Controlled beta for Google Ads advertisersRead the update
Integrations · what we read, what we can change

Four beta integrations. Every other status, named.

Google Ads, GA4, Merchant Center and Search Console are available to controlled-beta customers. Meta is reviewer-only, Shopify accepts no new public installs during review, and TikTok Ads remains a supervised test path. The implementation details below do not turn those limits into customer availability.

No card to connect. Every connection is read-only until you turn writes on, per account.

Not a demo: the same status words as the matrix below.

Section 01 · where each platform stands

Seven platforms, and six we have not built.

Six states for the platforms we have built, one for the platforms we have not, and no eighth. There is no coming-soon badge on this page, because a badge without a date is a promise we would be making with your money on the table. Read the status column before the two on its right: a platform whose code is finished says exactly that and nothing more, until production has evidenced the rest.

Where each platform stands today
PlatformStatusWhat Mako readsWhat Mako can change, only after you approve
Meta AdsReviewer-only · app review in progressAd accounts, campaigns, ad sets, ads and creative thumbnails, plus spend, impressions, clicks, CTR, CPC, CPM, frequency, reach, purchase ROAS and purchase actions, day by dayThree changes: pause or activate a campaign, set a campaign daily budget, move daily budget between two campaigns or two ad sets
Google AdsControlled beta · production evidence pendingCampaigns, ad groups, keywords, search terms, responsive search ad text and policy status, plus cost, impressions, clicks, conversions and conversion value, day by dayNine changes: pause, enable or rename a campaign, set a campaign daily budget, create a paused campaign, add or remove campaign negatives, manage positive ad-group keywords, pause, enable or rename an ad group, and pause or enable one existing ad
Google Merchant CenterControlled beta · production evidence pendingYour Merchant Center accounts, the data sources in them, and every product with its item-level issues and per-country approval statusOne change: publish the product feed Sable Mako builds from your Shopify catalog, which makes us the primary data source for that account
TikTok AdsSupervised validation · not customer availableAdvertiser accounts with currency and timezone, plus spend, impressions, clicks, conversions and TikTok's own attributed purchase value, by day, at account and campaign levelNothing today. Campaign creation, one card that builds a campaign, ad group and ad all paused, is written and switched off: three separate things hold it off, and any one of them alone would be enough
ShopifyExisting installs only · app review in progressShop name, domain, currency, plan and timezone; daily gross sales, discounts, returns, net sales, total sales and order count; product count; order count and a sampled revenue total for a windowNothing. Shopify is read-only today: no write permission is requested and no write path exists in the code
Google Analytics 4Controlled beta · production evidence pendingSessions, key events, purchases and revenue by traffic source and medium, day by day, plus the same window rolled up by channel groupNothing. The permission we request is read-only
Google Search ConsoleControlled beta · production evidence pendingSearch queries and pages, with clicks and impressions by day, plus the list of your verified sites at connect timeNothing. The permission we request is read-only
Six more platformsNot builtNothingNothing

In full: LinkedIn Ads, Microsoft Ads, Pinterest Ads, Snapchat Ads, Klaviyo, Amazon Ads. Section 04 says what not built means, and it is stricter than it sounds.

Section 02 · the two switches

Two switches stand between Mako and your account.

01

Writes are off when a connection is created.

Every connection is stored with write access off. While it is off, the change tools are left out of the request we send to the model, so the agent cannot emit a change even if you ask it to.

02

You turn writes on per account, and confirm it.

The switch lives on that one connection. Arming Meta never arms Google. Turning it on takes a confirmation and turning it off does not, and the code refuses to arm it at all for TikTok Ads, Shopify, GA4 and Search Console.

03

Every single change still needs its own approval.

The agent writes a proposal rather than a change. You see the current value, the proposed value, the numbers behind it and any warnings our server computed, above the approve button.

A proposal older than 24 hours will not execute and has to be asked for again. A double-click cannot execute it twice. After a change runs, Mako re-reads the platform in the same request and reports success only when the platform's own value matches what you approved. A mismatch is stored as a failed verification and shown to you as one.

The refusals, the audit record and the exact bounds are on the security page.

Section 03 · every field, per platform

Every field we ask for, one platform at a time.

Meta Ads

Reviewer-only · app review in progress

Why it is here. The account Mako audits, watches daily, and can be authorised to adjust.

Permissions we request:

ads_readads_managementbusiness_managementpages_show_listpages_read_engagement

Where the connection runs through Facebook Login for Business, our authorize request omits the permission list entirely and the granted set comes from a configuration inside our Meta app rather than from our code. Meta's own consent screen shows you the permission set you are actually granting, and that screen is the authority.

