approval-gated-mcp
Enables management of Google Ads campaigns and budgets, including listing campaigns and proposing budget or status changes subject to human approval.
Provides integration with HubSpot for CRM operations and record management.
Provides integration with Meta Ads for campaign and budget management under the same approval-gated workflow.
Connects to WordPress to manage site content and related operations through the MCP server.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@approval-gated-mcpraise the Brand – US campaign budget to $65/day"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
approval-gated-mcp
A small, working MCP server that shows the pattern I use in production AI agents: the model can read freely, but every write becomes a plan that a person approves. Budget caps are checked when a plan is made and again when it's applied. A stale plan is refused rather than applied, undo is itself a plan, and everything lands in an audit log.
There is deliberately no approve tool. Approval happens outside the model, so the model can't approve its own plans. In this repo a person approves with a CLI. In production it's a dashboard.
▶ Watch the 2-minute walkthrough of the production version (MegaMCP)
Why
Letting an LLM change a live system (an ad budget, a CRM record, an email send) is only safe if:
writes can't happen without a human decision,
the decision is made against an exact diff,
the world can't have changed between approval and execution without being noticed,
mistakes can be reversed, and
every step is recorded.
This repo implements those five rules in about 300 lines of TypeScript, against a sandbox ad account.
Related MCP server: agent-mcp-workflow-platform
Try it
npm install
npm test # 6 tests: approval gate, budget cap, drift refusal, undo, audit, MCP surface
npm run buildAdd it to Claude Desktop, Claude Code or any MCP client (stdio):
{
"mcpServers": {
"approval-gated": {
"command": "node",
"args": ["/path/to/approval-gated-mcp/dist/server.js"],
"env": { "AGM_DATA_DIR": "/path/to/approval-gated-mcp/data", "AGM_CLIENT_NAME": "claude" }
}
}
}Then ask Claude to "raise the Brand – US budget to $65/day". You get a pending plan back:
Plan 3f2c…: Set budget to $65.00/day
Status: pending
~ Budget for "Brand – US": $40.00 → $65.00/day
Waiting for a person to approve: npm run review -- approve 3f2c…Review and decide as the human:
AGM_DATA_DIR=./data npm run review # list pending plans with diffs
AGM_DATA_DIR=./data npm run review -- approve <id> # apply (re-checks caps and drift)
AGM_DATA_DIR=./data npm run review -- reject <id>Tools
Tool | Kind | What it does |
| read | Campaigns with status, budget, spend and conversions |
| write → plan | New daily budget, blocked above the cap |
| write → plan | Pause or enable a campaign |
| write → plan | Reverse an applied plan (needs approval too) |
| read | Diff and status |
Server instructions tell the model that account data is untrusted content, never instructions, and that a change isn't live until get_plan says it's applied.
Where this comes from
I'm Austin Drake. I build production AI agents and MCP servers.
MegaMCP: a hosted MCP server and dashboard that connects Claude, ChatGPT and Cursor to Google Ads, Meta, Microsoft Ads, GA4, Search Console, Tag Manager, WordPress and HubSpot through 170+ tools. It runs this same pattern at production scale: an OAuth 2.1 authorization server for MCP clients, an AES-256-GCM credential vault, budget "bumpers", drift detection on every executor, undo, and a flight recorder. Walkthrough video.
Toolcaise: supervision for AI agents in production, covering cost per run, budget stops, human approval of sensitive tool calls, and incidents when scheduled work goes missing.
The production codebases are private. This repo is an open, minimal reference implementation of the core idea.

License
MIT
Available Tools
6 toolsget_planBRead-only
Show a plan's diff and status.
