A safe automation checklist before AI touches an ad account
Checklist · 2 min read · Updated 2026-10-06 · By the Cofoundr team
Start read-only, scope access to specific accounts, require approval for any change, set limits on size and speed, log every action, test on a low-risk account first, and know how to revoke access in one step.
An ad account holds real money and a client's trust. The goal is not to avoid AI, it is to give it the smallest access that does the job, with a person approving anything that spends or changes money. Run this checklist before you connect a tool, and again when you widen what it can do.
1. Access
- Begin with read-only access. Reading data is low risk, and it already answers most questions.
- Scope each connection to the specific ad accounts it needs, nothing more.
- Use a separate connection for each tool or person, so you can revoke one without breaking the rest.
- Know how to remove access instantly, and test that it works.
2. Permission to change things
- Require a person to approve any change that spends or moves money: pausing, budgets, new campaigns, audiences.
- Keep new campaigns paused until a person reviews them.
- Limit how large a single budget change can be.
- Do not allow deletion.
3. Guardrails
- Leave campaigns in their learning phase alone.
- Use cooldowns so a rule does not fight a person's recent decision.
- Start rules in alert-only mode, and switch to automatic one rule at a time.
4. Logging and review
- Every action should record what changed, when, on which account and why.
- Review the log weekly for the first month.
- Keep the log where a new team member can find it.
5. Testing
- Try the tool on a low-risk or internal account first.
- Run in alert-only or read-only mode for a week before giving it more.
- Compare what it would have done with what a person would have done.
6. When something goes wrong
- Pause the affected campaigns first.
- Revoke the tool's access.
- Work out from the log what happened.
- Tell the client plainly, with what you have done to fix it.
Where Cofoundr helps
Cofoundr's MCP server is scoped per ad account, can be read-only or read and write, writes every action to an audit trail and can be revoked at any time. Hadya asks for approval before sensitive actions, and starter automation rules are created alert-only behind a confirmation.
Frequently asked questions
Should AI ever be allowed to change budgets by itself?
Start with approval for every change. If you later allow automatic changes, limit their size, keep logs and review them regularly.
What is the safest first step?
Read-only access scoped to one account, used for analysis and reporting questions.
How do I know what the AI did?
Use a tool that keeps an audit trail with the time, the account and the action, and review it on a schedule.