What we read

  • Which ad accounts your login can reach: account id, name, currency, account status, the business that owns it, and lifetime amount spent
  • Account summary: name, currency, status, lifetime amount spent, business name and timezone
  • Campaigns: id, name, status, effective status, objective, daily budget, lifetime budget and start time
  • Performance at account, campaign, ad set and ad level: spend, impressions, clicks, CTR, CPC, CPM, frequency, reach, purchase ROAS, actions, action values and cost per action
  • The same figures broken out by day, which is the history the daily watch compares against
  • Ads and creative: name, status, effective status, and the creative's id, name, thumbnail URL, image URL and Instagram permalink
  • The state of a campaign or ad set immediately before a change, and again immediately after, to verify it

What can change, after you approve it

  • Pause or activate a campaign.
  • Set a campaign daily budget. Campaign-level budgets only, so a campaign whose budget lives on its ad sets is refused, and so is one on a lifetime budget.
  • Move daily budget between two campaigns, or between two ad sets, inside one account, with the total held constant.

What we never touch: Creating or deleting campaigns, ad sets or ads. Uploading creative. Targeting, bidding, schedules and objectives. Lifetime budgets. Account settings. The Conversions API and your pixel. Pages, posts and audiences.

Guardrails, enforced in code

  • A budget increase over 300%, which is more than four times the current figure, is blocked before an approval card is ever created
  • A budget change over 20% in either direction shows a warning above the approve button, because it can restart Meta's learning
  • A rebalance across two different accounts is blocked and fails closed
  • A rebalance cannot take the source down to zero. Pausing is a separate, explicit action
  • A campaign covered by a lock rule you wrote cannot be paused, and the refusal quotes your rule back to you

Where this stands today. Meta reads and guarded write code exist, but Meta's app review is still in progress. New grants are limited to Meta reviewers and explicitly allowlisted supervised test accounts. Meta is not part of the ordinary beta offer, and its implemented write tools are not a general availability claim.

Google Merchant Center

Controlled beta · production evidence pending

Why it is here. The product feed behind Shopping, where a bad title costs every impression.

Permissions we request:

https://www.googleapis.com/auth/content

Google publishes one Merchant Center permission and it covers reading and writing, the same as Ads. There is no read-only version to ask for, so read-only is a behaviour we enforce rather than a permission we request: publishing starts off on your connection, and while it is off no publish tool is sent to the model and the server refuses a publish even if one were proposed.

What we read

  • The Merchant Center accounts your login can reach, with their names
  • The data sources in an account, so we adopt an existing feed rather than creating a second
  • Products already in the account, with their offer ids and attributes
  • Item-level issues and per-country approval status, which is what the feed audit reports
  • The same product list again after a publish, to confirm what was accepted

Product reads stop after 5 pages of 250. When a read is cut short we label it truncated rather than presenting a partial catalog as the whole account.

What can change, after you approve it

  • Publish the built feed. The first publish makes Sable Mako the PRIMARY data source for that Merchant Center account, which replaces whatever feed supplies your Shopping ads today, and the card says so before you approve. Only products that changed since the last publish are sent. Nothing is published if the build has an error Google would reject.

What we never touch: Bids, budgets or campaigns. Your Merchant Center account settings. Shipping, tax or returns configuration. Deleting a data source. Anything in an account you did not connect.

Guardrails, enforced in code

  • Publishing is off by default on the connection, and arming it takes a confirmation
  • A first publish also requires typing the word PUBLISH, because it replaces the feed serving your ads
  • The feed is rebuilt and revalidated at the moment you approve, so a card drafted against an older catalog cannot publish a feed nobody reviewed
  • A build with any error Google would reject cannot be published at all
  • Merchant Center accepts items one at a time, so a publish reports each item's outcome and can end partial rather than claiming success

Where this stands today. The connector, reads, catalog import, feed audit, rules and preview are implemented and open to the controlled beta. Publishing stays off until the write switch is armed and the exact publish is approved, and remains under supervised validation until publish, verify and recovery have a complete production evidence pack. If Google refuses to list your accounts at connect time, the screen says so and names it as ours to fix. Implemented code is not a customer-available publishing promise.

TikTok Ads

Supervised validation · not customer available

Why it is here. The hole in a blended number, for a store whose third channel we cannot see.

Permissions we request: There is no permission string in our code to print here. TikTok fixes an app's permission set when it approves the app in its own developer portal, so our authorize request sends no scope parameter at all. That makes this the one row on the page where the honest answer is a name from somebody else's dashboard rather than a literal from ours.