| Name | Required | Description | Default |
|---|---|---|---|
| plan_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The readOnlyHint annotation already establishes the safety profile. The description adds what is returned ('diff and status'), which is useful behavioral context beyond the annotation, but it omits auth requirements, pagination, or any detail about what the diff represents.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single six-word sentence with no waste, and the core action is front-loaded. It is appropriately sized for a simple read operation.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a one-parameter read-only tool with no output schema, the description is minimally adequate. It states the return content but does not explain how to obtain plan_id or what the diff and status mean in context, leaving gaps for an agent to infer.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not document plan_id at all. It only weakly implies that the parameter identifies a plan; no format, source, or constraints are given, so it fails to compensate for the absent schema documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Show') and resource ('a plan's diff and status'). It does not explicitly name or distinguish itself from sibling tools like list_plans, but the mention of diff and status gives enough specificity to separate it from list operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No when-to-use or when-not-to-use guidance is provided. The description only states what the tool does, leaving the agent to infer context from the name and sibling tools such as list_plans or propose_*.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_campaignsARead-only
List campaigns with status, daily budget, 30-day spend and conversions.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The readOnlyHint annotation already establishes the safe, non-mutating profile, so the description's main added value is naming the returned fields. It does not disclose scope (all campaigns vs. a plan), pagination, result caps, or ordering, which matter for a listing tool with no output schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence with zero filler, front-loaded with the verb and resource followed immediately by the payload. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description usefully enumerates the returned fields, which is exactly the gap it needs to fill. Minor omissions remain around scope and pagination, but for a zero-argument listing tool this is close to sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are zero parameters, so there is nothing for the description to disambiguate; the baseline for a parameterless tool applies. The description correctly avoids inventing arguments the schema does not support.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (List) and resource (campaigns), plus the concrete attributes returned (status, daily budget, 30-day spend, conversions). No sibling tool lists campaigns, so explicit differentiation isn't required, though it never names an alternative.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the name and the read-only listing semantics; an agent can infer this is the discovery step before propose_budget_change or propose_status_change. However, the description never states when to call it or how it relates to get_plan/list_plans.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_plansARead-only
List plans, newest first, with their status.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, so the safety profile is covered structurally. The description adds behavioral value by disclosing sort order and that status is included, but says nothing about pagination, result limits, or what 'status' values look like. With annotations carrying the safety burden, this is adequate but thin.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single tight sentence that front-loads the verb, resource, ordering, and included field. No waste, nothing to trim.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a parameterless read-only list tool with no output schema, the description covers purpose and return ordering sufficiently. Return value structure is unspecified, but the tool is simple enough that this is a minor gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters, so per the rules the baseline is 4. The description correctly implies a parameterless full enumeration, and there is no schema usage to clarify.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('List plans') and adds two useful qualifiers: ordering ('newest first') and content ('with their status'). It is clearly distinguished from write-oriented siblings like propose_budget_change, but it never explains how it differs from list_campaigns or get_plan, so sibling differentiation is incomplete.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this versus get_plan (single plan retrieval) or list_campaigns. The agent is left to infer that this is the broad enumeration tool, but no exclusions or alternatives are stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
propose_budget_changeA
Propose a new daily budget for a campaign. Returns a pending plan with a diff; a person must approve it.
| Name | Required | Description | Default |
|---|---|---|---|
| campaign_id | Yes | ||
| daily_budget | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes beyond annotations by disclosing that no change is applied immediately: it returns a pending plan with a diff and requires human approval. This is the most important behavioral fact for a mutation tool and the annotations (destructiveHint=false with no approval context) do not convey it. It stops short of describing plan persistence or expiry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the action and immediately followed by the return/approval behavior. No filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, and the description compensates by sketching the return value (a pending plan with a diff) and the approval workflow. Combined with non-destructive annotations, an agent has enough to call it safely, though parameter-level detail and preconditions remain thin.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% and both parameters are required, so the description carries the burden. It conveys only that daily_budget is the new daily budget; campaign_id semantics (format, source) and budget constraints (the schema's exclusiveMinimum > 0) are not addressed in prose.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (propose) and resource (new daily budget for a campaign), making the operation unambiguous. It does not explicitly contrast with the sibling propose_status_change or propose_undo, but the budget-specific resource is distinctive enough for an agent to route correctly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage through the approval note ('a person must approve it'), which signals this is the non-committal, review-first path, but it never states when to prefer this over alternatives or what preconditions exist (e.g., campaign must exist, valid budget range).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
propose_status_changeA
Propose pausing or enabling a campaign. Returns a pending plan; a person must approve it.
