Nestack Agent Care
Industries / Advertising & Marketing / Audience copilot

Advertising AI agent · Audiences

Audience-Targeting Copilot (Permitted-Use)

Define, document and maintain segments, lookalikes and suppression lists with the permission behind every input on file — a named person clears the legal basis and any restricted category before an audience ships.

4–6 weeksTypical delivery
Your stackDeployment
Human sign-offActivation
Agent CareAfter launch

What this agent does

Proposes the audience, not the delivery

In
01

Read the segment brief, the fields available in the CDP and the permission recorded against each one.

02

Pull the consent, preference and opt-out state for every source, stamped with the date it was read.

Reason
03

Draft inclusion and exclusion rules from fields the client is permitted to use for advertising, and no others.

04

Test every rule for proxies — the neutral-looking field that reconstructs a protected attribute.

05

Size the segment, model any lookalike from a named seed, and state how far the model sits from it.

Decide
06

Hold anything that reads as housing, employment or credit, or that rests on a sensitive-category inference.

07

Route every segment to a named approver with its inputs, permission record and proxy result attached.

Out
08

Push only the approved definition, apply the suppression list, and record the match rate as it came back.

09

Retain the brief, the rules, the permission evidence, the approver and the composition actually delivered.

Product statement

The agent proposes and documents audiences. It does not clear a legal basis, does not decide a restricted category, and does not control how a platform delivers.

Example workflow

One segment, end to end

AgentHuman
1Brief receivedA segment brief from a planner, or a scheduled refresh of an audience already running
2Permission checkedEvery field the segment would use, set beside the consent, contract and stated purpose behind it
3Rules drafted and sizedInclusion and exclusion rules, the seed for any lookalike, projected size and overlap with what is already live
4Proxy and category screenEach rule tested for proxies of a protected attribute, and the brief tested against the restricted-category list
No human action required

Stages 1 to 4 run without a person in the loop — the sourcing, the rule draft and the proxy screen are finished before anyone is asked to sign anything.

5DecisionSplits on restricted category and permission coverage
Category clear, permission covered

Reaches the approver ready to sign.

Restricted category or permission gap

Held with the field named, not built.

Audience approver and privacy reviewer

A named approver confirms the legal basis for every input and clears any restricted category. Nothing reaches a platform before that.

Approve · Narrow the rule · Send back
Approved — handed back
6Activated and suppressedPushed only to the platform and account the approver named, with the suppression list applied and the match rate recorded
7Delivery reviewedDelivered composition against intended, reach and frequency, and the slices where the two diverge
Rule changes

Every rule the approver narrows or removes is counted.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Shipping any audience in a restricted category.
Deciding the legal basis for a segment's inputs.
Adding a field the client cannot use for advertising.
Building a lookalike from an unapproved seed.
Automation boundaryAgent acts unaided
Draft segment rules from fields already cleared for advertising.
Check consent, purpose and opt-out state per input.
Test each rule for proxies of a protected attribute.
Size the segment, apply suppression and record the match rate.
Write actions run only inside the approval boundaries agreed during implementation. Pushing an audience to a platform is not among them.
Inferring health, religion, politics or sexual orientation.
Targeting an audience that may contain known minors.
Changing or switching off a suppression list.
Onboarding first-party data to a new platform or partner.

Example output

One segment definition, annotated

Everything the agent proposes is attached to the brief it came from.

Audience output · single segmentIllustrative example
Segment brief
Sources
Permission
Category
Confidence
Status
Renters near new listings
CDP plus a partner list
Read today
Housing — restricted
91%
Held, not built
As receivedThe brief as the planner wrote it, the sources it would draw on, and the date the consent and opt-out state were read.
Evidence used Consent record, dated Stated purpose on file Partner list, unpermitted
Why it is heldIt is a housing brief, and one source has no advertising permission. Both are named.
ActionApproveNarrow the ruleSend back
What the score decidesIt decides how hard the approver reads the rule set — not whether the audience is lawful to run.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every segment requestFrom planners, the CDP and scheduled refreshes
03Permission & purpose

Carry the permission with the field

Every field in a segment arrives with the consent, contract and stated purpose behind it, read at build time and stamped with the date.

