The Outloop Playbook · Free web guide · 12 chapters · Workflow catalog

The AI Marketing Agency Operating Playbook

From AI that suggests to AI workers that finish real client work.

Choose one real client workflow from the catalog, map its accounts, files, permissions and approval boundaries, then decide whether it is ready for client delivery.

Propose Approve Execute Audit

Contents 12 chapters
  1. Why trust this guide?
  2. Opening: before and after
  3. Five operating boundaries
  4. 01 Why agent demos do not survive client delivery
  5. 02 The operating model: propose, approve, execute, audit
  6. 03 Google Ads without the wrong-account mistake
  7. 04 Meta creative fatigue and the handoff to humans
  8. 05 Drive and Shared Drive are the real agency workspace
  9. 06 Reporting that becomes client-ready work
  10. 07 Project management is the approval surface
  11. 08 MCP is useful, but it is not the whole operating system
  12. 09 Browser automation is not an agency operating system
  13. 10 The access layer agencies are missing
  14. 11 Choose the first workflow to hand over
  15. 12 Final checklist
  16. From readiness to first proof
  17. Client Workflow Access Map
  18. Put the playbook to work

Founder note

Why trust this guide?

Adam Argaman, founder of Outloop

Adam Argaman

Founder, Outloop

I'm Adam Argaman.

For more than 15 years I've worked across marketing, creative, data, and systems — and for the last 7+ years I've been running a digital marketing agency: real clients, real ad accounts, real folders, real reports, real delivery pressure.

When AI agents became practical, I put them inside those workflows: Google Ads analysis, reporting, Drive and Shared Drive assets, creative briefs, project management, and client updates.

AI agents are not blocked by ideas.
They are blocked by the operating environment around them.

Every workflow in this guide comes from that work. So does Outloop — it started from repeated multi-client access pain: agents need access to client systems, but keys should not end up in chats, .env files, project folders, screenshots, or the wrong client workspace.

You can use the workflows here before using Outloop. But as soon as you run them across real clients, you will feel the same bottleneck: approved access, workspace scope, human approval, and audit.

"AI does not only help agencies write faster. It helps agencies deliver more client work with better margins, if the access layer is controlled."
The digital marketing agency team behind Outloop working across client campaigns, reporting, files, and creative
The agency team behind Outloop. The workflows in this guide come from this floor — real client campaigns, reporting, files, and delivery pressure.

Agents are easy in demos.

Real client work breaks on access.

When we first started using AI agents inside our agency, the demos were impressive. Agents could analyze campaigns, draft reports, organize tasks, and prepare creative recommendations.

But real delivery kept breaking on the same operational questions:

Which client is this?
Which account or folder is allowed?
Which credential should the agent use?
Who approves the action?
How do we prove what happened?
Why does a human need to rebuild the setup again?

The agents were getting smarter. The environment around them was still fragmented.

Real work means the agent needs to touch:

  • the right Google Ads account
  • the right Meta account
  • the right Drive folder
  • the right client assets
  • the right reporting data
  • the right Asana or ClickUp project
  • the right client workspace

Names and logos belong to their respective owners; Outloop is not affiliated with or endorsed by these platforms.

That is where most AI agency workflows break. Not because the model is not smart enough. Because the access layer is messy.

What changed

The shift happened when we stopped treating an agent like another chatbot and started treating it like a real worker.

The operating belief

When you hire a person, you give them a computer, files, tools, permissions, procedures, and working context. A serious AI agent needs the same kind of permanent operating environment.

For an agency, that environment must also separate every client workspace, bind the correct accounts and resources, define human approval boundaries, and preserve proof of what happened.

The model can change. The agency-controlled environment, knowledge, skills, workflows, and access remain.

This guide shows how to apply that operating model to one real client workflow — without turning every client into another manual setup loop.

The execution model is simple:

Propose. Approve. Execute. Audit.

The agent can help. The human stays in control. The right workspace gets the right access. The wrong client stays protected.

The map

Five boundaries every real agent workflow needs

Before the platform chapters, this is the shape of the whole thing. Every workflow in this guide is an answer to these five questions.

  1. Working environment — where the agent's files, skills, tools, and procedures live.
  2. Client workspace — which client, project, people, accounts, and folders apply.
  3. Approved access — which systems and resources the workflow may use.
  4. Action and approval boundary — what the agent may read, draft, write, publish, or never do.
  5. Proof and reuse — what happened, what was approved, and how the workflow becomes repeatable.

