A login carries a business decision
An advertising agent can be useful long before it deserves broad access. It might reconcile a campaign brief, inspect delivery, or prepare a budget change while a person retains the final decision. The trouble starts when a team connects those steps and treats the original login as permission for everything that follows. The agent has moved from helping someone think to acting on the company's behalf.
That distinction needs a plain definition. An agent is software that can choose and carry out steps toward a goal, often using several tools. Governance is the set of decisions and controls that determines which steps are allowed. Neither term guarantees intelligence, commercial judgment, or good results. A system can perform exactly as designed and still make a decision its owner never intended.
Authority narrows at each handoff
The owner names the campaign, permitted work, and expiry.
NIST's August 2026 discussion of agent identity identifies familiar weaknesses returning in agent deployments: shared credentials, long-lived access, and permissions that are too broad. It argues for identifiable agents with entitlements tied to the user or system behind them. The practical implication for a marketing team is simple: a campaign change should tell you which agent acted and whose authority it used.
Consider an illustrative campaign workflow. A planner can read campaign performance and suggest a change. A separate executor can apply an approved change to a specific campaign. Those are different jobs, even if one vendor supplies both. If the planner can hand the executor unrestricted account access, the original distinction has vanished. The business must define what can pass between them before switching on the connection.
Write that agreement in terms the campaign owner can inspect. Identify the account, campaigns, permitted actions, excluded data, spending boundary, expiry, and person responsible for exceptions. A technical permission such as account write access is too coarse to explain whether the agent can create a new audience, edit a sensitive claim, or increase total spend. Ask those questions individually.
An agent's authority should become narrower when work is delegated. Passing a task downstream should preserve its campaign boundary and expiry, with only the permissions needed for the next step. If a tool cannot enforce that distinction, keep the consequential action behind a separate approval or execution step. The missing control is part of the vendor assessment.
Standards help systems understand each other
The advertising industry is building common ways for agents to communicate. IAB Tech Lab's AAMP initiative, updated in August 2026, groups work across foundations, protocols, and trust and transparency. Its published materials connect agent workflows to existing advertising standards, including OpenDirect and the Deals API. This is more concrete than a vendor attaching the word agentic to a chatbot.
That work can reduce ambiguity about the objects and transactions moving between systems. Shared definitions help a buyer and seller describe inventory or a deal in compatible terms. A registry can help participants identify an agent. These are useful pieces of infrastructure. They don't decide whether your brand should enter a particular deal, use a particular audience, or accept the proposed commercial terms.

Treat interoperability as one part of procurement. Ask the vendor which specification and version it actually implements, which functions are available in your account, and which steps still need custom integration. Request a demonstration using a representative brief. A roadmap presentation is evidence of intended direction, while a working supported connection is evidence you can evaluate against a real task.
Then separate the identity question from the business decision. Knowing which agent requested a change doesn't establish that the change is permitted. A registered buyer agent may be legitimate and still lack authority over this campaign. Your system needs a way to check the exact action against current policy before execution. A recognizable name in a log cannot perform that check.
The commercial contract should match the operational arrangement. Identify who maintains the connector, who responds when it fails, and how the team retrieves its records after switching suppliers. Have the relevant owners review data use and retention. The marketing lead needs enough clarity to understand what leaves the account, what remains accessible to partners, and which party is expected to contain an incident.
Bring these questions into a short acceptance exercise. Can the vendor show an allowed action, a refused action, an expired permission, and the record for each? Can your team understand the result without a vendor engineer narrating it? That demonstration reveals more about day-to-day control than a long checklist of supported acronyms.
Make approval worth reading
A human approval button is useful when it interrupts a decision that deserves human attention. Put the same button on every harmless step and people learn to dismiss it. Put it after the consequential step and it records an event the team could no longer prevent. The position and frequency of approval requests are part of the control.
NIST also warns that excessive human-in-the-loop requests can create consent fatigue. Teams should take that warning seriously when designing advertising workflows. Requiring an analyst to approve every retrieval or draft revision creates a busy interface without necessarily improving campaign judgment. Give people fewer, clearer decisions whose significance they can assess.
Three different decisions
Routine work
Already inside a narrow, approved campaign boundary.
Exceptions
A person reviews the exact proposed change and its consequences.
Prohibited work
The system refuses it. More prompting does not expand permission.
For a material budget change, show the current state beside the proposed state. Explain which campaigns are affected, which constraint triggered the recommendation, which data window was used, and when the authorization expires. Keep the business tradeoff visible. A person cannot assess a request that says only 'improve performance' while hiding the account changes underneath it.
An approval should attach to a specific proposal. If the agent changes the audience, destination, spend, or creative after review, the previous decision should not silently cover the new version. Preserve the approved version and compare the execution against it. This is especially valuable when a plan moves through several tools, each capable of rewriting part of the request.
Choose routine actions according to their actual consequences. Reading a report and drafting a change are usually easier to contain than uploading customer data or publishing a new claim. Even a small edit can matter if it changes consent, pricing, or eligibility. Monetary size alone is an incomplete measure of whether a person should review the action.
Keep a route for refusal. When the reviewer rejects a proposal, the agent should record the reason and stay within its existing authority. It should not keep rephrasing the same request until someone agrees. A well-designed exception queue makes the unresolved decision visible to its owner, with enough context to settle it later without pressuring the reviewer to clear the screen.
