Claude and AI
AI that executes in the ads manager: what to allow and what to lock
Letting AI pause campaigns and change budgets saves hours and creates new risk. Which actions to allow, which to gate behind confirmation, and what to always log.
Also available in: Português · Español
Reading data with AI is comfortable: the worst that happens is a wrong answer you can check. Writing is different — pausing the wrong campaign on a Friday night costs a weekend of delivery.
The difference between useful automation and an expensive accident comes down to three protections, and they have to exist before the first write.
The rule that separates reading from writing
Reading is free. Checking spend, comparing creatives, surfacing a gap between CRM and platform: none of that changes the world. The cost of an error is you noticing and asking again.
Writing is confirmed. Any action touching money or delivery passes through an explicit human accept, with the effect described before the accept.
That boundary is not bureaucracy. It is what lets you use both comfortably: you read freely and review only what matters.
The three mandatory protections
1. Confirmation with the effect visible
Asking "confirm?" is not enough. The summary has to say exactly what will happen:
I will pause:
campaign "acme_tofu_leads_2026-09" (spend yesterday: $420)
Current state: active since 2 Sep
Confirm?
With spend and prior state in view, you immediately notice if the AI picked the wrong campaign. Without that, you are confirming an intent, not an action.
2. A cap per operation
Budget changes need a limit. An absolute cap (never above X per day) and a relative one (never more than Y% at once) turn a large mistake into a small one.
The cap also protects against a parsing failure: "raise it to a thousand" with the wrong unit is an order-of-magnitude accident, and exactly the kind of error a cap blocks.
3. A log of everything
A dedicated write log, separate from the platform's history, with who asked, what was executed, when, and what the previous state was.
Prior state is the part almost everyone forgets and the only one that allows undoing. Without it, you know the budget became $800, but not whether it was $600 or $1,000.
What to allow, by risk level
| action | risk | regime |
|---|---|---|
| Query any data | none | free |
| List audiences, pixels, creatives | none | free |
| Pause an ad | low, reversible | confirmation |
| Pause a campaign | medium | confirmation with summary |
| Change budget | high | confirmation + cap |
| Create a campaign | high | confirmation, born paused or active by setting |
| Publish a new ad | high | confirmation with the piece visible |
| Delete anything | high and irreversible | out of the AI's scope |
That last row deserves to be literal: deletion should not be available. The convenience gain is minimal and the cost of a mistake is permanent. Pausing covers 99% of cases and is reversible.
The errors that happen in practice
Name ambiguity. "Pause the leads campaign" in an account with four campaigns containing "leads" in the name. The protection is for the AI to list the candidates and ask, never to guess.
Wrong unit. A budget in cents treated as dollars, or the reverse. The cap blocks it; the summary with the formatted value shows it.
Wrong account. More than one account connected and the action going to the neighbor. The summary must name the account, always.
Action at the wrong time. Pausing on a Friday night leaves the whole weekend with no delivery. It is worth having a window where writes require an additional confirmation.
What careful use gains you
With the protections in place, the gain is real and specific:
Immediate action on a diagnosis. "Which campaign spent most with no sales?" followed by "pause that one" in the same place, without switching tools and without hunting the campaign in a list of thirty.
Fewer operational errors. Asking in natural language with a summary before the accept goes wrong less often than clicking fast through three screens.
A better trail than the platform's. Native history shows what changed; a dedicated log shows why — because it stores the request that produced the change.
Where to start
Do not allow everything on day one.
- Week 1: read only. Learn what the AI gets right and where it misreads.
- Week 2: allow pausing ads, the most reversible write there is.
- Week 3: allow budget with a tight cap.
- After that: creation, with the piece and the structure visible before the accept.
Each step only after the previous one runs without a scare. Rushing here does not save time — it produces the accident that makes someone switch it all off.
For the read questions that come before any write, see the 15 questions to ask AI.
Frequently asked questions
Is it safe to let AI change the ad account?
It is, with three protections: explicit confirmation before every write, a value cap per operation, and a log of everything done. Without all three, it is not.
Which actions should require confirmation?
Every action that touches money or delivery: pause, activate, change budget, create a campaign, publish an ad. Reading needs no confirmation.
Can AI create a campaign on its own?
It can assemble the structure and leave it ready, but activation should be an explicit human decision, with a summary of what will be created visible before the accept.
How do I audit what the AI did?
With a dedicated write log, separate from the platform history, storing who asked, what was executed, when, and what the previous state was.