Authorization scope
Provider permissions and account roles determine which businesses, managers, and ad accounts are reachable.
Security and controls
AdvisorPPC uses platform authorization, encrypted credential storage, narrowly scoped tools, and confirmation boundaries to reduce avoidable PPC account risk.


Stored platform tokens are encrypted at rest using the application's credential-encryption layer. Transport to the public service uses HTTPS. Users can revoke platform access through the provider and remove connected access from AdvisorPPC.
Control layers
Provider permissions and account roles determine which businesses, managers, and ad accounts are reachable.
The ChatGPT-facing product exposes a limited, reviewable set of Google and Meta workflows instead of a generic private dispatcher.
Manager and child-account discovery reduces the risk of applying a request to an unintended customer.
| Operation type | Examples | Control |
|---|---|---|
| Read | List accounts, list campaigns, retrieve performance, analyze search terms | Requires an authenticated user, eligible paid entitlement, and connected provider access |
| Write | Pause or enable a campaign, replace a Google campaign budget | Target and change must be explicit; confirmation is required before execution |
| Draft creation | Create a paused Meta campaign draft | Created paused by default so delivery does not begin automatically |
No internet-connected service can promise zero risk. AdvisorPPC does not claim that AI recommendations are infallible or that OAuth removes the need for careful account administration. Customers should use least-privilege roles, review access regularly, maintain conversion-tracking quality, and confirm high-impact decisions with an accountable specialist.
Send security, access, privacy, or deletion requests to support@advisorppc.com. Include the affected workspace and a description, but never send passwords, access tokens, or API secrets by email.