Plans
Learn Library

Before You Let AI Touch Your Ad Account, Install These Three Gates

A learn article on safely letting AI agents operate inside ad accounts, proposing three gates: complete data grounding, account-level policy rules, and human sign-off on every change request. It references Optmyzr's MCP data layer and its no-bypass approval pipeline for ad account changes.

adsai-marketingmcpworkflow
2026-09-15SupaMarketers11 min read

A few days ago, I had dinner with some friends who do media buying for a living. The topic that dominated the table wasn't whose account had made money. It was something that sent a chill down my spine:

AI agents can now operate directly inside your ad account.

You've probably seen the recent runaway-agent headlines — agents doing things nobody expected in production systems, everyone left wondering what just happened. Media buying raises the stakes even higher: real money flows in and out of your account every hour. Handing it to an AI is like letting it work with its hands inside your wallet.

Would you dare?

At dinner, almost everyone reached for the same opening line: "Do you trust AI or not?"

I said that's the wrong question.

Where does it go wrong? "Trust or not" is a dead end. If you trust, you let go completely; if you don't, you never use it at all. It takes an engineering question and turns it into an attitude question.

The question worth asking is: How do you make AI worthy of trust?

The two questions sound alike. They're worlds apart. One is a matter of faith; the other is a matter of engineering.

Ask the Question Differently, and the Answer Falls Out

What does "worthy of trust" actually mean?

Think about it: when your company signs on a new agency, you don't ask abstractly, "Do I trust them?" You ask three very specific questions: What data can they see? Which changes are allowed to go live first and get signed off later? And for every change — who reviews it, who signs?

Three questions, three sets of answers. You would never hand-wave all three away with "I trust them."

Now, the same three questions, aimed at your AI agent:

First: what can it see? An agent connected to only a thin slice of your data will answer with total confidence and perfect fluency. But it has seen only a third of your account. Worse, it doesn't know it's guessing — so it will never volunteer, "that part was a guess."

Second: what is it allowed to do? Note the question is not what you told it to do. It's what it is structurally barred from doing — even if it hears other instructions, or drifts off course mid-conversation.

Third: who signs off? Not "we'll scroll through the change log afterward." Before the fact, a living human being has said "yes."

These three questions map to three gates. Let me walk through them one layer at a time.

Hand-drawn AI agent passing three gates — see the whole picture, rules on the account, a human says yes — before reaching your ad account, with the caption "trust is engineering, not faith"

Gate One: Let It See the Whole Picture

What's the easiest way to make an agent do something dumb? Simple: make it fly blind.

Ask it: why did CPA go up last month?

The answer comes back in seconds. Fluent, confident, well-organized.

But what it's drawing on is only the small patch of data within its reach. What it can't see may be exactly where the whole answer lives. And the tone it uses when it's making things up sounds exactly the same as the tone it uses when it knows for sure.

Nothing will ping to tell you: it's guessing.

So let me hammer this point home: connect the agent to a sufficiently complete data layer — what the trade calls grounding. This is not a convenience feature. It's a safety feature.

The most dangerous thing about AI is not that it can't answer. It's that it doesn't know what it doesn't know.

So what does a qualified data layer look like? I took a look at the MCP that Optmyzr built (think of it as the data pipeline that plugs an agent into your ad account), and their checklist is good enough to copy outright:

  • A complete query layer. Google Ads resources, fields, metrics — whatever the API exposes, you get. Real GAQL queries, not a "curated digest" cherry-picked by a product manager. Once data has been curated, the questions you can ask get capped — and nobody tells you which ones.
  • GA4 and ads data side by side. "What happened after the click" is a single question; you shouldn't have to stitch two tools together by hand to answer it. The answers to many diagnostic questions live right on the border between ads data and website data. As long as that border exists, the agent keeps guessing at it.
  • Complete change history, not a single operator left out. UI edits, scripts, third-party tools — everything gets logged. Only then is "who caused that ROAS swing in March" a question with an answer, instead of a group chat reconstructing it from memory.
  • Negative keywords merged across all four levels. Account, shared lists, campaigns, ad groups — four places combined into one master ledger that can also tell you, deterministically, whether a given search term is already blocked, and by which rule. Agents stumble on negative keywords constantly, because the truth is scattered across four places and nobody has stitched it together for them.
  • Auction Insights that drill down to individual competitor domains, showing how you and each rival are playing every keyword you share. Competitor questions are the hardest to verify, because you hold no second, independent dataset to check answers against.
  • Industry benchmarks. Where your CTR, CPC, conversion rate, and impression share rank among your peers — in the top what percent. Not the averages from some blog post three years ago, a number everyone quotes and nobody can trace.
  • Cross-platform. Google, Microsoft, Meta, Amazon, LinkedIn, TikTok. Budget questions rarely belong to a single platform, no matter which one the person asking lives in all day.
  • A profile for every account: business model, profit structure, bidding strategy, account structure, what has been tried, and how it turned out. The agent reads it before it opens its mouth.

All of this is already in place at Optmyzr, installed with one click from Claude's directory. No API console to set up, no developer token to request, no engineer kept on standby.

Seeing everything is the first gate. The second gate is keeping it under control.

Gate Two: Set the Rules

How do you stop AI from burning through a month of budget overnight?