01Approved path

Cut the sourcing and sizing work

Sourcing, rule drafting, sizing and overlap are finished before a person opens the brief, so the approver reads a definition instead of building one.

02Human review

Surface the proxy before the push

Rules that reconstruct a protected attribute, and briefs that fall in a restricted category, are held now instead of found in a delivery report later.

04Build an evidence trail

Retain the brief, the rules, the permission evidence, the proxy result, the approver, the match rate and the composition delivered — on both paths.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

CDP & first-party dataSegment · Tealium · Adobe
BigQuery · warehouse exports
Platform audience APIsMeta · Google · The Trade Desk
Amazon Ads · retail-media APIs
Clean rooms & identityAds Data Hub · Amazon Marketing Cloud
LiveRamp · ID resolution

Agent

Audience targeting & suppression

Reads permission
Drafts segments
Routes for sign-off

Consent & preferencesOneTrust · Didomi
Preference centres · suppression lists
Measurement & observabilityOpenTelemetry · Langfuse
Supported measurement/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the platform

Each control wraps the one inside it. A segment clears every layer before it is pushed, and how the platform then delivers it sits outside all six.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modePause activation and pull live audiences if signals or evaluations degrade.Roll back
L5TraceabilityRecord the brief, the inputs, the permission, the approver and the push.Record
L4SuppressionOpt-outs and exclusion lists are applied before anything activates.Subtract
L3Restricted categoryHousing, employment and credit briefs stop for a named approver.Gate
L2Proxy auditRules that reconstruct a protected attribute are blocked, not warned.Block
L1Permitted useEvery field carries a recorded consent, contract and stated purpose.Verify
Model coreProposal — segment rules, seed, projected size, suppression and confidence
L1 – L2Decide whether the segment may stand
L3Decides who clears a restricted brief
L4 – L5Keep exclusions applied and the trail intact
L6Pulls automation back when signals degrade

How Nestack evaluates it

Evaluate the definition and what was delivered against it.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the segment definition a person approves
Depth of coverage ▼
E1Final-output evaluationDid the segment match the brief, and was every input permitted?
E2Step-level evaluationDid it read the current consent and opt-out state before drafting a rule?
E3Tool evaluationDid it push the approved definition to the right platform and account?
E4Category and proxy detectionDoes it catch a restricted brief and a proxy rule, and how often does it miss?
E5Slice evaluationHow does performance change across sources, platforms and segment types?
E6Business outcomeDelivered-versus-intended composition, match honesty and audiences pulled at review.
Floor — the composition the platform actually delivered

Failure modes

Where each failure originates in the agent

Seven failure modes plotted against the five stages of the agent lifecycle.

Agent lifecycleDirection of processing →
01 · Sourcing2 modes
AT-01

Unpermissioned input

A field the client may not use for advertising.

AT-02

Sensitive category inferred

Behaviour is read as a health or belief signal.

Stage gathersFields, consent state, opt-outs and partner permissions
02 · Definition1 mode
AT-03

Proxy rebuilds a protected attribute

A neutral field stands in for race, age or sex.

Stage proposesInclusion, exclusion, the lookalike seed and its size
03 · Activation2 modes
AT-04

Suppression not applied

Someone excluded by name is targeted anyway.

AT-05

Match rate not verified

An inflated overlap hides a broken join.

Stage pushesOnly the definition and platform a person approved
04 · Delivery1 mode
AT-06

Audience collapses at delivery

The approved segment reaches almost nobody.

Stage reviewsWhat the platform delivered against what was intended
05 · Change / Version1 mode
AT-07

Lookalike drifts from seed

A refresh moves the model off the seed.

