AgentXray Blog

AI Drafts, You Approve: The Airlock Between Your Assistant and Your Amazon Account

AI Drafts, You Approve: The Airlock Between Your Assistant and Your Amazon Account

TL;DR

How AgentXray lets your own AI draft Amazon PPC changes — bids, budgets, negatives, campaign state — while a token-level airlock makes it technically unable to apply any of them.

> ✨ **AI-assisted research, automated editorial review by Avanta Global EOOD.** [Learn more](/disclosure)

![AI Drafts, You Approve: The Airlock Between Your Assistant and Your Amazon Account](/blog/images/ai-drafts-human-approves-amazon-ppc-airlock/hero.png)

Every Amazon PPC tool eventually makes the same offer: hand us the keys, and the algorithm will manage your bids. Some sellers accept and stop looking at their campaigns. Many more refuse, because they have watched an "optimizer" cut the one campaign that was quietly carrying the account — and they would rather spend Sunday evening in a bid console than find out on Thursday what a rule did on Monday.

We think both camps are responding to the same design flaw. The problem was never automation. The problem is that the tools ask for trust *up front*, before any individual change can be inspected, and settle accounts *afterwards*, if at all. So we built the opposite shape, and this post explains it properly: what the airlock is, why it is enforced with tokens rather than promises, and what happens to a change after you let it through.

## The shape: your AI drafts, your browser approves

When you connect your own AI assistant to AgentXray [over MCP](/connect), it gets 19 tools. Thirteen of them read: your measured profit, your fees as Amazon actually posted them, Buy Box history, inventory age, advertising performance down to the search term. Six of them write — and this is the part that matters — **none of the six writes to Amazon. Each one produces a draft.**

Ask your assistant to cut a bid, add a negative keyword, change a budget, pause a campaign, update a listing, plan a shipment — it can draft all of those. The draft lands in a queue in your AgentXray panel. It sits there, doing nothing, until you open it in your browser and approve or reject it. Approval is the only path by which anything reaches Amazon.

This is not a settings toggle we hope stays on. It is the architecture.

## Two keys, and the assistant only holds one

The obvious objection: every tool *says* the AI can't act without permission, and permission systems have a way of eroding — a scope too broad here, a convenience flag there. So the honest question to ask any vendor is not "does a human approve?" but "**what, technically, stops the machine from approving?**"

Our answer: the credential that creates a draft and the credential that applies one are different keys, held by different parties.

- The MCP connector token — the thing your assistant holds — authenticates the drafting endpoints and the thirteen read tools. Presented to the approval endpoint, it is rejected as unauthenticated. Not "forbidden but recognised" — rejected outright.
- The approval endpoint accepts only a logged-in browser session. That session exists on your machine, behind your login, and is never given to the assistant.

We didn't take this on faith from our own design docs. We tested it against the live production server: took a real, valid connector token, pointed it at the approval endpoint, and confirmed the rejection. That check now lives in our test suite and runs before every deploy. If a code change ever lets a connector token approve its own draft, the deploy fails before it reaches the server.

The practical consequence for a seller: you can let an AI reason about your account as aggressively as you like, because the blast radius of a wrong idea is a draft you delete.

## Priced, not suggested

A draft queue would still be a chore if every draft were a bare "raise bid to $1.40." The reviewing human needs to know what the change costs, and that number is different for every seller.

So every PPC draft is priced against **your own settlement history** — the fees Amazon actually deducted from your account, per unit, not a category fee table. From those fees and your product cost, AgentXray derives your contribution per unit and, from that, the break-even cost-per-click for the target in question. The draft arrives carrying that arithmetic: here is the proposed bid, here is your measured break-even, here is the gap between them.

And when the arithmetic can't be done — no unit cost saved for the SKU, or too little settled history to measure the fee — the draft says **unpriced**, in those words. It does not substitute an industry average and call the change safe. An unpriced draft is a prompt to go add your product cost, not a smaller promise.

## Warnings, never blocks

Here is a design decision we made deliberately and expect some people to disagree with: a draft whose economics look bad is still approvable. The panel will warn you — this bid exceeds your measured break-even — and then it will let you do it anyway.

Because sellers act above break-even on purpose, for reasons no measurement layer can see: launching a product, clearing stock before long-term storage fees, buying rank into a seasonal peak. Software that blocks those moves isn't protecting you; it is overruling you with less information than you have. The only changes that get blocked are the ones Amazon itself would reject.

The division of labour is strict: the numbers inform, the human decides.

## Fourteen days later, the receipt

The loop closes after the change is applied, and this is where we part company with the whole ACoS-report genre.

Every applied change is re-measured fourteen days later and judged on **net contribution**: orders attributed to the target, times your measured contribution per unit, minus what the ads spent. Not ACoS — ACoS is the metric that *improves* when you pause a profitable campaign, because the spend disappears from the denominator while nobody counts the contribution that left with it. A verdict that can't distinguish "we saved money" from "we turned off revenue" is not a verdict.

Your assistant can ask for the receipt directly — the connector ships a tool called `did_my_changes_work` — and the honest range of answers includes *inconclusive*. Fourteen days of a low-volume target is sometimes just noise, and a measurement layer that never says "too early to tell" is manufacturing certainty it does not have.

## What this is not

Three sentences we are careful never to write, because each one would claim something the system deliberately does not do:

- **"AI manages your PPC."** It does not. It drafts; you manage.
- **"Automated bid optimisation."** Nothing here is automated past the draft. That is the point, not a limitation we plan to remove.
- **"This change will improve your performance."** Unknowable in advance — which is precisely why the fourteen-day measurement exists. A tool that promises the outcome has no reason to measure it.

## Seeing it without connecting anything

The [/connect](/connect) page runs the read tools live against a synthetic demo seller, in your browser, with no account. The step-by-step setup — Seller Central, then Claude, ChatGPT or any MCP client, then your first drafts — is in our [complete MCP connector guide](/blog/connect-amazon-seller-account-ai-assistant-mcp).

---

## About this article

This article was researched and drafted with AI assistance. Before publication, it passed automated editorial review against Avanta Global EOOD's published editorial standards (factual accuracy, source attribution, voice & readability). Our [editorial standards page](/disclosure) documents exactly what we check. Learn more about our [editorial process](/disclosure) and the team [behind AgentXray](/about).

*Want to see your own numbers instead of a demo's? [Try AgentXray](https://agentxray.ai).*

## Related reading

- [Connect your Amazon seller account to your own AI: the complete MCP guide](https://agentxray.ai/blog/connect-amazon-seller-account-ai-assistant-mcp)
- [Amazon seller analytics: the metrics guide](https://agentxray.ai/blog/amazon-seller-analytics-metrics-guide)
- [Amazon repricing automation: AI strategies](https://agentxray.ai/blog/amazon-repricing-automation-ai-strategies)

About this article

This article was researched and drafted with AI assistance. Before publication, it passed automated editorial review against Avanta Global EOOD's published editorial standards (factual accuracy, source attribution, voice & readability). Our editorial standards page documents exactly what we check. We continuously monitor published content for accuracy and update articles when new information emerges. Learn more about our editorial process and the team behind AgentXray.