A dark-haired man wearing glasses and a denim shirt sits at a wood desk using a keyboard and mouse, looking intently at two monitors displaying colorful pie charts, bar graphs, and line charts, with additional printed chart pages visible in the foreground.

Frequency capping is one of the oldest levers in programmatic buying. Set a ceiling, protect the user experience, avoid waste. The problem is that frequency caps are enforced against identity tokens — cookie IDs, device IDs, hashed emails, RampIDs — not against people. When the identity graph underneath your DSP maps one real person to three or four unresolved fragments, that person receives your cap multiplied by the number of fragments the system sees as distinct. You set a cap of five. They see fifteen. Your reporting shows a clean five.

The Fragmentation Mechanics Behind the Gap

Identity graphs are probabilistic at their edges. Deterministic linkage — the confident match between a verified email and a device — exists for a meaningful but minority share of any graph. The rest is probabilistic inference: shared IP ranges, household modeling, behavioral co-occurrence patterns. Those probabilistic connections break under normal usage conditions. A user switches from home Wi-Fi to mobile data, logs out of a browser, or resets an advertising ID. The graph can no longer confirm the link, so it temporarily — or permanently — treats the same person as two separate IDs.

This fragmentation is not a bug a vendor can patch and ship next quarter. It is structural. The data signals that enable probabilistic matching are increasingly sparse: third-party cookie deprecation has already removed one of the most reliable cross-session stitching mechanisms in the open web. Mobile identifier availability has tightened significantly following platform-level opt-in enforcement. What remains is a graph that, by most current industry estimates, fails to resolve between 20 and 40 percent of cross-device touchpoints for a given real-world person into a single unified profile.

Why Your Controls Operate at the Token Level

DSPs enforce frequency caps against the identifier present in the bid request, because that is the only signal available at decision time. If your campaign is running on three channels — display, video, CTV — each with different dominant identifier types, your DSP is making three independent cap calculations. Display may be tracking a browser cookie. CTV is tracking a device ID. Your DMP onboarded a hashed email for the same person under a third token. These are not coordinated. They are siloed.

The practical consequence: a single user in a fragmented graph state can exhaust your cap on each channel independently. A five-impression cap on display, five on CTV, and five on video means fifteen impressions for someone your system officially believes saw only five. Your budget consumption per person is tripled. Your reach metric is understated, because you are counting fragments as distinct people rather than one person many times over.

This also corrupts your reach-versus-frequency tradeoff analysis. If your campaign shows an average frequency of 4.2, that number was computed on token-level events, not person-level. The true per-person frequency distribution is almost certainly bimodal: a large segment of genuinely distinct people reached once or twice, and a smaller segment of fragmented individuals reached far beyond your intended ceiling — the latter masking as the former in aggregate reporting.

What This Means for Audience Exclusions

The fragmentation problem compounds when you apply audience exclusion logic on top of a broken cap structure. Suppose you suppress current customers using a hashed email match. That suppression fires against the deterministic ID associated with their email. But if the same customer is browsing from a device the graph hasn't confidently linked to that email — which, given current signal loss, is a realistic scenario for a substantial portion of your list — the exclusion simply doesn't trigger. The bid request arrives under an unresolved token. The DSP has no instruction for it. The impression delivers.

This is not a data onboarding latency issue, though that is a separate and real problem. This is a structural resolution failure that occurs in real time, at bid decision, because the identity graph cannot confirm the relationship between the token in the request and the suppressed record in your list. The better your suppression hygiene at onboarding, the more false confidence you carry into delivery.

Diagnosing the Problem Before It Distorts Your Next Flight

Most buyers never see this in their reporting because standard campaign dashboards surface token-level delivery metrics, not person-level resolution quality. There are practical diagnostic steps worth building into your pre-flight and mid-flight process.

First, request identity resolution confidence scores from your data partner or DSP before activation, not after. Some platforms expose per-segment resolution confidence at the ID level. A segment with 40 percent of records in a low-confidence probabilistic state is a segment where your controls are unreliable for nearly half the audience. Adjust suppression strategy and cap settings accordingly.

Second, cross-reference your reach numbers against third-party measurement that uses a different identity methodology than your DSP. A meaningful divergence in unique reach counts between your DSP report and a measurement vendor using panel-based or survey-validated methodology is a signal of fragmentation inflation. It won't tell you the exact magnitude, but it confirms the direction.

Third, pressure-test your frequency distributions. If your campaign shows an unusually smooth frequency curve with very few individuals above your cap, that is not evidence your cap is working — it is evidence your reporting is aggregating fragmented impressions under distinct token counts and smoothing the distribution artificially. A realistic frequency distribution under functional caps should show a hard drop-off at your ceiling. If it doesn't, ask your DSP what the cap enforcement unit actually is.

The Strategic Implication

Identity graph quality is not a vendor relationship question you resolve once at contract. It is an ongoing delivery operations variable that directly determines whether your frequency caps, budget controls, and audience exclusions function as designed. As the addressable identifier ecosystem continues to thin — and the signals supporting probabilistic linkage continue to contract — the gap between intended controls and actual delivery behavior will widen, not narrow.

Buyers who treat identity resolution as a procurement checkbox and move on are, operationally, flying with instruments that are reading fragments instead of people. The frequency cap you set is a real number. The person it's meant to govern may be invisible to the system enforcing it.