Write the answers down for one workflow before you automate it. If a line is blank, that blank is where the workflow will break across clients.

Template

One-workflow map

Workflow:
Business outcome:
Client workspace:
Agent/runtime:
Systems required:
Accounts/resources:
Files/folders:
Read actions:
Draft actions:
Write actions:
Human approver:
Blocked actions:
Completion proof:
Reusable skill or procedure:
Start now

You do not need to finish all 12 chapters before putting this into practice. Choose one workflow, download the matching skill, and run it in read-only or draft-only mode. A human reviews anything that could change a client system.

Chapter 01

Why agent demos do not survive client delivery

Most agent demos are clean because they avoid the messy parts.

They use fake data. They use one account. They use one folder. They use one user. They do not cross client boundaries. They do not need approvals. They do not need audit. They do not need to explain what happened later.

Client work is not like that.

A real agency has many clients, many tools, many folders, many tasks, and many people involved. The agent is not just writing text. It needs to work inside the delivery system.

That means:

  • reading performance data
  • finding waste
  • preparing recommendations
  • organizing assets
  • creating tasks
  • drafting reports
  • preparing client updates
  • sometimes executing approved actions

The workflow breaks when the agent asks:

Where is the key?
Which client is this?
Which account should I use?
Can I access this Drive folder?
Is this the final asset or a draft?
Can I write to this account?
Who approved this?
Where do I log what I did?

This is why the real problem is not AI intelligence. The real problem is operational access.

Key idea

If you cannot explain which client, which workspace, which tool, which permission, and which approval gate the agent is using, the workflow is not ready for real client delivery.

Do this now

Map one workflow you want an agent to run. Then ask: where does it need access?

Chapter 02

The operating model: propose, approve, execute, audit

The safest pattern for agency agents is not “let the agent do everything.”

The safest pattern is:

  1. Propose
  2. Approve
  3. Execute
  4. Audit

Propose

The agent reads approved data and creates a structured recommendation.

Example: the agent reviews Google Ads search terms and marks each one as keep, negative candidate, needs review, or do not touch.

At this stage, the agent should not change anything.

Approve

A human reviews the recommendation. The approval should be explicit.

Good approval: approved checkbox · approved task status · named approver · approved change list.

Weak approval: “looks good” · “ok” · “maybe” · silence · a Slack reaction.

Execute

Only approved changes move to execution. Execution should be scoped: one client, one account, one action set, one workspace, one approved task.

Audit

After execution, a separate read-only check confirms what changed. The audit should answer:

  • what was requested
  • what was approved
  • what was executed
  • which account was touched
  • whether the agent saw a raw secret
  • whether the request was allowed or denied

This pattern lets agencies use agents without pretending humans disappear. Humans approve. Agents help operate. The system keeps boundaries.

Template

Workflow readiness checklist

What data does the agent need to read?
What action might the agent propose?
Who approves it?
How is approval recorded?
What can the agent execute?
What must stay blocked?
What audit proof is produced?
Do this now

Use this checklist on one real client workflow before automating it.

Chapter 03

Google Ads without the wrong-account mistake

Google Ads is one of the best agency workflows for agents. It is also one of the most dangerous if access is messy.

A good Google Ads agent workflow does not start with mutations. It starts with read-only analysis.

Recommended first workflows:

  • search terms audit
  • budget loss analysis
  • rank loss analysis
  • campaign performance summary
  • negative keyword candidates
  • landing page mismatch notes
  • query cluster opportunities

The agent should produce recommendations shaped like: campaign, ad group, search term, spend, clicks, conversions, reason, recommended action, confidence, human decision.

The output should not be: “Here are 100 changes I already made.”

The output should be: “Here are 100 candidates. Approve the ones you want.”

Common access failure

An agency has one manager account and many client accounts. The agent must not just “use Google Ads” — it must know which customer account is allowed for this workspace.

Wrong model: one shared credential can touch everything and the agent decides.

Better model: one approved agency credential can be reused, but runtime activity is pinned to the right client account.

What the agent can do safely first: read campaign data, classify search terms, draft negative keyword candidates, flag budget/rank loss, prepare an approval task.

