All posts

ads_management vs ads_read: why many ad tools can read your campaigns but not change them

ads_read lets a tool report on Meta ad accounts; ads_management lets it change them. What App Review asks for, what a declined permission looks like from the inside, and how Google, LinkedIn and Snapchat draw the same line.

overads team10 min readPublished
Title card on a dark, misty photograph: the overads wordmark, the label Paid media, and the headline ads_management vs ads_read: why many ad tools can read your campaigns but not change them

TL;DR

  • ads_read lets an app pull ad reports for the Meta ad accounts it can reach; ads_management lets it read them and also create and manage campaigns. A tool used by other businesses needs each one approved separately in Meta App Review, after Business Verification.
  • Meta asks for an unapproved permission only from people with a role on the app. Everyone else connects without it, sees no error, and the gap shows only when the tool tries to change something.
  • In its App Review decision of July 28, 2026, Meta approved ads_read and business_management for overads and declined ads_management. overads reads Meta, Google and Snapchat ads read-only and proposes changes that a person applies.
  • LinkedIn splits read (r_ads) from write (rw_ads). Google Ads and Snapchat each have one scope that allows both, so on those two the advertiser's lever is the role of the person who connects the tool.
  • Before connecting an ad tool, check which permission it asks for, connect it from the narrowest role that still works, and know where to remove it: Business integrations on Facebook, linked apps in a Google Account.

What ads_read and ads_management allow

ads_read and ads_management are the two Meta permissions an outside app uses to work with ad accounts: ads_read covers reporting, and ads_management covers reporting plus changes. Meta's permissions reference, updated September 29, 2026, defines both. ads_read gives an app the Ads Insights API, which returns report data for ad accounts the user owns or has been given access to. ads_management lets an app both read and manage those ad accounts.

ads_read and ads_management side by side, from Meta's permissions reference, read October 5, 2026
Questionads_readads_management
What it allowsPull ad report data through the Ads Insights API, and send web events from a server through Meta's server-side APIRead and manage the ad account
Allowed usage Meta listsCustom dashboards and data analytics; sending web eventsCreating campaigns, managing ads and fetching metrics; building ad management tools
Permissions it depends onNonepages_read_engagement and pages_show_list
Screencast Meta asks forThe login, a business reaching its ad data, and metrics such as impressions, spend and clicks on screenThe same three steps
Needed to serve other businessesAdvanced Access, through App ReviewAdvanced Access, through App Review

Two details in that table are easy to miss. ads_read is not purely passive: Meta's reference says it also lets advertisers send web events from their servers to Facebook, so a reporting permission can carry data in as well as out. And the screencast requirements for ads_management repeat the ones for ads_read word for word, all about showing performance data. Meta's App Review tutorial adds the general rule: recordings must show actions that require the permission requested, and a permission without a recording will not be approved.

The same reference now lists a third ads permission, ads_mcp_management, which lets an app reach Meta's ads Model Context Protocol server so AI agents can create and manage campaigns and read reports for advertisers.

How Meta decides which apps get each permission

Meta lets an app use ads_read or ads_management for people outside its own team only with Advanced Access, which Meta grants one permission at a time through App Review, after Business Verification. Meta's access levels page sets out the split. Every Business app gets Standard Access automatically, but a permission with Standard Access can only be requested from people who have a role on the app, such as its admins, developers and testers. Advanced Access lets the app request the permission from anyone.

The App Review process page says Meta's reviewers test the app itself. If they can test the app but cannot test the feature that needs a permission, that permission is not approved. For a tool that will serve other businesses' ad accounts, Meta's pages describe this path:

  1. Build and test with Standard Access, which works for people with a role on the app.
  2. Complete Business Verification for the business that owns the app.
  3. Make at least one successful API call with each permission within 30 days before submitting.
  4. Record a screencast for each permission that shows the login and the actions that use it.
  5. Tell reviewers how to reach the app. Meta tests with its own test accounts and asks applicants not to share personal credentials.
  6. Submit, and wait for the decision. The tutorial says it should arrive within a week.
  7. Separately, move the Marketing API Access Tier from Limited to Full access, which needs at least 500 Marketing API calls in the last 15 days and an error rate under 15% across the last 500 calls.

The last step is about volume, not permission. Meta's Marketing API authorization page, updated May 5, 2026, says Limited access is heavily rate-limited and meant for development, not for apps serving live advertisers. The page also notes that Meta renamed the tiers: what it called Standard Access for this feature is now Limited access, and Advanced Access is now Full access.

What happened when overads applied

Meta approved ads_read and business_management for overads and declined ads_management, in an App Review decision dated July 28, 2026. That one decision is why overads' ad-account access is read-only today.

