DSPs, agencies, advertisers, and everyone who buys

By Luca Passani, @Scientia_CTO, June 2026
In the previous installment, we climbed the supply side of the programmatic mountain. We observed the publishers trying to extract maximum yield from their inventory, SSPs caught between serving publishers and satisfying DSPs, and a few other platforms and companies that have built businesses around those tensions. Now we cross to the other side, the Audient side, where the people with the advertising budget dwell. Let’s start with the platform that sits at the center of it all.
The DSP: to Bid or Not to Bid?
The Demand-Side Platform (DSP) works for advertisers and agencies. Its job is to find the right audience, in the right context, at the right moment, at the lowest possible price, and prove that the spend produced a result.
The DSP landscape is more concentrated than the SSP market. At the top — in terms of market share and economic weight — sit the “walled gardens”.
Note: Walled Garden refers to a closed or exclusive ecosystem — be it a software platform or a digital advertising network — where the owner strictly controls access to content, applications, data, and user experience. Walled Gardens are the opposite of open web technologies built for collaboration with other industry players.
Examples: Apple’s App Store and Google’s Play Store; Facebook, Instagram, and X; Advertising and marketing technology platforms built on top of massive identity graphs that the owner won’t share with anyone.
Google’s DV360, Amazon DSP, and Meta Ads Manager combine DSP functionality with massive first-party data assets and owned inventory, putting them in a category that independent DSPs cannot fully replicate.
Note: Google’s DV360 and Amazon DSP support OpenRTB auctions, while Meta doesn’t. Meta is a Walled Garden in the purest sense. Meta’s Ads Manager does not act as an open programmatic DSP; it strictly buys inventory within Meta’s closed ecosystem (Facebook, Instagram, Messenger, WhatsApp) and the Meta Audience Network.
Among the independents, The Trade Desk (TTD) is the dominant player by a significant margin and the most vocal about transparency and open internet principles, making it the default choice for agencies and brands seeking an alternative to Google.
Note: The Trade Desk’s OpenPath initiative tries to bypass SSP intermediaries to access publishers directly. This hasn’t exactly made TTD the most beloved demand partner among supply-side players. Being aware of this tension will make you look “in the know” when discussing programmatic in polite company. Beyond the supply chain optics, OpenPath is also TTD’s attempt to create a supply path that bypasses Google’s server-side auction infrastructure (Google Open Bidding). The details are technically complex and contested. Arguably, TTD would prefer to buy inventory in auctions where Google doesn’t control the plumbing.
Microsoft Advertising (formerly Xandr), Viant, Adform, StackAdapt, and Criteo round out the tier of platforms that regularly appear in enterprise conversations, each with a distinct specialization — Criteo in commerce and retargeting, StackAdapt in native and programmatic display, Adform in European privacy-compliant buying and Viant in people-based targeting. Liftoff dominates mobile app install campaigns. The distinction between walled gardens and independents matters more in DSPs than in SSPs — because the data advantage the walled gardens hold is structural, not just a matter of scale.
DSPs are measured on campaign performance: ROAS and CPA for direct-response campaigns, and CPM plus viewability, brand safety, and incrementality for brand campaigns.
ROAS (Return on Ad Spend) and CPA (Cost per Action) are the bottom line — did the campaign generate revenue relative to what was spent, and at what cost per conversion? Viewability asks whether the ad was actually seen: not just served, but visible in the user’s viewport long enough to register. Brand safety asks whether it appeared next to content that could embarrass the advertiser. Finally, incrementality — the most demanding metric of all — asks whether the ad actually caused the conversion, or whether the user would have bought anyway. A DSP that can demonstrate true incrementality to its clients is offering something genuinely valuable.
Note: Attribution and incrementality are related but distinct concepts. Attribution asks which ad in the customer journey gets credit for a conversion — last-click, first-click, linear, or data-driven models each give a different answer, and that answer directly affects how budgets are allocated. Attribution is the industry standard, but has a known flaw: it measures correlation, not causation. A user who was going to buy anyway still triggers an attribution event. Incrementality fixes this by asking whether the ad actually caused the conversion, not just preceded it.
If you are familiar with supply-side concepts, you’ll notice how none of these metrics care about publisher yield. None of them reward a DSP for being generous to the sell side. A DSP that consistently overpays for impressions doesn’t keep clients (agencies and advertisers).
