What to look for when choosing a Google Ads and Meta Ads tool
You are about to connect a tool to the account your monthly budget runs through. Check three things first: how it protects your data, how it makes decisions, and who has the final say on a change.
7 days of PRO free · no cardFeature lists look alike across tools. The difference shows when something goes wrong: measurement double-counts conversions, a campaign is in its learning phase, and someone in a chat says "raise the budget on what works".
This guide is a set of criteria, not a feature list, for telling a tool that helps from one that speeds up your mistakes. We illustrate each criterion with how Phanes works.
Data security: how account access is protected
An ad account access token is the key to the budget. A good tool encrypts it, keeps it out of logs and separates client data in every query. Here is how Phanes does it:
AES-256-GCM encryption
Google and Meta tokens and cached API responses are encrypted with a random 96-bit IV and an authentication tag. Without the key, production refuses to store a token.
Masking in logs
Meta and Google tokens, API keys and Bearer headers are stripped from every error message before it reaches the database.
Account isolation
Direct table access is blocked by database policies, and the application checks the account owner and the confirmed account selection on every query.
Least privilege
GA4 and Search Console are read-only. The Meta connection is protected by a one-time key in an httpOnly cookie.
Learning without exposing your data
Knowledge from many accounts is used only as an aggregate of at least 3 accounts, none with more than a 40% share. No names, no identifiers.
Many tools mention encryption only in general terms. Ask for specifics: what is encrypted, with which algorithm, and where the key is kept. In Phanes: access tokens and cached API responses, AES-256-GCM, and a key stored outside the database.
Conversion measurement: the criterion few people ask about
Most tools assume the account's conversions are real. But a GTM tag can count a conversion on every page view, two tags can count the same transaction, and a purchase can reach GA4 without a value. Optimizing on such data moves budget to where numbers are inflated, not to where the sales are.
Phanes starts with a measurement verdict, which has four states. Missing data never counts as "all OK"; the engine treats it as unverified. When measurement is suspect, conversion-based cards are not published and you see what needs fixing. If you know measurement is fine, you can mark it as correct yourself.
Decision security: where a recommendation comes from
A language model can answer differently on the same data, even at temperature 0, as model vendors themselves admit. In a draft text that is a detail; with an ad budget it is not. That is why the rules engine makes the decisions in Phanes, and every change follows the same path:
Measurement verdict
First, a check on whether conversions can be trusted.
A rule from knowledge
The recommendation follows from a specific rule and the account's numbers, and the card cites the rule.
Dry run in the API
Every Phanes query is checked against a catalog of 3,050 Google Ads API fields, and the change passes a write validator and a write test without writing (validateOnly). The button appears only once there is a validation proof.
Diff preview
You see exactly what changes: before and after.
Your approval
Nothing reaches the account without a human click. At approval the account state is checked again.
Verification and undo
After execution Phanes checks that the change went through, and you can undo it for 30 days.
This approach has a cost: Phanes sometimes declines to recommend because the data is incomplete or a campaign is in its learning phase. The reason for the refusal is visible on the card, and that beats confident advice built on bad numbers. When a recommendation does appear, it comes with a button: Phanes executes about 115 change types in Google Ads and 34 in Meta Ads through the API.
Four layers of validation before you see the button
The Google Ads API has thousands of fields and hundreds of operations, and some do not behave the way the documentation says. A tool that sends changes "to see what happens" is experimenting on your account. Phanes checks every change with four layers before anything reaches the account:
A catalog of 3,050 read fields
Every Phanes query to the Google Ads API is checked against a catalog of 3,050 fields (v24 resources, attributes, metrics and segments). A field outside the catalog is flagged before the query reaches production.
Write validator
Each of close to 150 change types (about 115 in Google Ads and 34 in Meta Ads) passes a validator that checks the operation's structure against the API contract before it is sent.
A write test without writing
At preview, Phanes sends the change to the API in validateOnly mode: Google answers whether it would accept the change, but writes nothing.
Validation proof
The button in a recommendation appears only when a stored validation proof exists for that change type. No proof, no button.
So the change you approve has already been checked by the platform's API. A rejected operation in the middle of a large change will not stop the whole campaign, because the problem shows up at preview, not in the account.
AI chat with skills, rules tool or expert engine
Typical traits of three tool categories. Specific products can differ, so ask the vendor about every point.
| AI chat with skills | User-defined rules tool | Phanes | |
|---|---|---|---|
| Same data gives the same answer | No | Yes | Yes |
| Built-in expert knowledge (hundreds of rules) | Partly | No | Yes |
| Checks measurement before recommending | Partly | No | Yes |
| Change validated in the API before approval | No | No information | Yes |
| A human approves every budget change | Partly | No | Yes |
| Undo an executed change | No | No information | Yes |
| Encryption of ad account tokens | Partly | Partly | Yes |
| History of daily metrics, not just one export | Partly | Partly | Yes |
- Yes
- Partly
- No
- No information
An AI chat with skills is a good assistant for analysis and writing. Rules tools are predictable but need an expert to design the rules. Phanes combines expert knowledge written into rules with a measurement check and a safe change path.
How to test a tool in 7 days
The best test is your own account. Here is how to use the 7 days of Phanes PRO to check every criterion in this guide.
Day 1: connect and audit
Connect Google Ads and Meta Ads, run the audit and look at the measurement verdict. It is your first answer on whether the numbers can be trusted.
Days 2-3: recommendations
Compare the cards with what you know about the account. Check that each one cites a rule, numbers and a loss amount.
Days 4-5: one small change
Approve one small change and look at the before and after diff, the verification after execution and the undo option.
Days 6-7: monitoring and reporting
Enable care, check the alerts and share analytics by link with whoever you report results to.
Five red flags
- The tool asks for your ad account password instead of OAuth sign-in.
- Budget changes can reach the account without your click, and that is the default.
- A recommendation does not say which rule and which numbers it comes from.
- Nobody checks whether conversions are counted correctly before a change is proposed.
- An executed change cannot be undone and has no visible history.
Seven questions for the vendor before you connect an account
- How do you encrypt access tokens, and do they appear in logs?
- How do you separate my accounts' data from other clients' data?
- Does my data reach an AI model, and does the model learn from it?
- What does the tool do when conversion measurement is broken?
- Will the same data give me the same recommendation?
- Who approves a budget change, and can I see the diff before clicking?
- Can an executed change be undone, and where is its history?
How do I check whether a Google Ads and Meta Ads tool is secure?
Ask about five things: how and where access tokens are encrypted, whether tokens end up in logs, how client data is separated, whether account data goes to external AI models, and whether every change needs approval and can be undone. In Phanes, tokens are protected with AES-256-GCM and a key kept outside the database, logs are masked, data is isolated by owner, Phanes's own model Aether runs on Phanes infrastructure, and you approve every change and can undo it for 30 days.
How does an AI chat with skills differ from a rules engine in advertising?
An AI chat with skills interprets instructions probabilistically, so the same data can produce a different answer. A rules engine like the one in Phanes always gives the same result for the same data, cites the rule and the numbers, checks conversion measurement first and validates a change in the API before approval.
Can I try Phanes for free?
Yes. Sign in with Google, accept the terms and you get 7 days of the full PRO version, no card required.