Controlled beta for Google Ads advertisersRead the update
All writing

5 min

Read-only agents are more useful than they sound

An agent that cannot touch your account still removes the slowest part of the job, which is knowing where to look.

The instinctive read on a read-only agent is that it is a demo. If it cannot change anything, what is it for? You still have to do the work; it just tells you about it first.

That reasoning assumes the expensive part of media buying is making the change. It is not. Making the change takes about forty seconds. Knowing which change to make takes the afternoon.

Where the time actually goes

Break a typical optimisation down honestly and the shape is consistent: noticing that something moved, pulling the data that might explain it, ruling out the explanations that do not hold, deciding what to do, and then doing it. The last step is the only one that needs write access, and it is comfortably the shortest.

A read-only agent removes the first three. What remains is the decision, which is the part you are actually paid for, and the click, which was never the bottleneck.

The asymmetry of attention

There is a second effect that matters more over a quarter. A person can hold two or three accounts in their head. Past that, the accounts get read on a rota, which means most of them are being looked at for the first time in a week whenever something goes wrong in them.

Reading has no such limit. An agent reading eleven accounts every morning is not doing anything clever in any one of them; it is simply being present in all of them on the same day. Most of what a good buyer catches, they catch by being there when it starts, and being there is the thing that does not scale with headcount.

Why read-only is a feature, not a phase

It is tempting to treat read-only as the trial version of write access. It is better understood as a permanent setting that many accounts should stay on.

  • A read has no blast radius. The worst outcome of a wrong read is a wasted minute; the worst outcome of a wrong write is a wasted budget.
  • Read-only is auditable in a way that write access is not. If the agent never writes, the question of what it did is answered entirely by what it said.
  • It makes the trust decision incremental. You can watch an agent reason about your account for a month before deciding whether its judgement is worth granting anything more.

The last one is the important one. Handing an autonomous system write access to a spending account is a large decision, and the usual way it gets made is all at once, on the strength of a sales demo. Read-only lets it be made slowly, on the strength of a month of the system being visibly right or visibly wrong about accounts you know well.

What to expect it to be bad at

A read-only agent cannot tell you whether a change worked, because it cannot make one and then re-read the result. It can tell you what happened after a change you made, if you tell it that you made one, which is a meaningfully weaker claim.

It will also surface things you already knew, particularly in the first fortnight, and this is a reasonable price. An agent that only reported findings you had not already had would be an agent that stayed quiet through most of the obvious problems.