To perform well, a DSP needs signal quality, i.e. complete, accurate information in every bid request to make a confident decision. Is this a real user or a bot? Is this inventory on a brand-safe page or a domain-spoofed imitation? Is this authenticated user token a precise match for our identity graph, or a decaying probabilistic guess? Is this a premium smartphone or a misclassified generic device? A DSP flying blind on any of these questions is making consequential decisions based on data it knows is unreliable.
Note: make no mistake: of all signals, the identity graph is by far the most powerful for advertisers. I will illustrate the machinery that powers behavioral targeting in greater detail in the next chapter. As a rough guide, the identity graph is how ad tech finds out you’re pregnant before you tell anyone.
Signal quality is not the only important aspect, though. Cost minimization is equally important. Every bid request a DSP evaluates costs money — servers, bandwidth and engineering capacity. A DSP that receives millions of requests per second and bids on only a fraction of them is maintaining enormous infrastructure to process noise. When SSPs send everything, DSPs respond by throttling — setting hard QPS caps, deprioritizing SSPs that send too much irrelevant traffic, or cutting them off entirely. This is not a technical preference. It is a commercial ultimatum. The QPS crisis mentioned in Article 1 was not created solely by SSPs. It was the predictable result of DSPs finally saying “enough”.
These two demands — better signals and less noise — have been the central pressure shaping programmatic infrastructure for a decade. Traffic shaping, curation, and Supply Path Optimization are all, at their core, the ecosystem’s attempts to satisfy a DSP that wants to receive only what it can act on with confidence.
Note: A few campaign optimization plays worth knowing (and the terminology and concepts that come with them):
Supply Path Optimization (SPO) is the practice of auditing and rationalizing which SSPs and intermediaries a DSP buys through. In the header bidding era, the same impression can arrive simultaneously from five different SSPs, each taking a fee. SPO identifies the shortest, most transparent, and most cost-effective path from DSP to publisher, eliminating redundant hops. For SSPs, SPO is existential pressure — if a DSP decides it doesn’t need you in its supply path, your volume drops overnight.
Bid shading is the practice of submitting a bid below what a DSP would actually be willing to pay, exploiting the mechanics of auctions to minimize cost. In a first-price auction, you pay what you bid, so bid shading algorithms analyze historical auction data to estimate the lowest price likely to win and bid just above it. The result is lower publisher revenue and higher DSP margin. Publishers responded with dynamic floor pricing — which is why auction mechanics have become a significant battleground in programmatic. The shift from second-price to first-price auctions around 2019-2020 changed the calculus considerably but didn’t eliminate bid shading.
Audience segmentation is how DSPs translate advertiser objectives into bidding logic. A campaign targeting “in-market car buyers, 30-45, household income above $80k” requires the DSP to identify which bid requests match that profile — using identity graph data, contextual signals, and behavioral patterns — and bid aggressively on those while passing on everything else. The quality of the segmentation determines the quality of the campaign.
DSP’s incentives and disincentives summary:
| Incentives | Maximize campaign performance for advertiser clients; reduce wasted spend on poor-quality or misclassified inventory; process fewer but better bid requests — quality over volume |
| Disincentives | Overpaying for inventory destroys client relationships; processing irrelevant bid requests wastes infrastructure budget; poor signal quality forces conservative bidding that underdelivers campaigns (i.e. causes campaigns to underperform) |
| Temptations | Bid shade (i.e. strategically “lowball”) aggressively to underpay for inventory at the expense of publishers; use SPO to bypass SSPs and access publishers directly, cutting intermediaries who add cost; optimize for budget clearance rather than campaign efficiency; maintain algorithmic and inventory opacity that forces advertisers to trust reported outcomes rather than verify them — limiting the client’s ability to identify inefficiencies, question allocation decisions, or evaluate alternative platforms |
The Agency: The Advertiser’s Strategist and Gatekeeper
Before programmatic even existed, advertising agencies were the undisputed power brokers of the media world. A brand with a budget hired an agency — WPP, Publicis, Omnicom, IPG (now part of Omnicom), Dentsu — and the agency decided where the money went: which TV stations, which magazines, which billboards. The agency had the relationships, the expertise, and, crucially, the media-buying power that individual brands couldn’t replicate on their own.
Programmatic didn’t eliminate agencies. It complicated them.
