Agent
Agent is the AI assistant built into Pluto Ads. Ask it in plain words to create launches, move ads, look up spend, prepare a publish or plan budget changes. It works with your own permissions, shows every step it takes, and asks you first before anything risky, the way you choose in Settings > Agent.
Opening Agent
Agent is on every page. Open it the way that suits what you're doing:
- Home has the composer. Type a question and press
Enter: Home turns into the chat, with its own address, and the reply appears there as it's written. A few suggestions under the composer get you started. - Agent in the bar at the bottom of every page opens a new chat in a panel over the page you're on. The bar also shows your recent chats: select one to open it in the panel, just above where you clicked.
Cmd+J(Ctrl+Jon Windows) opens a new chat in the panel from anywhere, and closes it again. On a chat's page it moves to that chat's composer instead.
The panel stays open while you move between pages. Minimize it, close it, or select Open as page: the same chat opens full size, a reply in progress keeps going there, and the panel closes. Closing the panel doesn't stop Agent: a reply keeps running and is there when you come back.
Press Enter to send and Shift+Enter for a new line. Dictate lets you speak your message instead,
and Attach files adds images and videos (up to 20 per message). Agent also knows which page you're
on, so "move these ads to Broad DK" in the panel over a launch means that launch.
A chat's page keeps its address, so you can reload it or bookmark it. New chat at the top of the page takes you back to Home.
The model
Agent runs on Claude Opus 5.5. When your workspace offers more than one model, you pick one in the composer as you write, and owners and admins choose the Default model new chats start with and the Allowed models members may pick, in Settings > Agent. Loops' AI steps run on the same models. Each answer records the model that wrote it.
Guidance and skills
Settings > Agent starts with your own settings, under Personal. They're only for you, in this workspace: your teammates have their own.
- Guidance: personal instructions and context Agent follows when it answers you, such as your brands, your naming rules or how you like numbers reported. It saves as you type, up to 4,000 characters.
- Skills: reusable prompts. Select New skill, give it a name, say When should Agent use this?
and write its instructions. Agent picks a skill up on its own when a request matches, and you can run
one yourself: type
/at the start of a message, choose the skill, and add your request. The name the skill runs as (for example/weekly-report) comes from its title; select it to change it. Open a skill to edit it, or delete it from its menu.
Agent reads your guidance and skills, but only you change them: in the app, or through an agent you connected yourself (see Agents).
What it can do
Agent does what an agent connected through MCP does, through the same actions and checks: more than 200 of them, covering launches, media, review, analytics, loops, Meta, members and settings. It doesn't read all of them for every message. It keeps the everyday ones at hand and looks up the rest when your request needs them, so a request for something less common works too. See What agents can do for the full picture. In short:
- Read and search launches, ads, media, results, loops and the Meta connection.
- Create and edit launches, ad sets and ads, in bulk too, and move, duplicate, archive and restore them.
- Comment, change review statuses and tags, and follow long-running work.
- Look at your media and your ads' creatives: an image, or a few frames of a video.
- Tell you what still blocks a launch from publishing, with a link to where each item is fixed.
- Publish, change live budgets and bids, pause, and delete in Meta, and plan several live changes at once for you to review.
It never does more than your role allows, and it works in the workspace you're in. Agent is for members, admins and owners: guests can't use it.
Long-running work it starts, such as publishing, shows in the activity indicator in the top bar with its progress, the same as work you start yourself.
How it answers
While it works, Agent shows the step it's on, such as "Reading Summer sale" or "Moving 12 ads to Broad DK". When it's done, the steps fold into Worked for 8 seconds. Select it to see every step and what each one found or changed.
Launches, ad sets, ads, media and loops it mentions or changes appear as links with their name. Select one to open it. The copy button under an answer copies it as text. Thumbs up and down under an answer tell us whether it helped.
Numbers come from your data. When you ask what you spent last week, Agent looks it up in the same analytics the dashboard uses and quotes the result, per currency. It doesn't estimate or fill in missing numbers. If there is no data for a period, it says so.
Choosing when Agent asks
In Settings > Agent, under Approvals, Ask before acting decides when Agent stops to ask you. It's your own choice, in this workspace, and it follows you to every device.
| Choice | What Agent does |
|---|---|
| Ask for risky actions (the default) | Asks before it spends, deletes, sends or changes settings. Reads and edits it can undo inside Pluto Ads, such as drafts, archives, tags and folders, run directly. |
| Ask every time | Asks before every change. Reads never ask. |
| Run everything | Acts without asking, within your permissions. |
Risky actions are the ones that spend money or change what's live in Meta, change members, credentials, integrations, billing or settings, send something outside Pluto Ads (such as a Slack message or a reply to a comment), or delete something that can't be brought back.
Even with Run everything, some actions always ask:
- The budget guardrail. A budget or bid increase, or new spend such as publishing or turning delivery back on, above the workspace's guardrail. Decreases and pauses never count against it, and a change Pluto Ads can't measure always asks.
- Changing usage limits or who may run without approvals.
- Inviting or removing people and changing their roles.
- Creating API keys, agent credentials or webhooks, whose secret is shown only once.
- Deleting a workspace.
Under Workspace, owners and admins set the rules for everyone:
- Run without approvals: All members (the default) or Only admins. With Only admins, members don't get Run everything, and a member who had chosen it is asked for risky actions again.
- Budget guardrail: Largest budget change without approval is a percent (+50% unless an admin changes it). Largest amount without approval optionally adds an amount per change in one currency; leave it empty for none.
