Watch spend against budget and flight, catch under- and over-pacing and cost breaks early, tell a real change from a reporting artefact, and escalate with evidence — a named owner decides whether money moves.
Read the released budget, the flight dates and the pacing target for every line in scope.
02
Pull spend and delivery from each platform on a fixed interval, with the pull time recorded.
Reason
03
Compare spend to date against the flight's own curve, not a flat line drawn through the budget.
04
Separate a real change from a restated figure, a missing pull or the platform's own pacing rules.
05
Group related signals into one incident, so a single upstream break is not seven separate alerts.
Decide
06
Rank by the money at stake and the time already elapsed — under-delivery is ranked, not ignored.
07
Escalate to the named owner with the evidence, the likely cause and the actions open to them.
Out
08
Raise the incident on the rota and hold it open until a person records what they decided.
09
Retain every alert, the data it fired on, what it was later confirmed to be, and who acted.
→Product statement
The agent watches, classifies and escalates. A named owner decides whether to pause, move or leave money alone, and any automatic pause is a pre-authorised exception with a stated limit.
Example workflow
One anomaly, end to end
AgentHuman
1Pacing checkedSpend to date against the released budget and the flight's own curve, on the interval agreed with the client
2Signal raisedAn over- or under-pace, a cost or delivery break, or a line that has stopped spending altogether
3Data tested firstWhether the figure has settled, whether a pull returned nothing, and what the platform is itself allowed to spend
4Incident assembledRelated signals grouped, the money at stake sized, the likely cause named and the actions open to the owner listed
No human action required
Stages 1 to 4 run without a person in the loop — the pull, the data test and the grouped incident are finished before anyone's phone rings.
5DecisionSplits on whether the change is confirmed and how much money is moving
Explained by the data
Closed with the reason recorded.
Real, and money is moving
Paged to the owner on the rota.
Named owner
The owner reads the evidence, the money at stake and what was ruled out, then decides whether to pause, move or leave it alone.
Pause · Adjust · Leave it
Decided — handed back▼
6Owner acts, agent followsOnly what was pre-authorised is applied; the line is watched until the next settled figure agrees
7Outcome evaluatedWhether the alert was real, how long detection took, what the owner did, and how many alerts closed as noise
Pre-authorised pauses
A pause covers one line, for a stated ceiling, and any owner can reverse it.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Pausing anything outside the pre-authorised lines.
Raising, lowering or moving a budget or cap.
Closing an anomaly as not worth acting on.
Muting or suppressing an alert for a client.
Automation boundaryAgent acts unaided
✓Read released budgets, flights and delivery from every platform in scope.
✓Test whether a figure has settled before treating it as a change.
✓Group related signals into one incident and size the money at stake.
✓Escalate to the named owner with the evidence and the actions open to them.
Write actions run only inside the approval boundaries agreed during implementation. A pause runs unattended only on lines the client authorised in writing, with a ceiling, a window and a reversal.
Changing a pacing threshold, baseline or alert rule.
Telling a client that spend or delivery went wrong.
Claiming a make-good or a credit from a platform.
Turning monitoring off for a campaign or a client.
Example output
One alert, annotated
Everything the agent raises is attached to the pull and the released budget it came from.
Pacing alert · single line itemIllustrative example
Line item
Flight
Released budget
Classification
Confidence
Status
Paid social, one market
Day 6 of 14
$120,000
Over-pacing, confirmed
88%
Paged to the owner
As receivedThe line, its flight and the budget released against it — nothing on this side is inferred.
Evidence usedTwo pulls, both settledPlatform pacing allowanceFlight curve to date
Why it was raisedPast the allowance the platform grants itself, on a day that has already settled.
ActionPauseAdjustLeave it
What the score decidesWhether the owner is paged now or reads it at the stand-up — not whether to pause.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every line, every intervalFrom the platforms and the budget record
03Triage
Test the data before raising it
Check whether the figure has settled, whether a pull returned nothing and whether the platform is inside its own pacing allowance, before anything reaches a person.
01Approved path
Take the watching off the team
Pacing is checked on an interval through the night and the weekend, so the first person to look is reading an assembled incident rather than opening a dashboard.
02Human review
Escalate with enough to act on
The owner receives the money at stake, the likely cause, what was ruled out and the actions open to them, so triage takes minutes instead of starting from nothing.
