ott.
  • Pricing
  • Blog
  • Documentation
  • FAQ
  • Contact
Sign InStart Free Trial
ott.

The PPC analytics platform for marketing agencies. Manage Meta campaigns, track Telegram conversions, and optimize performance across all your clients.

© Copyright 2026 Ott. All Rights Reserved.

About
  • Blog
  • Contact
Product
  • Documentation
  • Pricing
  • PPC Reporting Tool
Use Cases
  • CAMPAIGN TRIAGE
  • CONVERSION & CUSTOM KPI TRACKING
  • CRYPTO & WEB3 AGENCIES
  • FOREX & PROP FIRM AGENCIES
  • HIGH-RISK & REGULATED AGENCIES
  • iGAMING AFFILIATES & OPERATORS
  • MULTI-BRAND CLIENT MANAGEMENT
  • SIGNAL PROVIDERS & COPY-TRADING
  • TELEGRAM CONVERSION TRACKING
  • TOPUP & BUDGET TRACKING
Comparisons
  • vs. Adzooma
  • vs. AgencyAnalytics
  • vs. Bïrch
  • vs. ClickGram
  • vs. DashThis
  • vs. Databox
  • vs. Looker Studio
  • vs. Madgicx
  • vs. NinjaCat
  • vs. Supermetrics
  • vs. Swydo
  • vs. TGTracker
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
MCP Ecosystem·Competitive Positioning·Regulatory Compliance·Finance Agency Operations

MCP Compliance: 7 Write Servers in One Weekend, Zero in 16 Weeks

A vendor shipped seven write-capable MCP servers in one weekend. Sixteen weeks in, mcp compliance for finance is still zero: tool proof isn't regulator proof.

By Lukas·10 min read·Sep 6, 2026

The most careful write-enabled MCP servers this market has produced shipped in a single weekend. Sixteen weeks and roughly 171 servers after the first weekly scan, mcp compliance for regulated advertising — the ability to prove what an AI assistant did to a live ad account, by whom, for which client, under which rules — is exactly where it was on June 1. Both facts are true, and the distance between them is the story.

Seven Servers in One Weekend

On August 29 and 30, a vendor calling itself Get MCP Ads (GitHub org getmcpads-com) published seven open-source MCP servers — Meta Ads, Google Ads, TikTok Ads, Pinterest Ads, Google Analytics 4, Search Console, and X Ads — all Apache-2.0, all self-hosted or gateway-hosted with your own credentials. The first went up at 20:09 UTC on Saturday. The seventh went up at 19:59 UTC on Sunday. That is not a roadmap. That is a product family shipped in roughly twenty-four hours.

It was not a repo dump. The company — BENLY HLG, a named entity with terms, privacy policy, and a contact address — launched a complete product site the same weekend: hero copy reading “Run your ads from ChatGPT or Claude,” a docs section, a pricing page, a /security page, a changelog, a comparison page against the official platform MCPs, and an llms.txt that documents the whole surface for AI clients. Six sources are marketed today (X Ads is live in the org but not yet listed; the llms.txt notes Microsoft Advertising as “not shipped yet”). The gateway publishes 195 tools over one URL, and the per-server counts are public: Meta Ads 42 tools with 10 write tools, Google Ads 41 with 7, TikTok 35 with 5, Pinterest 32 with 5, Search Console and GA4 read-only — “this one cannot write at all.”

For context on how fast the lane is moving: the week’s other big write-era signal is Ryze AI’s Google+Meta+GA4 aggregator (irinabuht12-oss/google-meta-ads-ga4-mcp), which sat at ★1,125 on August 31 and is at ★1,476 today — a 31% jump in six days that puts it ahead of Pipeboard’s Meta server (★1,241) and Google’s own official server (★915) in the tracked set. A Facebook Ad Library scraping lane is heating up (two competing servers at ★297 and ★233). The first Telegram Ads MCP appeared August 29. The write era is no longer a collection of hobby repos. It is an industry, and it is industrializing fast.

The Most Careful Write Protocol Yet

Here is the part that matters for agencies, and it is genuinely good. Get MCP Ads ships what it calls Safe Writes, and its docs page for the mechanism is the most honest description of write-side risk we have seen in sixteen weeks of monitoring:

“A write tool called without confirm: true changes nothing. It returns what it would do, in the units the platform expects, and stops. The same call repeated with confirm: true applies it.”

Two calls, every time. The first describes the change and stops — “Nothing has moved.” The second carries the confirmation, “and only then does the platform hear about it.” The homepage frames it as “Nothing changes until you say so, twice.”

The safety list goes further. Of the 195 tools, only 27 change something, and they are absent from the Free plan’s tool list and “refused if called anyway.” The gateway will not create a campaign in an active state (“Creation is always PAUSED, with no option to override it”), delete anything, duplicate a campaign or ad set, change targeting, bidding audiences, or creative content, or upload creative assets. Budget amounts above 1,000,000 units are refused outright to catch double-conversion errors. Writes are off by default per workspace. Credentials are encrypted at rest with AES-256-GCM and never leave the server — the connected assistant holds no ad token. The security page publishes its claims in three machine-readable formats (security.md, security.json) so buyers can audit the promises.

If you run ad accounts for other people, most of your operational-safety checklist is answered here. This is the most governance-conscious write surface any tracked vendor has shipped. Read that sentence again, because the next one is the point.

Proof of the Tool Is Not Proof for the Regulator

Now read their vocabulary the way a compliance officer would.