What should require explicit approval: adding negatives, changing budgets, pausing keywords, changing campaign settings, creating new campaigns, editing ads.

Template

Google Ads recommendation output

Summary
Evidence
Suggested action
Risk level
Account affected
Human approval required
Rollback note
Post-check required
Where Outloop fits

The hard part is not writing the recommendation. The hard part is letting the agent use the right client account without seeing the raw key or touching the wrong account.

Google Ads API access is owned by your agency: your own manager account, your own developer token, your own Google Cloud project. The Google Ads setup guide walks the whole path, including the access levels that decide what you can reach today.

Send us one Google Ads workflow. We’ll show you where access needs to be scoped.

Request a Workflow Review

Chapter 04

Meta creative fatigue and the handoff to humans

Creative fatigue is a good AI workflow because it connects data, assets, and people.

The agent can help detect: rising frequency, falling CTR, rising CPA, falling ROAS, winner decay, audience saturation, creative format fatigue.

But the agent should not decide creative strategy alone.

A better workflow:

  1. Read campaign and creative performance.
  2. Match fatigue signals to the actual creative assets.
  3. Create a creative brief.
  4. Create a designer task.
  5. Human reviews.
  6. Human approves production.
  7. Human approves the client-facing version.

The agent's job is to reduce friction. It should produce: what is fatiguing, why it matters, what new angle to test, what asset is needed, what the designer should create, what claim must be checked, what client approval is needed.

Common failure

The agent sees an ad ID but not the actual asset. Or it sees the asset but cannot find the final file. Or it creates a brief that does not match the client's real offer. Creative workflows need clean file structure and approved access to the right folders.

Template

Creative fatigue brief

Campaign
Creative asset
Fatigue signal
Performance evidence
Suggested new angle
Required format
Required asset source
Designer task
Approval owner
Client approval needed: yes/no
Where Outloop fits

This workflow crosses ad data, Drive assets, and project management. Without scoped access, teams either keep the agent read-only forever or give it too much access.

Meta access is owned by your agency too: your own Meta Developer account, your own app, your own Business Verification and App Review. The Meta Ads setup guide separates what always applies from what depends on your permissions and access level — and Business Verification is the long pole, so start it before you need it.

Do this now

Use the fatigue brief template on one client this week.

Chapter 05

Drive and Shared Drive are the real agency workspace

Most agency work does not live only in ad platforms. It lives in folders.

Strategy docs. Reports. Videos. Thumbnails. Creative briefs. Captions. Client approvals. Exports. Drafts. Final assets.

If your Drive is messy, your agents will be messy.

Recommended client folder structure

Template

Client workspace folders

Client Workspace
• 00 Admin
• 01 Strategy
• 02 Ads
• 03 Creative
• 04 Reports
• 05 Client Approvals
• 06 Final Assets
• 07 Archive

Creative folder
• Briefs • Raw Assets • Drafts • Final • Published • Rejected

Naming rule:

YYYY-MM-DD_client_campaign_assettype_status_version

Example: 2026-07-03_clientA_meta_summer-video_final_v03.mp4

Agent rules

Agents may: list approved folders, read approved files, draft reports, organize proposed file moves, upload approved generated assets to staging, create task-linked file references.

Agents should not: delete client files without explicit approval, move final assets without approval, create public links without approval, change ownership, access unrelated client folders, publish files without a gate.

Common Drive failure

The agent creates a great report but a human still needs to move it, rename it, upload it, or put it in the right client folder. That is not full automation. That is text generation plus human file labor.

Adding approved Google Drive API access to a client workspace in Outloop
Approved Drive access is added once in Outloop, then granted to the right client workspace — the agent uses it without ever seeing the credential.
Where Outloop fits

Real agency agents need safe access to client files, not just prompts. The right model is approved file access for the right workspace, with audit and redaction.

Do this now

Audit one client folder. If an agent cannot tell what is draft, final, approved, or published, fix the structure before automating.

Chapter 06

Reporting that becomes client-ready work

A weekly report is not just a summary. It is a decision tool.

A good agent-assisted report should include: what changed, why it changed, what we did, what we recommend next, what needs approval, what needs client input, what data cannot be trusted yet.

The agent can draft the report. But it must know which data matters. Do not rely only on platform numbers.