Stage tracksModel, rule, seed and suppression-list changes
Sev-1 · the audience should not run at all Sev-2 · the wrong people are reached or missed Sev-3 · the segment is unusable as built

Affected slices

Most of the exposure sits in a few kinds of brief

An aggregate failure rate can look acceptable while a small number of brief types carry nearly all of the proxy findings, the permission gaps and the audiences pulled after sign-off. Nestack reports performance by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Housing, employment and credit briefs6.2%3.9× Review
Onboarded partner and second-party data4.3%2.7× Review
Lookalikes built from small seeds2.9%1.8× Watch
Repeat first-party refreshes1.0%0.6× Normal
Bar: failure-rate lift vs. first-party refresh baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

An approved audience does not stay approved

Consent is withdrawn, opt-outs arrive and platforms change what a category may target. A segment nobody re-checks drifts out of permission while it runs.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

A proxy finding, a permission gap or a delivery skew shows up in one kind of brief.

02Diagnose

Traced to a source field, a rule, the seed, the suppression list or a platform policy change.

03Improve

The field, rule or list is changed, re-cleared by the named approver and version-linked.

04Verify

Re-run against held-out briefs, including the audiences that were pulled after sign-off.

05Learn

The pulled audience becomes a regression case and the rule enters the targeting standard.

Learn → DetectThe return edge. Every cycle also re-reads consent, opt-outs and the platforms' category rules — an audience cleared last quarter is not cleared now.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, permission mapping, rules and proxy testing, evaluation, activation, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Workflow discovery and automation-boundary definition.
02CDP, warehouse and source assessment.
03Permitted-use, consent and contract mapping.
04Restricted-category rules and named approvers.
05Segment rule drafting and sizing logic.
06Proxy audit and protected-attribute testing.
07Suppression, opt-out and preference wiring.
08Approval workflow and sign-off record.
09Evaluation suite, slices and regression briefs.
10Platform audience APIs and clean-room joins.
11Match-rate and composition reporting.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne platform, one segment set ProductionProduction CDP integration AdvancedMulti-platform / multi-brand
Introduced at Pilot
Segment definition and sizing
Permitted-use and consent checks
Restricted-category flagging
Named-approver sign-off
Baseline evaluation
Introduced at Production
Proxy audit on every rule
Suppression and opt-out enforcement
Platform audience APIs — approver pushes
Match-rate and composition reporting
Introduced at Advanced
Clean-room joins and identity resolution
Multi-brand and enterprise controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on platforms and data sources in scope, consent and preference systems, clean-room and identity integrations, segment volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01The platforms and segment types you want in scope Platform audience APIs and activation scopingWeek 1
02Your data sources and what each was collected for Permitted-use, consent and contract mappingWeek 1
03Access to the CDP, warehouse and consent platform Source assessment, consent and preference wiringWeek 2
04Suppression lists, opt-outs and do-not-target rules Suppression, opt-out and preference enforcementWeek 3
05The proxies and protected attributes you already watch Proxy audit and protected-attribute testingWeek 3
06Segments you have had to pull, and the reason Evaluation suite, regression briefs and slice reportingWeek 4
07Named approvers for legal basis and restricted briefs Approval workflow, then activation under sign-offWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Phases are drawn over the weeks they actually occupy. Week 5 carries the first audiences pushed under sign-off.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Platforms and segment types in scope; who clears a restricted brief W2Source assessment, permitted-use mapping and consent wiring W3Segment rules, proxy audit and suppression enforcement W4Approval workflow, evaluation suite and slice reporting W5Platform APIs, first audiences pushed under sign-off W6Live audiences under approval, then Agent Care monitoring
Reading the bandThe proxy audit and the suppression wiring land in week 3, before any audience can be pushed in week 5. The bars show that dependency, not a smooth ramp.
At the end of W6Audiences have gone live under sign-off with the permission behind every field on file, then Agent Care takes over monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Advertising AI agent

Build an audience-targeting copilot around your data stack.

Show us the segments you build most often, where their data comes from and what each source was collected for, and who signs off a restricted brief today. We'll rebuild one live audience from its brief, show you the permission behind every field and the proxies it would have carried, then scope from there.

Nestack Agents · Audience targeting & suppressionAGT-AM-04 · Agent Care available after launch