Who, Right Now, Has Permission to Change Your Meta Ad Budgets?
Not rhetorically — actually think about it. When did you last check? If you've connected an AI agent to your Meta Business account at any point since April 2026, there's a real chance the answer is: an AI, without you explicitly approving that specific action.
Meta quietly rolled out the MCP Permissions Panel on August 11, 2026. You'll find it at Business Settings > Integrations > Ads MCP Server. It's the first proper interface that lets advertisers control what an AI agent can and can't do inside their ad accounts — which Pages it can see, which Instagram accounts, which business portfolios, and which specific actions it's allowed to take.
That's good news. The uncomfortable part is what was happening before you knew this panel existed.
Jon Loomer, one of the most thorough independent Meta Ads researchers working today, ran an audit of his own accounts after the panel launched. His finding: all 7 write actions were enabled by default. Budget changes, campaign creation, ad set creation, ad creation — the works. Turned on. No opt-in required.
If you run a D2C brand on Meta and you're using any AI connector, this is the article you need to read before you open Ads Manager today.
What the MCP Permissions Panel Actually Controls
MCP stands for Model Context Protocol — it's the standard that lets AI tools like Claude connect to external platforms and take actions on your behalf. Meta's Ads MCP Server is their implementation of this, and it's what makes "ask Claude to analyse my campaigns" actually work at a data level.
The Permissions Panel sits on top of that connection. Think of it as a bouncer that decides what your AI agent can see and what it can touch.
Three layers of control
The panel operates across three layers:
- Account-level access: Which Pages, Instagram accounts, and business portfolios the AI agent can even see
- Ad account visibility: Which specific ad accounts are exposed to the agent (notably, Loomer flagged there's currently no way to limit this at the point of initial setup)
- Tool-level permissions: Approximately 100 individual actions the agent can or cannot perform — from reading campaign data to creating and modifying live ads
That third layer is where it gets granular. And where, right now, most advertisers are completely exposed.
Read vs. write — why it matters
There's a fundamental difference between an AI reading your data and an AI changing it.
| Permission type | Example actions | Risk if left unchecked |
|---|---|---|
| Read | View campaigns, pull spend data, analyse creatives | Low — agent can see but not touch |
| Write (low sensitivity) | Add comments, export reports | Low-medium |
| Write (high sensitivity) | Change budgets, create campaigns, edit bids | High — live money at stake |
The 7 write actions flagged as on-by-default sit in that high-sensitivity column. That's the problem.
Why This Surfaced Now (And Why No One Warned You)
Meta hasn't published an official documentation page for the MCP Permissions Panel yet. As of September 2026, what we know comes primarily from Jon Loomer's hands-on audit, not from Meta's Help Centre or any advertiser notification.
That's a significant gap. Meta's MCP connector for Claude was quietly available to advertisers earlier in 2026. Many businesses — including agencies managing multiple client accounts — may have authorised the connection without understanding the default permission state they were agreeing to.
The "connected since April" window
If you or your agency connected an AI agent to Meta between April 2026 and August 11, 2026 (when the panel launched), you had zero visibility into what that agent was permitted to do. You couldn't review it, restrict it, or audit it through any official Meta interface.
Now you can. But only if you know to look.
This isn't a hypothetical concern. AI agents connected via MCP can execute actions autonomously if they're triggered to do so — whether through a scheduled workflow, a chat prompt, or an automated process. An agent with write access to your ad budgets can change them if instructed to. The question is whether you authorised that capability knowingly.
The Step-by-Step Audit Checklist
Here's exactly what to do. This takes about 15 minutes if your Business Manager access is clean.
Step 1 — Find the panel
- Log into Meta Business Suite
- Go to Business Settings (gear icon, bottom left)
- In the left sidebar, look for Integrations
- Click Ads MCP Server
If you don't see Integrations in your sidebar, check your admin permissions. You'll need Business Admin access to view this section.
Step 2 — Check which accounts are connected
The panel will show you which AI connectors are currently linked to your business. Note down every connector that appears. If you see something you don't recognise, flag it immediately before you do anything else.