Better reporting stack

  • Google Ads for spend and campaign signals
  • GA4 for site behavior
  • Search Console for organic visibility
  • CRM for lead quality
  • revenue or sales source for business truth
  • project management for what the team actually did

The agent should flag: tracking gaps, missing revenue data, unusual conversion swings, high spend with low CRM quality, strong platform performance but weak business outcome, tasks that were planned but not executed.

Template

Weekly client report

1. Executive summary
2. Performance movement
3. What changed this week
4. What we did
5. What needs approval
6. Risks or tracking issues
7. Next actions
8. Internal QA note
Important

The internal QA note should not automatically go to the client. It is for the agency team.

Do this now

Do not let an agent send reports directly until you have a client-safe approval layer.

Chapter 07

Project management is the approval surface

Asana or ClickUp should not be a dumping ground. It should be the approval surface.

Good agent-created tasks include: client, workspace, workflow, source data, recommendation, risk level, approval owner, deadline, affected account or folder, proposed action, audit link or proof note.

Bad agent-created tasks: vague title, no source, no priority, no owner, no client context, no approval state, no link to evidence, no clear action.

Recommended task types

  • Review recommendation
  • Approve execution
  • Creative brief
  • Reporting issue
  • Tracking issue
  • Client approval
  • Post-execution audit
  • Data quality issue

Task status should separate:

proposed · needs review · approved · executed · verified · blocked · rejected

This gives the agent a clean path. The agent does not need to guess what “done” means.

Where Outloop fits

When project management becomes the approval surface, access should follow approval. The agent should not receive write capability just because it can create a task.

Do this now

Pick one workflow and define exactly which task status unlocks execution.

Chapter 08

MCP is useful, but it is not the whole operating system

MCP is useful. It gives agents a standard way to call tools.

But MCP alone does not solve the agency operating problem.

A real agency needs to know: which client, which workspace, which account, which folder, which access, which approval, which audit trail, which human is responsible.

The distinction

MCP connects tools. Outloop controls which client access the workflow may use.

Both can be true at once. Outloop does not replace your MCP connectors — it decides which client the workflow is allowed to reach.

Common MCP problems in agency work

  • one connection tied to the wrong account
  • auth expires
  • connector is missing
  • connector is read-only when the workflow needs write
  • connector can write but not safely per client
  • agent does not know which account is allowed
  • no clean audit for client proof

MCP is part of the stack. It is not the access governance layer.

Do this now

Do not ask “Do we have an MCP connector?” Ask “Can this agent safely use the right client access from the right workspace?”

Chapter 09

Browser automation is not an agency operating system

Browser automation can be useful. It can help when: no API exists, a UI-only workflow is needed, the task is low risk, a human can supervise, the browser session is stable.

But browser automation is fragile for real client operations.

It can break because of: login sessions, 2FA, popups, UI changes, slow pages, permissions, ad platform restrictions, account switching mistakes, hidden state, browser profile problems.

For ad platforms, reporting, files, and client systems, APIs are usually safer. They are:

  • more stable
  • more auditable
  • easier to scope
  • easier to test
  • easier to repeat
The rule

Browser automation can be a fallback. Approved API access is the preferred operating path when available.

Neither is banned. Mark each workflow honestly, and keep the fragile path supervised.

Do this now

For each workflow, mark it as API-first, browser fallback, or human-only.

Chapter 10

The access layer agencies are missing

By now, the pattern should be clear. Agents can help with real client work. But every serious workflow eventually hits the same wall:

Access.

The agency needs a way to answer:

Which client is this?
Which workspace is allowed?
Which account can this workflow touch?
Which folder can the agent read?
Can the agent write?
Did a human approve it?
Did the agent see a secret?
What exactly happened?

Without this layer, teams fall back to bad workarounds: pasted API keys, .env files, shared credentials, broad owner accounts, browser sessions, manual copy/paste, one-off scripts, disconnected MCP setups.

That works for demos. It does not scale across real clients.

Outloop is built for this layer

Outloop lets agencies:

  • connect approved API access once
  • assign it to the right client workspace
  • let agents use it without seeing the raw secret
  • block wrong-client access
  • keep local-first runtime control
  • produce audit proof like secret_exposed:false
Outloop: add approved API access once
1 Add the credential once
Outloop: approve the client workspace
2 Grant it to the right workspace
Outloop: agents use approved access without seeing the credential
3 Agents use it without seeing it
Redacted Outloop audit proof of an agent request with secret_exposed:false
The audit proof: the agent used approved access, the response is redacted, and secret_exposed:false is on the record.