What the decline looks like in practice is the useful part:

  • The login does not fail. overads' Meta connection asks for both ads_read and ads_management. Because ads_management has only Standard Access, Meta asks for it only from people with a role on overads' Meta app. Every customer's connection comes back holding ads_read alone, with no error.
  • The gap shows up later. A connection without ads_management can read every report. A change sent through it would come back refused: Meta's Graph API error guide lists codes 200 to 299 as permission errors, meaning a permission was never granted or has been removed.
  • Approval is per app and per permission. overads runs separate Meta apps for ads and for publishing. On the same date, Meta renewed pages_read_engagement for the ads app and declined it for the publishing app.

overads handles this by reading which permissions each connection actually holds from Meta, rather than trusting the list it asked for. A change the connection was not granted is refused before anything is sent, and the change controls are switched off in production. The overads channel hub states the same thing for each connection. This article does not guess at the reviewers' reasons.

How Google, LinkedIn and Snapchat separate reading from changing ads

Google Ads, LinkedIn and Snapchat each draw the line between reading and changing ads in a different place. LinkedIn draws it in the permission, as Meta does. Google draws it in the developer's approved use. Snapchat leaves it to the role of the person who connects the tool.

Where four ad platforms separate reading ads from changing them, from each platform's developer docs, read October 5, 2026
PlatformRead-only permissionPermission that can change adsWhat the developer needs firstRead-only role for the person connecting
Metaads_readads_managementApp Review for each permission, after Business VerificationPartial access with View performance
Google AdsNone: one scope, adwords, covers bothThe same adwords scopeA developer token access level; at Standard access, a Reporting permissible use limits the tool to read-only callsRead-only access level
LinkedInr_ads and r_ads_reportingrw_adsApproval for the Advertising API, which comes with bothViewer (allowed r_ads only)
SnapchatNone: one scope, snapchat-marketing-api, covers bothThe same scopeAn Organization Admin creates the OAuth app in Snap Business ManagerReports role

Google Ads. Google's OAuth guide for the Google Ads API names a single scope for the API, and Google's list of OAuth scopes describes it as access to "see, edit, create, and delete" Google Ads accounts and data. So a reporting tool and a bidding tool ask for the same consent. The read-only limit Google offers sits with the developer: its access levels page, updated September 30, 2026, lists four access levels (Test, Explorer, Basic and Standard). Its permissible-use section applies to Standard access only, and its Reporting use limits a project to search requests and other read-only calls.

LinkedIn. LinkedIn's Marketing API key concepts define rw_ads as managing and reading a member's ad accounts, limited to members with a billing admin, account manager, campaign manager or creative manager role. r_ads reads ad accounts and also works for the Viewer role. LinkedIn's access page lists both among the permissions that come with approval for the Advertising API.

Snapchat. Snapchat's Marketing API authentication page says its one scope lets an app read and write, and that the access token reflects the user's own permissions. Its roles page defines a Reports role with read-only access to an ad account.

On every platform, the person's role caps what any tool can do through them. Meta's task-based access table gives View performance the right to view ads and access reports, but not to create or edit ads. Google's account access levels let a Read-only user view campaigns and run performance reports, while only Standard and Admin users can edit campaigns.

Is read-only ad access safer?

Read-only ad access is safer in one specific way: a tool that cannot write cannot pause a campaign, launch an ad or raise a budget, whether through a bug, a bad suggestion or a leaked token. How firmly that holds depends on who enforces it:

  • Enforced by the platform. On Meta, a token without ads_management cannot change ads. On LinkedIn, a token without rw_ads cannot either.
  • Enforced by the tool's code. On Google Ads and Snapchat, a reporting tool usually holds a scope that allows changes. Unless its developer token is limited to Reporting, its read-only status is a choice in its code.
  • Enforced by your own role. On all four platforms, connecting a tool from a read-only role limits it to reading, whatever scope it holds.

Read-only access has costs too. A tool that cannot write cannot act at night or at the moment a campaign goes wrong; a person has to make every change. And read access still exposes spend and results, so the usual checks on who can see a client's numbers still apply.

How changes get made when a tool cannot write

When an ad tool cannot write, a change moves from the tool to a person: the tool proposes it, and someone with an editing role makes it in the platform's own ad manager. The handoff usually runs in four steps:

  1. The tool names the campaign, ad set or ad and the figure behind the suggestion.
  2. A person checks it against context the tool does not have, such as a launch date, a stock problem or a test still running.
  3. That person makes the change in Meta Ads Manager, Google Ads or Snapchat's ads manager, from a role that can edit.
  4. The tool sees the result on its next data sync.

For changes that should happen without a person, the platforms' own automated rules run inside the platform and need no third-party write access. Automated rules in Meta Ads Manager check campaigns, ad sets and ads against conditions you set, then notify you or act, for example by pausing an ad or raising a budget. Google Ads automated rules can change ad status, budgets and bids. Our guide to human in the loop AI for marketing covers which changes are worth leaving to a person.

