Let Your AI Agent Do Marketing Without Wrecking Anything: Split Reads From Writes, Keep a Human on Publish, Start Ads Paused
You already let Claude Code or Cursor touch your codebase, because git can undo anything it does. Marketing has no git revert. A post that went out at 9am to the wrong account has been seen by 9:05, and an ad that went live with a typo in the budget field has spent money by the time you notice.
So the usual pattern is: connect the agent, get excited, watch it do one wrong thing, and disconnect it. This page is about keeping it connected. The method works with any agent and any marketing tools. At the end there’s how AutoWhisper’s MCP server applies it, with a table you can keep open.
What actually goes wrong
The failures people describe on Reddit are rarely “the AI wrote bad copy.” They’re about the agent doing something real that nobody approved.
- A founder of a social scheduler (they say so at the top of the post: “Disclosure: I am the founder of PostFast”) wrote up what broke after agents started posting through their MCP server. Approvals had to become a tool, not a dashboard setting, because “without this, teams turn the agent off after the first wrong post” (r/SaaS). They also found agents don’t know which account you meant when a brand has two Facebook Pages, and that a dropped connection plus a retry produces two scheduled posts.
- An OpenClaw user gave their assistant read access to their mailbox. “Weirdly it did send an email as me and promise me it won’t do it again so I need to lock that down” (r/openclaw). The agent promising not to do it again doesn’t count as a control.
- A SaaS co-founder who runs most of their sales from one Claude chat with MCP says follow-ups “sometimes mix up details from different calls or promise things we never discussed,” so “nothing gets sent without me reading it first. Everything goes to drafts, never straight out.” Their first lesson: “Start with read-only tools” (r/SaaS).
In that last thread one reply puts the whole method in four words: “Split it by blast radius.” Let the model read everything, and let it write only where a mistake is cheap to undo.
Sort every action into four tiers
Before you connect anything, list what the agent will be able to do and put each action in one tier. A tier is decided by the worst thing a mistake can cause, not by how often the action happens.
| Tier | Examples | Worst case if wrong | Who says yes |
|---|---|---|---|
| 1. Read | List drafts, check what posted, read results, check balance | A wrong summary | Nobody. Let it run. |
| 2. Draft | Write a caption, generate a video draft, edit copy that hasn’t gone out | Wasted credits, a draft you reject | The agent, within a budget you set |
| 3. Publish | Post to a channel, reschedule, retry a failed post | Your brand saying something you didn’t mean, in public | You, every time |
| 4. Spend | Launch or boost an ad, raise a budget | Real money gone | You, in the ad platform itself |
Tier 1 is where most of the time savings are, and it’s the tier people lock down by accident. If the agent asks permission to read the post queue, you’ll start clicking “allow” without reading, and then you’ll click “allow” on a publish too. Allow reads permanently, so that a permission prompt means something is about to change.
Five rules that keep it switched on
1. Reads are free and unrestricted. No prompts, no rate you have to watch. This is what lets you ask “what’s waiting for me?” ten times a day.
2. Drafts are cheap to undo, so let the agent make them. A rejected draft costs some credits and nothing else. If generation costs money, cap it with a prepaid balance, not with prompts on every call.
3. Publishing and spending need a human yes, and the yes can’t come from the agent. This is the rule people get wrong. If the approve step is just another tool call, an agent that wants to finish the task will call it. The yes has to come through something the agent can’t press for you: a permission prompt in your client, or a button in a different app.
4. Ads start paused, and the cap is set outside the conversation. The agent can build the campaign; it shouldn’t be able to make money start flowing. The budget ceiling should live in a settings page you filled in once, not in a number the agent picks mid-chat.
5. Every action leaves a record you can read later. What was approved, what posted, what failed and why, where each credit went. When something goes wrong at 3am you need to find out what happened without asking the agent to remember.
Set expectations on ads: faster, not cheaper
Agents in ad accounts save hours. They don’t make your customers cheaper to get. In a thread asking whether the Meta Ads MCP lifted lead quality or cost per lead, one advertiser who uses a third-party Meta MCP answered: “It won’t magically improve your results, but it avoid wasting hours in the business manager for repetitive tasks” (r/ClaudeAI). The same reply gives a warning worth keeping: new objects get created paused by default, “but still, if you change budget etc it goes straight to live.”
That’s rule 4 in practice. Pausing new ads isn’t enough if the agent can still change the budget on an ad that’s already running.
What lowers cost per customer is the creative and the offer. If that’s the bottleneck, the agent’s job is to produce more angles to test, and How to Test Ad Creative covers what to do with them.
How AutoWhisper’s MCP server applies the five rules
AutoWhisper is an AI marketing tool: it turns a product page into short videos and image posts, publishes to TikTok, YouTube, Instagram, Facebook, X, LinkedIn, Threads, Bluesky and Pinterest, and builds ads on Meta, TikTok and LinkedIn. It exposes 13 MCP tools. Here’s how they map to the tiers. (Installing it is covered in Before You Start: Which Path Are You On and in the setup guide.)