On paper, programmatic should have made agencies less necessary. If a brand can buy audiences directly through a DSP, why pay an agency to do it? In practice, programmatic made the media buying landscape more complex, not less — more channels, more platforms, more data, more vendors, more opportunities to waste money in ways that are difficult to detect. Most brands don’t have the internal expertise to navigate that complexity alone. Agencies do, or at least claim to.
The agency’s position in the programmatic stack is important to understand. Agencies typically hold DSP contracts on behalf of their clients, meaning they control which DSPs have access to advertiser budgets and under what terms. They negotiate volume deals with DSPs and SSPs that individual advertisers couldn’t achieve alone. They own the campaign data — audience segments, performance benchmarks, attribution models — which creates a dependency that makes switching agencies painful even when performance disappoints.
This concentration of power has not gone unnoticed. Large advertisers have created in-house programmatic teams to bypass agencies entirely. This came as a direct response to the opacity of agency relationships. Brands that have looked closely at where their money actually goes have sometimes found that the answer was uncomfortable. A 2016 report on media transparency by the Association of National Advertisers found evidence of undisclosed rebates flowing from media owners to agencies without client knowledge. This was a watershed moment that made the industry clean up some of its practices.
Note: The Association of National Advertisers (ANA) is the leading U.S. trade association for advertisers. Founded in 1910, it represents major brands that collectively spend hundreds of billions of dollars on marketing each year. The ANA acts as the primary collective voice for the buy side. It has become an influential advocate for greater media transparency, improved measurement standards, brand safety, and fairer relationships between advertisers, agencies, and tech platforms. Its research reports and model contract templates are widely referenced and frequently shape how large advertisers structure their agency agreements and media buying practices.
Agencies also play an important gatekeeping role that is rarely acknowledged: they are frequently the ones who approve or reject vendor relationships on the demand side. A technology vendor trying to reach a brand advertiser often has to go through the agency first — and agencies have their own preferred vendor lists, technology partnerships, and incentives to favor certain solutions over others. Understanding this is essential for anyone trying to sell into the demand side of the programmatic ecosystem.
The Agency’s incentives and disincentives summary:
| Incentives | Retain client budgets by demonstrating superior performance; leverage volume buying power to negotiate favorable terms with DSPs and SSPs; build proprietary data and technology assets that create client dependency |
| Disincentives | The in-housing trend reduces the scope of agency relationships; programmatic transparency requirements make undisclosed margins harder to sustain; clients who build internal expertise become harder to retain |
| Temptations | Accept undisclosed rebates from media owners without passing savings to clients; favor DSPs and SSPs that offer better commercial terms over those that actually perform best; use proprietary ad tech stacks that create lock-in and obscure true costs |
The Advertiser: The One Holding the Budget
Every dollar that flows through the programmatic ecosystem originates from an advertiser. Coca-Cola, IKEA, a regional car dealership, a direct-to-consumer startup — they are the demand side in the most literal sense. They have a product, a message, and a budget. Everything else in the ecosystem ultimately exists to connect that budget to an audience.
Advertisers rarely interact with the programmatic stack directly. Most work through agencies that plan and buy media on their behalf, or through DSP account teams that manage campaign execution. The advertiser sets the objective: reach this audience, drive these conversions and keep the cost per acquisition (CPA) under a target. The agency and DSP figure out how to achieve it across the available inventory.
What advertisers actually care about is deceptively simple: did the ad reach a real person, on a real device, in a context that made the message land, and did it produce a measurable outcome? The entire measurement apparatus of programmatic — viewability, brand safety, attribution, incrementality — exists because advertisers kept asking that question and the industry kept struggling to answer it convincingly.
The advertiser’s relationship with the ecosystem is one of managed dependence. They need programmatic to reach audiences at scale, but they have limited visibility into where their ads actually appear, what they actually paid at each step of the supply chain, and whether the impressions they bought were seen by humans. Brand safety failures — ads appearing next to extremist content — make headlines precisely because advertisers discovered, often publicly, that the ecosystem they trusted had failed them.
Increasingly, large advertisers are responding by bringing programmatic buying in-house, bypassing agencies and negotiating direct relationships with DSPs and premium publishers. This trend — called “in-housing” — is one of the more significant disruptions to the agency model, shifting the balance of power in ways the ecosystem is still adjusting to.
