Vendors love the word "manage" precisely because it is vague. Here is the unvague version: the entity-by-entity list of what an MCP-connected agent can read, what it can change, what gates each write, and the column that is deliberately empty — every row a lever it pulls on your word, in seconds. The list below is AdCopilot's — 54 exposed Google Ads tools (as of v2.16.0) — and it is the level of specificity you should demand from any tool.
The capability table: entity by entity
| Entity | Read | Create / change | Never |
|---|---|---|---|
| Campaigns (Search, PMax) | Performance, settings, status | Create (paused by default), rename, pause/enable, budget, bidding strategy and target | Delete |
| Budgets | Amounts, pacing, limited-by-budget flags | Raise or lower, campaign by campaign | Delete |
| Ad groups | Performance, structure | Create, rename, default CPC bid, pause/enable | Delete |
| Keywords | Performance, match types, bids | Add, change CPC bids, pause/enable | Delete |
| Negative keywords | Existing negatives at all levels | Add (exact/phrase/broad) to a campaign, account-wide, or to a shared list attached to campaigns — not at ad-group level | Delete |
| Ads (RSAs) | Copy, performance, policy status | Create, pause/enable | Delete |
| Assets (ten types) | Coverage, performance | Create sitelinks, callouts, snippets, images and more; link to a campaign, an ad group or the account; pause/enable a link | Delete |
| Conversion actions | Every action, its settings, recent volume | Create a website conversion action (existing ones are never edited) | Delete |
| Google's auto-applied recommendations | Which types are switched on | Pause a type | — |
| Geo targeting | Current targets, per-location performance | Add location targets and exclusions | — |
| Ad scheduling | Current schedule | Set day/hour schedules | — |
| Device bids | Per-device performance, current adjustments | Set device bid adjustments | — |
| Billing | — | — | Everything |
| Account settings (ownership, currency, time zone) | Basic account metadata | — | Everything |
Three structural facts sit behind the table.
Campaigns and budgets: create, adjust, pause, enable
The agent builds a complete campaign — search or Performance Max, with ad groups or asset groups, keywords, ads and assets — in one approved sequence, in the time it takes to describe it. Campaigns are created paused by default, so a build cannot spend until a human enables it. Budget changes and status flips are single-tool writes: proposed with evidence, approved in one click, live immediately, and attributed to your sign-in in change history.
One change deserves more friction than the rest: the agent can switch an existing campaign's bidding strategy — to Maximize Clicks with a cap on the cost of a click, Maximize Conversions, a target CPA, Maximize Conversion Value or a target ROAS. It is proposed like every write, and it is the one to read twice, since a strategy switch resets learning.
Keywords, negatives, ads and assets
Keywords add with chosen match types and CPC bids; existing ones can be re-bid, paused or enabled. Negative keywords — the highest-value, lowest-risk write in ads — add at campaign level, account-wide or through a shared list, from search-term evidence. Responsive search ads are created complete (up to fifteen headlines, four descriptions) and can be paused or enabled; revising copy runs as create-the-new, pause-the-old — a sequence the agent handles in one conversation. Asset coverage — sitelinks, callouts, structured snippets, images and the rest of the ten types — is often where accounts are thinnest and where an agent's patience shows first.
The never column: what is absent on purpose
Three absences define the safety model, and they are absences of capability, not policy promises:
- Deletion. No remove tools are exposed, and any mutate carrying a REMOVED status is refused server-side in any letter case. In Google Ads, removal is permanent — which is exactly why it is not a tool at all rather than a gated one.
- Billing. No tools touch payment methods, cards or invoicing. The agent allocates budgets; it cannot reach the instrument that pays them.
- Account ownership and structure. Creating or closing accounts, changing access, currency or time zone — none of it is in the toolset.
The result is a bounded worst case: everything the agent can do wrong, a human can put back.
How approvals gate each write in practice
The flow is the same for every row of the table. The agent reasons, then proposes a specific tool call — the campaign update with the new budget, the negative-keyword add with the exact list. Your MCP client displays it and waits. You approve, and the change executes through Google's API, landing in change history under your name and in the connector's audit trail with tool, account, outcome and timestamp. You decline, and nothing happened.
Reads change nothing, so allow them once (in Claude, set the read-only tools to Always allow) and analysis stays frictionless, which is what makes the agent worth having. Clients also let you loosen the gate per tool once trust is earned — negatives on auto-approve, budgets always manual is a common resting point. The approval workflow tutorial shows the configuration, and what an ads agent is covers where the read/write boundary should sit for a new connection.
Print the table, and put the same three questions to any tool you evaluate: what can it change, what gates each change, and what can it never do. If you want to see the full list live, the free trial exposes every tool above on the full Pro plan for seven days for a new workspace, no card, then drops to the Free plan rather than cutting off.