AI advertising operations

Build an AI ad agent permissions matrix

An AI ad agent permissions matrix assigns authority to specific actions in specific accounts. Start with read-only analysis, separate preparation from execution, and require evidence that an approved change reached the intended account before treating it as complete.

A team can agree to “let AI manage the account” while disagreeing about almost every action that phrase includes. One person expects a daily analysis. Another expects automatic budget changes. A third assumes new ads will still go through brand review. The permissions matrix makes those differences visible before software acts on them.

The useful unit is an action on a named resource. “Marketing access” is too broad. “Read campaign results for the selected account” and “increase this campaign's budget within an approved monthly plan” are different permissions, even if they appear in the same interface.

This guide proposes an operating worksheet. It is not a claim that every advertising platform exposes these exact controls.

Start with four levels of authority

Use four verbs: read, recommend, prepare, execute. Reading retrieves existing information. Recommending describes a possible change. Preparing creates a reviewable proposal or draft. Executing changes something in the advertising platform.

A draft can still have consequences. If preparing an ad means uploading an asset to a live account, that upload deserves its own row. If a draft exists only in your internal workspace, describe it that way. Avoid giving the same label to different behaviors.

The distinction follows a broader security principle: give an agent only the permissions needed for its task. The OWASP AI Agent Security Cheat Sheet recommends scoped tools and independent checks on sensitive actions. Your matrix translates that principle into advertising work.

A starter matrix for a small team

The following is an illustrative policy, not a universal recommendation to automate these actions.

TaskStarting authorityEvidence requiredDecision owner
Summarize campaign resultsReadAccount identity, dates, attribution definitionMedia lead
Identify possible creative fatigueRecommendComparable periods and alternative explanationsMedia lead
Draft a new creative briefPrepare internallyApproved offer, claims, and brand inputsCreative lead
Upload a creative to an ad accountApproval requiredExact asset, account, and intended useAccount owner
Publish an adApproval requiredFinal copy, destination, targeting, and budget contextAccount owner
Raise a budgetApproval requiredCurrent value, proposed value, remaining exposureBudget owner
Change the conversion goalApproval requiredMeasurement impact and validation planMeasurement owner
Delete campaign assetsNo authority by defaultSeparate justification and recovery implicationsAccount owner

The last column matters as much as the authority level. “Approval required” without a reachable approver becomes an ambiguous queue. Give each decision one accountable owner and a backup. If two teams must review different parts, split the decision into those parts.

Record scope before discussing autonomy

Add an account section above the table. Include the advertising platform, account identifier, business owner, timezone, currency, and permitted campaigns. Human-friendly names are useful, but names alone are not reliable identifiers when agencies manage similarly named accounts.

Also record exclusions: campaigns managed by another team, geographic restrictions, seasonal promotions, contractual spending limits, or products that cannot be advertised. These are business instructions. They should not be inferred from yesterday's performance.

For Google Ads specifically, access can come directly from an advertiser account or indirectly through a manager account. The Google Ads access model explains that hierarchy. A connection that works is therefore not proof that its scope is as narrow as you intended. Inspect the effective account access, not just the account selected in your own interface.

Make an approval describe the exact change

An approval should answer five questions without requiring someone to reread a long chat:

  1. Which account and campaign will change?
  2. What is the current state?
  3. What will the new state be?
  4. Why is the change proposed now?
  5. What spend, delivery, or measurement consequence could follow?

Consider a proposal to increase a campaign from an illustrative $100 to $125 average daily budget. “Approve scaling” omits the actual amount, the account, the remaining monthly plan, and whether other campaigns will change. A useful approval includes those details and expires if the underlying state changes materially before execution.

The expiry rule avoids a familiar problem: a buyer approves a recommendation in the morning, a colleague changes the budget at noon, and an agent executes the original recommendation later against a different baseline. At that point the approved proposal no longer describes the proposed action.

Define what happens when evidence is missing

Do not leave uncertainty as a blank cell. A matrix needs a rule for stale reporting, an unavailable approver, missing product information, and an ambiguous account match.

For example, your policy might allow the agent to summarize available results while requiring it to withhold a budget recommendation when purchase tracking is incomplete. A missing margin value could block a profitability claim without blocking a creative brief. This preserves useful work while keeping unsupported decisions out of the execution path.

Treat a missing permission as unresolved. Do not infer approval from silence, from a similar previous action, or from the fact that the vendor interface exposes a button. A team can intentionally grant continuing authority, but it should define the limits of that authority in the matrix.

Test the matrix with realistic situations

Before enabling execution, ask the operator to handle several scenarios using the same policy:

  • A campaign appears unprofitable, but the latest conversion import failed.
  • A creative performs well, but its claim is absent from approved product materials.
  • A client asks to “scale everything” while one campaign belongs to a separate launch team.
  • A budget change was approved, but the current budget no longer matches the approved baseline.
  • The connection includes an account that is outside this engagement.

The correct response is not always a refusal. It could be a scoped analysis, a request for one missing business fact, a revised proposal, or a clearly explained wait. Record whether the operator chose the right level of authority and whether the user could understand the reason.

A shadow-mode pilot is a useful place to run these scenarios before the operator can make changes.

Keep the policy usable after launch

Review the matrix when a new account, action type, integration, or owner enters the workflow. Do not expand permissions simply because the system completed many low-risk tasks. Reading a report successfully does not establish competence to change conversion settings.

Attach the active matrix to onboarding, approval review, and incident response. Store a version date and the person who accepted it. When a permission changes, record the previous policy and why the team changed it, so old decisions remain interpretable.

Finally, connect the matrix to an action log. The log should show what was proposed, what was approved, what was attempted, and what the advertising platform actually changed. Pair that with budget guardrails so authority is connected to business exposure. The matrix is successful when a teammate can look at a proposed action and know who may authorize it, what evidence it needs, and how completion will be verified.

Set budget guardrails for an AI media buyer

Define spending authority for an AI media buyer with account scope, remaining-budget calculations, cumulative-change limits, and a reviewable approval example.

An advertising agent change log you can actually audit

Build a change log that separates AI recommendations, approvals, attempted actions, confirmed platform changes, and later campaign outcomes.

Run an AI media buyer in shadow mode

Evaluate an AI media buyer beside your existing workflow using a decision journal, matched evidence windows, and explicit pilot acceptance criteria.

Resolve conflicting instructions in ad automation

Set a practical precedence policy for brand rules, account goals, campaign briefs, approvals, and external research used by an AI advertising operator.

Have a correction or a question about the workflow? Contact GaaS. Read our editorial standards for sourcing and example conventions.