Members see these rules but can't change them. Loops don't follow this setting: each loop asks according to its own steps (see Loops).
Approving publishing and admin actions
When Agent needs your yes, the answer shows the action as a row with Reject and Approve. Several waiting together show as one block with Approve all and Reject all. Select a row's title to see the exact effect: for a publish, the launch and its version, the ad account, what gets created, and every budget as an amount in the ad account's currency.
- Approve runs the action as you, once. Pressing it twice, or on two devices, never runs it twice.
- Reject tells Agent you declined. It stops or suggests something else.
- If the launch changed after the row appeared, the approval fails and says why. Ask again to get a fresh one with the current values.
- You need the permission the action needs. Without it, the row says who can approve, for example "Needs permission to publish."
- Sending a new message closes any open approval in that chat without running it.
- Creating an API key, an agent credential or a webhook shows its secret once, right after you approve. Select Copy: the chat doesn't keep it.
Once decided, the row becomes a quiet line in the chat, such as what was done, or what was rejected or failed. Approving needs a connection. Offline, Approve stays off until you're back online.
Reviewing a plan of changes
When a request changes several live budgets, bids or delivery statuses at once, such as "pause the ads under 1% CTR and move their budget to the winners", Agent proposes a plan instead of making the changes one by one. The plan shows in the chat with its totals per ad account and its status.
- Approve and apply applies the current version of the plan as you, change by change. Nothing changes before you approve.
- Open in Inbox opens the full review: every change with its current and new value and Agent's reason. There you can edit a new value, remove a change, Reply with changes so Agent makes a new version, or Reject it with an optional reason.
- A plan applies only the version you saw. If Agent makes a newer one, review that before approving.
- After a plan is applied, Undo sets a change back where that's safe, such as pausing again or lowering a budget.
Each change is checked before it's proposed and again when it's applied: a budget moves at most +100% or -90% in one change, and anything that fails a check is left out with the reason. A plan waits a limited time for a decision and says when it expires. Loops and connected agents propose plans the same way.
Stopping and retrying
- Stop (or
Escin the composer) stops Agent. Steps that already ran stay done: an ad it already moved stays moved. - If a reply fails, the chat shows what went wrong and a Retry button that runs the same request again.
- You can't send a new message while Agent is working in the same chat. Stop it first, or wait.
Seeing what it changed
Agent works in the open, like any connected agent. Changes it makes directly carry the name Pluto Agent via your name, for example "Pluto Agent via Anna", in presence, activity and the Inbox. Your teammates see what it did and that you asked for it. Actions you approve, and actions it runs for you under Run everything, run as you and show your own name. Workspace admins see all of it in Settings > Audit log.
Anything Agent reads in your workspace, like ad copy, file names and comments, is content. It isn't an instruction to Agent.
Chat history
Your chats are private: other members of the workspace, admins included, can't see them. They are stored per workspace and follow you to every device where you're signed in. A chat you start on one device shows new replies on the others as they arrive.
Open Chat history from the history button in the bottom bar or at the top of a chat's page. Chats are grouped into Today, This week and Older, with a dot on chats that have a reply you haven't read. Search chats by title. From a chat's menu you can Rename or Delete it. Deleting a chat deletes its messages and can't be undone; changes Agent already made stay.
Usage and limits
Agent's work is usage, charged by the tokens the model reads and writes at the model's rates (see Models & rates). Every plan includes a set amount each month, shared by the organization, and the free trial includes a set amount for the whole trial; beyond that it continues only when an organization owner or admin turned on on-demand usage. Owners and admins can also set a monthly limit for each member, and on Business for each workspace. See Billing.
When a limit is reached, Agent stops before its next step and the chat says which limit it was, with the way forward: Enable on-demand usage, Raise the limit or Upgrade. Nothing you started before is lost. Owners and admins see the organization's usage in Usage and change limits in Spending, in settings.
Limits
- Attached images and videos go to your media library first, and Agent works with them by reference (for example to create ads from them). What it looks at counts as input tokens. A chat holds a limited number of images; when it's full, start a new chat.
- It needs a connection. Offline, the composer stays off and your chats stay readable.
- It's AI, and it can be wrong. Check what it proposes before you approve, and check its changes as you would a teammate's.
- It doesn't set special ad categories (political or social issues, housing, employment, credit) or target ads for them. Do that yourself in the launch editor.
Common questions
Why did it ask me to approve? The action is risky under your Ask before acting choice, it's above the budget guardrail, or it's one of the actions that always ask. See Choosing when Agent asks.
Can it publish without asking? Only if you chose Run everything, your workspace lets you, and the new spend is within the budget guardrail. Otherwise every publish needs your approval, bound to the exact launch version, ad account and budgets you saw.
Why can't I choose Run everything? An owner or admin set Run without approvals to Only admins.
Why can't a teammate see my chat? Chats are private to you. The changes Agent makes are not: they show in activity like anyone's.
Why did it stop and name a limit? Your organization, workspace or your own monthly usage limit was reached, the included usage is used and more isn't turned on, or the trial's AI usage is used. An organization owner or admin can change the limit or turn on more in Spending; otherwise it resets with the billing period. On the trial, an owner or admin chooses a plan in Plan & billing.
Which model does Agent use? Claude Opus 5.5, unless your workspace offers more models. Then new chats start with the workspace's Default model, and you can pick another allowed one as you write.
Can an API key use Agent? No. Chats belong to a person, so Agent needs someone signed in. An agent acting for you can open chats, but only you, signed in to the app, can approve.