The set was read-only until 2026-08-18, when TikTok approved a second application covering campaign, ad group and ad management, audiences, creative, catalogs, pixels and measurement. We deliberately left out TikTok Shop and GMV Max, which are a campaign type this product does not use, and Automated Rules, because nothing here ever writes without your approval and holding a permission for unattended changes would contradict that. TikTok's own consent screen shows you the set you are actually granting before you approve it, and that screen is the authority, the same way Meta's is. TikTok reports the granted set back to us as numeric ids and we store what it reports rather than what we asked for. It publishes no map from those numbers to permission names, which is why the check in front of every TikTok write still does not recognise the grant and still refuses.

What we read

  • Which advertiser accounts your login can reach: advertiser id and name
  • Account details: name, currency, timezone and account status. That is a second call, because the account list carries none of them
  • Daily performance for the account: spend, impressions, clicks, conversions and TikTok's own attributed purchase value
  • The same figures per campaign, with the campaign id and campaign name, day by day

A day TikTok sends no row for is stored as unread rather than as a zero. TikTok filters days with no data out of the response entirely, so a day with no spend and a day we never read arrive looking identical, and writing zeros there would understate spend and inflate every ratio built on it. A window TikTok answers as partially successful is stored incomplete rather than whole. The purchase value above is what TikTok attributed to its own ads: there is no attribution-window parameter on the reporting endpoint, each ad group carries its own windows, so those figures are not comparable with Meta's and are never labelled revenue.

What can change, after you approve it

  • Create a new campaign, ad group and ad in one card, every object paused. Off for every account today, and held off by three separate things: the capability switch is a constant in our source, the write switch does not accept TikTok as a provider at all, and the permission check in front of every TikTok write does not recognise the grant TikTok reports back. When on, nothing is activated by the approval: the tree is created paused and you turn it on yourself in TikTok Ads Manager. TikTok publishes no way to validate a campaign before creating it, so the card says we checked it and TikTok did not.

What we never touch: Deleting anything. Changing a campaign, ad group or ad that already exists: budgets, bids, targeting, schedules and statuses. Uploading creative: the video has to be in your account already and we send its id. Audiences, pixels and the Events API.

Where this stands today. TikTok approved the developer app and the read code is implemented, but no sanitized production read evidence pack is complete. New grants are restricted to allowlisted supervised tests. Campaign creation is switched off, numeric write-scope mapping still fails closed, and no TikTok write is offered. No audit check reads TikTok yet; the eleven Meta checks and eleven Google Ads checks are separate engines.

Shopify

Existing installs only · app review in progress

Why it is here. Your revenue and returns are what turn a ROAS number into a profit judgement.

Permissions we request:

read_ordersread_productsread_reportsread_analyticsread_inventory

All five are read permissions. read_inventory reads a variant's unit cost, so a product's margin can inform its Shopping feed; the other four cover sales and catalog. We deliberately do not request read_all_orders, the protected permission that would let us list orders older than 60 days, because the reporting gain does not justify the access. Shopify shows you the permission list on its own install screen before you approve it, and a store that granted a wider set at some earlier install keeps that grant: what bounds the reads is the code, and no Shopify customer, line item or fulfilment endpoint is called anywhere in it.

What we read

  • Shop settings: name, domain, currency, plan and timezone
  • Daily sales from Shopify's own analytics: gross sales, discounts, returns, net sales, total sales and order count
  • Product count
  • Order count for a window, and a revenue total summed from the orders themselves
  • Cancelled order count for a window

The revenue total for a window is a sample and the sample size travels with the figure. Orders are read 100 rows at a time and we follow Shopify's cursor rather than stopping at the first page, up to a budget of 50 pages. Past that the window comes back marked incomplete instead of being passed off as the whole total. When Shopify counts orders and returns none of them, revenue comes back empty with the reason in plain language, never as zero. A day holding an order whose money we cannot read is removed whole and named, from the live total and the stored series alike, so the two never disagree about what a day was worth.

What can change: Shopify is read-only today. It is absent from the list of providers the write switch accepts, so the switch refuses to arm for it, no proposal tool exists, and the code that executes approved changes has no Shopify branch. The only request we send to Shopify that is not a read is the install handshake itself.

What we never touch: Customer names, emails and addresses. Line items. Fulfilment and shipping. Discount codes. No customer, line-item or fulfilment endpoint is called anywhere in our code.

Where this stands today. Your gross margin sets the ROAS a campaign has to clear. Once there are enough measurable returns, that bar is raised by your own return rate rather than by an industry figure. Blended MER joins live Meta spend to Shopify revenue in one number, and it excludes Google Ads spend, which the number says on its face. New installs are closed while Shopify's own app review completes; a store already installed keeps syncing every night.

