AI for Marketing

AI agent governance for marketing: permissions before autonomy

Quick answer

Decide what an AI agent may do before you connect it to live marketing systems. Reading a report, drafting an email and spending money are different permissions. Keep approval with a person until you’ve tested each action and know how to recover from a mistake.

A wrong answer is different from a wrong action

An assistant that invents a campaign number creates a reporting problem. An agent that uses that number to increase a live budget creates a spending problem as well. Connecting tools changes the consequences of a mistake, even if the underlying model is unchanged.

The word agent covers systems with very different abilities. Some follow a fixed sequence; others choose tools and decide what to do next. Anthropic’s engineering guidance distinguishes predefined workflows from agents that direct their own process. Its advice to begin with simple arrangements is particularly relevant when a marketing team already knows the steps it wants automated.

Read our explanation of how AI agents work before comparing demonstrations. The key purchasing question is what the system can change, under whose authority, and how that change is reviewed.

Write an action inventory

List the actual operations, not just the connected applications. Reading campaign performance, drafting a recommendation, editing a budget and sending an email are separate permissions. A connection to an advertising account should not automatically permit all four.

Assign an owner to each action and a consequence if it goes wrong. Reading an aggregate report is usually easier to contain than exporting contact records. Drafting a landing page is easier to inspect than replacing the published version. A proposal to delete inactive audiences should include the exact audience names and a recovery plan.

NIST’s Generative AI Profile provides a broader framework for managing these risks. A marketing team can apply that principle through a short operational register rather than treating governance as a policy document that nobody uses.

Permissions by consequence
ActionStarting controlEvidence to retain
Read reportingScoped read accessSource and retrieval time
Draft contentHuman review before publicationSources and proposed text
Change budgetApproval of the exact changeBefore and after values
Contact customersApproved recipients and messagePermission basis and delivery record

Use three gates at the point of action

First, check authority: is this agent allowed to perform this operation on this specific account? Second, check evidence: does the proposal identify its inputs, affected objects and expected consequence? Third, check approval: has the right person accepted the concrete change?

Giving an agent a £500 daily spending limit doesn’t settle the matter. Five individually permitted changes could still undermine a campaign or move spend away from the intended audience. Set limits for the total change over a period, and require the proposal to show the before and after state.

Approvals should expire when material inputs change. A budget recommendation based on yesterday’s campaign is no longer the same proposal after someone changes its targeting. Requiring a fresh review in that case prevents a valid approval from being applied to a different action.

Plan for partial failure

Connected workflows rarely fail neatly. A CRM record might update while the notification fails. A request might time out after the advertising platform has already applied it. Blindly retrying can create duplicate records, messages or changes.

Use unique operation identifiers where the systems support them. Record the request, response, affected record and completion state. On an uncertain result, read the platform’s current state before retrying. Keep credentials scoped to the task and avoid giving the agent unrestricted access simply because it is easier to configure.

Our marketing operations agent guide describes bounded reporting workflows. Apply those controls before extending the same agent into execution. Customer-facing agents also need a clear handoff to a person when the available evidence is insufficient.

Test the cases a demonstration leaves out

Include an ambiguous campaign name, a stale report, missing permission, a contradictory instruction inside a retrieved document and an unavailable tool. The agent should stop or ask for a narrower instruction when it cannot establish the right target.

For a publishing agent, test whether it preserves a draft when a source link is missing. For a reporting agent, test whether it distinguishes absent data from zero. For a budget agent, test whether a duplicate request is recognised. Record these as observable behaviours, not a general confidence score.

We’d give an agent more freedom one action at a time. An agent can be excellent at analysis and still be unready to publish. Progress from read access to drafts, then to narrowly approved changes. Keep a human-owned route for switching back to the previous process, and practise it before the first serious failure.

Related reading

AI marketing ROI: measure the cost of work you can actually use · Marketing data quality audit: start with the errors that change decisions · UTM naming conventions: a campaign tracking system people will use

Photo: Albert Stoynov / Unsplash.

Leave a Reply

Your email address will not be published. Required fields are marked *