Two answers, and neither works: one, be nicer to it; two, write "please be careful" into the prompt a few more times.

What actually works is a policy layer that sits independent of the AI.

Write the rules onto the account, once and for all. No single bid increase above 10%. Budget changes capped at some ceiling. These campaigns, nobody touches. Competitor brand terms, never added. Every "absolutely not" in your business, written down line by line.

The key is one sentence: Don't write the rules in the prompt. Write them on the account.

Why? Rules written in a prompt are, at their core, pleading with it to comply. One injected instruction hidden in a document it was asked to read, and it may change; one long conversation in which it slowly drifts, and it may change. Rules written on the account hold, no matter which door the instruction comes through.

And the rule doesn't play favorites.

The agent proposes a 20% bid increase — blocked. A hallucination hits and it starts making wild changes — blocked. A malicious instruction hidden in a document — blocked. A new colleague fat-fingers a decimal point — blocked. You, at 11 p.m. on a Friday, rushing to green-light it from your phone — blocked all the same.

Same rule, same verdict. It doesn't weigh good intentions, and it doesn't weigh seniority.

A genuine emergency that must go through? Fine — take the explicit override, and leave your name in the log. A guardrail you can step over without feeling a thing is not a guardrail. It's a painted speed bump.

This approach has a name — automation layering — and it has been around in media buying for years. The idea never changes: one system does the work; another system checks the work. The first layer used to be the platforms' own smart bidding and budget automation, and you used your own scripts and your own rules to verify whether its moves fit your business. Now the first layer is AI. The more creative and less predictable the first layer becomes, the more the second one matters.

Gate Three: Make It Report Before It Acts

Everyone says "there's a human in the loop."

Push one follow-up question: In which interface? Which person? Which queue? Most people go quiet on the spot and finally manage "we'll check the change log afterward."

Checking afterward is roughly the same as nobody checking.

Let me do the math for you. Three months from now, a client asks: why did you change my target CPA in March? What do you pull up? The chat history? You and the AI traded two hundred perfectly courteous exchanges — point out to me which sentence was the basis for the decision.

Engineering slammed this door shut long ago: without code review, no one pushes code to production. A rule with decades behind it. What I have never understood is why an ad account burning six figures a month deserves less rigor than changing one line of CSS. Our industry has never dared to answer that question head-on.

Optmyzr has blocked that road completely: from agent to ad account, there is no path that bypasses a living human. Five steps:

  1. The agent can only propose. Bid changes, budget edits, pausing a campaign, adding a negative keyword — every write operation becomes a change request draft that stops halfway and goes nowhere.
  2. The policy layer vets it first. Every line of the change is checked against the account's rules, and the verdict is attached right to that line: blocked, and why — out in the open, not buried in a log.
  3. The ticket lands with a human. The reasoning behind every line, the policy warnings, the timeline, who is eligible to approve — all visible at a glance.
  4. What you see is the exact content that will go live. "Change the target ROAS of the Brand campaign from 200% to 220%" — word for word, deterministic. Not the agent paraphrasing in natural language, "this is roughly what I intend to do."
  5. You nod. Only then does it move.

Hand-drawn pipeline: the AI proposes, the policy layer checks, a human signs off with "yes", then it goes live — with the dashed bypass path crossed out, labeled "no bypass"

When a coworker proposes a change, it goes through this pipeline, and you are the second pair of eyes. When AI proposes a change, it goes through the same pipeline, and you are the first pair of eyes.

An Unexpected Bonus

This change-request queue was built for safety. In daily use, it turned out to solve another long-standing headache along the way: there was no paper trail to follow.

Because the queue stores more than actions — it stores complete intent. What was proposed, what the reasoning was, what the policy verdict was, who approved, and when. All of it.

Change history tells you what changed. It never tells you why. And that layer of "why" is exactly the layer you will need three months later.

For agencies, this is more than safety. It's credibility. Whenever a client asks, you can produce the complete case file on the spot.

The Best State Is Boring

Install all three gates, and you get a certain state. I'll describe it with a word that sounds strange: boring.

Not useless. Boring.

You know what it can see. You know what it structurally cannot do. You know that nothing can slip past you and go live. Surprises should show up in the insights — not in "what did it do during the half hour I was at lunch."

This is the passing line I draw for every AI media-buying system, Optmyzr's included — even their own:

  • It can see the whole account. Because whatever it cannot see is exactly where it starts making up stories with a straight face.
  • It is fenced in by the rules you wrote. The rules live on the account, not in the prompt, and they apply to everyone.
  • It cannot act on its own. Every write operation is a change request — reviewed by someone, logged, and closed with that one word: "yes."

You don't have to do it all at once. Plug whichever hole hurts the most, and once it's running smoothly, plug the next. And if you tried AI media buying before, got one confidently wrong answer, and quietly let the tool gather dust — yours is the failure I would most recommend revisiting.

One last thing, and I'll say it straight.

Safe AI media buying has never been something you get automatically by picking the right model. It is built: layer upon layer of data, rule upon rule, signature upon signature. The model is someone else's. The gates are yours.

May your AI always be boring.

(Optmyzr's safe media-buying setup comes with a 14-day free trial. If you're curious, take a look on their website.)

Continue reading