Google Analytics 4

Controlled beta · production evidence pending

Why it is here. What the site itself recorded, checked against what an ad platform claims for the same traffic.

Permissions we request:

https://www.googleapis.com/auth/analytics.readonly

Read-only by definition. This permission cannot change anything in your property, and Google shows it to you on its own consent screen before you approve.

What we read

  • Your GA4 account summaries and the property list under them, so you can pick a property
  • Sessions, total users, engaged sessions, key events, ecommerce purchases, purchase revenue and total revenue, by traffic source and medium, day by day
  • The same window rolled up by channel group: paid social, paid search, organic search, direct, email and referral

These are the site's own numbers, not an ad platform's attributed figures, and they will not match what Meta or Google Ads reports for the same traffic. That difference is the reason to read both, not an error in either one. A property GA4 reports no currency for comes back with its revenue named as an unknown unit rather than assumed to be dollars.

What can change: Nothing. There is no write permission and no write path.

What we never touch: Audiences, custom dimensions, user-level or demographic breakdowns, and real-time reports. The seven metrics listed above are the whole set we request, and no audience, demographic or real-time endpoint is called anywhere in our code.

Where this stands today. The connector, nightly sync and two live read tools are implemented, Google approved analytics.readonly, and GA4 is open to the controlled beta. Production evidence is pending: no sanitized connect-and-read pack is complete yet. No audit check reads GA4 and no write path exists.

Google Search Console

Controlled beta · production evidence pending

Why it is here. What people searched to find your site, and the pages they landed on, read nightly and live in chat.

Permissions we request:

https://www.googleapis.com/auth/webmasters.readonly

This is the read-only variant. It cannot add a site or submit a sitemap even if we wanted it to. Google classes it as non-sensitive, so it needed no verification.

What we read

  • The list of your verified sites, so you can pick one
  • Search queries and the pages they landed on, with clicks and impressions, day by day

What can change: Nothing. There is no write permission and no write path.

What we never touch: Sitemaps, URL inspection, indexing coverage, mobile usability, Core Web Vitals and rich-result status. Only search queries and pages are read.

Where this stands today. The connector, the two spine tables, the nightly sync and two live agent read tools are built and shipped, and Search Console is open to the controlled beta: a connected site is read every night the same way Meta and Google Ads are, and the agent reads its search queries and pages live in chat. The button stayed closed for a week on the belief that webmasters.readonly needed Google's verification; it is a non-sensitive scope and never did. Production evidence is pending: no sanitized connect-and-read pack is complete yet.

Full permission table and security controls

Section 04 · what we have not built

What we have not built, named before you find it.

There is no connector, no login flow, no API client and no agent tool for any of these. Not a beta, and not behind a flag. We write not built rather than planned, because planned is a delivery promise and there is no date behind one.

LinkedIn AdsMicrosoft AdsPinterest AdsSnapchat AdsKlaviyoAmazon Ads

If your money is mostly in one of these, Sable Mako has little to offer you this month. Tell us which one at support@sablemako.com and it moves up the list.

Two more things worth knowing before you connect

  • A lead-generation advertiser gets less of this than a store does. Every profit check assumes purchases and a gross margin, and campaigns that convert in a chat are left out of the Meta sales universe on purpose. If your Meta objective is messages or form fills, you get the account, tracking and structure checks and very little of the rest, and no connection changes that.
  • Team access is deliberately simple. Solo includes one login; Studio, Agency and Scale allow multiple people. A workspace has Owner and Member roles. Members can use the agent, read audits and approve changes for the brands the Owner has given them, while billing, account connections and write access stay with the Owner. There is no read-only role or ownership transfer yet.

Section 05 · why we ask for this much

Why we ask for this much and no more.

01

The audit is why we ask to read.

eleven deterministic checks run against a Google Ads account, each naming the rule, entity and number behind it. One initial audit is included per eligible account. Repeat audits, daily monitoring and alerts require an active trial or plan. Meta's eleven checks are implemented but Meta remains reviewer-only during app review.

02

The daily watch is why we ask for history.

With an active trial or plan, once a day from 07:00 in your brand's own timezone, each eligible connected ad account is read again and compared with its last scheduled run. You are alerted on new or worse findings only, never on the same problem twice.

03

The write permission is the one we cannot narrow.

Meta requires ads_management for the three Meta changes, and Google publishes a single Ads permission that covers reads and writes together. Neither platform offers a read-only alternative, so read-only is a behaviour we enforce rather than a permission we request. That is what the two switches above are for.

Section 06 · connecting and disconnecting

Connecting goes through their front door. Leaving takes one click.

