Blog4 min read

Meta Shipped an Operator to Agencies and an Analyst to Small Businesses

Meta gave agencies write access to ad accounts and small businesses read-only, four months apart. Five AI agent products shipped in 2026 with four different permission models. The pattern is not indecision.

MB
Michael Bennett · AI marketing systems
The owner of a small independent shop standing alone behind the counter, looking at a phone.

In April 2026, Meta launched Ads AI Connectors, an official MCP server and command line interface that, in Meta's own words, let advertisers and agencies "create, manage, and analyze campaigns."

Create. Manage. That is write access. An operator.

In August, Meta shipped new Meta AI features for small businesses. Meta AI can now work with Facebook and Instagram analytics, review advertising performance, and compare results.

Read. Review. Compare. That is an analyst.

Same company, same underlying capability, four months apart, opposite permission models.

That looks like inconsistency. I think it is the most coherent decision either platform has made this year.


The permission question keeps getting asked wrong

The industry has been arguing about whether AI agents should be allowed to change ad accounts as though there is a single correct answer waiting to be discovered.

Look at what has actually shipped in 2026:

ProductPermission
Google Ads MCP serverRead-only
Google Analytics MCP serverRead-only
Google Merchant API MCP (alpha)Read-only plus low-risk write
Meta Ads AI ConnectorsCreate and manage
Meta AI for small businessesRead and analyze

Five products. Four distinct permission models. Two companies with more behavioral data on advertiser competence than anyone reading this will ever have.

If there were one right answer, they would have converged on it. They have not, and the reason is that the question is underspecified. Should an agent have write access is not answerable without asking whose account, and what happens when it is wrong.

Five products across four permission models, from read-only for the Google Ads and Google Analytics MCP servers, through read and analyze for Meta AI for small businesses and read-only plus low-risk write for the Google Merchant API MCP alpha, to create and manage for Meta Ads AI Connectors.
Four models, two companies, no convergence. The variable is who owns the account.
Meta AI, AGENT PERMISSIONS

The variable is the review layer

An agency running forty accounts has infrastructure around a change: a QA step, a naming convention, a second person who reviews before it goes live, a weekly performance review that surfaces anomalies within days. Write access removes tedium, and the failure mode is contained by process that already exists for human error.

A small business owner has none of that. They have a phone, a business to run, and no second pair of eyes. For them, an agent that restructured a campaign at 11pm would be indistinguishable from the platform malfunctioning, and they would have no way to diagnose which it was.

So Meta gave the party with a review layer more capability, and the party without one more guardrails.

That is not a compromise between two positions. It is the recognition that permission should scale with the capacity to catch mistakes, and that capacity varies enormously between customers of the same platform.


Google made the same move on a different axis

Google did not segment by customer. It segmented by consequence.

Read-only for Ads and Analytics, where a wrong action spends real money in real time and the state you return to after an undo is not the state you left, the learning phase is gone, the auction position is gone, the budget is spent.

Read-only plus low-risk write for Merchant Center, where creating a data source is recoverable and Google explicitly limits the write surface to actions of that kind: "strictly limited to read-only operations and low-risk write tools... as a safety guardrail."

Two different segmentation strategies, same underlying logic: match the permission to the blast radius.


What this means for your team

The useful question is not "do I trust the model." It is "would I catch this, and how quickly?"

That reframes it into something you can actually assess:

Do you review account changes on a schedule, or when something looks wrong? Scheduled review is a genuine safety layer. Reactive review means your detection time is however long it takes for damage to become visible in a report.

Would a bad change be obvious or subtle? A paused campaign is obvious. A slightly wrong target CPA is not, and will quietly underperform for a week while looking approximately normal.

How many accounts, and how often do you look at each? Blast radius scales with count and inversely with attention. Forty accounts reviewed monthly is a very different risk posture from one account you know intimately.

Who explains it to the client? "The agent did it" is not an answer. If you would not be comfortable describing the change after the fact, you should not have delegated it in advance.


The resolution

The industry has not failed to decide. It has decided something more useful than a single answer: that the right permission level is a property of the relationship, not the technology.

Two companies looked at the same capability and segmented it, one by customer sophistication, one by consequence severity. Both are right, because they are answering different versions of the question for different populations.

Which means the decision is yours to make deliberately rather than to inherit from a default. Work out where your team sits on review capability and blast radius, and pick accordingly.

Then write it down, because the defaults will keep moving.

MB
Michael Bennett
I build AI marketing systems that acquire, convert & retain customers.

Working out where AI actually fits in your marketing?

I write these while building the systems behind them: measurement, creative pipelines, and agents that do real work. Connect on LinkedIn and tell me what you are working on. That is where these conversations start.

Connect on LinkedIn