The point is not “hide a key.” The point is:

Run more client AI workflows without rebuilding access every time.

Send us one workflow. We’ll map where access breaks and what should be API, MCP, browser fallback, human approval, or blocked.

Request a Workflow Review

Chapter 11

Choose the first workflow to hand over

Do not automate the whole agency first. Hand over one workflow, prove it, then widen. This chapter is how you pick that one.

Every workflow below is a real agency job, and every one of them is already free to browse and download — no email, no account. The hard part was never getting the list. It is knowing which one to start with and what it needs before an AI worker touches a client account.

Step 1 — Pick the area you already run

Start where your agency already does the work by hand every week. Unfamiliar territory is a bad place to learn what an AI worker gets wrong.

  • Paid Media — 5 workflows
  • Commerce — 2 workflows
  • CRM & Sales — 17 workflows
  • Files & Content — 11 workflows
  • Social & Publishing — 4 workflows
  • Research & Data — 7 workflows
  • Agency Operations — 18 workflows

Step 2 — Pick a sensible first workflow

Inside that area, the first one should be all four of these:

  • Repeated — it happens weekly or per client, not once a quarter.
  • Currently manual — a person is doing it by hand right now.
  • Easy to verify — you can tell within minutes whether the output is right.
  • Low consequence if the first run is wrong — nothing a client sees, nothing you cannot undo.

That fourth test is the one people skip. The safest first runs are the workflows that cannot change a client system at all — they read, classify and draft, and a human decides what happens next. 37 of the 64 are exactly that:

If you want a first pass that touches nothing at all, the five read-only starter skills further down are deliberately smaller versions of the same idea.

Step 3 — Choose one

Write it down as a sentence, not a category: “Every Monday, someone on my team pulls last week's search terms for each client and flags the waste.” If you cannot write that sentence, you have picked an area, not a workflow — go back to step 2.

The full catalog, if you want to scan it in one place:

Every workflow, free to browse at /skills
WorkflowMain systemsWhat it can change
Paid Media
Google Ads Campaign BuilderGoogle AdsChanges with approval
Google Ads Optimization and GovernanceGoogle AdsChanges with approval
Marketing Experiment DesignGoogle Ads, Meta, Google AnalyticsDraft only
Meta Ads Optimization and GovernanceMetaChanges with approval
Performance Growth OperatorGoogle Ads, Meta, Google AnalyticsChanges with approval
Commerce
Affiliate and Partner OperationsCustom APIDraft only
Google Merchant Center OperationsGoogle Merchant CenterDraft only
CRM & Sales
Buyer Signal ResearchFirecrawl, Apify, AirtableDraft only
CRM ArchitectureAirtable, HubSpot, Zoho CRMChanges with approval
CRM Data HygieneAirtable, HubSpot, Zoho CRMDraft only
CRM Revenue RecoveryAirtable, HubSpot, Zoho CRMChanges with approval
Email Deliverability AuditGmail, InstantlyDraft only
Email Follow-UpGmailDraft only
Email Infrastructure OperationsGmail, Instantly, MailerLiteChanges with approval
Email Marketing OperationsMailerLite, Klaviyo, Custom APIChanges with approval
GTM Pipeline OperationsAirtable, Custom APIChanges with approval
Lead and Call QualityAirtable, HubSpot, Zoho CRMDraft only
MailerLite Email MarketingMailerLiteChanges with approval
Outbound ProspectingApify, InstantlyChanges with approval
Outreach Pipeline PlanningAirtable, InstantlyDraft only
Professional Network OutreachCustom APIDraft only
Sales Discovery and ConversionAirtable, Custom APIChanges with approval
Telephony Workflow DesignCustom APIDraft only
WhatsApp Lead Follow-UpWhatsApp Business Platform, AirtableChanges with approval
Files & Content
Avatar Video ProductionCustom APIDraft only
Business Document ProductionDraft only
Content Production PipelineGoogle Drive, OpenAIChanges with approval
SEO Content and Editorial PlanningGoogle Search Console, Custom APIChanges with approval
Creative Production and BriefingGoogle Drive, OpenAIDraft only
Frontend Interface ReviewDraft only
Google Drive and Shared Drive File OperationsGoogle DriveChanges with approval
Screen Demo ProductionDraft only
Short-Form Video EditingDraft only
Website and Form ImplementationCustom APIDraft only
Website Content ManagementCustom APIChanges with approval
Social & Publishing
Facebook and Instagram Community OperationsFacebook, InstagramChanges with approval
Instagram Message OperationsInstagram, FacebookChanges with approval
Multi-Channel Social PublishingFacebook, Instagram, YouTubeChanges with approval
YouTube Publishing and Channel OperationsYouTubeChanges with approval
Research & Data
Analytics Measurement PlanGoogle Analytics, Google Search ConsoleDraft only
Landing Page Conversion AuditDraft only
Reddit Research OperationsApify, Firecrawl, AirtableDraft only
SEO, Analytics and Search IntelligenceGoogle Search Console, Google AnalyticsDraft only
SEO and GEO Website StrategyGoogle Search Console, Google Analytics, FirecrawlDraft only
Social Intent ResearchApify, FirecrawlDraft only
Web Research and Structured ExtractionFirecrawlRead only
Agency Operations
Agency Onboarding and RunbooksAirtable, Custom APIDraft only
API Integration DevelopmentCustom APIDraft only
Automation Architecturen8n, AirtableDraft only
Cross-Channel Performance ReportingGoogle Ads, Meta, Google AnalyticsDraft only
Custom API OperationsCustom APIChanges with approval
Data Sync and Workflow Orchestrationn8n, AirtableChanges with approval
GTM Performance ScorecardAirtable, Google Analytics, Custom APIDraft only
ICP and Positioning Strategy BuilderFirecrawlDraft only
MCP Integration DevelopmentDraft only
Outloop Custom API SetupCustom APIChanges with approval
Project Board and Approval OperationsAsana, ClickUpChanges with approval
Project Knowledge MaintenanceChanges with approval
Proposal from DiscoveryDraft only
Recruitment Evidence OrganizationDraft only
Reusable Skill AuthoringDraft only
SaaS Catalog and Billing OperationsCustom APIRead only
Software Release VerificationDraft only
Workspace Context PreparationChanges with approval

