Advertising
Meta ads: your AI Cofounder runs your ads inside bounds you sign.
Connect your Meta account in Settings → Advertising. Your AI Cofounder plans and manages your Meta ads — but spend stays inside the limits you sign. You set the guardrails in plain numbers, sign them, and can block every further change with one tap.
Open Settings → AdvertisingRoles
Who can do what
Only the workspace owner can connect Meta, sign the scale policy, change the spend guardrails, or flip the kill switch. Team members can read the policy but can't sign or change it.
Step 1
Connect Meta
- Open Settings → Advertising and choose your workspace.
- Click Connect Meta. This only links your Meta login — it doesn't run ads or spend anything.
- Meta asks for your permission. Armalo only requests the access connecting needs — never the right to change ads.
- Back in Armalo, choose the ad account and Facebook Page for this workspace. Armalo reads the ones your login can access.
- Click Verify ownership. Armalo confirms the ad account and Page belong to your business, then shows Connected with the date.
What each status means
- Connected — your login, ad account, and Page are linked and verified. The connection is healthy.
- Almost there — your Meta login is linked, but you haven't picked an ad account and Page yet. Pick them and verify ownership to finish.
- Needs attention — your login expired or lost permission, or Meta flagged the ad account. Nothing changes while the connection needs attention. Click Reconnect Meta to fix it; your previous choices are saved.
Disconnect
Click Disconnect, confirm, and Armalo removes the ad account and Page from this workspace and revokes its access to your Meta login. Nothing else changes.
Step 2
Sign your scale policy — the spend authority
Before your Cofounder can make any spend-increasing move on its own, you sign a scale policy: the pre-approved bounds, in plain numbers.
- Daily ceiling — the most your Cofounder may spend per day.
- Max scale step — the biggest single budget move, in percent. Never above 30% — enforced at signing, not just displayed.
- ROAS floor — only revenue Armalo can verify counts.
- Minimum verified conversions — confirmed conversions your Cofounder must see before scaling.
- Expires — 30, 60, or 90 days, or a custom date. After the expiry date the policy approves nothing.
You review the full breakdown first, then Sign this policy. Signing is the approval gate: the signature is recorded with your identity, and every spend-increasing move inside these bounds is pre-approved by you. Without a signed policy, every spend-increasing move lands in your inbox for one-by-one approval instead.
- The receipt shows the exact breakdown you attested to: version number, bounds, who signed, when, and a fingerprint proving the record hasn't been tampered with. Copy it or email it to anyone.
- Policy history lists every signed version, chained so each new version supersedes the last. Versions are never edited or deleted.
- Revoke policy stops auto-execution immediately.
Only the workspace owner can sign. Your Cofounder can never sign its own policy.
Step 3
Spend guardrails
Settings → Advertising shows the guardrail panel: the kill switch first, then the guardrails, then the full change history.
Test mode vs live mode
Every workspace starts in Test mode: your Cofounder plans changes but touches nothing. To go live, click Go live — which needs a live, signed scale policy first. An environment safeguard can only hold you in test mode; it can never push you into live.
Spending authorization ceiling
The spending authorization ceiling - a limit on new spend Armalo may authorize, across all campaigns. The loop reads the latest number at the start of each cycle, so changes take effect from the next cycle on. Set it to 0 and Armalo authorizes no new spend from that cycle on. Changing the ceiling never pauses campaigns already running at Meta and never recalls spend already committed.
Kill switch
The emergency stop. Engaging blocks every change Armalo would make to your Meta ads - pausing, activating, budget moves, all of it - starting with the next attempted change. There is no cycle to wait for, and reading your results keeps working. The switch sends nothing to Meta: campaigns already running keep running and keep spending under the budgets Meta already has, and while the switch is engaged Armalo cannot pause them for you. To stop spend already in flight, pause those campaigns in Meta Ads Manager.
- Engaging asks for a short reason, which goes into the change history. One tap: Stop all ad changes.
- While engaged, the page proves the halt: it shows how many ad changes were attempted since you engaged the kill switch — all blocked — or, if nothing has been attempted, that the guard blocks the next one automatically.
- Resuming also needs a reason, and only the owner can resume.
- Every engage, resume, mode change, and ceiling change lands in Change history: what changed, who made it, when, and why. The history is append-only — entries are never edited or deleted.
Upkeep
When the connection needs attention
Armalo checks your Meta login regularly and refreshes it before it expires, so it usually just keeps working. If a refresh fails — or Meta reports that the permission was revoked or the ad account was disabled or closed — the connection flips to Needs attention and every workspace owner gets an alert: Reconnect your Meta account.
The alert links to Settings → Advertising — refresh-failure alerts pin your workspace and highlight the reconnect step. Reconnecting runs the Meta login flow again; your ad account and Page choices are saved.
While the connection needs attention, no ad changes go out — the automation stops rather than guessing with a dead connection.
Proof
Receipts for every spend decision
Every spend-affecting decision is filed as a durable spend packet: what was decided, the mode (test or live), your verified ad account and Page, the signed policy version and fingerprint, the cost ceilings, each expected change to Meta (and whether each change can be undone), and the outcome.
A receipt email goes to every workspace owner — for decisions, policy signs and revokes, mode and ceiling changes, kill-switch flips, and scale outcomes. Each email names the decision, the mode, the policy version, the ceilings, and the outcome, and links back to Settings → Advertising. (The packet itself is always recorded in your audit trail; the email follows when email delivery is configured.)
Learning
Real revenue only — how your Cofounder learns
Meta reports conversions; Armalo doesn't take its word for it. A conversion only counts toward scaling decisions when Meta's record can be matched to a confirmed payment. Anything Meta claims but can't be matched stays observed — it's never used to judge a campaign.
- The ROAS floor in your policy is measured on verified revenue only — no attributed-conversion fallback.
- Your Cofounder must see your minimum number of verified conversions before it scales.
- Conversions Meta can't tie to a specific campaign are rolled up to the workspace — Armalo never invents campaign attribution.
Billing
Who bills what
Your ad spend is billed by Meta to the ad account you connected — the account stays in your business's name. Armalo never sees that bill, never adds a fee to it, and can't change it.
Connecting is free, and Armalo doesn't charge per seat: adding people to your workspace never changes what advertising costs.
Fair use
Fair use of the shared app
Your ads run through Armalo's shared Meta app, alongside other workspaces. So one workspace can't crowd out another, every workspace gets an hourly budget of Meta API calls (240 by default).
- If your workspace uses its budget, new Meta calls wait until the next hour. Owners get one alert per hour: Meta Ads call budget used up — “It resumes on its own — nothing to fix.”
- Only your workspace waits; everyone else is unaffected.
- Test mode counts against the budget exactly like live, so testing never gets a free pass the live system doesn't have.
FAQ
Frequently asked
Do I need my own Meta app?
No. Armalo runs one shared Meta app for all workspaces. Per-workspace Meta apps are a later enterprise option.
Does connecting spend money?
No. Connecting only links the account. Money can only move inside a signed policy, and Test mode touches nothing.
Who bills my ad spend?
Meta — to the ad account you connected, under your business's billing. Armalo never sees that bill and never adds a fee to it. Armalo doesn't charge per seat either, so adding people to your workspace never changes what advertising costs.
What if I set the ceiling to $0?
From the next cycle on, Armalo authorizes no new spend. Your Cofounder can still plan, but nothing new can be spent. Campaigns already running at Meta keep spending under their Meta budgets; pause them in Meta Ads Manager.
Can my Cofounder change my policy?
No. Signing and revoking are owner-only, and the signature records who signed. Your Cofounder works inside the policy; it can't write its own.