Enterprise AI ad ops — approval gates, audit trail, your own model endpoint
At enterprise scale the question isn't whether an AI agent can optimize a campaign — it's whether you can prove what it did, restrict who can let it act, and keep model traffic on infrastructure you control. Agent Planners is built with those as defaults rather than add-ons: approval is on for every write by default, hands-off is an explicit opt-in that still stops at the guardrails, the irreversible or money-moving writes always wait for a person, every action is recorded, roles keep integrations with admins and editors, and Bring Your Own Model routes LLM calls to your own endpoint.
Governance with defaults that hold
- Approval on every write, by default — hands-off (auto-approve on a task or schedule, or an API key minted for autonomous writes) is an explicit opt-in, still runs every write through the guardrails — magnitude caps, protected campaigns, the monthly spend cap — and never covers a write a platform marks as a person's decision, such as a permanent delete, a store refund or publishing a Tag Manager container.
- Stale-state revalidation — an account is re-read immediately before a change applies, so an approved-but-aged recommendation can't fire against a since-changed account.
- Audit trail — a durable record of what was proposed, who approved it and what applied.
- Role separation — Admins control membership and billing; Admins and Editors authorize integrations and manage the connected accounts; Members use the agent. Approving a pending write is open to every member of an organization, so approval authority follows organization membership.
Bring your own model
Every agent's LLM calls can route to your own OpenAI-compatible endpoint instead of the built-in gateway — relevant when model traffic has to stay on infrastructure you control for data-residency or procurement reasons. LLM tokens on your endpoint are zero-rated in credits; a platform-infrastructure fee still applies for the compute, database and streaming work of running the task.
Programmatic access, both directions
| Direction | What it enables |
|---|---|
| Outbound — your systems call us | Per-organization API keys over a REST API, plus an MCP endpoint so your own agents (Claude, ChatGPT, internal tooling) can drive tasks |
| Inbound — we call your systems | Custom MCP servers expose your internal tools and proprietary data to the agent, alongside 250+ SaaS apps via Composio |
Workspace isolation
Each organization is a fully isolated workspace — its own connected accounts, integrations, account memory, skills, audit log and billing. Nothing is shared across organizations unless a skill is deliberately shared, which makes brand-, region- or business-unit-level separation structural rather than procedural.
Where the honest limits are
Worth naming directly, because it should factor into an enterprise evaluation: this is a self-serve product with usage-based plans (Scale at $500/month, Agency at $1,000/month) rather than a sales-led enterprise contract, and we don't currently publish SOC 2 or ISO certification. Teams with a formal vendor-certification requirement should raise it before committing, not after — and the governance controls above are real regardless of what a certification page would say.
Frequently asked questions
- Can the AI agent be prevented from acting without human approval?
- That is the default: every write waits for approval unless someone opts a task, a schedule or an API key into hands-off — and even then every write passes the guardrails, and the irreversible, money-moving or public writes still never apply without a person.
- Can we keep LLM traffic on our own infrastructure?
- Yes — Bring Your Own Model routes every agent's LLM calls to your own OpenAI-compatible endpoint. Those tokens are zero-rated in credits; a platform-infrastructure fee still applies for the compute and orchestration of running each task.
- Is there an audit trail of what the agent did?
- Yes — actions are recorded per organization, covering what was proposed, who approved it and what applied, so a change can be traced after the fact.
- Can our internal systems drive the agent programmatically?
- Yes, in both directions — per-organization API keys and an MCP endpoint let your systems and agents drive tasks, and custom MCP servers let the agent reach your internal tools and data.
- Do you have SOC 2 or ISO certification?
- Not currently published. If formal vendor certification is a hard requirement for your procurement process, raise it before committing — the governance controls (approval by default with person-only writes, audit trail, role-separated integrations, workspace isolation, BYOM) are real and independently verifiable regardless.