> ## Documentation Index
> Fetch the complete documentation index at: https://help.autoady.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Understand permissions and approvals

> Choose the right safeguards for the AutoAdy Agent, Autopilot, and an external client.

Connecting an account lets AutoAdy reach the data your identity can access. Applying a change also depends on your role, provider permissions, plan, and the workflow’s approval rules.

**Owners** and **Media Buyers** can perform permitted changes; **Client Viewers** are read-only. Billing, team invitations, and client-workspace administration remain owner-only. Provider permissions and plan requirements still apply.

## Match the approval to the workflow

| Workflow | How changes are controlled | What to check |
| - | - | - |
| **AutoAdy Agent** | Supported ad changes use an approval preview in the conversation. | Selected account, affected entity, action, amount and currency before confirming; actual tool result afterward. |
| **Autopilot** | **Off**, **Approval**, or available **Auto** mode for the selected Meta account. | Mode, pending Action Inbox items, daily caps, and executed-action ledger. |
| **External Claude, ChatGPT, or API client** | The client supplies its tool choices and confirmation policy; AutoAdy applies server permission and write checks. | Which identity authorized the client, reachable accounts, allowed tools, and each proposed change. |
| **Scheduled tasks** | A saved revision needs its supported preview and approval before running. | Exact task, scope, schedule, approved revision, and run result. |

A read-only report or recommendation does not apply its proposed change. A message saying “done” is also not a substitute for the action result: inspect the receipt or tool outcome and the provider’s current state.

## Start with a read

1. Choose the intended account and ask for a specific period or entity.
2. Check that the actual result refers to that account and period.
3. If you need a change, review the exact entity and proposed action before confirming through that workflow.
4. Afterward, check whether the result succeeded, partly succeeded, failed, or remains unknown. Use the original attempt’s recovery before submitting the same change again.

Follow [Agent chat](/agent/chat), [Autopilot setup](/automation/autopilot), or [connect an external client](/agent/connect) for the actual controls.

## Keep external-client scope clear

AutoAdy does not currently offer a per-key account scope or a selectable read-only API-key scope. The credential acts as you; an owner’s account selection is a default, not a security boundary. Teammates remain restricted by their role and account access.

Configure a client allowlist or confirmation policy where that client supports it, and begin with account listing or a report. A connector authorization screen grants the connection; it is not a substitute for reviewing every later action. Revoke unused access in **AutoAdy API keys**. [Credential scope and revocation](/developers/authentication).

## If a control is blocked

Follow the displayed role, account, plan, credit, or provider-permission reason. Some older automation paths are unavailable even when a credential is valid or a messaging channel has Full Access. [Current automation availability](/automation/availability) explains those boundaries.

Autopilot’s automatic daily caps apply to that lane, not all account spending or every manual/API action. Turning on Auto is conditional on its availability; raising caps does not enable a disabled mode. [Set Autopilot caps](/automation/autopilot#set-and-verify-caps).

*Last reviewed: October 5, 2026.*


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.