Step 4 — Map what it actually needs

Now take that one workflow into the Client Workflow Access Map below. It walks the accounts, resources, permissions, approvals and proof the workflow depends on, and finishes with the platform readiness gap that is actually blocking it. Everything you type stays in your browser tab.

Rule

A skill file is instructions, not a permission system. Choosing the workflow and writing the skill is the easy half; approved access, workspace scope, write boundaries and audit are enforced separately — and that is what decides whether the workflow survives a real client.

Do this now

Choose one workflow. Map it. Then decide whether it is ready for a real client.

Chapter 12

Final checklist

Before an agent works on a real client workflow, answer these:

  • Is the client workspace defined?
  • Is the tool account defined?
  • Is the Drive or Shared Drive folder defined?
  • Is the action read-only, draft-only, write, or destructive?
  • Is there a human approval point?
  • Is approval explicit?
  • Is there audit proof?
  • Can wrong-client access be blocked?
  • Can the agent complete the workflow without seeing raw secrets?
  • Can the human understand what happened afterward?

Those ten questions collapse into three outcomes:

Can the agent complete useful work?
Can it use only the correct client resources?
Can a human understand and verify what happened?

If any answer is unclear, the workflow is not ready to scale yet.

Before the worksheet

From platform readiness to first proof

Chapters 3 and 4 assumed the access already worked. For Google Ads and Meta it usually does not yet — and the reason teams stall is that they treat one long checklist as a single job. It is four, and only the last two are ours.

01

Platform developer readiness

Who owns it: Your agency. One-time per platform, reused across every client.

Outloop: None. Outloop cannot apply, accelerate, or guarantee an outcome.

02

Client account and resource access

Who owns it: Your agency, granted by the client.

Outloop: None. The platform decides what your credential can reach.

03

Connection to Outloop

Who owns it: Your agency, locally.

Outloop: Credentials entered once, stored in the macOS Keychain, pinned to one workspace and one client resource.

04

First runtime proof

Who owns it: Your agency.

Outloop: Outloop performs and audits it: correct identity and resource, a safe real read, secret_exposed:false, and a wrong-client request denied before any backend call.

