Field notes · 03
AI that can't touch your budget without a paper trail
2026-07-02 · 5 min · Revenue Arc
The reason most teams don't let AI optimize live spend isn't capability. Models have been good enough to move budgets for years. It's accountability: when a black-box optimizer moves $40K between channels overnight, who explains it to the client — and with what evidence?
The rule
We built ArcOps on a single architectural rule: the copilot proposes; a human — or an explicit policy a human wrote — disposes. Nothing changes silently. Not during a demo, not at 3am, not when the model is very confident.
Concretely, the recommendation engine is deterministic: same metrics in, same recommendations out, each carrying its rationale and the exact change it wants to make. An LLM helps explain and prioritize — it is structurally incapable of inventing an action. The set of things that can happen to your budget is written in reviewable code, not sampled from a distribution.
Autonomy is a dial, not a switch
- Manual — run it. Every recommendation waits for a human verdict. Day one for every campaign.
- Assisted — have us run it. Changes that clear your guardrails (per-action spend cap, allowed channels, max daily delta) are pre-cleared for one-click operator approval; everything bigger needs a fuller human review.
- Autonomous — let it run. On Scale, the current product executes guardrail-cleared actions for simulated campaigns inside hard limits. Live platform writes remain separately disabled until connector-specific go-live gates are armed.
The dial is per-campaign. A simulated always-on retargeting campaign can run autonomous while a new simulated brand launch stays manual. For live campaigns, the same policy model is visible today, but no vendor write occurs unless that connector's separately reviewed go-live gates are armed.
The receipts
Every acted-on recommendation becomes one immutable decision record: what was proposed and why, who or what approved it (and under which policy tier), what the vendor said when the change was applied — including failures. Failed applies are recorded, never swallowed; a double-click can't double-apply; the audit log is append-only.
That record is the difference between “the AI did something” and “on day 14, the copilot flagged an invalid-traffic signature on CTV, the operator applied the assisted policy's pre-cleared pause under the $15K cap, and here's the delivery curve after.” One of those sentences survives a client QBR.
Why this beats a smarter black box
A black box asks for trust up front and returns it as a metric. An approval rail earns trust incrementally and returns it as evidence. When the inevitable weird week happens — tracking outage, seasonal cliff, a vendor's attribution hiccup — the black box's answer is “the number moved.” The rail's answer is a decision log you can read.
Guardalo in azione
ArcOps monitora ognuno di questi segnali sull'intero portafoglio e presenta raccomandazioni che approvi — o deleghi a una policy. La configurazione richiede due minuti.
Ricevi il prossimo
Un'analisi alla volta, nella tua casella. Disiscrizione quando vuoi.