Read and report
AgentInspect data, compare periods, find anomalies, and prepare a sourced summary.
Evergreen guide
Use this boundary before an AI agent receives access to customer data, campaigns, flows, catalogs, budgets, or live sends.
Why this matters nowAn agent may have the technical ability to perform an action. That does not give it business authority.
Write down who owns each consequence before connecting the account. The rule should cover five things: the action, the allowed scope, the approval point, the activity record, and the rollback.
Inspect data, compare periods, find anomalies, and prepare a sourced summary.
Prepare segments, flows, campaign copy, tests, and catalog changes without making them live.
Edit an existing segment, flow, template, integration, or catalog only after a person checks the proposed difference.
A person owns live sends, audiences, suppressions, budgets, publishing, and irreversible account actions.
A usable approval gate records the proposed action, the authority granted for this action, and the person accountable for the consequence. Tool access alone proves none of those things.
Impact inputs: customer or public harm, evidence and regulatory exposure, sensitive-data use, audience size, money at risk, and permission scope. Do not copy another company's dollar or recipient limit.
Recovery class: reversible means the prior state can be restored; stoppable means future delivery can cease but completed delivery remains; remediable means the event cannot be undone and requires correction, notification, refund, suppression, or another response.
Decision: require a named human when an action is customer-facing, money-moving, privacy-sensitive, access-changing, or not immediately reversible. Record the organization's threshold owner, rationale, effective date, and next review date.
Example boundary: every number in the questions below is a hypothetical calculation, not a benchmark or universal approval threshold. Each organization defines its own spend, audience, quality, compliance, and payback limits before an action is requested.
Proposed action: publish a win-back email flow. The agent may prepare the segment, draft, links, and QA record. It may not release the flow.
Approval evidence: the reviewer checks the current audience count, suppression rules, consent basis, rendered email, claims, destination links, send schedule, and approved commercial limit.
After release: the owner verifies the live flow and suppression behavior, keeps the prior version, and can pause the flow if the live state differs from the approval record.
This control structure applies the govern, map, measure, and manage functions in the NIST AI Risk Management Framework Core. Claims and endorsements still require substantiation and clear disclosure under FTC advertising guidance and the FTC Endorsement Guides.
A screenshot of a finished screen is weak proof. Compare the executed payload and live account state with the approved version. A successful API response does not prove that the intended audience, message, budget, price, or permission is live.
An email agent can receive draft access without send authority. An ad agent can analyze and propose changes while a buyer-owned administrator retains publishing, billing, and user-management control. A catalog agent can edit a staged feed without changing live price or availability. Grant only the action, account, data, duration, and volume required; use separate identities and revoke access when the task expires.
Review instant approvals, reviewer disagreement, exceptions, rejected payloads, near misses, incidents, and time-to-decision. Repeated instant approval or high reviewer load can signal rubber-stamping. Narrow or automate only recurring low-impact actions whose error, exception, and recovery records support the change; reapprove the new boundary and keep sampled human review.
Automation should remove repetitive work. Authority stays visible wherever the action spends money, contacts customers, changes customer eligibility, or alters commerce.
Have us run itAnswer owner · reviewed 2026-08-23
AI should not publish legal, medical, financial, safety, pricing, budget, customer-specific, or reputation-sensitive claims without a named human approval. Keep sensitive customer data out of general-purpose tools unless the approved agreement and configuration permit it. Log inputs, outputs, approver, action, cost, and rollback.
AI prepares a bounded change.
A named owner checks the final payload.
The approved action enters the live account.
Confirm the live state or return to the last known good version.
Q091
AI should not independently publish high-consequence claims, prices or discounts, personalized messages using sensitive data, regulated advice, synthetic endorsements, crisis responses, account-permission changes, audience exclusions, material budget changes, or anything legally binding or difficult to reverse. Approval should depend on impact, not content format. Require a named reviewer to inspect the exact audience, payload, evidence, spend, timing, and rollback path before release.
Decision rule: Human approval is mandatory when an error could materially harm a person, mislead a buyer, expose data, spend beyond a limit, change access, violate policy, or resist immediate rollback.
Example: A draft inside a sandbox can use automated QA; any live spend, high-volume send, sensitive-data audience, or access change must stop at the named approval gate and organization-specific threshold.
Field note: Approve the rendered final payload, not the prompt or strategy; last-mile substitutions, links, audiences, and platform settings are where many consequential errors enter.
