For agencies
Every client account behind one control plane
Run agents across client accounts with per-client isolation, caps on every budget write, and a ledger you can hand to the client — filterable, exportable, tamper-evident.
Need → mechanism
What you need, and the thing that enforces it
Client accounts must stay isolated
Workspaces + scoped tokens
Group client accounts into workspaces and mint tokens scoped per platform, per tool class, even per client account. The agent working Client A's Google Ads cannot see Client B exists.
Clients ask exactly what the agent changed
The ledger you show clients
Every tool call lands in a hash-chained, append-only audit log with filters and export. “What changed in your account this month” becomes a download, not an archaeology project.
One bad budget move can lose the client
Caps + the approval inbox
Numeric ceilings per policy row cap every budget and bid write server-side. Flag the classes that matter — big moves wait in your approval inbox; routine changes execute instantly.
Onboarding a new client has to be fast
OAuth connect, read-only start
Connect a client's accounts by OAuth in minutes. Everything starts read-only, so the agent can audit and report from day one while you decide which writes to grant.
Isolation
One agency. Isolated client workspaces.
Each workspace holds one client's connections and policies; each token sees exactly one slice.
Client A
Google Ads · GA4 · GTM
token: ads_* + preview-only
Client B
Meta Ads · TikTok Ads
token: reads + capped budgets
Client C
Search Console · GA4
token: read-only
FAQ
The questions this page raises
Can each client see their own audit trail?
How many client accounts can we connect?
Put your client accounts behind the control plane
5 client workspaces on Consultant, 20 on Agency — each with unlimited platform accounts. Every account starts read-only.