What to never let Claude do in your ad account
Not a list of scary things. A sort that still works at 11pm when the suggestion sounds completely reasonable.
Sort every action into four classes and the question answers itself. Read pulls data and changes nothing — let it run freely. Draft creates paused things — also free, because paused costs nothing. Status turns things on and off — confirm the specific entity first. Financial moves budgets, bids and caps — never, not on a rule, not on a schedule, not "just to test." The line is not about trusting the model. It is that the first three are reversible in seconds and the fourth is not reversible at all.
Most advice here is a list of scary things phrased as vibes: be careful, use guardrails, keep a human in the loop. None of it tells you what to do on a Tuesday when the model offers to shift budget from a losing ad set to a winning one and it sounds completely reasonable.
The four classes do, because they sort by how expensive it is to be wrong rather than by how risky the action sounds.
The four classes
| Class | Examples | Cost of being wrong | Rule |
|---|---|---|---|
| Read | Insights, previews, entity lists, creative, error states | None — nothing changed | Let it run |
| Draft | Create campaigns, ad sets, ads, creatives, copy | None — it is paused and spends nothing | Let it run |
| Status | Activate, pause, archive | Minutes of delivery, or a live ad you did not review | Confirm the entity by name first |
| Financial | Budgets, bids, spend caps | Money, immediately, and you cannot un-spend it | Never autonomously |
The useful property of this split is that it survives contact with a persuasive argument. When something sounds sensible at 11pm, you are not deciding whether it is a good idea. You are checking which box it lands in.
Campaigns, ad sets and ads created through the official connector come back paused, and all three creation tools declare it — none of them exposes a status parameter. So a bad draft is a wasted five minutes, not a wasted budget. That is what makes "let it draft freely" a defensible position rather than an optimistic one. Confirm status after anything gets created anyway.
The one that catches people
Financial is obvious once written down. The class people get wrong is Status, because it feels administrative and it is the one an assistant will offer to batch.
"Shall I pause the five ad sets that haven't converted this week?" is a Status action wearing Read's clothing. It sounds like tidying. It is five delivery decisions made on one sentence, and if the underlying window was wrong — a partial week, a shifted attribution setting — you have just paused five things for a reason that does not exist.
The rule that holds: an action on more than one entity needs the entities named. Not "the underperformers." The names.
These four classes are the spine of the whole weekly routine — they decide what Monday, Wednesday and Friday are each allowed to do. See how the week is split →
Check what you have already agreed to
You probably have at least one standing arrangement you would fail to justify if asked — a saved instruction, a project note, or simply a habit of approving things quickly. This is checkable, and it takes a minute:
List every change made to this ad account in the last 30 days,
grouped by who or what made it. For each, say whether it was a
budget or bid change, a status change, or a new draft.
Every change an agent makes lands in the activity log like any other change. Read the list. If there is a budget or bid row you did not personally decide, that is your answer and it is worth knowing tonight rather than at the end of the month.
Where the line moves with spend
- At the smaller end of the range. Status is the class that matters, because with few enough ad sets a single wrongly paused one is a meaningful share of your delivery. Financial barely comes up — you are not moving budget in a hurry.
- In the middle. All four classes are live at once, and Draft is where the leverage sits — enough creative throughput to matter, few enough people that you are still doing it yourself.
- At the top of the range, with a team. The classes stop being personal discipline and become access control — portfolio-level rules, one project per account, and the activity log as an audit trail rather than a curiosity.
What this is not
It is not a claim that the model is dangerous. Read and Draft cover most of what is useful, and both are free of consequence. The restriction is narrow and it is aimed at exactly one thing: an irreversible action taken on a number nobody checked.
Which is worth saying plainly, because the failure mode here is almost never dramatic. It is a confident wrong figure that nobody questioned, turned into a budget change by a system that was allowed to make one.
Try this tonight Run the activity-log prompt above for the last 30 days. If every row is Read or Draft, you are already operating the way this post describes and you can stop reading. If there is a Financial row you did not decide, that is the one thing to change this week — and the change is a sentence in your project instructions, not a new tool.
If you have not connected an account yet, the setup covers what the connector actually exposes, and the same four classes are written into the free skill.
Frequently asked questions
Is a pause-by-rule automation ever acceptable?
A rule you wrote, that you can state out loud, that fires on a metric you have verified, and that you review weekly — that is a Status action you have pre-approved, and it is defensible. "Pause anything underperforming" is not a rule; it is a delegation of judgement with a threshold attached afterwards.
What about budget changes I have explicitly approved?
Then you made the decision and the tool executed it, which is fine. The class is about who decides, not who types.
Does this change if the numbers get more reliable?
Financial stays where it is regardless. Reversibility, not accuracy, is what puts it in its own class — a perfectly accurate wrong decision still spends the money.
How do I apply this if someone else runs the account?
Write the four classes into whatever brief they work from, and use the activity log to check rather than to ask. It is a faster conversation when you already know what happened.
The routine these classes hold up
The Claude Ads Operator is the weekly system built on this split — what Monday reads, what Wednesday drafts, what Friday launches, and what never runs without you. Everything it drafts starts paused.
See what's inside — $67 founding pricePre-sale: the modules are still being recorded and founding members get the checkout link first. No charge today. Public price $97.