DEV Community

Xin Jiang
Xin Jiang

Posted on

Let Your AI Agent Do Marketing Without Wrecking Anything

帖子

Most people unplug their marketing agent after its first wrong post.

Sort every action by blast radius: read, draft, publish, spend. Let reads run free. Make publish and spend need a yes the agent can't give itself. Start every ad paused.

Link in the first reply.

第一条评论

https://autowhisper.xyz/en/playbook/agent-marketing-guardrails?utm_source=x&utm_campaign=playbook

X 长文版

Let Your AI Agent Do Marketing Without Wrecking Anything

You already let Claude Code touch your codebase because git can undo anything it does. Marketing has no git revert. A post that went to the wrong account at 9am has been seen by 9:05.

So the usual arc is: connect the agent, get excited, watch it do one wrong thing, disconnect it. I build an MCP server for marketing, and I've spent a lot of time reading how this goes wrong for people. Here's what I'd do before connecting anything.

What goes wrong isn't the copy

The founder of a social scheduler (he discloses it up front) wrote about agents posting through his MCP server. His line that stuck with me: without approvals as a tool, "teams turn the agent off after the first wrong post." https://www.reddit.com/r/SaaS/comments/1wallmc/we_let_ai_agents_schedule_social_posts_through/

An OpenClaw user gave his assistant read access to his mailbox and "it did send an email as me and promise me it won't do it again." The promise isn't a control. https://www.reddit.com/r/openclaw/comments/1rx6q03/omg_im_absolutely_terrified_and_blown_away_at_the/

A SaaS co-founder running sales from one Claude chat: "Nothing gets sent without me reading it first." And in the replies, the whole method in four words: "Split it by blast radius." https://www.reddit.com/r/SaaS/comments/1wsgm36/i_run_most_of_our_saas_sales_from_one_claude_chat/

Four tiers

  1. Read: drafts, post status, results, balance. Worst case: a wrong summary. Let it run, no prompts.
  2. Draft: write copy, generate a video draft. Worst case: wasted credits. Cap it with a prepaid balance.
  3. Publish: post, reschedule, retry. Worst case: your brand says something you didn't mean, in public. You approve, every time.
  4. Spend: launch or boost an ad, change a budget. Worst case: money gone. You, inside the ad platform.

Allow reads permanently. If every read prompts you, you'll start clicking "allow" without looking, and one day that click will be a publish.

The rule people get wrong

The yes for publish and spend can't come from the agent. If approval is just another tool call, an agent trying to finish the task will call it. The yes has to come through something it can't press for you: your client's permission prompt, or a button in another app.

And ads: an agent saves you hours in Ads Manager. It doesn't make customers cheaper. One advertiser using a Meta MCP put it plainly: "It won't magically improve your results." He also warned that new objects start paused but budget changes go straight to live. https://www.reddit.com/r/ClaudeAI/comments/1uluxxq/anyone_using_the_meta_ads_mcp_with_claude_for/

How we built AutoWhisper's MCP around this

  • 8 of the 13 tools are read-only: feed, post queue (with failure reasons), platforms, wallet, performance and so on. No credits, nothing sent.
  • Approving is publishing. approve_feed_item schedules to every connected channel, and on a video draft it starts the render, 45 credits.
  • Every autowhisper_action call returns a confirmation id first. Nothing runs until autowhisper_confirm gets "yes".
  • Ads on Meta, TikTok and LinkedIn are built paused, with the daily budget from a settings field you filled in. Empty field, no ad. You press start in your own ads console. We never spend ad money for you.

The honest gap: autowhisper_confirm is itself a tool, so an agent can confirm its own request. Close it in your client. In Claude Code, put the 8 read tools under permissions.allow and autowhisper_action + autowhisper_confirm under permissions.ask. The full JSON is in the article.

New accounts get 65 credits. A full video is 52.

Full write-up with the tool table and settings: https://autowhisper.xyz/en/playbook/agent-marketing-guardrails

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.