ai agents.an agent connected to your accounts is one more user. give it user permissions.
Meta introduced its agent platform for businesses and opened Muse to them. Connecting an agent to an account is the easy part. The decision that matters is what it can do there and who finds out when it does.
in three lines
- On 28 September Meta introduced its agent platform for businesses, and on the 29th it opened Muse to businesses, with connectors to Instagram, Pages and ad accounts.
- The coverage we read doesn't spell out which permissions each connector requests or whether they can be limited. That gets checked on the connection screen, before accepting, not after.
- An agent with access is one more user on the account: it needs scoped permissions, someone who authorised it by name and date, and a record of what it does.
what meta launched and when
On 28 September 2026 Meta introduced, in its newsroom, an AI platform for businesses that brings together Muse, Meta Business Agent, a Muse API and Muse Code. It is led by CJ Desai, the former CEO of MongoDB. The next day it announced Muse for small businesses, with connectors to Instagram, Facebook Pages and ad accounts.
This isn't a niche product. According to TechCrunch, by 25 September Muse had 3.4 million downloads, and Meta has been promoting it in its own Facebook, Instagram and WhatsApp placements since 9 September. It will reach brand accounts by the shortest route: someone on the team tries it and gives it access.
what hasn't been published yet
The coverage from those days describes what can be connected, not with what scope. We found nothing published on which permissions each connector requests, whether an agent can be kept read-only, or whether it can touch budgets and posts without human confirmation.
With those questions open, the honest answer is neither yes nor no: read the permissions screen before accepting, and don't connect any account whose scope can't be explained in one line.
why the permission is the decision
The same week brought three warnings about agents with too much access. On 27 September The Verge reported that OpenAI paused its most capable models after incidents involving agents. On the 28th, The Decoder reported tens of thousands of agent security incidents at OpenAI, Anthropic, Meta and Google. On 2 October the same outlet reported more than 13,000 internal screenshots uploaded by AI agents to public GitHub repositories.
The gap isn't only technical. According to Digiday, an IAB Europe survey found that 38% already use agents to buy programmatic media, but fewer than 25% train their people on when to step in. The agent gets installed fast; the rule for when to stop it doesn't.
And what you tell an assistant can end up somewhere else. On 26 September PPC Land noted that Meta has used interactions with its AI to personalise ads since December 2025, and that a Cologne court barred Snap from using conversations with its assistant for advertising without consent. Pasting a brand's data into a conversation is also a permissions decision.
how we work with it
Our network runs on agents every day, and the rule that has served us best is to treat each agent as a user: permissions are split by type of action —measure, propose, edit, publish— and enabled one at a time. An agent being able to read an account doesn't mean it can change it.
Each permission has a human owner, with the name and date of when they authorised it. Every change an agent makes leaves a record with proof of what it did, and when in doubt the change stays as a draft until a person approves it. It's what you'd ask of any new user on the account: nobody gets admin access on day one.
Muse can now connect to Instagram, Pages and ad accounts. The scope of each connector hasn't been published: read it before accepting.
what changes in the operation
connections need written permission
No brand account gets connected to an agent because someone wanted to try it. It is connected with authorisation from whoever is accountable for the account, by name and date.
reading and changing are two permissions
If the connector lets you separate read from write, start with read. If it doesn't, that is already information for the decision.
what you type in the chat counts too
A brand's budgets, results and plans don't get pasted into an assistant without knowing whether that conversation can be used for something else.
in regulated industries, legal goes first
A healthcare or financial services brand doesn't connect its accounts to an agent until its legal or compliance team has reviewed the scope.
questions we get
Can Muse change my campaigns?
The launch coverage confirms it connects to ad accounts, but doesn't detail which actions it can take or with what confirmation. Check that on the connection's permissions screen before accepting it.
Should we avoid it?
Not necessarily. Use it with the same standard you'd apply to a new person on the account: scoped access, someone who authorised it, and a record of what it does.
Does this only apply to Meta?
No. Any agent that asks for access to an account, on any platform, gets assessed with the same three questions: what can it do, who authorised it, and where is it recorded.
where this comes from
- Launch of Meta's AI platform for businesses (Muse, Meta Business Agent, Muse API, Muse Code), Meta Newsroom and TechCrunch, 28 September 2026.
- Muse for small businesses, with connectors to Instagram, Pages and ad accounts, Meta Newsroom, 29 September 2026.
- Muse downloads and its promotion in Meta's placements, TechCrunch, 25 September 2026.
- Use of Meta AI interactions for ads and the Cologne ruling on Snap, PPC Land, 26 September 2026.
- OpenAI pausing models after agent incidents, The Verge, 27 September 2026.
- Agent security incidents, The Decoder, 28 September 2026; internal screenshots uploaded by agents to GitHub, The Decoder, 2 October 2026.
- IAB Europe survey on programmatic buying with agents, Digiday, picked up on 29 September 2026.
- Daily sweeps by AIRadar and SocialRadar, Champe Agency's own agents, 26 September to 2 October 2026.
Sources are cited as text, with outlet and date. We don't link addresses we haven't verified.
and what it takes
The note explains the problem; the services explain the work.
the other notes
the facebook link quota
With Meta One, an external link on a Facebook Page went from being a low-reach format to being a rationed resource. The question is no longer how to add the link: it is which posts deserve one.
read the note → 08 · September 19, 2026the unranked feed
In a single week, three governments moved on the same front: who can hold an account, which feed they see and which ads reach them. For a brand the effect is neither moral nor legal: it is about reach and measurement.
read the note → 07 · September 12, 2026declaring ai use
Instagram flags barely retouched real photos as AI and lets generated images through. If detection gets it wrong in both directions, disclosure cannot depend on it.
read the note → 06 · August 28, 2026running on agents
Plenty gets said about agencies using AI, and very little about how one is actually run. This is the method from the inside: how knowledge is organised, where the human sits, and what breaks when nobody looks after it.
read the note → 05 · August 28, 2026reading year-over-year comparisons
Global CPM is up 32% since 2024 and US inventory is at an all-time high. A campaign can look worse in this year's report without having gotten worse for a single day.
read the note → 04 · August 28, 2026originality and reach
Instagram no longer rewards originality out of principle. It measures it. Reposting loses reach in ways you can verify, the penalty has moved beyond video, and the hashtag no longer makes up for anything. Here is what counts.
read the note → 03 · August 28, 2026measuring without e-commerce
Most real work doesn't end in a cart. It ends on a shelf, in a store, in a doctor's appointment. That can be measured. What can't be done is inventing the metric at month end.
read the note → 02 · August 28, 2026meta placement controls
Meta has finished retiring the manual placement selector. What remains are value rules with a hard floor of -90%. Brand safety stops being a list of unchecked boxes and becomes a production decision.
read the note → 01 · August 28, 2026creative volume on meta
Meta split the decision of which ad you see into two stages. The first one reads the creative, not the targeting. That is where creative volume stopped being a production luxury.
read the note →