What to ask any ad tool before connecting it

Five questions show what an ad tool can do in your accounts before you connect it:

  1. Which permissions or scopes does it request? On Meta, ads_management means it can change ads. On Google Ads and Snapchat every tool's scope allows changes, so ask what its code actually calls.
  2. Which of those has the platform approved? A Meta permission without Advanced Access works only for people on the developer's own team.
  3. Does a change need a person to confirm it? Ask whether the tool shows the exact change first and keeps a record of who approved what.
  4. Does it work from a read-only role? If the tool only reports, ask whether it runs when connected from Meta's View performance access, Google's Read-only level, LinkedIn's Viewer role or Snapchat's Reports role.
  5. How do you remove it? On Facebook, the business integrations settings list every connected tool with a Remove button; a removed tool can no longer manage your ads but may keep information it already had. In a Google Account, the linked apps page has a Remove access button.

Where overads fits

overads fits a team that wants to read Meta, Google and Snapchat ads in one place and keep every change in a person's hands. overads Ads manager reads those three platforms read-only and proposes changes, each linked to the campaign it refers to, for a person to apply in the platform's own ad manager. The platforms overads connects differ in depth: Meta and Google sync campaigns, ad sets and ads, while Snapchat syncs at the account level only. The LinkedIn and X ad connections are built, and no data flows from them yet.

The read-only limit has two sources in overads. On Meta it is Meta's: customers' connections hold ads_read only, after the July 28, 2026 decision. On Google and Snapchat it is overads' own: its Google connection uses Google's only Ads scope, which Google describes as "see, edit, create, and delete", and its Snapchat connection uses Snapchat's single read-and-write scope, but overads' code calls only their read endpoints. overads workflows follow the same rule: when one decides a campaign should be paused, it proposes the change and someone applies it.

overads does not fit a team that wants software to apply changes on its own. It cannot pause, edit or launch an ad or change a budget on any platform. For that, the platforms' own automated rules run without a third-party tool, and a tool that has passed Meta's review for ads_management can write on Meta. Our comparison of cross-platform ad management tools sets out what else is available.

Frequently asked questions

Does an app need App Review to manage only its owner's ad account?

No. Meta's Marketing API authorization page says standard access to ads_read and ads_management is enough for an app that manages only your own ad account. Advanced access is needed to manage other people's ad accounts.

Can a Google Ads tool at Explorer or Basic access change campaigns?

Google's access-level page restricts Explorer projects from account creation, user management, planning and billing services, not from campaign changes, and its read-only Reporting use applies only to Standard access. So at Explorer or Basic access, only the user's role or the tool's own code keeps a tool read-only.

How long does Google take to review a Google Ads API developer token?

Google's access-level page gives a typical review time of 10 business days for Standard access, which involves a manual audit. It says Google may upgrade a project to Explorer or Basic access automatically after the application.

Sources

  1. Permissions Reference for Meta Technologies APIs. Meta for Developers. Accessed Oct 5, 2026.
  2. Access Levels. Meta for Developers. Accessed Oct 5, 2026.
  3. Marketing API: Authorization. Meta for Developers. Accessed Oct 5, 2026.
  4. App Review process. Meta for Developers. Accessed Oct 5, 2026.
  5. App Review tutorial. Meta for Developers. Accessed Oct 5, 2026.
  6. Graph API: Handling errors. Meta for Developers. Accessed Oct 5, 2026.
  7. Business portfolio assets and their task-based access settings. Meta Business Help Centre. Accessed Oct 5, 2026.
  8. How do I edit the privacy and settings for my business integrations or remove them from Facebook?. Facebook Help Centre. Accessed Oct 5, 2026.
  9. About automated rules in Meta Ads Manager. Meta Business Help Centre. Accessed Oct 5, 2026.
  10. OAuth 2.0 internals for Google Ads API. Google for Developers. Accessed Oct 5, 2026.
  11. OAuth 2.0 Scopes for Google APIs. Google for Developers. Accessed Oct 5, 2026.
  12. Access levels and permissible use. Google Ads API. Accessed Oct 5, 2026.
  13. About access levels in your Google Ads account. Google Ads Help. Accessed Oct 5, 2026.
  14. Manage links between your Google Account and apps from other developers. Google Account Help. Accessed Oct 5, 2026.
  15. Set up automated rules. Google Ads Help. Accessed Oct 5, 2026.
  16. LinkedIn Marketing API: Key Concepts. Microsoft Learn. Accessed Oct 5, 2026.
  17. LinkedIn Marketing API: Increasing Access. Microsoft Learn. Accessed Oct 5, 2026.
  18. Marketing API: Authentication. Snap for Developers. Accessed Oct 5, 2026.
  19. Marketing API: Roles. Snap for Developers. Accessed Oct 5, 2026.

Drafted with AI assistance, then checked against primary sources and the product itself by the overads team.

Read Meta, Google and Snapchat ads in one place

overads Ads manager reads your ad accounts read-only and proposes changes for a person to apply in each platform's own ad manager.

Start free