Analytics and Tracking

Custom Template

Also called GTM community template gallery

A reusable Google Tag Manager tag or variable built in sandboxed JavaScript, with a settings form and a declared list of permissions.

Quick facts: Custom Template

Category
Analytics and Tracking
Also called
GTM community template gallery
Level
Advanced
Affects
Tag security, consent compliance, container maintenance
Where to see it
Google Tag Manager Templates section, Community Template Gallery, Tag Manager preview mode
In this article4
  1. How a custom template works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A custom template in Google Tag Manager is a reusable tag or variable built in a restricted form of JavaScript, with a form for its settings and a declared list of what it is allowed to do. Most people meet them through the Community Template Gallery, where software vendors and developers publish templates that anyone can add to a container.

How a custom template works

A template has three parts. The fields are what you see when you use it: boxes for an account ID, an event name or a consent option. The code is written in sandboxed JavaScript, a cut-down version of the language that can only reach the browser through approved functions. The permissions state exactly what that code may do, such as inject a script from one named domain, read one specific cookie or send data to one URL.

Tag Manager enforces those permissions. If a template’s code tries to contact a domain it did not declare, the request fails. That is the main difference from a custom HTML tag, where pasted code can do anything at all.

Web containers use tag and variable templates; server-side Tag Manager containers use those too, plus client templates that receive incoming requests. You can build your own in the Templates section of a container, or import one from the gallery. Gallery templates are kept in public code repositories, and Tag Manager tells you when an installed template has an update waiting.

Why it matters

For a UK business the biggest practical use is consent. Many consent management platforms publish a gallery template that sets consent mode defaults and updates them when the visitor makes a choice, which is far tidier than a hand-pasted script. Every template tag also has the same consent settings as any other tag, so you can require consent before it fires.

The second benefit is visibility. Before a template goes live you can read its permissions and see, for example, that a review widget wants to read every cookie on the site. With a custom HTML tag you would have to read the code line by line to find that out. For a business accountable under UK GDPR for what third-party code does on its pages, that visibility is worth having.

Templates are also easier for non-developers to use correctly. Labelled fields with validation are harder to get wrong than a script in which one missing quotation mark breaks the page.

Common mistakes

  • Installing without reading the permissions. The list is shown before you add the template. A simple pixel that asks to read all cookies or load scripts from several domains deserves a question.
  • Treating the gallery as vetted. Gallery templates are built by third parties, not by Google, so a listing is not a guarantee of quality or safety. Prefer templates published by the vendor whose product they load.
  • Accepting updates blindly, or never. An update can fix a bug or widen permissions. Review what changed before accepting it.
  • Running the template and the old script together. Switching to a template but leaving the custom HTML version live fires everything twice.
  • Building a template for a one-off. Writing your own makes sense for code you reuse across tags or containers. For a single tag it can be more work than it saves.

How to act on it

Go through the custom HTML tags in your container and search the gallery for an official template for each one, starting with your consent platform, then analytics and advertising pixels. Before importing, read the permissions and confirm the publisher is the vendor or someone you trust.

Test the template in preview mode with consent both granted and declined, then pause the old tag rather than removing it until you are sure the replacement works. Keep a note of which templates are installed and check for updates whenever you review the container. A tidy container built on templates is how I prefer to set up tracking for performance marketing, because it is easier to audit, hand over and keep compliant.

Do and do not

Do

  • Prefer templates published by the vendor whose product they load
  • Read the permissions before importing a template
  • Review what changed before accepting a template update

Do not

  • Run a template and the old custom HTML tag side by side
  • Treat a gallery listing as a security check
  • Build your own template for code you will only use once

Questions people ask about this

Are Community Template Gallery templates safe to use?

Most are fine, but safety depends on who built the template and what it is allowed to do. Check the publisher, read the permissions and look at when it was last updated. A template from the vendor whose product it loads is usually the best choice; an abandoned one from an unknown author is best avoided.

Can a custom template replace every custom HTML tag?

Usually, where a template exists for that vendor. Sandboxed JavaScript cannot do everything ordinary JavaScript can, such as freely changing the page, so some unusual scripts still need custom HTML. In that case keep the custom HTML tag, but limit where it fires and add consent checks.

Do I need a developer to use a custom template?

Not to use one from the gallery: you search for it, add it, fill in the fields and test. Building a template from scratch is different, and needs someone comfortable with JavaScript and with Tag Manager's permission model. For most small businesses, gallery templates cover everything they need.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.