope limit that applies to website visitor tracking generally. Read what is website visitor tracking and how to track website visitors alongside this page before treating any identification report, from Raydar or anyone else, as a complete picture. And before trusting a match rate figure from any vendor, check what that number actually measures and how the underlying identifiers get linked together in the first place, covered in what is an identity graph.

Common questions

Can company-level identification tell me the name of the person browsing?
No, not directly. Company-level identification resolves an IP address to an organization. Any named individual attached to that visit came from a separate inference, usually guessed from a professional network profile, not from anything directly observed during the visit.

Is person-level visitor identification legal?
It depends on the method and jurisdiction. Matching a visitor against a business's own existing contacts is on firmer ground than buying a broker's cookie-to-name graph to identify a stranger, and laws like GDPR and CCPA treat named-individual data differently from company-level data.

Why does a B2B visitor identification tool miss so many remote workers?
Because it matches against IP ranges registered to a company's office network. A remote worker on a home connection or mobile hotspot routes through their ISP or carrier's IP range instead, which contains no information tying it back to their employer.

Is company-level identification the same as an identity graph?
No. Company-level identification typically runs a direct IP-to-business lookup. An identity graph is a broader structure that chains multiple identifiers, cookies, devices, IPs, together across hops, which is a different and generally less certain mechanism.

Which is more accurate, person-level or company-level identification?
Company-level is generally more reliable, because it only has to match an IP to one of a limited, relatively stable set of registered business ranges. Person-level identification depends on cookie persistence and broker data freshness, both of which degrade quickly.

Related: What is de-anonymization? · What is an identity graph? · What is a match rate? · Intent data vs visitor identification