Rehearse the stop before the launch
A stop control deserves a rehearsal with the team that will use it. The exercise should answer what stops immediately, what is already in flight, and what requires a separate action in an advertising platform. Those are different states. A reassuring status message in the agent's interface cannot tell you whether a previously submitted campaign update has already taken effect.
Singapore's Model AI Governance Framework for Agentic AI, version 1.5 published in May and updated in June 2026, addresses agent-specific governance through assessing and bounding risks, human accountability, technical controls, and end-user responsibility. It is a governance framework, not proof that a particular product meets your requirements. Use it to structure questions and tests around the system you are actually deploying.
Stopping work has three different consequences
Identify new, queued, and completed actions before assuming a stop covers them all.
Run an illustrative containment exercise in a sandbox or draft environment. Start with a permitted campaign change, then withdraw the executor's authority while a second request is waiting. Confirm that new work is refused. Inspect the waiting request separately. Check whether it was canceled, remained queued, or needs intervention in the destination system. Record what your particular tools do.
Next, distinguish containment from repair. Disabling an agent prevents future activity within the scope of that control. It does not recover money already spent, remove every distributed creative, or erase data delivered to another service. The recovery plan needs an owner for each affected system and a description of what can realistically be restored.
Keep an incident record that someone outside the original project can follow. Preserve the request, permission, relevant inputs, approval, tool response, and observed result. Record times consistently. Avoid collecting unnecessary customer data just because logs are convenient. The evidence should support investigation while respecting the access and retention rules already attached to the campaign.
Finally, make the stop usable during an ordinary bad day. The designated operator may be away. A supplier may be slow to respond. An account administrator may need to help. Test the alternate route and keep its instructions close to the people responsible. A stop procedure that depends on finding the person who built the demo is unfinished.
Measure the business outside the loop
An agent that changes a campaign and explains its performance has two roles in the same decision. The team still needs a way to challenge the result. Platform metrics are useful operational inputs, but the outcome the business cares about may include returns, margin, customer quality, or demand that would have happened anyway. Decide which of those the pilot is meant to improve.
The earlier AI media-buying analysis separates execution efficiency from independent proof of business value. The same distinction belongs in the governance plan. Fewer hours spent moving settings can be a worthwhile operational gain. It should be recorded as such, without turning it into an unsupported claim that the agent increased profitable demand.

Before the pilot starts, write down the measurement window, the comparison, and the conditions that would make the result unusable. If the team changes promotions, inventory, and targeting at the same time, a before-and-after chart will have several possible explanations. An analyst should be able to flag that problem without the agent immediately treating the new chart as a reason to expand.
Keep a small operational record alongside commercial outcomes. Track which recommendations were accepted, which were refused, which could not be executed, and which required correction. Those categories tell you where the workload moved. A tool that saves setup time but creates a large investigation queue may still be valuable, but the time claim needs to include both sides of the work.
Watch the quality of the inputs as closely as the output. Missing purchase events, delayed conversion imports, or outdated product availability can change what a recommendation means. Set a response for those conditions. The appropriate action may be to hold the current state and ask for a data check, rather than continue optimizing from a degraded signal.
Give someone outside the implementation team the final assessment. That person should be able to inspect the results and challenge the interpretation without owning the vendor relationship. Independence here can be modest and practical. It means the person deciding whether the pilot worked has permission to say that the evidence is inconclusive.
Expand one permission at a time
Start with a task whose success and failure are both recognizable. Campaign reconciliation, a draft plan, or a bounded maintenance change can expose how the agent handles incomplete instructions without handing it an entire account. The best starting point depends on the tools available and the team's ability to supervise them. Choose a job with a clear owner and a manageable recovery path.
Record the boundary before testing. Specify the account, data sources, allowed changes, excluded actions, review requirements, and end date. Include what the agent should do when information is missing or contradictory. Otherwise, the demonstration may succeed because an operator quietly resolved every ambiguity, leaving the production behavior untested.
A release decision the team can explain
Define scope
One business objective, one owner, and a limited campaign scope.
Review behavior
Inspect refusals, exceptions, outcomes, and operator effort.
Approve scope
Expand only the permission supported by the evidence.
Inspect the failed and refused cases, too. A system that stops when an instruction conflicts with its permissions may be doing exactly what the business needs. A system that completes every task by finding a broader route deserves investigation. Completion rate alone gives both behaviors the wrong incentive if the task definition omits the boundaries.
At the end of the pilot, approve a concrete next step. Granting permission to update bids within one campaign doesn't automatically justify creating new campaigns or uploading a customer list. Each expansion introduces a different consequence and may require a different reviewer. Keep the record specific enough that a replacement team can understand what was agreed.
Use the same discipline when the supplier changes the product. A new model, connector, default setting, or execution capability can alter how an existing workflow behaves. Decide which changes require another rehearsal. That decision is easier when the original acceptance exercise was preserved, because the team can repeat it and compare behavior against a known expectation.
The useful question in the next vendor meeting is whether the team can reconstruct and stop a representative action using its own people and records. Ask for the demonstration. Give the agent a narrow job, introduce an exception, and watch which boundary holds. The answer will tell you where the next investment belongs.

