Skip to content
BOOSTD

AI search · 5 min read

Where an AI marketing agent should stop and ask you first

An AI marketing agent should watch and measure freely, ask before any visible change or spend, and stay off checkout, login, payment and legal pages by default.

Rather check it yourself? Try our free SEO tools

An AI answer

Example

Who fixes burst pipes near me tonight?

Your Business Plumbing offers 24-hour emergency call-outs and lists its service area and prices on its site.

  • yourbusiness.comCited
  • a local directory
  • a review site
Example AI answer with an invented business. It shows the idea, not a real result or a promised citation.

Published by Zubair Afzal, responsible editorUpdated We check this page every three months. Next check: .

The short answer

Ask what it may do, not what it can do

Every demo of marketing software that acts on its own shows capability: pages written, listings updated, bids adjusted, reports produced. Capability is the easy part, and not the part that will hurt you.

What matters is which of those things it may do without asking, what stops it, and how a wrong change gets undone. A supplier who answers in specifics has thought about the problem. One who answers with the word autonomous hasn’t.

What follows is a permission ladder you can hold any supplier to, including us.

The ladder

Five levels, and who signs off at each

Risk isn’t one dial. Reversibility, reach, visibility to a customer and whether money moves come apart constantly.

A permission ladder for automated marketing work, from read-only analysis to changes that need two people
DimensionWhat sits at this levelWho should sign it off
Read onlyCrawling, measuring, comparing, watching for change. No external system is altered.Nobody. This should run constantly, and most of the useful work lives here.
Reversible and invisibleTitle tags, meta descriptions, alt text, structured data, an internal link on an ordinary page.Nobody, provided the previous version is stored so it can be put back in one step.
Visible copy changesRewriting a section, adding a question and answer block, refreshing an existing page.You or an administrator, because a customer will read it and it speaks in your name.
Publishing and spendingNew pages, redirects, template or call-to-action changes, outbound messages, anything that commits ad spend.You, every time, with the draft in front of you and a budget ceiling already set.
Off limits by defaultDeletion, bulk redirects, checkout, login, payment, legal and authentication pages, DNS, navigation rebuilds.Two people who both understand the consequence, or nobody at all.

Protected surfaces

Pages that should be read-only unless you say otherwise

Not because the search impact is large, but because the failure mode is a business that can’t take money.

  • Checkout, cart, basket and order pages
  • Login, sign-in, registration, account and password pages
  • Payment, billing and invoice pages
  • Authentication flows, including single sign-on and two-factor pages
  • Terms, privacy, cookie, disclaimer and accessibility pages
  • Regulatory disclosures, and any page a compliance team signed
  • Pricing pages, where a wrong number costs a refund, not a ranking
  • Any URL you nominate yourself, for reasons you don’t have to justify

Before you switch anything on

Three controls to insist on

Each of these is a mechanism you can be shown, not a policy you have to believe.

  1. A snapshot before every change

    Nothing should be altered without storing what it said beforehand. This makes the other controls affordable, because a change you can undo in a minute needs less scrutiny than one you can’t. Ask to watch a change and an undo on a page that doesn’t matter.

    You get: A stored previous version for every automated edit

  2. A budget ceiling checked before the work, not after

    Model costs, tool costs and ad spend should be reserved against a limit before an action runs. Reporting an overspend afterwards isn’t a control. Ask what happens when the ceiling is reached, and listen for whether the work stops and somebody is told.

    You get: A spend limit that halts work instead of reporting on it

  3. A record you can read without asking

    Every automated change should leave a line you can find yourself: what changed, on which page, when, why, on what evidence, and how to reverse it. If reviewing the month means requesting a report from the supplier, you don’t have a record, you have a relationship.

    You get: A change log in plain language, available on demand

The limit

What should stay with a person whatever the controls say

Some decisions aren’t risky because they’re hard to reverse. They’re risky because they’re judgements about the business, and running them more often doesn’t make them better.

What the company competes on. Which customers are worth pursuing. What a page should promise. Whether a market is worth entering. Whether a claim is true. None of these improves by being made daily, and somebody has to be able to defend each later.

The right scope for automation is gathering, watching, checking and drafting: a large share of the hours in marketing work and a small share of the decisions. A supplier who describes it that way is describing the job. One who promises the decisions is describing a risk.

Questions

Common questions about letting software act

Does requiring approval defeat the purpose of automation?

No. The expensive part of marketing work is rarely the approving. It’s the watching, gathering, checking and drafting, and all of that can run continuously without touching anything.

A supplier who says approvals make the product pointless is describing a product whose value is output volume, the version most likely to damage a site that already works.

What should never be automated at all?

Anything on a checkout, login, account, payment, authentication or legal page. Anything that deletes, redirects in bulk, or changes DNS. Anything that publishes a claim about results, pricing or safety.

The test isn’t how risky the change looks. It’s what the worst case costs and whether you could undo it before it mattered.

How do I know a rollback works?

Ask to see one. Have the supplier make a small change on a page that doesn’t matter, then undo it while you watch, and show you the record of both events afterwards.

A rollback that exists only in a feature list is a promise. A rollback you have seen performed on your own site is a control.

What about spending money on ads?

Spend needs a ceiling checked before the work starts, not after. Ask whether budget is reserved before an action, so an unexpected loop can’t run past the limit before anyone notices.

Ask what happens when the ceiling is reached. The right answer is that the work stops and somebody is told, not that it continues and reports the overspend later.

Who is accountable when an automatic change is wrong?

A named person at the supplier, or you. Those are the only two options, and the contract should say which. Software isn’t an accountable party and can’t be one.

If a supplier answers this with a description of their technology instead of a name and a process, that’s the answer to your question.

Put the ladder to whoever is selling you this

Take the five levels and the three controls to any supplier, us included, and ask them to place their product on it. The answers are usually short, and the gaps are usually obvious within ten minutes.

References

Sources

The official documents and research this page is based on. Platform rules change, so check the source before you act on a detail.

  1. NIST AI Risk Management Framework
  2. Google Search Essentials: spam policies, including scaled content abuse
  3. Anthropic: building effective agents

Last updated