| Name | Required | Description | Default |
|---|---|---|---|
| status | Yes | ||
| campaign_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare readOnlyHint=false and destructiveHint=false, which alone would not tell the agent that nothing changes immediately. The description adds the crucial behavioral fact that this returns a pending plan requiring human approval, materially improving the agent's understanding beyond structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the action and followed by the key behavioral consequence. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, and the description does tell the agent the return is a pending plan. However, it leaves the workflow incomplete — nothing about how to retrieve or act on the plan, and no parameter detail for a 2-required-parameter tool with 0% schema coverage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% and both parameters are required, yet the description says nothing about campaign_id format or the meaning of the ENABLED/PAUSED enum values beyond what the schema already shows. With no schema prose to lean on, the description fails to compensate for the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (propose) and resource (campaign pause/enable status), and adds the outcome that a pending plan is produced. The resource naming naturally separates it from propose_budget_change and propose_undo, though it does not explicitly name those siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage via the approval workflow ('a person must approve it'), but gives no explicit when-to-use or when-not-to-use guidance, and does not point to get_plan/list_plans for tracking the resulting plan.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
propose_undoA
Propose reversing an applied plan. The undo is itself a plan that needs approval.
| Name | Required | Description | Default |
|---|---|---|---|
| plan_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=false and destructiveHint=false, so the safety profile is partly covered. The description adds genuine context beyond that: the undo is not executed directly but is a proposal requiring approval, which explains why a write-hinted tool is non-destructive. It still omits what happens on rejection or who approves.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, the core action front-loaded and the important workflow caveat second. No filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a one-parameter proposal tool with no output schema and annotations covering the safety profile, the description supplies the essential non-obvious fact (approval-gated undo). Only the meaning of the response and approval flow are left unstated, which is minor here.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% and the single param plan_id is undocumented, but the description's use of 'an applied plan' implies plan_id identifies which plan to reverse. It doesn't confirm the identifier semantics or the expected format, leaving a small gap over the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('propose reversing an applied plan'), which is clearly distinct from the sibling propose_budget_change and propose_status_change. It stops short of naming those alternatives, so the differentiation is implicit rather than explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The line 'The undo is itself a plan that needs approval' implies this is the entry point for reversing an applied plan and that a separate approval step follows, but it never states when to use this versus alternatives (e.g., get_plan to inspect first) or any precondition like the plan having actually been applied.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.1.0- First observed
get_plan - First observed
list_campaigns - First observed
list_plans - First observed
propose_budget_change - First observed
propose_status_change - First observed
propose_undo
TDQS
Scored across 6 tools
Each tool targets a distinct resource or action: listing campaigns vs. plans, proposing budget/status/undo changes, and fetching a single plan. There is no meaningful overlap or confusing boundary between tools.
All names use snake_case with a small set of predictable verb prefixes (list_, propose_, get_). The pattern is consistent throughout, including propose_budget_change, propose_status_change, and propose_undo.
Six tools is well-scoped for an approval-gated campaign change server. Each tool covers a necessary read or propose operation, and none feels redundant or missing at the count level.
The surface covers listing campaigns, proposing budget/status changes, proposing undos, and inspecting plans. It is strong, but if the server is meant to support broader campaign changes, other proposal types (e.g., creative or targeting) would be needed.
Maintenance
Related MCP Connectors
Google Ads MCP with 20,000+ account peer context and staged approve-then-execute writes.
Google Ads MCP: reports, search terms, negatives, budgets, campaigns. Approval on every write.
Read-only MCP for identity resolution and write guardrails.
Hosted Google Ads MCP: build Search campaigns and make only the changes you approve, with undo.
Related MCP Servers
- AlicenseAqualityBmaintenanceAn MCP server that extends the official Google Ads MCP with safe, confirmed campaign administration across manager accounts, featuring immutable mutation plans, multi-step approvals, and post-write verification.8Apache 2.0
- FlicenseNot gradedqualityCmaintenanceEnables approval-gated incident response workflows that gather evidence through read-only MCP tools, perform idempotent writes, and preserve a durable audit trail.-
- AlicenseAqualityAmaintenanceAn MCP server that enables safe, audited mutation of Google Ads campaigns—creating ads, ad groups, keywords, and assets or adjusting budgets and statuses—with a dry-run default and an optional guarded remove operation, plus read-only Keyword Planner ideas.221MIT
- AlicenseAqualityCmaintenanceEnables policy-governed MCP interactions with deterministic authorization, tenant isolation, minimized PII exposure, and human approval gates for sensitive mutations, while producing structured audit events.3MIT