Q096
Use only customer data that is necessary for the defined task, lawfully and contractually permitted, minimized, access-controlled, retained for a documented period, and processed in a tool approved for that data class. Public product data, consented preferences, and appropriately aggregated performance data are lower risk. Credentials, payment data, sensitive traits, minors' data, and raw personal records require explicit security, privacy, and legal review rather than casual prompting.
Decision rule: Before upload, name the purpose, fields, lawful or consent basis, vendor terms, access, retention, deletion, location, and fallback; if any answer is unknown, do not send the data to the tool.
Example: Replace a customer export containing names, emails, addresses, and order notes with aggregated fields for channel, cohort month, product category, and order value when individual identity is unnecessary.
Field note: Classify prompts and outputs together; a harmless prompt can cause the system to reproduce sensitive retrieved data in logs, drafts, or downstream tools.
Q097
Compare the same volume and quality of work before and after automation using fully loaded cost. Include labor, software, integration, review, rework, errors, incidents, and ongoing maintenance; then add verified incremental revenue or avoided cost. Monthly net savings equal avoided labor and other costs minus tool, oversight, and failure costs. Track quality and cycle time separately so cheaper output does not hide worse business results.
Decision rule: Keep the automation only if net value remains positive after review and error costs, required quality and compliance thresholds hold, and one-time implementation cost pays back within the team's accepted window.
Illustrative calculation, not a benchmark: Work falls from 20 to eight hours at $60 per hour, saving $720. Subtract a $200 tool and $120 of review for $400 monthly net savings; a $1,600 build pays back in four months.
Field note: Measure where time moved, not just where it disappeared; automation often shifts labor from production into exception handling, QA, and data cleanup outside the original budget line.
Sources1
Q098
Test AI-generated creative with the same commercial rigor as human creative plus extra provenance, claim, likeness, brand, and variation controls. Hold audience, offer, placement, budget logic, and conversion definition constant when comparing the creative source. Predefine the hypothesis and stopping rule, review every asset before launch, and evaluate qualified conversion, contribution value, complaints, and policy failures, not click-through rate alone.
Decision rule: Run an AI-versus-human comparison only when each arm has equivalent strategic inputs and spend conditions; stop any asset immediately for unsupported claims, rights issues, harmful representation, or brand-critical errors.
Example: Test four approved human and four approved AI variants under the same audience, offer, placements, and conversion event; compare cost per qualified purchase and gross profit after reaching the predeclared sample requirement.
Field note: Separate production method from creative concept; otherwise an AI arm with many concepts is being compared with a human arm with one, and the result cannot identify what caused the lift.
Q099
Disclose AI involvement when law or platform policy requires it, or when omitting it could materially mislead a reasonable person about identity, authenticity, endorsement, evidence, or how a consequential message was created. Synthetic people, cloned voices, fabricated scenes presented as real, testimonials, and news-like or regulated communications deserve special scrutiny. Routine grammar or production assistance does not automatically require a blanket label, subject to current rules.
Decision rule: Ask whether knowing about AI would change a reasonable buyer's interpretation of who is speaking, what actually happened, or why the claim should be trusted; if yes, disclose clearly and near the representation.
Example: Label a synthetic customer video before or with the endorsement, not in a footer reached after playback; a disclosure that requires an extra click is unlikely to correct the initial impression.
Field note: Record the disclosure decision with the asset provenance; future edits can turn harmless assistance into a synthetic representation without reopening the original review.
Q100
Classify each automated action by impact, then enforce least-privilege access, draft and approval separation, exact payload review, versioning, an immutable activity log, spend and audience limits, dry runs, idempotency, stop conditions, and a tested rollback playbook. Record who approved what and when. After release, verify the live state and outcomes; a successful API response is not proof that the intended message, audience, or budget is live.
Decision rule: No automation may change live state unless the action has an accountable owner, bounded authority, preflight validation, named approval where required, observable live-state proof, and a rollback path tested within the needed recovery time.
Example: A campaign may auto-draft and QA, but publishing requires approval; it auto-pauses at the pre-agreed daily spend or complaint threshold, preserves the prior version, and alerts the owner with a one-step restore action.
Field note: Design rollback before optimization: if the team cannot identify the last known good audience, payload, settings, and dependencies, the automation is not production-ready.