The Advertiser’s incentives and disincentives summary:
| Incentives | Reach the right audience at the lowest possible cost; prove measurable return on ad spend; protect brand reputation through safe, premium placements |
| Disincentives | Limited visibility into where ads actually appear; ad tech tax means a significant share of budget never reaches publishers; brand safety failures are public and reputationally damaging |
| Temptations | Prioritize vanity metrics (impressions, clicks) over genuine business outcomes; accept inflated viewability numbers from self-reported SSPs; use market power to demand preferential pricing that squeezes publishers |
Ad Networks: The Old World
Ad networks predate programmatic and, in many ways, represent the architecture they were built to replace. An ad network aggregates inventory from multiple publishers and sells it packaged to advertisers, typically without the transparency or real-time pricing of RTB auctions. This is called arbitrage, i.e. the network buys low from publishers and sells at a higher price to advertisers, pocketing the margin.
The model has largely been absorbed by SSPs and exchanges. Most of what ad networks used to do is now done programmatically, with better price discovery and more transparency. You still encounter the term in mobile, niche verticals, and in outdated books about ad tech. In the open web context, treat it as legacy vocabulary — useful for understanding the history but not central to how the ecosystem operates today.
Note: AdMob — the mobile ad network acquired by Google in 2009, and full disclosure, a company I worked for at some point — is a good example of this trajectory: founded as an independent mobile network, absorbed into Google’s advertising stack, and now effectively a publisher SDK that feeds into programmatic infrastructure rather than an independent marketplace.
The Data Management Platform: Party like it’s 2016
The Wild West wasn’t lawless because men were evil. It was lawless because the law hadn’t arrived yet. And it was fascinating. What a fantastic sense of freedom it must have given those who ventured out there first. But all good things come to an end, and it’s usually for a reason.
The DMP era was the Wild West of audience data. No consent banners, no IAB frameworks, just third-party cookies and the quiet understanding that if you could see it, you could sync it. DMPs built empires on that assumption — vast empires of pseudo-anonymous profiles, traded and retargeted without anyone ever opting in. Seems like a century ago.
Note: Here are the main player names in the DMP industry: BlueKai (Oracle), Acxiom, Adobe Audience Manager, Salesforce DMP, Lotame, Exelate, but the list could be long. Some of these have shut down or gone out of business. Others have pivoted into Customer Data Platforms (CDPs), clean rooms, identity graphs or a combination of these elements. Stay tuned for an explanation of all of these terms.
Data Management Platforms were the backbone of audience targeting for the better part of a decade. There was a time when a DMP would collect behavioral signals from multiple sources — website visits, ad interactions, third-party data purchases — organize them into audience segments, and make those segments available for targeting. Buy a ticket to the Netherlands from an airline and a totally unrelated website would offer you accommodation in Amsterdam.
Of course, the foundation of all this was the DMP’s ability to unequivocally identify users. Easy peasy lemon squeezy. Be it a third-party cookie, a pseudo-anonymous (but unique) device ID, or an email address, programmatic players knew who the user was. A DSP using a DMP could say: “target users in the ‘in-market car buyer’ segment, 25-34, sports enthusiast”.

Figure: Where DMP data came from. Two of these three pipes are now significantly restricted. The industry has been improvising ever since.
At this point, you might have a question or two.
If DMPs are a thing of the past, why are we paying them so much attention?
Hold on a sec. Isn’t this something that the modern ad tech stack can pull off even today?
Two great questions that point directly to two faces of the same coin. Something happened in 2016. A sheriff was appointed, and the wild west — or at least its free-for-all version — was over. The gold rush ended. The name of that sheriff was GDPR, the EU regulation that made it really clear that personal information is sacred and that companies cannot share it with one another except under tightly controlled and regulated conditions. The maps got redrawn, the tolls went up, and “anonymous” stopped meaning what the DMPs thought it meant.
Note 1: GDPR was only the beginning. The Safari browser started limiting third-party (3p) cookies, followed by Firefox. Cross-site tracking started falling apart. California created its own version of the GDPR, and other US states followed suit. Brazil, Australia and other countries enacted similar regulations. GDPR rulings in the EU made it legally untenable to rely on US-based DMPs. Google announced that it’d also remove support for 3rd-party cookies. Privacy regulation frameworks are such a fundamental component of programmatic advertising that I’ll dedicate an article to the subject in the near future.
