NotFairNotFair
Start now

Google Ads MCP · safety architecture

Approval-gated Google Ads MCP: inspect, diff, approve, measure, undo

An approval-gated Google Ads MCP never silently mutates campaigns: the agent reads live state, proposes an exact change, waits for explicit user approval, executes, logs provenance, and—on NotFair—supports impact review and undo metadata for supported mutations. That is the production contract operators need when connecting Claude to paid accounts. NotFair implements this lifecycle end-to-end on a hosted endpoint. Draft buffers or paused-by-default creates on other products are different mechanisms; evaluate them on documentation, but NotFair’s model is built for in-chat review plus recovery.

Last verified · September 30, 2026 · NotFair product team

The NotFair write contract

Six checkpoints from prompt to reversal

The approval moment matters, but it is only the middle of the system. NotFair gives an MCP client typed read and write tools while keeping execution, auditability, and recovery on the server side.

  1. 01

    Inspect live state

    The agent reads the target account, current value, recent performance, and freshness metadata before recommending a mutation.

  2. 02

    Prepare an exact operation

    The proposal identifies the account, entity, intended value, and the tool that would execute it. Ambiguous account targeting is resolved before the write.

  3. 03

    Apply server-side limits

    Guardrails reject unsafe ranges and malformed operations even if a model proposes them. For example, material bid and budget changes are bounded on the server.

  4. 04

    Wait for explicit approval

    The client surfaces the proposal. Execution begins only after the user approves the staged operation.

  5. 05

    Record and verify

    The result includes an operation or change identifier and is recorded with provenance. A follow-up read can verify the new state.

  6. 06

    Review impact or reverse

    The agent can compare a post-change window and, where an exact inverse exists, propose a second approval-gated operation to restore the prior value.

Evidence table

What each safety control prevents

ControlWhat it protects againstWhat the operator sees
Explicit account routingReading or mutating the wrong MCC clientNamed account and account ID before action
Typed operationsInvented fields, invalid GAQL-shaped writes, and ambiguous mutation intentA documented tool with validated arguments
Server-side guardrailsModel compliance failures and changes outside accepted limitsA rejection with the violated boundary
Approval gateSilent or autonomous spend changesThe exact staged operation before execution
Operation provenanceUnattributed changes and weak incident reconstructionOperation ID, author context, timestamp, result
Impact reviewLeaving a harmful change in place because nobody checkedBefore/after evidence and a recommended next step
Undo metadataGuessing the old value during rollbackThe stored inverse where exact reversal is supported

Limits and honest boundaries

  • Approval reduces accidental execution; it does not make a strategically bad recommendation good.
  • A before/after comparison is evidence, not automatic proof that the change caused the outcome.
  • Some platform operations are not exactly reversible. NotFair surfaces that limit instead of manufacturing an undo claim.
  • Google Ads policy, permissions, API limits, and account-level restrictions still apply after approval.

Frequently asked questions

What does approval-gated mean?

An approval-gated Google Ads MCP never silently mutates campaigns. The agent reads live state, proposes an exact change, and waits for explicit user approval before the Google Ads API write runs. NotFair also logs provenance and, for supported mutations, impact review and undo metadata.

Can NotFair change Google Ads without asking me?

No. Read tools can inspect the account, but write tools are staged for explicit approval before execution. The proposal identifies the operation and target so the user can approve or reject it.

What is logged (operation_id, author, timestamp)?

The operation log records the operation ID, target account, tool and arguments, authoring user or agent context, timestamp, outcome, and available inverse-operation metadata. Google Ads also records API mutations in its own change history.

What can be undone?

Many common changes have an exact inverse and store undo metadata, including status, bid, budget, and keyword operations. NotFair does not label an operation reversible when the previous state cannot be restored exactly; those limits are surfaced instead.

How does this differ from draft-only buffers?

Draft buffers or paused-by-default creates keep a change out of serving until a later publish or status flip. NotFair’s model is in-chat review of the exact mutation, then execution, provenance, impact review, and supported reversal. Evaluate draft-only products on their own documentation; they are a different mechanism.

How does impact review work?

NotFair can inspect performance before and after a recent change and return an evidence-based review. Impact review does not prove causality by itself; it gives the operator a structured basis for keeping, adjusting, or reversing the change.

How do I try the public verification prompts?

Use the same prompts published on the Google Ads MCP server comparison. They cover plan limits, tool inventory, MCC routing, a previewed write, provenance, impact review, and undo. Rerun them against any server you evaluate.