Explainer · 2 min read · Updated
Read-only or write access? How to let an AI near your marketing accounts
Reading your data is low-risk. Changing a live ad budget or publishing a page is not. Here is which servers do what, and the controls vendors give you.
By the editors of Best Marketing MCPs.
Disclosure: the publisher of this site has commercial relationships with some of the companies whose products we rank. Read our full disclosure.
Why it matters
Assistants are good at following instructions, including bad ones. A tool that can write gives a mistaken or manipulated request real consequences: a paused campaign that unpauses, a page that publishes early, a contact list that changes.
Who can change what
| Server | Can change | Built-in control |
|---|---|---|
| Semrush, DataForSEO, Google Analytics, Google Ads | Can changeNothing in your accounts (per documented tools) | Built-in controlRead-only by design |
| Search Console (mcp-gsc) | Can changeSitemaps and properties | Built-in controlReview each tool call |
| Meta Ads | Can changeCampaigns, ad sets, ads, catalogs | Built-in controlAds MCP server rules set by portfolio admins |
| Klaviyo | Can changeCampaigns, profiles, segments, templates | Built-in controlread-only=true in the URL |
| HubSpot | Can changeCRM records, campaigns, CMS pages, email drafts | Built-in controlEach user’s HubSpot permissions |
| Webflow, Wix | Can changeSite design, content and publishing | Built-in controlPlatform roles and permissions |
| Dance (both connectors) | Can changeDrafts and previews; live changes only after approval | Built-in controlApproval checked by Dance, not by the model |
Details and sources are on each profile.
A sensible order to switch things on
- Start with read-only servers on the accounts you already use.
- When you add a writer, use its narrowest mode first, such as Klaviyo’s read-only flag.
- Keep your assistant’s per-tool confirmations on for anything that publishes, spends or sends.
- Set platform rules where they exist, such as Meta’s ads MCP server rules.
- Prefer servers that make drafts and require explicit approval before going live.
Watch for instructions hidden in content
Web pages, reviews and customer replies can contain text written to steer an AI. Klaviyo lets you disable tools that read customer-written content. Dance’s documentation says fetched website content is treated as evidence, never as instructions. Elsewhere, read what a tool is about to do before approving it.