Note 2: I’m tempted to assume you already know the difference between first-party and third-party cookies. If not, first-party cookies are set by the website you’re actually visiting — they remember your login, your preferences, your shopping cart. They are widely considered privacy-safe because the relationship is direct and expected. Third-party cookies are set by a different domain than the one you’re visiting — typically an ad tech company whose tracking code is embedded on the page. They are the mechanism that allowed DMPs to build cross-site behavioral profiles without users ever knowingly interacting with the company doing the tracking. As noted previously, Safari and Firefox blocked them years ago. Chrome is the last major holdout.
Note 3: The diagram above refers to 1st, 2nd and 3rd-party data. Generally speaking, first-party data is the data a company collects directly from its own users through those first-party cookies and other direct interactions. Third-party data is what DMPs were built on: behavioral signals purchased from brokers who aggregated them across many sites using third-party cookies. Second-party data sits between the two: it’s someone else’s first-party data, shared directly with you through a partnership agreement. A publisher sharing their audience segments with an advertiser, or two brands exchanging customer lists, are classic second-party arrangements. The data is of higher quality than third-party because it comes from a direct relationship — but in Europe, GDPR’s purpose limitation principle makes these arrangements legally fraught: the users who consented to interact with Publisher A did not consent to have their data shared with Advertiser B.
The underlying unit of a DMP is typically a third-party cookie or device ID, such as IDFA and GAID (look them up if you are curious). Which is precisely why DMPs ended up in structural decline. Device IDs have been progressively removed or made inaccessible. As far as cookies go, third-party cookies have eroded, and browsers are now restricting cross-site tracking. The mechanism that powered DMP audience segmentation stopped working. The data became stale, the segments became unreliable, and the targeting became less precise.
Yet, we want to pay close attention to what the DMPs achieved and how that technology worked because what happens in today’s programmatic can be easily explained in the terms of replicating those functions in ways that are — arguably — respectful of today’s normative landscape, thanks to clean rooms, identity graphs, privacy-enhancing technologies (PETs) and more additions to the Rube Goldberg machine. A fully-fledged privacy stack today would include identity resolution, clean room, consent machinery and legal costs. As a rule of thumb, that’s probably 10x as expensive as a DMP license. This has made the cost of entry for smaller players notably higher.
Note: I made similar comments in previous articles, but it’s worth reiterating. If you are a privacy advocate, don’t be too hard on programmatic ad tech players. The walled gardens are running fully-fledged DMPs privately behind their fences. It’s all first-party data to them.
As far as DMPs go today, they haven’t disappeared — large enterprises still use them for first-party (1p) data activation — but their role has narrowed significantly. The industry has moved toward CDPs for first-party data and identity graphs for cross-device resolution. DMPs answer the question: What kind of person is this? Identity graphs answer: Who specifically is this? In a cookieless world, the second question is harder to answer but considerably more valuable.
The CDP: from the Saloon to the Bank
If a DMP is a saloon in a Western film, a CDP is a vault in the bank in the same movie. The Customer Data Platform collects, organizes, and activates data that a company gathers directly from its own customers and users. Purchase history, content consumption, login behavior, email engagement, and app activity are all good examples of the precious resources a CDP manages.
What you bought in the past is great insight to a retailer, just like which articles you read and for how long is great insight to a publisher. App creators want to know which features you use daily and which you’ve never touched. This data is first-party by definition: collected with the user’s knowledge (and consent), within a direct relationship, and owned entirely by the company that gathered it.
What distinguishes a CDP from a DMP is both the data source and the underlying identifier. DMPs were built on third-party cookies and device IDs — deterministic within a single browser or device, but relying on probabilistic inference when trying to connect the same person across devices. CDPs are built on known users: people who have logged in, made a purchase, subscribed to a newsletter, or otherwise established a direct relationship with the brand. The identifier is typically a first-party cookie, a hashed email address (HEM), or a CRM record — deterministic signals that don’t disappear when a browser blocks third-party cookies, and that can optionally be passed to identity providers like LiveRamp or The Trade Desk to generate portable cross-site identifiers.
Note: An email address like sloane@email.com (or any string of characters, for that matter) can be run through a one-way mathematical formula that yields 938baa3d…026511d94. This string cannot be casually reversed to the original email address, but it retains its uniqueness for matching purposes. This makes it pseudo-anonymous for the purposes of handling personal information.
In the programmatic context, a CDP allows a publisher or advertiser to bring their own audience data into the auction rather than relying entirely on what SSPs and DSPs can infer from bid-stream signals. A publisher who can say “this user is a verified subscriber who reads technology content daily and has a household income above $100k” is offering something that no amount of third-party inference can reliably produce. That’s a genuinely differentiated signal — and in a cookieless world, differentiated signals command premium CPMs.
