ArcOps

Field notes · 03

AI that can't touch your budget without a paper trail

2026-07-02 · 5 phút · Revenue Arc

The reason most teams don't let AI optimize live spend isn't capability. Models have been good enough to move budgets for years. It's accountability: when a black-box optimizer moves $40K between channels overnight, who explains it to the client — and with what evidence?

The rule

We built ArcOps on a single architectural rule: the copilot proposes; a human — or an explicit policy a human wrote — disposes. Nothing changes silently. Not during a demo, not at 3am, not when the model is very confident.

Concretely, the recommendation engine is deterministic: same metrics in, same recommendations out, each carrying its rationale and the exact change it wants to make. An LLM helps explain and prioritize — it is structurally incapable of inventing an action. The set of things that can happen to your budget is written in reviewable code, not sampled from a distribution.

Autonomy is a dial, not a switch

  • Manual — run it. Every recommendation waits for a human verdict. Day one for every campaign.
  • Assisted — have us run it. Changes that clear your guardrails (per-action spend cap, allowed channels, max daily delta) are pre-cleared for one-click operator approval; everything bigger needs a fuller human review.
  • Autonomous — let it run. On Scale, the current product executes guardrail-cleared actions for simulated campaigns inside hard limits. Live platform writes remain separately disabled until connector-specific go-live gates are armed.

The dial is per-campaign. A simulated always-on retargeting campaign can run autonomous while a new simulated brand launch stays manual. For live campaigns, the same policy model is visible today, but no vendor write occurs unless that connector's separately reviewed go-live gates are armed.

The receipts

Every acted-on recommendation becomes one immutable decision record: what was proposed and why, who or what approved it (and under which policy tier), what the vendor said when the change was applied — including failures. Failed applies are recorded, never swallowed; a double-click can't double-apply; the audit log is append-only.

That record is the difference between “the AI did something” and “on day 14, the copilot flagged an invalid-traffic signature on CTV, the operator applied the assisted policy's pre-cleared pause under the $15K cap, and here's the delivery curve after.” One of those sentences survives a client QBR.

Why this beats a smarter black box

A black box asks for trust up front and returns it as a metric. An approval rail earns trust incrementally and returns it as evidence. When the inevitable weird week happens — tracking outage, seasonal cliff, a vendor's attribution hiccup — the black box's answer is “the number moved.” The rail's answer is a decision log you can read.

Xem nó hoạt động

ArcOps theo dõi từng tín hiệu này trên toàn danh mục của bạn và đưa ra khuyến nghị để bạn phê duyệt — hoặc ủy quyền cho một chính sách. Thiết lập mất hai phút.

Nhận bài tiếp theo

Mỗi lần một phân tích, gửi vào hộp thư của bạn. Hủy bất cứ lúc nào.