🎯 Digital Marketing Strategy

Meta's MCP Permissions Panel: Who Can Change Your Ad Budgets Right Now?

Meta launched an MCP Permissions Panel in August 2026 that controls what AI agents can do inside your ad accounts — and several sensitive write actions are reportedly enabled by default. If you've connected any AI agent since April, you need to open this panel today.

DDigistex4u Team••8 min read
Meta's new MCP Permissions Panel controls what AI agents can do in your ad accounts. Several write actions are on by default — here's the audit guide.

Who, Right Now, Has Permission to Change Your Meta Ad Budgets?

Not rhetorically — actually think about it. When did you last check? If you've connected an AI agent to your Meta Business account at any point since April 2026, there's a real chance the answer is: an AI, without you explicitly approving that specific action.

Meta quietly rolled out the MCP Permissions Panel on August 11, 2026. You'll find it at Business Settings > Integrations > Ads MCP Server. It's the first proper interface that lets advertisers control what an AI agent can and can't do inside their ad accounts — which Pages it can see, which Instagram accounts, which business portfolios, and which specific actions it's allowed to take.

That's good news. The uncomfortable part is what was happening before you knew this panel existed.

Jon Loomer, one of the most thorough independent Meta Ads researchers working today, ran an audit of his own accounts after the panel launched. His finding: all 7 write actions were enabled by default. Budget changes, campaign creation, ad set creation, ad creation — the works. Turned on. No opt-in required.

If you run a D2C brand on Meta and you're using any AI connector, this is the article you need to read before you open Ads Manager today.


What the MCP Permissions Panel Actually Controls

MCP stands for Model Context Protocol — it's the standard that lets AI tools like Claude connect to external platforms and take actions on your behalf. Meta's Ads MCP Server is their implementation of this, and it's what makes "ask Claude to analyse my campaigns" actually work at a data level.

The Permissions Panel sits on top of that connection. Think of it as a bouncer that decides what your AI agent can see and what it can touch.

Three layers of control

The panel operates across three layers:

  • Account-level access: Which Pages, Instagram accounts, and business portfolios the AI agent can even see
  • Ad account visibility: Which specific ad accounts are exposed to the agent (notably, Loomer flagged there's currently no way to limit this at the point of initial setup)
  • Tool-level permissions: Approximately 100 individual actions the agent can or cannot perform — from reading campaign data to creating and modifying live ads

That third layer is where it gets granular. And where, right now, most advertisers are completely exposed.

Read vs. write — why it matters

There's a fundamental difference between an AI reading your data and an AI changing it.

Permission type Example actions Risk if left unchecked
Read View campaigns, pull spend data, analyse creatives Low — agent can see but not touch
Write (low sensitivity) Add comments, export reports Low-medium
Write (high sensitivity) Change budgets, create campaigns, edit bids High — live money at stake

The 7 write actions flagged as on-by-default sit in that high-sensitivity column. That's the problem.


Why This Surfaced Now (And Why No One Warned You)

Meta hasn't published an official documentation page for the MCP Permissions Panel yet. As of September 2026, what we know comes primarily from Jon Loomer's hands-on audit, not from Meta's Help Centre or any advertiser notification.

That's a significant gap. Meta's MCP connector for Claude was quietly available to advertisers earlier in 2026. Many businesses — including agencies managing multiple client accounts — may have authorised the connection without understanding the default permission state they were agreeing to.

The "connected since April" window

If you or your agency connected an AI agent to Meta between April 2026 and August 11, 2026 (when the panel launched), you had zero visibility into what that agent was permitted to do. You couldn't review it, restrict it, or audit it through any official Meta interface.

Now you can. But only if you know to look.

This isn't a hypothetical concern. AI agents connected via MCP can execute actions autonomously if they're triggered to do so — whether through a scheduled workflow, a chat prompt, or an automated process. An agent with write access to your ad budgets can change them if instructed to. The question is whether you authorised that capability knowingly.


The Step-by-Step Audit Checklist

Here's exactly what to do. This takes about 15 minutes if your Business Manager access is clean.

Step 1 — Find the panel

  1. Log into Meta Business Suite
  2. Go to Business Settings (gear icon, bottom left)
  3. In the left sidebar, look for Integrations
  4. Click Ads MCP Server

If you don't see Integrations in your sidebar, check your admin permissions. You'll need Business Admin access to view this section.

Step 2 — Check which accounts are connected

The panel will show you which AI connectors are currently linked to your business. Note down every connector that appears. If you see something you don't recognise, flag it immediately before you do anything else.

Step 3 — Review the tool-level permissions

Click into each connector. You'll see a list of approximately 100 tool-level permissions. This is the core of the audit.