The limitation is equally clear: CDPs only know about users who have a direct relationship with that specific publisher or advertiser. The anonymous visitor, the unauthenticated browser, the CTV user who never logged in — they remain invisible. CDPs are powerful within the known audience and blind beyond it. Which is why they complement rather than replace identity graphs and device-level signals.
The CDP market is considerably more fragmented than the DMP market it replaced. At the enterprise level, Salesforce, Tealium, Adobe, and Treasure Data lead the main analyst rankings. Segment (Twilio) dominates among engineering-led organizations. Amperity is strong in retail. The honest observation is that CDP category definitions are blurry: some are data warehouses with a marketing layer, others are identity resolution engines, others are campaign activation tools. What they share is the first-party data foundation that DMPs lacked — and that’s the point.
DMP vs CDP: The Saloon vs The Bank
The following table compares the main aspects of DMPs and CDPs respectively.
| DMP – The Saloon | CDP – The Bank Vault | |
| ID | 3p cookie, IDFA, GAID. Anonymous, probabilistic* | HEM (Hashed EMail), 1p cookie ID, RampID/UID2, CRM ID. Known, deterministic* |
| Data Source | 3rd party broker data. Everyone’s data, bought | 1st party data. Company’s data, owned |
| Scale | Massive. 80%+ of web users, but anonymous | Limited. Only authenticated users. 5-30% of traffic |
| Accuracy | Modeled, aggregated, decays fast. “Likely in-market” | Deterministic, event-level, persistent. “Purchased 3x” |
| Business Model | Data brokerage. Rent segments to anyone | Data stewardship. Monetize your own vault, directly |
* Both DMPs and CDPs can layer in probabilistic signals — DMPs relied on them as a foundation, CDPs use them to extend coverage at the edges, primarily for cross-device stitching and anonymous visitor resolution where no deterministic signal is available.
The CDP’s incentives and disincentives summary:
| Incentives | Activate first-party data to command premium CPMs; reduce dependence on third-party data vendors; build durable audience intelligence that survives cookie deprecation |
| Disincentives | Only covers known, authenticated users — a fraction of total addressable inventory; requires significant data infrastructure investment; GDPR and CCPA compliance obligations attach to every data use |
| Temptations | Overstate the coverage and accuracy of first-party segments to attract premium demand; use CDP data for purposes beyond what users consented to; aggregate data across partners in ways that effectively recreate third-party tracking under a first-party label |
If DMPs represented the gold rush age, CDPs are a more civilized way to obtain the same thing: personal data. The DMP era ended. The functions it served did not. In the next installment, I’ll look at how the industry rebuilt those capabilities — audience identification, behavioral targeting, cross-device resolution — on a new foundation designed to survive the regulatory and technical landscape that killed the original model. CDPs, identity graphs, and clean rooms are the three pillars of that reconstruction. Each solves a different piece of the puzzle. Together, they perform roughly the same job a DMP did in 2016, at considerably more complexity and cost, with considerably more legal cover. Whether that legal cover is genuine or performative is a question I’ll also address in due time.
Before we move on, it’s worth acknowledging a few other important players on the demand side. Not every company buys inventory directly, but several have carved out valuable niches. Just as I described on the supply side, not every player in programmatic has a seat at the main table, but a few are worth knowing because you’ll encounter their names — along with the concepts and the terminology they have created — in industry conversations.
The Supporting Cast
Not every player on the demand side buys inventory. All this complexity has created space for players who specialize in niche roles. I’ll introduce some of those here.
The supply-side forensic accountants
As I have shown in the previous article and in this one, every player has temptations. If you think about it, billions of dollars in programmatic advertising are transacted on JSON files (text files, essentially) that each intermediary can mess with. It shouldn’t come as a surprise that players do mess with the information in those files with varying degrees of dishonesty, creativity and plausible deniability.
Two companies worth knowing in this context are DeepSee.io and Jounce Media, founded by Chris Kane (whom I watched speak at many events). Both specialize in programmatic supply chain analytics — independently evaluating the quality, authorization, and directness of supply paths to help advertisers and agencies understand where their money actually goes. Chris Kane coined the MFA (Made for Advertising) term, and his research helped surface that at its peak, MFA inventory was appearing in 30% of open web auctions — a figure the industry could no longer ignore once it had a name. DeepSee.io focuses specifically on CTV and streaming supply chain transparency, where the measurement gaps are even larger than on the open web. Think of them as the independent auditors of an ecosystem that has historically been very reluctant to audit itself.
