Documentation
Security, scopes, and approvals
Lily treats reporting, self-serve writes, and recurring Autopilot actions as separate levels. The AI client does not need the reusable Apple Ads credential, and self-serve campaign changes remain approval-first.
6 minUpdated Aug 4, 2026
Credential and client authorization are separate.
Apple Ads access is authorized to Lily. Compatible AI clients connect to Lily through scoped authorization, so account secrets do not need to enter the conversation context.
Self-serve writes are reviewable.
A recommendation should identify the account objects, current values, proposed values, and rationale. The operator approves the discrete change before application.
Autopilot follows program guardrails.
Recurring actions are limited by the app, market, budget, objective, permitted operations, and stop conditions defined for the program. Runs remain visible in an operating log.