# AI Facebook ads safety: why we never auto-activate

> AI Facebook ads safety in Tempomat: every campaign is built paused, and nothing spends until a person with the right role approves it.

*Product · By The Tempomat team · Published Oct 4, 2026* · https://tempomat.tech/blog/paused-by-default

AI Facebook ads safety comes down to one rule in Tempomat: the agent can build a campaign, but it can't spend money. Every campaign, ad set and ad is created paused in your Meta account, and it only goes live when a person with the right role confirms the brand, the ad account and the budget.

## What does paused by default mean?

**Paused by default** means every ad object Tempomat creates on Meta starts with the status PAUSED. That covers campaigns built from chat, campaigns from the [Campaign Builder](https://tempomat.tech/features), every row of a Bulk Launch, and copies made with "duplicate". A paused campaign is real: it sits in Ads Manager with its targeting, budget and creative, and you can open it there. It just doesn't deliver, so it costs nothing.

The build itself runs step by step: campaign, ad set, media upload, creative, ad, then a final check. Each step is recorded with its Meta ID. If Meta rejects step five, steps one to four stay paused in your account, the card says what failed in plain words, and Retry starts again from the failed step without creating a second campaign.

> **There is no auto-activate setting:** Not hidden in settings, not on a higher plan. Turning a campaign on is always a separate, explicit action by a person.

## Why don't we let the AI turn campaigns on?

Because the two mistakes don't cost the same. If the agent builds a campaign you don't want, you delete a paused draft. If it turns on a campaign you didn't mean to run, you pay for the impressions before anyone notices. A language model can misread a budget, pick the wrong ad account in an agency workspace, or take an instruction from text it was only meant to read. None of that should reach your card.

So we split the work. The agent does the slow part: it asks for what is missing, picks the Page and pixel, writes the names, uploads the media and waits for Meta to process a video. You do the fast part, which is reading four facts and clicking one button. The click takes seconds; it is also the moment someone who knows the business looks at the budget.

Meta adds its own step after yours. Its help center says ads are reviewed against Meta's Advertising Standards before they run, and that "most ads are reviewed within 24 hours" ([Meta Business Help Center, About ads in review](https://www.facebook.com/business/help/204798856225114), checked on 2026-10-04). That review checks policy, not whether the budget is the one you meant. Ours checks the budget.

## What does an approval look like?

There are two doors to the same check, and both end in the same server code that writes to Meta.

1. **From a page.** On a campaign built with us, Activate opens a confirm dialog titled "Turn on this campaign?". It lists the brand, the ad account (name and ID), the campaign name and the daily budget, and notes that Meta will review the ad before it runs. Escape doesn't close it; only Cancel or Turn on does.
2. **From chat.** If you type "turn it on", the agent can't do it directly. It asks for approval, and the chat shows an approval card marked "This starts spending." Nothing happens until someone approves it.
3. **After the click.** The ad, then the ad set, then the campaign are switched to ACTIVE, and the card shows Meta's status, often "In review" at first.
4. **On the record.** Every change is written to the [Activity Log](https://tempomat.tech/features) with who approved it and the approval reference, so you can trace any live campaign back to a person and a moment.

One more guard sits under both doors. If an ad links to a store product that is a draft, hidden, archived or gone from your Shopify, YouCan or Lightfunnels store, turning it on is refused: the link would land on a dead page. An out-of-stock product only shows a warning, because waitlist and pre-order ads are real.

## Who can approve spend in a workspace?

Approving spend is a permission, not a button anyone can press. It is checked again at the moment of the click, from the database, so a role changed a minute ago already counts.

*Who can turn campaigns on and change budgets*

| Role | Build paused campaigns | Turn on, change budgets, approve AI Actions |
| --- | --- | --- |
| Owner | Yes | Yes |
| Admin | Yes | Yes |
| Member | Yes | Only if the workspace setting "Members can activate campaigns" is on |
| Viewer | No | No |

For agencies this means a junior buyer can prepare ten campaigns for a client and an admin turns on the two that are ready. The brand is shown on every confirm dialog and approval card, so nobody approves a budget for the wrong client by accident.

## Which other actions need a person's yes?

The same rule covers anything that spends money or that a customer would notice. Reading data never asks; building something paused never asks; going live always does.

*What asks for approval*

| Action | What happens |
| --- | --- |
| Turn on a campaign, ad set or ad | Approval every time |
| Change a budget | Approval every time |
| Pause from chat | Asked the first time in a conversation (pausing stops spend) |
| Approve an AI Action | A pause runs when you click Approve; a budget change opens the confirm dialog first |
| Undo a pause approved from AI Actions | Possible for 10 minutes, through the same confirm dialog |
| Start a Meta A/B test or enable an automated rule | Approval (rules are created switched off) |
| Generate media costing 20 credits or more in chat | Approval, with the cost shown first |
| Publish a product, change a live product's price, update an order | Approval on your store connection |

This is what makes it safe to give the agent real tools. It can explore your account with Meta's own Ads MCP server, which we connect read-only, and it writes only through our own tools, each one tagged read, build or spend. If you want the longer list of what the agent can do, the [features page](https://tempomat.tech/features) has it, and [what a credit buys](https://tempomat.tech/blog/what-a-credit-buys) explains the costs you see before any job runs.

**Paused by default, in short**

1. Everything is created paused in your Meta account.
2. Going live is one explicit click by a person.
3. The dialog shows brand, ad account, campaign and budget.
4. Only owners and admins approve spend, unless you allow members.
5. Every approval is in the Activity Log.

## Frequently asked questions

**Can Tempomat turn on my Facebook ads automatically?**

No. Tempomat creates every campaign, ad set and ad paused. Turning one on needs a person with the right role to confirm it, either in a confirm dialog or on an approval card in chat. There is no setting that switches this off.

**Does a paused campaign cost anything?**

No. A paused campaign doesn't deliver, so Meta doesn't charge for it. It stays in your ad account with its settings until you turn it on, edit it or delete it.

**Who can approve a budget change?**

Owners and admins of the workspace. Members can too, but only when an owner or admin switches on "Members can activate campaigns". Viewers never can. The role is checked again at the moment of the click.

**What happens if a campaign build fails halfway?**

What was created stays paused in your account, the card explains what failed, and Retry continues from the failed step. Nothing is created twice and nothing goes live.

**Does Meta still review my ads?**

Yes. After you turn a campaign on, Meta reviews the ad against its Advertising Standards. Meta says most ads are reviewed within 24 hours.

**Let the agent build. You decide what runs.** Connect your Meta account, build a campaign from one message, and turn it on when you're ready. Plans and limits are on the [pricing page](https://tempomat.tech/pricing).

[Start your 7-day free trial](https://app.tempomat.tech/signup)