Sincera deserves a mention too — a startup that aggregates metadata and media telemetry data about the programmatic supply chain, crawling publisher ad stacks to reveal which identifiers appear in bid requests, how often ads refresh, and whether consent is being properly collected. The Trade Desk acquired them in early 2025 and subsequently launched OpenSincera as a free, open tool available to the entire industry, which is either a genuinely altruistic transparency initiative or the savviest possible way to position yourself as the supply chain’s neutral referee.
I can actually think of a plethora of other companies that could deserve a mention here. I’ll introduce them in the next few chapters as I illustrate the mechanics that deliver the different programmatic signals. There is one final aspect before I embark on signals.
The Elephant in the Room: Why the Gardens Stay Walled
Once you understand the sheer friction of the independent programmatic landscape — the Ad Tech Tax bleeding the demand side, the identity signal degradation panicking the supply side, and the constant threat of arbitrage — a fundamental question emerges for the uninitiated:
Why does anyone bother with the open web at all? Why not just hand the entire budget to Google, Meta, and Amazon?
The truth is that is exactly what most advertisers do. By operating fully vertically integrated stacks, the Walled Gardens act as the agency, DSP, SSP, and publisher simultaneously. They don’t have a middleware tax; their identity signals are bulletproof because users are permanently logged in, and the bad guys can’t inject fraudulent inventory into an Instagram feed the way they can exploit the open-web bidstream.
Looking at the money at play helps to understand the scale of what open web programmatic is competing against. The diagram below maps the approximately $1 trillion global advertising market as it stood in 2024.

Figure: Directional figures compiled from GroupM, WARC, and ANA. Treat as orders of magnitude, not precise accounting. China’s domestic market (Douyin, Baidu, WeChat) is excluded.
The numbers make the stakes concrete. Digital advertising now accounts for roughly 80% of total ad spend. Of that digital spend, the walled gardens — Google, Meta, Amazon, ByteDance — capture approximately 60%. If you add a share of the other digital that also benefits Google, Meta and Amazon, walled gardens can be credited for 75% to 80% of the market.
The entire independent open web programmatic ecosystem, the one this series has been describing in detail across four articles, competes for roughly 7% of digital ad spend. That context is what makes the “existential race” framing more than rhetoric — it is an accurate description of the competitive situation.
Yet there are a few reasons advertisers still pour tens of billions of dollars into open-web programmatic. Walled Gardens solve for efficiency, not for every use case. Advertisers need incremental reach beyond social and search — the B2B buyer reading trade press, the local news reader, the CTV household that cut the cord. They need context they can contractually guarantee, not an algorithm that might place them next to a conspiracy video. They need to own their audience data rather than rent it to maintain leverage when one platform changes the rules, and to access formats — DOOH, in-game audio, sponsored podcasts — that don’t exist within the feed. In short, the Gardens are efficient banks, but not every company wants all its money in three banks.
But the open web’s share of total ad spend remains small. Which brings us to the ultimate irony of modern technology policy. While antitrust regulators claim they want to break up tech monopolies, privacy regulations like GDPR and CCPA push in the exact opposite direction. I will illustrate this in more detail in a future installment. By heavily penalizing the transmission of identity data between independent companies over the open web, privacy laws have inadvertently created a multi-billion-dollar compliance moat around Big Tech’s data empires.
The independent ad tech ecosystem — with its Prebid wrappers, identity graphs, and device signals — is not just an optimization exercise. It is an existential race to make the open web as efficient, safe, and transparent as a Walled Garden, before independent content creators are starved out entirely.
This concludes the high-level view of ad tech players and their incentives. A longer list would be possible, but the risk of information overload is real, and the landscape shifts fast enough that any list is already aging by the time it’s published. The best I can do is mention Lumascape by LUMA partners, the iconic infographic that has mapped the entire digital advertising ecosystem since 2010. The maps Terence Kawaja created remain the industry’s clearest visual reference for understanding how the complex programmatic supply chain actually works.
Want to stay updated on future posts? Follow me on X @Scientia_CTO. Spotted any inaccuracies? Slide into my DMs @Scientia_CTO
