Vendors love the word "manage" precisely because it is vague. Here is the unvague version: the entity-by-entity list of what an MCP-connected agent can read, what it can change, what gates each write, and the column that is deliberately empty — every row a lever it pulls on your word, in seconds. The list below is AdCopilot's — 32 exposed tools — and it is the level of specificity you should demand from any tool.
The capability table: entity by entity
| Entity | Read | Create / change | Never |
|---|---|---|---|
| Campaigns (Search, PMax) | Performance, settings, status | Create (paused by default), rename, pause/enable, budget | Delete |
| Budgets | Amounts, pacing, limited-by-budget flags | Raise or lower, campaign by campaign | Delete |
| Ad groups | Performance, structure | Create, rename, default CPC bid, pause/enable | Delete |
| Keywords | Performance, match types, bids | Add, change CPC bids, pause/enable | Delete |
| Negative keywords | Existing negatives at all levels | Add (exact/phrase/broad) | Delete |
| Ads (RSAs) | Copy, performance, policy status | Create, pause/enable | Delete |
| Assets (15+ types) | Coverage, performance | Create sitelinks, callouts, snippets, images and more; link to campaigns | Delete |
| Geo targeting | Current targets, per-location performance | Add location targets (exclusions stay a UI job) | — |
| Ad scheduling | Current schedule | Set day/hour schedules | — |
| Device bids | Per-device performance, current adjustments | Set device bid adjustments | — |
| Billing | — | — | Everything |
| Account settings (ownership, currency, time zone) | Basic account metadata | — | Everything |
Three structural facts sit behind the table.
Campaigns and budgets: create, adjust, pause, enable
The agent builds a complete campaign — search or Performance Max, with ad groups or asset groups, keywords, ads and assets — in one approved sequence, in the time it takes to describe it. Campaigns are created paused by default, so a build cannot spend until a human enables it. Budget changes and status flips are single-tool writes: proposed with evidence, approved in one click, live immediately, and attributed to your sign-in in change history.
One honest limitation worth knowing before you plan around it: the agent does not switch an existing campaign's bidding strategy. That decision stays in the Google Ads UI — deliberately, since strategy changes reset learning and deserve friction.
Keywords, negatives, ads and assets
Keywords add with chosen match types and CPC bids; existing ones can be re-bid, paused or enabled. Negative keywords — the highest-value, lowest-risk write in ads — add at campaign level from search-term evidence. Responsive search ads are created complete (up to fifteen headlines, four descriptions) and can be paused or enabled; revising copy runs as create-the-new, pause-the-old — a sequence the agent handles in one conversation. Asset coverage — sitelinks, callouts, structured snippets, images and the rest of the 15+ types — is often where accounts are thinnest and where an agent's patience shows first.
The never column: what is absent on purpose
Three absences define the safety model, and they are absences of capability, not policy promises:
- Deletion. No remove tools are exposed, and any mutate carrying a REMOVED status is refused server-side in any letter case. In Google Ads, removal is permanent — which is exactly why it is not a tool at all rather than a gated one.
- Billing. No tools touch payment methods, cards or invoicing. The agent allocates budgets; it cannot reach the instrument that pays them.
- Account ownership and structure. Creating or closing accounts, changing access, currency or time zone — none of it is in the toolset.
The result is a bounded worst case: everything the agent can do wrong, a human can undo.
How approvals gate each write in practice
The flow is the same for every row of the table. The agent reasons, then
proposes a specific tool call — update_campaign with the new budget,
add_negative_keywords with the exact list. Your
MCP client displays it and waits. You approve,
and the change executes through Google's API, landing in change history
under your name and in the connector's audit trail with tool, account,
outcome and timestamp. You decline, and nothing happened.
Reads never prompt — analysis stays frictionless, which is what makes the agent worth having. Clients also let you loosen the gate per tool once trust is earned — negatives on auto-approve, budgets always manual is a common resting point. The approval workflow tutorial shows the configuration, and what an ads agent is covers where the read/write boundary should sit for a new connection.
Print the table, and put the same three questions to any tool you evaluate: what can it change, what gates each change, and what can it never do. If you want to see the full list live, the pilot exposes every tool above on up to five accounts for seven days, no card.
Frequently asked questions
Can an AI agent change my billing details?
No. AdCopilot exposes no billing tools, so payment methods, cards and billing profiles are outside anything a conversation can reach — there is no tool to call. Billing lives in Google's own billing interface under your sign-in. The agent's writable world is campaign management: structure, targeting, budgets, creative — money allocation, never money collection.
Can it change things without asking me?
Your AI client decides that, and the default answers no: MCP clients such as Claude and ChatGPT surface each write as a permission prompt naming the tool and values before executing, while reads flow freely. Most clients let you whitelist specific tools for unattended runs — a deliberate loosening you perform per tool, not something the agent can grant itself.
Does the agent bypass Google's own checks?
No. Every write lands through the official Google Ads API, so Google's validation, policy review and change history apply exactly as they would to a human edit. New ads still enter ad review; invalid values are still rejected; everything is attributed to your sign-in. The agent is a faster hand on the same official levers — not a side door.
Try it on your own account for a week
The full set of tools for the week, so you can see what it actually does — and it still cannot delete anything. No cost, no card, no contract: you connect your own Google account and can withdraw the access whenever you like.
- Up to 5 accounts
- One week
- Full tools
- No card
- Autonomous agentsLevels of autonomy in Google Ads management, which optimisation work is safe unattended versus which needs approval, and why irreversible actions should not be automated.
- Google Ads MCP serverWhat a Google Ads MCP server is, how free self-hosted servers compare to a hosted one, the full tool list AdCopilot exposes, and what you need to connect.
- Connect ClaudeStep-by-step instructions for adding a Google Ads MCP connector to Claude Desktop, claude.ai and Claude Code, including what to ask it first and how to revoke access.
- Connect ChatGPTStep-by-step instructions for adding a Google Ads MCP connector to ChatGPT, what it can read and change, and how to withdraw access.