Your agency owns the developer identity on every platform. Your own Google Cloud project and your own developer token from your own manager account; your own Meta Developer account and your own Meta app. Outloop does not supply a shared developer account, a shared app, or a shared token, and cannot shorten a platform review. What Outloop does is start at stage three: your approved credentials entered once, pinned to the right client resource, used without the agent ever seeing them, and proved.

The two long poles are worth knowing before you plan a date: on Google Ads it is the developer token application and the access level it grants; on Meta it is Business Verification. Both are elapsed time, not effort — so start them early and do the rest of the setup while you wait. Full steps live on the Google Ads guide and the Meta Ads guide, with the wider model in professional API access readiness.

The proof to aim for

A safe read on the right client resource, returning a real result with secret_exposed:false, plus a request naming another client's resource denied before any backend call. That is the first proof — not the ceiling. Approved write actions follow, with resource pinning, audit and human approval gates.

The worksheet

Client Workflow Access Map

One real client workflow. Not three. Fill this in for the workflow that breaks most often, and you will finish with every account, resource, approval and proof it needs written down — plus the platform readiness gap that is actually blocking it.

Everything you type stays in this browser tab. Nothing is saved, uploaded, or sent to Outloop, and nothing you type reaches analytics. Print it or copy it out — closing the tab clears it. Never write a token, API key, client secret or developer token in this worksheet, or anywhere else outside the Outloop credential flow.

The workflow

Google Ads

Fill this block only if your workflow touches Google Ads.

Who must own it: Your agency. Google usually grants one developer token per company, and states that if you use a third-party app or service, the developer of that app needs its own token — so the token, the Google Cloud project and the OAuth client are all yours.

Authentication model: OAuth 2.0 (client ID, client secret, refresh token) plus a developer token

Developer app / token requirement: A developer token from the API Center of your own Google Ads manager account (MCC), plus your own Google Cloud project and OAuth client.

Always required

  • Google Ads manager account (MCC). The developer token is issued here — not from Google Cloud. You must be signed into a manager account.
  • Google Cloud project. A dedicated project with the Google Ads API enabled, kept separate from website or product infrastructure.
  • OAuth consent screen and OAuth client. Configured with a neutral, accurate app name and a business contact email.
  • Developer token. Requested in Tools & Settings → Setup → API Center. The application asks for company name, company URL and an API contact email.
  • Refresh token. The long-lived OAuth token Outloop stores locally so it can mint short-lived access tokens host-side.
  • Client customer ID. The specific account this workspace may touch, distinct from the MCC login customer ID.

Depends on permissions, access level, business type and intended actions

  • Access level. Test Account Access reaches test accounts only. Explorer Access reaches production at a lower daily limit. Basic and Standard Access are applications with Google-published review windows. You do not need the top level to run a first proof.
  • API token application. Required for higher access levels. Answer for what the tool actually does — internal users, the campaign types and capabilities you genuinely use.
  • Write capability. Budget, bid, status and structural changes stop for a named approver. Account-level deletions are blocked outright.

Permissions / scopes — request only what the workflow needs

  • https://www.googleapis.com/auth/adwords — The single Google Ads API scope. Read and write are governed by account permissions and Outloop approval gates, not by separate scopes.

Safe first proof: One account-scoped read on the approved client customer ID under the correct MCC login context, returning HTTP 200 with secret_exposed:false — plus a request naming a different customer ID, denied before any backend read. A safe read is the first proof, not the limit — approved write actions follow with resource pinning, audit and human-approval gates.

Wrong-client denial: RESOURCE_ID_NOT_ALLOWED

Timing: Google publishes its own review windows for Basic and Standard Access. Treat them as Google's figures, check the current documentation, and remember Google decides both the level and the timeline.

Setup guide: Connect Google Ads API to Outloop · Google Ads API access levels · Google Ads API developer token

Stays in this tab. Never sent anywhere.

Current readiness state

Meta Ads

Fill this block only if your workflow touches Meta Ads.

Who must own it: Your agency. You create and control your own Meta Developer account and your own dedicated Meta app, and you own the business relationship, the permissions, the review status and the credential lifecycle. Outloop provides no shared developer account, no shared app and no shared token.

Authentication model: Access token generated from your own Meta app, typically via a System User

Developer app / token requirement: Your own Meta Developer account and your own dedicated Meta app, connected to your Business Portfolio, with the permissions your workflows need approved at the access level they need.

