A GEO and AEO audit of Michaelshof Sammatz, what we found
Michaelshof Sammatz, Niedersachsen, Germany. A biodynamic community running four businesses from one campus.
In July 2026 we audited the website of Michaelshof Sammatz, a biodynamic community in rural Niedersachsen, and found twenty-five confirmed problems. Some of them had been sitting there for years. The short version is that an organisation with four decades of standing in the real world had almost no legible presence in the places search engines and AI assistants actually look.
A reputation that never made it online
Sammatz is not a small operation and it is not obscure. It holds 1,156 Google reviews at an average of 4.80, has around twelve thousand Instagram followers, carries a UNESCO BNE-Actor designation, is Demeter certified, holds Arche-Hof status for rare breed preservation, and partners with the Elbtalaue Biosphere Reserve. Tens of thousands of volunteers from more than sixty-eight countries have passed through the campus over forty years.
Ask ChatGPT or Perplexity about it and you get very little. That gap between real-world standing and machine-readable presence is the whole problem, and it is more common than people expect, because the things that build a reputation offline are not the things that make an entity legible to a language model.
What the structure was doing
The most consequential finding was also the least dramatic. The entire website ran under a /blog/ subdirectory rather than the root domain, a leftover from how WordPress had been installed years earlier. Every URL on the site carried it. Nobody had noticed because the site worked fine for humans.
Below that, the basics were missing rather than broken. Not a single page on the site had a meta description. The homepage title tag rendered as a single pipe character. The same twenty meta keywords appeared identically on every page, which stopped being a useful signal roughly fifteen years ago. More than fifty newsletter archive pages had been indexed by Google as thin content, diluting the quality signal across the whole domain and spending crawl budget on pages nobody would ever want to read. Images uploaded in 2019 were still loading over plain HTTP on an otherwise secure site.
The site had German and English versions with no hreflang annotations connecting them, so search engines had no reliable way to know they were the same content in two languages. And the organisation was spread across four separate properties: the main site, two different online shops on two different base domains, and a subdomain for events. Each one diluted the others.
The AI visibility layer, which barely existed
There was no structured data anywhere on the site. No LocalBusiness markup, no Event markup for a place that runs events constantly, no FAQPage. For a model trying to establish what this organisation is, where it is, and what it does, there was nothing clean to read.
There was no FAQ content of any kind, which meant Sammatz appeared in People Also Ask results for none of the dozens of questions visitors ask every day about visiting, volunteering, and staying there. We could not confirm a Wikidata entry, which caps what the Knowledge Graph can represent and, downstream, caps what an assistant will confidently say.
The thing we were not looking for
While fetching subpages we found casino spam injected into the live site. A paragraph on the English homepage, sitting inside the Arche-Hof content block, promoted Norwegian online gambling and linked out to an affiliate site. On the café page a link had been hidden inside a single period character, invisible to any visitor and perfectly readable by Google.
This is a common WordPress injection pattern and it usually enters through an outdated plugin or a weak admin password. What makes it worth mentioning is that it had been live long enough to be indexed, and nobody on the team had any reason to look for it, because it was written to be invisible to exactly the people who would have removed it. We flagged it as the first thing to fix, ahead of everything else in the audit, and it was cleaned.
What we recommended
The audit came with a seventeen-page amplification strategy built in five layers, on the explicit condition that the technical problems get fixed first, because amplifying a broken site just gets the broken version in front of more crawlers.
The first layer is entity establishment: a Wikipedia article, a Wikidata entity, and a claimed Google Knowledge Panel, which together give assistants something authoritative to anchor to. The second is press coverage across five specific story angles, aimed at German-language and international outlets. The third activates the alumni network, which is the most underused asset the organisation has, as a multilingual source of genuine references. The fourth builds twelve articles mapped to real search demand, turning the site itself into something worth quoting. The fifth pursues citations from authority bodies like Demeter Deutschland and Slow Food, which carry more weight per link than almost anything else available.
What we do not know yet
This audit is a diagnosis, and diagnoses are only worth what gets done with them. At the time of writing, the technical remediation is partially complete and the amplification strategy has not been fully implemented, so we cannot yet point at a measured before and after.
If we ran it again we would establish a proper baseline first, recording exactly how several assistants answer a fixed set of questions about the client on a given date. We did not do that thoroughly enough, and it means that when the improvements do land, proving they landed will be harder than it needed to be. That is the main thing we changed in how we run these now.
The gap between what an organisation is and what a machine can say about it is closeable. It just takes finding out how wide it currently is.
FAQ
Why doesn’t my business appear when someone asks ChatGPT about it? Usually because there is nothing structured for a model to read. Assistants rely on clean entity definitions, structured data, and citations from sources they trust. A business can have excellent reviews and a long history and still be invisible if none of that exists in a machine-readable form on its own site or in reference databases like Wikidata.
What is the difference between SEO, AEO and GEO? SEO aims at ranking in a traditional list of blue links. AEO aims at being the answer in featured snippets and People Also Ask. GEO aims at being cited by generative assistants when they compose an answer. They overlap heavily in the technical fundamentals, but AEO and GEO put much more weight on structured data, self-contained answers to real questions, and citations from sources a model already trusts.
How long does a GEO audit take? The audit itself takes a few days. Fixing what it finds depends entirely on the state of the site, and the amplification work that follows runs over months rather than weeks, because it depends on third parties like press, directories, and reference databases moving at their own pace.