Look specifically for anything in these categories:

  • Budget modifications
  • Campaign creation or editing
  • Ad set creation or editing
  • Ad creation or editing
  • Bid strategy changes
  • Audience modifications
  • Payment or billing actions

Step 4 — Disable write permissions you haven't deliberately enabled

For most advertisers, the right posture is: read access yes, write access only where explicitly intended.

If you're using an AI agent for reporting, analysis, or creative review — it doesn't need write access. Disable it.

If you're using an AI agent to actually make changes (like auto-optimising budgets via a workflow you've designed and tested), leave only the specific write permissions that workflow requires. Disable everything else.

Step 5 — Document what you've approved

Keep a record of what you've enabled and why. This matters for team accountability and for your own audit trail if something goes wrong.


What the Defaults Tell You About Meta's Posture

The fact that all 7 write actions were enabled by default isn't an accident. It reflects how Meta wants these integrations to work — frictionless for the AI, minimal friction for advertisers at setup, with the assumption that most people won't go digging through a permissions panel they didn't know existed.

That posture works fine for consumer apps. It's a real problem when the "frictionless" default means an AI agent can change a live advertising budget at scale.

This is the same pattern we've seen with other platform integrations: OAuth scopes for Facebook app connections, Google Ads API access, Shopify app permissions. Default = broad. Restriction = manual. Awareness = on you.

The difference with MCP is the capability range. These agents can potentially take a long sequence of actions in a short time. A bug, a misread prompt, or an agent operating on stale context could cause real damage before anyone notices.


Practical Posture for D2C Brands

If you're running growth marketing campaigns on Meta, here's how to think about AI agent permissions going forward.

For brands using AI for analysis only

Disable all write permissions. Full stop. Your agent doesn't need them. Give it read access to campaigns, ad sets, creative performance, and audience data — and nothing else.

For brands using AI in active workflows

Be surgical. Map out exactly which actions your workflow requires, enable only those, and disable the rest. Re-audit every time you add a new workflow or update an existing one.

For agencies managing multiple client accounts

This is the highest-stakes scenario. Each client's business account needs to be audited individually. An agency AI agent with write access across 20 client accounts — all with default permissions enabled — is a significant liability. Prioritise this.


What we still don't know

A few things remain unclear as of today:

  • The exact list of the 7 default write actions — Meta hasn't published this officially. Loomer's audit identified them in his accounts, but the list may vary.
  • Whether defaults changed between April and August — it's possible the permission defaults shifted during that period without notice.
  • How ad account scope works at setup — Loomer noted that at the point of connecting an AI agent, there's currently no way to limit which ad accounts are visible. That's a gap Meta needs to close.

Watch for official Meta documentation. When it drops, it'll likely be under the Business Help Centre under Integrations or API access. Until then, what's in the panel is what you've got.


One Thing to Do Before You Close This Tab

Open the MCP Permissions Panel today. Business Settings > Integrations > Ads MCP Server. Check every connected agent. Turn off every write permission you didn't consciously choose to enable.

Your ad budgets are real money. The AI agents connected to your account are powerful tools — but they should be operating within boundaries you've set deliberately, not defaults Meta chose for you. Take the 15 minutes. Lock it down.


Sources: Jon Loomer Digital (August 2026 audit findings); Meta Business Settings — Ads MCP Server panel (live as of August 11, 2026). No official Meta documentation page exists at time of publication.

Frequently asked questions

Where do I find Meta's MCP Permissions Panel?
Go to Meta Business Settings, then Integrations, then Ads MCP Server. The panel became available on August 11, 2026.
What are the 7 write actions that are enabled by default?
The exact list hasn't been officially published by Meta, but Jon Loomer's audit revealed all 7 write actions in his accounts were on — these include actions like changing budgets, creating campaigns, creating ad sets, and creating individual ads.
I connected Claude (or another AI agent) after April 2026. Am I affected?
Very likely yes. If you authorised any MCP-compatible AI connector during that window, your account may have broad write permissions active. Open the panel immediately and review each tool-level permission.
Does Meta have official documentation on the MCP Permissions Panel?
As of September 2026, no official Meta documentation page exists. The panel itself is live, but guidance has come from independent researchers like Jon Loomer rather than Meta's Help Centre.

Ready to put this into action?

Digistex4u runs performance, CRM, CRO and growth as one engine for D2C brands. Book a free 20-minute call and we'll map your fastest path to scale.

✉️

Get the D2C growth playbook

One practical teardown a week — the Meta, Google, SEO, CRM and retention tactics we run on real D2C brands. No fluff, no spam.

Join D2C founders getting our weekly growth playbooks. Unsubscribe anytime.