Security and controls

Account access is scoped. Live changes are deliberate.

AdvisorPPC combines Google authorization, encrypted credential storage, tenant isolation, a fixed public tool allowlist, and confirmation before campaign changes.

Illustration of a shield protecting account actions
Illustration of protected account access and approval controls

Google Ads authorization

The user authorizes Google through its OAuth flow. AdvisorPPC receives scoped tokens rather than a Google password and can reach only the accounts and operations permitted for that identity.

Provider tokens are encrypted at rest. HTTPS protects transport to the public service. Users can revoke Google access through Google or use an available AdvisorPPC disconnect control.

Boundaries

Several controls work together.

Fixed allowlist

The public profile exposes thirteen concrete tools and blocks hidden tools when called directly by name.

Account context

MCC and child-account discovery reduces the risk of selecting an unintended customer.

Two-step writes

Pause, enable, and budget replacement require an explicit confirmed retry with the exact target and effect.

Read and write operations

OperationExamplesControl
ReadList accounts and campaigns; retrieve performance and search termsAuthenticated user and connected Google Ads access
AnalysisFind wasted-spend evidenceReturns findings only and never applies them
WritePause, enable, or replace a campaign budgetExact target plus a separate confirmed=true retry

Report a concern

Email support@advisorppc.com without sending passwords, tokens, or API secrets.