Always required

  • Meta Developer account. Registered to your agency.
  • Your own Meta app. Created in the App Dashboard, with the app type and use case that match what you actually do.
  • Business Portfolio. Your app connected to your own Business Portfolio.
  • Client asset access. Approved access to the ad account, and to the Page or Instagram business account where the workflow touches them.
  • An active ad account. Required to run campaigns and manage billing.

Depends on permissions, access level, business type and intended actions

  • Standard vs Advanced Access. Business apps receive Standard Access automatically, which only lets you request permissions from people who hold a role on your app. Production scale needs Advanced Access.
  • Business Verification. Required when your app requests advanced-level access and will be used to reach data belonging to businesses outside your own — the normal agency situation. It is the long pole; start it first.
  • App Review. Required per individual permission and feature at advanced level. Meta expects at least one successful call using each requested permission within the 30 days before you submit.
  • Live mode. Required before advanced-level permissions work for people without a role on your app.
  • System User. The right choice for unattended agency automation and the flow the setup guide documents — but not universally mandatory. Which token type you need depends on the connection flow and the assets involved.
  • Data Use Checkup. An annual re-certification once you hold permissions.

Permissions / scopes — request only what the workflow needs

  • ads_read — Read ad reports and ad account data. Enough for a first proof.
  • ads_management — Read and manage ads. Request only where the workflow genuinely writes.
  • business_management — Manage business assets. Request only where genuinely required.
  • pages_* / catalog_management — Only for workflows that touch Pages, connected Instagram business resources, catalogs, products or product sets.

Safe first proof: A read on the pinned ad account that confirms the correct identity and resource, returns a real API result with secret_exposed:false, and shows a request naming another client's resource denied before any backend call. A safe read is the first proof, not the limit — approved write actions follow with resource pinning, audit and human-approval gates.

Wrong-client denial: CUSTOMER_RESOURCE_PIN_REQUIRED

Timing: Meta does not publish a guaranteed review time for Business Verification or App Review, so plan around the dependency rather than a date. Outloop cannot influence either.

Setup guide: Connect Meta Ads API to Outloop · Meta app access levels · Marketing API authorization · Meta App Review

Stays in this tab. Never sent anywhere.

Current readiness state

Any other system

Drive, a CRM, a project board, a custom API — same four questions, same readiness ladder.

Current readiness state

Finished? Copy the map and send it with an AI Workflow Review request — we will read a workflow you have already documented, and tell you where access will break.

Request a Workflow Review

The Skill Pack

Put the playbook to work

Download all five public-safe skills and start with one real client workflow today. Each skill finds, classifies, or drafts. A human approves anything that could change a client account, file, report, or project board.

How to use them: download the pack, unzip it into your agent's skills folder (for Claude Code: .claude/skills/ — each skill ships as <skill-name>/SKILL.md), or open any single skill file and paste it into your agent as instructions.

Download the starter skills

Google Ads Waste & Search Terms Auditor

SKILL.md

Classifies every search term as KEEP, NEGATIVE CANDIDATE, NEEDS HUMAN REVIEW, or DO NOT TOUCH — with the evidence attached. Read-only, report only.

Creative Fatigue Signal Scanner

SKILL.md

Flags decaying paid-social creative only when two or more signals agree, ranked by severity against each ad’s own baseline. Detection only.

Drive & Asset Hygiene Auditor

SKILL.md

Maps a client’s folder tree, names the specific mess (drafts mixed with finals, naming drift, orphans), and proposes a clean structure. Never touches a file.

Weekly Client Report Drafter

SKILL.md

Turns raw platform data into a plain-language draft led by the client’s real success metric, with anomalies flagged. A human reviews and sends every report.

PM Task Hygiene Scanner

SKILL.md

Classifies every open Asana/ClickUp task with confidence levels and evidence, plus a high-confidence “propose to close” batch. Permanently read-only.

Each skill carries its own safety rules and a human approval checkpoint — run them read-only, exactly as written.

Names and logos belong to their respective owners; Outloop is not affiliated with or endorsed by these platforms.

Send me one real client agent workflow.

I'll help you map the systems, resources, approval points, and access boundaries that are likely to break when you run it across real client workspaces.

No API keys or private client data are required.