04Build an evidence trail
Retain the alert, the data it fired on, what was ruled out, who was paged, what they decided and what it was later confirmed to be — on both paths.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Ad platformsGoogle Ads · DV360 · Meta The Trade Desk · Amazon Ads · retail media
Budget & flight recordMedia plans · flights and IOs Order management · finance systems
Alerting & on-callSlack and Teams · email PagerDuty and Opsgenie · on-call rotas
Agent
Spend pacing & anomaly triage
Watches pacing Tests the data Escalates to owner
Warehouse & incidentsBigQuery · Snowflake · dbt Jira and ServiceNow · incident records
Alert precision can look acceptable in total while a handful of platforms, hours and account sizes produce most of the false alerts, most of the late detections and nearly all of the incidents nobody was paged for. Nestack reports performance by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Overnight and weekend windows
5.2%
2.8×
Review
Platforms that restate late
3.9%
2.1×
Review
Promotional and seasonal peaks
3.0%
1.6×
Watch
Large steady always-on accounts
1.4%
0.8×
Normal
Bar: failure-rate lift vs. steady-account baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
The alerts that never fired are the expensive ones
Precision is easy to see and recall is not. Every cycle re-reads the quiet periods as well as the loud ones, because a miss leaves no alert behind to review.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Alert precision, detection time or a missed incident moves on one platform or client.
02Diagnose
Traced to the pull, the settlement test, a threshold, a baseline or the escalation rule.
03Improve
The threshold, baseline or routing is changed, re-approved by the operations lead and version-linked.
04Verify
Re-run against recorded incidents, including the ones nobody was paged for.
05Learn
The miss becomes a regression case and the threshold enters the pacing runbook.
Learn → DetectThe return edge. A threshold is only as current as the budget behind it, so every cycle re-reads the thresholds against the flights running now.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, pulls and pacing arithmetic, detection and escalation, evaluation, on-call integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Monitoring discovery and automation-boundary definition.
02Budget, flight and pacing-target record.
03Reporting API and data-latency assessment.
04Scheduled pulls and day-boundary rules.
05Pacing arithmetic and allowance rules.
06Anomaly detection and seasonality baselines.
07Settlement and restatement tests before alerting.
08Alert grouping, severity and escalation policy.
09Precision, recall and detection-time evaluation.
10Pre-authorised pause limits and reversal drill.
11Warehouse, on-call and incident integration.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne client, one platformProductionProduction monitoring pipelineAdvancedMulti-client / overnight rota
Introduced at Pilot
Pacing checks against budget and flight✓✓✓
Delivery and cost anomaly detection✓✓✓
Settlement and restatement tests✓✓✓
Escalation to a named owner✓✓✓
Baseline evaluation✓✓✓
Introduced at Production
Alert grouping and severity policy—✓✓
Seasonality and promotion baselines—✓✓
On-call routing and incident records—✓✓
Precision and recall reporting—✓✓
Introduced at Advanced
Pre-authorised pause with stated limits——✓
Multi-client and enterprise controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on the platforms and clients in scope, reporting latency, alerting and on-call tooling, pause authorisation and limits, and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01The budgets, flights and pacing targets in scope→Budget, flight and pacing-target recordWeek 1
02Access to the platform reporting APIs you buy on→Reporting API and data-latency assessmentWeek 2
03Your markets, currencies and reporting day boundary→Scheduled pulls and day-boundary rulesWeek 2
04The promotions and seasonal peaks already planned→Anomaly detection and seasonality baselinesWeek 3
05Who is on call, and who may pause spend today→Alert grouping, severity and escalation policyWeek 4
06Incidents you had, and the alerts you ignored→Evaluation suite, regression cases and failure-mode testingWeek 4
07What may be paused without asking, and up to what→Pre-authorised pause limits, then the reversal drillWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Phases are drawn over the weeks they actually occupy. Week 5 carries both the evaluation slices and the first alerts reaching a live on-call rota.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Budgets, flights and pacing targets; who may pause spendW2Platform pulls, day boundaries and reporting-latency limitsW3Pacing arithmetic, seasonality baselines and settlement testsW4Alert grouping, escalation policy and the precision-recall suiteW5First alerts on a live rota, the pause drill and correctionsW6Production validation, threshold review and Agent Care handover
Reading the bandThe pause limits and the reversal are drilled before any alert is allowed to stop spend, not after. The bars show that dependency, not a smooth ramp.
At the end of W6Alerts have run on a live rota through at least one weekend, and every threshold has been re-read against the flights running now, then Agent Care takes over monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Advertising AI agent
Build a spend-pacing agent around your budgets and your rota.
Show us the last three pacing incidents you had, how long each took to notice and who was allowed to stop the spend. We'll replay those three against your own reporting latency and show you which ones this agent would have caught, and which ones it would still have missed.