Skip to content

Guarded Autopilot

Automation you can hand to a client without losing sleep

Autopilot is not a rules engine with API keys. Every change begins as a typed proposal, passes a policy check, is previewed where the provider allows it, executes against a bounded object set and is verified by a follow-up read.

  • Risk tiers

    What may run unattended

  • Spend exposure caps

    Daily and per workspace

  • Blackout windows

    Launches and client freezes

  • Verify and roll back

    Follow-up read, then reversal

Decorative scene description: connected terrain zones for paid media, SEO and GEO, conversion rate optimisation and revenue outcomes send data streams into a central ABP.Marketing intelligence core.

Value

What changes for your team in the first month

Each claim below maps to a surface in the product and to a record you can open.

Automate the safe work, escalate the rest

Risk tiering separates reversible, bounded changes from material ones, so routine hygiene runs while judgement calls still reach a human.

Tier and route shown on every proposal before it runs

Give clients a control surface, not a promise

Caps, permitted action types, execution hours, approvers and blackout windows are configured per workspace and visible to the client in their portal.

Policy changes recorded in the audit trail

Prove what happened, every time

Each execution stores the exact request, the provider response, the verification read and the actor, so a change can always be explained after the fact.

Receipts are immutable and exportable

Governance

What the system actually does

  • Risk tiers decide what can run unattended and what always needs a human.
  • Spend exposure caps limit how much budget any automated change can move per day and per workspace.
  • Approval matrices route material actions to the right internal or client approver.
  • Blackout windows stop changes during launches, sales periods or client freezes.
  • Every execution produces an immutable receipt: request, response, verification and actor.
  • Reversible actions roll back automatically when verification fails or a performance threshold is breached.

Capabilities

Built as a governed workflow, not a dashboard

Every capability produces an auditable record: what was observed, what it was compared against, what was proposed and what happened next.

Policy

Workspace policy engine

Per-workspace policy defines eligible action types, tiers, caps, approvers, expiry windows and required evidence thresholds.

Safety

Preview and validate

Where the provider supports it, ABP.Marketing runs a preview or validate-only request and shows the projected provider response before execution.

Recovery

Verification and rollback

After execution the provider state is read back. Mismatches and threshold breaches trigger reversal and an alert to the owner.

Demo

A receipt that survives the awkward client question

Approval, bounds, request, response, verification and outcome are stored as one immutable record per execution.

Execution receipt

Illustrative interface
Action type
Pause ad group · reversible
Bounds
1 object · no budget change · expires in 24h
Policy check
Passed — within tier 1 and daily exposure cap
Approved by
Named approver · client role · 09:42
Provider response
Accepted · request ID stored
Verification read
State confirmed paused at 09:47
Rollback
Available · prior state recorded
Illustrative only. Nothing is shown as executed until a provider accepted the request, and nothing is shown as verified until a follow-up read confirms the state.

Evidence model

Every finding shows its working

Authorisation
Who approved, when, on what evidence, and for how long.
Bounds
Object set, permitted values, spend exposure and expiry timestamp.
Provider response
Raw accepted response stored with the receipt, secrets redacted.
Verification
Follow-up read result and pass or fail status.

Boundaries

What we will not claim

  • No external action can bypass the proposal, policy and audit layers.
  • The language model has no unrestricted database access and no generic provider call tool.
  • Nothing shows as executed until the provider accepted the request.
  • Autopilot can be paused instantly per action type, workspace, tenant or provider.

Objection handling

Objections, answered directly

See it against your own accounts

Connect a read-only workspace and we will walk the Outcome Graph, the reconciliation and your first findings with you.