Tier 1: eight read-only tools. autowhisper_products_summary, autowhisper_products, autowhisper_status, autowhisper_feed (drafts waiting for review), autowhisper_posts (the post queue, with the reason for every failure), autowhisper_wallet, autowhisper_platforms (what’s connected and whether the connection is healthy) and autowhisper_performance (funnel, per-channel breakdown and ad spend). None of them spend credits or send anything out. Each is marked readOnlyHint: true in its MCP annotations, which is how clients decide not to prompt you.
Tier 2: autowhisper_cmo and autowhisper_edit_content. autowhisper_cmo is a conversation with the AI CMO: add a product, make a batch, plan what to post. When you ask for content directly, it generates and charges credits. When the CMO proposes something you didn’t ask for, it stops and asks first. A video draft costs the script and first frame up front (3 + 4 credits); the render (45 credits) only happens when you approve it. Image posts render right away, so their credits go immediately. autowhisper_edit_content rewrites copy directly and costs nothing.
Tier 3: approving is publishing. autowhisper_action with approve_feed_item is not a bookmark. On a finished piece it schedules the post to every connected channel. On a video draft it starts the render and charges for it. Retry, reschedule, reject and boost live in the same tool.
The confirmation step. Every call to autowhisper_action comes back with a confirmation message_id instead of executing. Nothing happens until autowhisper_confirm is called with that id and "yes". The CMO does the same for anything that publishes, deletes, or changes automation settings.
Tier 4: ads are built paused. If you’ve connected a Meta, TikTok or LinkedIn ad account, sending a finished piece also builds an ad there, paused. It spends nothing until you press start in your own ads console. Each ad gets the daily budget from Workspace settings → Ad channels → Starting budget per ad, a number you typed into a form, not one the agent chose. If that field is empty, no ad gets built. AutoWhisper never spends ad money on your behalf and never fronts it.
The record. Every review card keeps its status (pending, approved, rejected, executed). Every post keeps its status and failure reason. The wallet page lists every credit transaction. CMO conversations held through the agent are saved in that workspace’s chat history in the dashboard.
The gap you close yourself
autowhisper_confirm is a tool, so an agent can call it right after autowhisper_action and approve its own request. The confirmation id means the request can’t run without a second call. It doesn’t mean a human made that call. Rule 3 says the yes has to come from somewhere the agent can’t press, and in practice that’s your client’s permission prompt.
Both write tools carry destructiveHint: true and openWorldHint: true, so well-behaved clients ask before running them. Make that explicit. In Claude Code, put this in .claude/settings.json (the server name autowhisper matches the claude mcp add command in the setup guide):
{
"permissions": {
"allow": [
"mcp__autowhisper__autowhisper_products_summary",
"mcp__autowhisper__autowhisper_products",
"mcp__autowhisper__autowhisper_status",
"mcp__autowhisper__autowhisper_feed",
"mcp__autowhisper__autowhisper_posts",
"mcp__autowhisper__autowhisper_wallet",
"mcp__autowhisper__autowhisper_platforms",
"mcp__autowhisper__autowhisper_performance"
],
"ask": [
"mcp__autowhisper__autowhisper_action",
"mcp__autowhisper__autowhisper_confirm"
]
}
}
Reads never prompt. Approving, publishing, retrying and confirming always do. Leave autowhisper_cmo and autowhisper_edit_content at your client’s default, or move them to ask too if you want to see every generation request. In claude.ai and other connector clients, the same choice is a per-tool permission setting on the connector.
Then say it to the agent once, at the start of a session:
Before you call autowhisper_confirm, show me what it will publish or charge and wait for me to type yes. Never confirm on my behalf.
What you say, what it calls, what it costs
| You say | Tool it calls | Spends credits? | Goes out in public? |
|---|---|---|---|
| “What’s waiting for my review?” | autowhisper_feed |
No | No |
| “Did yesterday’s posts go out? Why did any fail?” | autowhisper_posts |
No | No |
| “Which channels are connected, and is any of them broken?” | autowhisper_platforms |
No | No |
| “How did the last 14 days do, ad spend included?” | autowhisper_performance |
No | No |
| “How many credits are left?” | autowhisper_wallet |
No | No |
| “Make three UGC videos for the travel adapter” | autowhisper_cmo |
Yes: script and first frame now, render later | No, they land in the review feed |
| “Cut the hook on that second one to under eight words” | autowhisper_edit_content |
No | No |
| “Approve the second one” | autowhisper_action → returns a confirmation id |
Not yet | Not yet |
| “Yes, confirm it” | autowhisper_confirm |
Yes, if it’s a video that still needs rendering | Yes: scheduled to every connected channel, plus a paused ad on each connected ad account |
| “Retry the LinkedIn post that failed” | autowhisper_action → autowhisper_confirm |
No | Yes |
| “Start the Meta ad” | Nothing. You press start in Meta Ads Manager |
The last row is on purpose. No tool starts an ad, so there’s nothing to misfire.
What to do next
Copy the permissions block above into your project before you connect anything, so the first time the agent tries to publish, you get asked. If you haven’t installed AutoWhisper yet, the setup guide takes you from install to the first post in one sitting, with prompts you can paste. A full video costs 52 credits and new accounts start with 65: create an account.