  1. You connect through each platform's own login flow. The permission screen you approve comes from Meta, Google or Shopify, and we never see or store a platform password.
  2. Access tokens are encrypted with AES-256-GCM before they reach the database, under a key held in the server environment rather than in the database, and each token is cryptographically bound to the one connection it belongs to.
  3. Writes start off. You arm them on one connection at a time and confirm the dialog. Turning them back off takes one click and no confirmation.
  4. Meta's long-lived login tokens run about 60 days and we do not renew them for you. There is no Meta refresh path in our code and no stored expiry, so the first sign is a read that fails and the fix is to reconnect Meta from Integrations. Google connections hold a refresh token and renew themselves.
  5. Disconnecting deletes the stored credential outright. It is a delete rather than a flag. Metrics already pulled stay, so your history does not develop a hole where the connection used to be.
  6. You can revoke access from Meta, Google or Shopify at any time without touching Sable Mako, and that ends our access on the spot. If you delete your account, revoke there as well: we do not do it on your behalf.

Data handling, subprocessors and deletion are set out in the privacy policy, and the controls behind all of this are on the security page.

Section 07 · before you connect

Before you connect. The questions people actually ask.

Can Mako change my campaigns without asking?

No. Write access is off on every new connection, the change tools are not even sent to the model while it is off, and each individual change needs its own approval. After a change runs, Mako re-reads the platform and reports success only when the platform agrees.

What if I connect and never turn writes on?

Read-only use does not require turning writes on. During an active trial or plan, repeat audits, the daily watch, alerts, chat and analysis can run while every platform change remains disabled. Your included first audit also runs before writes are enabled.

What exactly can it change, at most?

Fourteen operations across four platforms: pause or activate a Meta campaign, set a Meta campaign daily budget, move budget between two Meta campaigns or two ad sets, pause or enable a Google campaign, rename one existing Google campaign, set a Google campaign daily budget, add negative keywords to a Google campaign, remove campaign negatives, add, pause, enable or remove positive keywords in one ad group, pause, enable or rename one Google ad group, pause or enable one exact existing Google ad, create a Google campaign paused, publish the product feed to Merchant Center, and create a TikTok campaign paused. Both campaign creations, Google and TikTok, are switched off for every account by a constant in our source code, and the feed publish stays off on each connection until its own write switch is turned on. That is the complete list, and a test in this codebase fails the build if a fifteenth appears without this page being rewritten.

A change failed halfway. Now what?

A budget move is two steps, and if the second fails the first is put back automatically and the result is shown to you. For a single change that executed but did not verify, the card says so and names the discrepancy. There is no undo button today: to reverse a change, ask Mako to propose the opposite one.

Do you read my customers' data from Shopify?

No. We read shop settings, daily sales totals, product count, order counts and order totals. No names, emails, addresses, line items or fulfilment, and no endpoint that would return them is called anywhere in our code.

Do you need my Meta or Google password?

No. Connections run through each platform's official login flow and we store a revocable token, never a credential you typed.

My platform is not here.

Then it is not supported, and there is no beta and no flag that changes that. Nothing on this page is a roadmap. Email us and we will tell you honestly whether it is close.

What does connecting cost?

Connecting Google Ads and running one initial deterministic audit needs no card. Repeat audits, daily monitoring, alerts and the agent require an active trial or plan. Meta and TikTok Ads are not ordinary beta connection options yet.

Controlled beta

See what your Google Ads account is doing.

Apply for a supervised design-partner place. One initial deterministic audit is included before you choose a plan.

No card for the included audit. Nothing changes without exact approval.

Receipts

  1. The permission strings on this page are the literal values our code sends. The platform's own consent screen is what actually grants them, and it shows you the set before you approve.
  2. Write access is stored per connection and starts off. While it is off, the change tools are left out of the request sent to the model, so the agent is never handed them.
  3. A proposal older than 24 hours is refused and has to be asked for again, because the numbers on the card describe a moment that has passed.
  4. Every approved change is executed once and then verified by re-reading the platform in the same request. Success is defined by the platform's own value, never by the platform's response.
  5. Shopify revenue for a window is summed from the orders themselves and carries its sample size. Orders are paged through 100 rows at a time up to a budget of 50 pages, and a window that runs past it is returned as incomplete rather than as a total.
  6. Platforms marked not built have no connector, no login flow, no API client and no agent tool anywhere in the product.
  7. Tokens are encrypted with AES-256-GCM under a key held outside the database, and the row holding one is deleted when you disconnect.
  8. Meta login tokens last about 60 days and we do not renew them. Nothing in our code stores their expiry, so the first sign is a read that fails.