“Approval.” In Safe Writes, approval is an API parameter. The docs are explicit about why the two-call design exists: “The preview exists because a model composes these calls. It can pick the wrong account, the wrong campaign, or the wrong order of magnitude on a budget.” The second call is “the same call repeated with confirm: true“ — nothing in the documentation requires a named human to send it. On a write-enabled workspace, the same model that composed the preview can send the confirmation. That is a safety gate against model error. It is not an accountability record of who approved a change.

“Record.” The homepage promises: “Every call is recorded — Tool, account, and what came back. Yours to read.” That is a call log of what the gateway did. It is not a record of the decision layer around the call: which person approved it, which client’s money it moved, which jurisdiction’s financial-promotion rules applied, what the ad said at the time of the claim it is now being asked to support.

“Proof.” The site has a section literally titled Proof: “What is true here, and how you can check it. No customer count, no logo wall, no quote from someone who does not exist. Four guarantees the gateway enforces on every call, and six documents you can open right now and hold this page to.” Admirable — and it is proof about the product. The category a regulated agency lives in is different: proof that what ran for a client was approved by the right people, under the right rules, retrievable in a form a regulator accepts.

Same words. Two categories. Tool-level governance answers “did the tool do what the tool said?” Agency-level governance answers “who is accountable for what ran, and can you show it?” The sixteen-week scan keeps finding vendors who build the first and stop.

The absence is measurable, not vibes. A full-text scan of the Get MCP Ads homepage, pricing page, and security page returns zero hits for compliance, governance, regulation, finance, or jurisdiction. “Audit” appears exactly as two skill names — “Account audit” and “Tracking audit” — both meaning account-health review, not evidence. The vendor’s own llms.txt describes the product for someone who “needs their own advertising data.” Nothing on the surface addresses the agency that must prove what it ran to an FCA, an SEC, or a licensing body.

The Sixteen-Week Build Log

This is the sixteenth consecutive weekly check since June 1, and the ledger has not moved. The August 31 scan counted 171 unique MCP repos (152 ad-marketing-relevant, 29 created in that single week — almost all zero-star clones of the meta-ads and google-ads servers). Write capability is fully commoditized: 7 servers in a weekend, aggregators at four figures of stars, scraping lanes with competing implementations. The compliance side of the ledger contains exactly two repos — kapoost/abzu-governance (AdCP budget-cap enforcement plus an audit ledger, pushed September 3, still 0★ and unmarketed) and auditsocials/auditsocials-compliance-mcp (pre-publish content checks, 0★). Neither is finance-specific. Neither has a product behind it. Zero finance-vertical compliance MCPs with any traction. Sixteen weeks running.

None of this is an accident of immaturity anymore. The vendor that shipped seven servers in a weekend also shipped docs, pricing, a security model, and an llms.txt in the same forty-eight hours. When a market can industrialize write capability that fast, the constraint was never technical. The constraint is who pays. Write tools make the vendor money. Proof of the agency’s decisions makes the agency money — by not losing it in an enforcement action — and no tool vendor has found a way to price that back to the agency. So the market builds the tool, the tool records itself, and the agency is still on the hook for the record nobody sells.

The regulators keep supplying the context. The FCA published research on August 27 showing 44% of young investors believe AI-generated financial information is regulated — it is not — and 38% would invest on AI output alone. The same week, the SEC charged 38 entities with feigning legitimacy through false filings to lure retail investors. Google Ads now requires CFTC certification for prediction-market advertisers and bans the affiliate and signal sites around them. Every one of those enforcement surfaces is answered with the same artifact: a record of what ran, who approved it, and under which rules.

The Layer Around the Tool

A two-call confirm protocol is good hygiene, and any agency running AI-assisted PPC should keep it. But it lives inside the vendor’s session. The layer a regulated agency still has to own is the one around the tool:

  • Who approved it — every change tied to a named person, including AI agents attributed by name, not “the system.”
  • Which client and jurisdiction — an MCC or Business Manager holding many accounts is not a compliance boundary; the client engagement and its rules are.
  • The before and after — what value changed to what value, timestamped, append-only, stored independently of the platform that made the change.
  • An export path — the record in a form you would hand over in a meeting, in minutes, not weeks.

That is the data model Ott was built around: Activity Logging with actor attribution and a ~90-second export, a Budget Ledger with named approval gates, Agency Hierarchy jurisdiction tags, and Telegram conversion tracking with CAPI postbacks so the funnel baseline lives off-platform where no AI answer can rewrite it. Honest scope: Ott records the operations layer the agency owns — joins, approvals, config changes, spend decisions. It does not log inside a vendor’s gateway session, and it should not have to: the agency’s accountability is decided by its own record of decisions, not by the tool’s record of calls.

Three questions for the write era, the next time a vendor demo shows you confirm: true:

  1. When the second call carries the confirmation, who has to send it — a named human, or the agent on a write-enabled workspace?
  2. Does the tool know which of your accounts belong to which client, under which jurisdiction, before it changes anything?
  3. If a regulator asked tomorrow for every change made to one client’s campaigns in the last 90 days — who approved each one, when, and from what value to what value — what would you export, and from where?

Sixteen weeks. Roughly 171 servers. The most careful write protocol yet shipped in a weekend, and it still stops at the tool. The seventeenth weekly check lands Monday. The tool records itself. The agency’s record is still the agency’s job — and that is exactly why Ott exists.

Meta PPC analytics, built for finance agencies.

Campaign analytics, Telegram and FTD tracking, and client hierarchy in one platform. Flat pricing, no per-client fees.

Start Free TrialBook a Demo

Keep reading

MCP Ecosystem

The unit of work is named and the record of the unit of work does not exist.

AI Agent Governance Has 500 Stars. Advertising Compliance Has 1.

Sep 13, 2026Read article→
View all articles →