Step 3 — Review the tool-level permissions
Click into each connector. You'll see a list of approximately 100 tool-level permissions. This is the core of the audit.
Look specifically for anything in these categories:
- Budget modifications
- Campaign creation or editing
- Ad set creation or editing
- Ad creation or editing
- Bid strategy changes
- Audience modifications
- Payment or billing actions
Step 4 — Disable write permissions you haven't deliberately enabled
For most advertisers, the right posture is: read access yes, write access only where explicitly intended.
If you're using an AI agent for reporting, analysis, or creative review — it doesn't need write access. Disable it.
If you're using an AI agent to actually make changes (like auto-optimising budgets via a workflow you've designed and tested), leave only the specific write permissions that workflow requires. Disable everything else.
Step 5 — Document what you've approved
Keep a record of what you've enabled and why. This matters for team accountability and for your own audit trail if something goes wrong.
What the Defaults Tell You About Meta's Posture
The fact that all 7 write actions were enabled by default isn't an accident. It reflects how Meta wants these integrations to work — frictionless for the AI, minimal friction for advertisers at setup, with the assumption that most people won't go digging through a permissions panel they didn't know existed.
That posture works fine for consumer apps. It's a real problem when the "frictionless" default means an AI agent can change a live advertising budget at scale.
This is the same pattern we've seen with other platform integrations: OAuth scopes for Facebook app connections, Google Ads API access, Shopify app permissions. Default = broad. Restriction = manual. Awareness = on you.
The difference with MCP is the capability range. These agents can potentially take a long sequence of actions in a short time. A bug, a misread prompt, or an agent operating on stale context could cause real damage before anyone notices.
Practical Posture for D2C Brands
If you're running growth marketing campaigns on Meta, here's how to think about AI agent permissions going forward.
For brands using AI for analysis only
Disable all write permissions. Full stop. Your agent doesn't need them. Give it read access to campaigns, ad sets, creative performance, and audience data — and nothing else.
For brands using AI in active workflows
Be surgical. Map out exactly which actions your workflow requires, enable only those, and disable the rest. Re-audit every time you add a new workflow or update an existing one.
For agencies managing multiple client accounts
This is the highest-stakes scenario. Each client's business account needs to be audited individually. An agency AI agent with write access across 20 client accounts — all with default permissions enabled — is a significant liability. Prioritise this.
What we still don't know
A few things remain unclear as of today:
- The exact list of the 7 default write actions — Meta hasn't published this officially. Loomer's audit identified them in his accounts, but the list may vary.
- Whether defaults changed between April and August — it's possible the permission defaults shifted during that period without notice.
- How ad account scope works at setup — Loomer noted that at the point of connecting an AI agent, there's currently no way to limit which ad accounts are visible. That's a gap Meta needs to close.
Watch for official Meta documentation. When it drops, it'll likely be under the Business Help Centre under Integrations or API access. Until then, what's in the panel is what you've got.
One Thing to Do Before You Close This Tab
Open the MCP Permissions Panel today. Business Settings > Integrations > Ads MCP Server. Check every connected agent. Turn off every write permission you didn't consciously choose to enable.
Your ad budgets are real money. The AI agents connected to your account are powerful tools — but they should be operating within boundaries you've set deliberately, not defaults Meta chose for you. Take the 15 minutes. Lock it down.
Sources: Jon Loomer Digital (August 2026 audit findings); Meta Business Settings — Ads MCP Server panel (live as of August 11, 2026). No official Meta documentation page exists at time of publication.
Frequently asked questions
Where do I find Meta's MCP Permissions Panel?
What are the 7 write actions that are enabled by default?
I connected Claude (or another AI agent) after April 2026. Am I affected?
Does Meta have official documentation on the MCP Permissions Panel?
Ready to put this into action?
Digistex4u runs performance, CRM, CRO and growth as one engine for D2C brands. Book a free 20-minute call and we'll map your fastest path to scale.
Get the D2C growth playbook
One practical teardown a week — the Meta, Google, SEO, CRM and retention tactics we run on real D2C brands. No fluff, no spam.
