Nestack Agent Care
Industries / Marketing / Risk assessment agent

Marketing AI agent · risk assessments

Marketing Risk Assessment AI Agent

Catalogue every activity that sells or shares personal information for cross-context behavioural advertising, assess each one before it starts under § 7150, and hold the summary a named executive attests to.

4–6 weeksTypical delivery
Your stackDeployment
One attestationNamed executive
Agent CareAfter launch

What this agent does

Assembles the register, never the attestation

In
01

A tag is added, and § 7150 wants the assessment finished before the processing starts.

02

An audience is exported, and selling or sharing for behavioural advertising is the trigger.

Reason
03

An SDK ships inside an app, and the assessment weighs purpose against harm and safeguards.

04

A CTV integration goes live, and the register has to show what leaves and where it lands.

05

A conversions API is wired, and the opt-out has to reach it, not only your own ad platform.

Decide
06

An activity changes materially, and the re-review clock runs from the change itself.

07

A pixel predates the register, and no assessment can be conducted after the fact it was owed before.

Out
08

A reporting period closes, and § 7157 wants the summary with the CPPA by 1 April 2028.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent maintains the register and drafts the assessments. A named business executive attests to the § 7157 submission under penalty of perjury.

Example workflow

One activity, register to attestation

AgentHuman
1Activity evidence receivedTag manager exports, SDK manifests, CTV integrations or audience destinations
2Activity context assembledThe activity, whether it sells or shares, the purpose it serves and the day it went live
3Assessment evidence draftedThe activity, its purpose, the negative impacts, the safeguards and completeness
4Controls appliedTrigger checks, pre-processing date checks, re-review clock checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is attested at any of them — the agent is assembling, and the privacy lane opens at the completeness gate.

5DecisionSplits at the completeness gate
Evidence sufficient

Goes to the attesting executive to approve.

Anything thin

Adds a privacy counsel read first.

Privacy review

The assessment is held with its activity, its purpose and the safeguards behind it.

Attest · Append evidence · Send to privacy review
Attested — by a named executive
6Register and activity records updatedOnly where write access and records policy allow it
7Outcome evaluatedTrigger accuracy, assessment coverage, reviewer corrections and what the read found
Corrections

Each privacy correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Attesting to the § 7157 summary.
Deciding an activity needs no assessment.
Certifying the cybersecurity audit under § 7124.
Telling the CPPA an activity was lawful.
Automation boundaryAgent acts unaided
Maintain the register of every sell-or-share activity.
Run the § 7150 assessment before processing begins.
Track the re-review clock that a material change starts running.
Flag the activity whose stated purpose the record cannot evidence.
Nothing is attested or filed except by a named person, inside the agreed boundaries.
Judging whether an assessment may be attested.
Telling the CPPA the register is complete.
Setting the lawful purpose an activity runs on.
Changes to tags, audiences or destination records.

Example output

One activity, annotated

A marketing department with a direct relationship to its customers is not a data broker, and a sale is still a sale; this record is what one activity carried into the register.

Register entry · single activityIllustrative example
Activity
Recorded as
Trigger
Evidence of record
Confidence
Held for
Audience export, § 7150
Assessed before launch, safeguards recorded
Sell or share
Register entry, 3 August 2026
Held unattested
The attesting executive, by name
As receivedTaken from the tag manager export and the destination record — it reaches as far as those sources do.
What the record holds Tag manager export Destination record Opt-out signal log
Why no attestation hereWhether an assessment may be attested is reserved to a named executive.
ActionAttestAppend evidenceSend to privacy review
What the score decidesBelow the configured threshold an entry picks up a privacy read before the executive sees it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every activityFrom the system that runs it
03Evidence

Where the evidence is used

Our audience targeting copilot yields an audience — internal, continuous and per-segment; this one yields a dated external filing with a named signer, working on processing activities rather than people.

01Approved path

The register is the assessment

An assessment attaches to a processing activity, not to a segment, and § 7150 wants it settled before that activity begins.

02Human review

What was checked, and not found

The verbatim § 7157 wording and the title it demands of its signer, the revenue thresholds deciding who is caught, a retention period put at five years by some sources and three by others, the tally of comprehensive state privacy laws, the states whose statutes compel a browser opt-out signal and the per-day penalty sums were each checked against the CPPA consolidated text, which truncated on every fetch, and none was confirmed.

04Build an evidence trail

The activity, the purpose it serves and the executive who attested stay on the record.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Tag and pixel sourcesTag manager · containers
Site and app SDKs
Ad platforms and destinationsConversions APIs · CTV
Audience export records
Consent and opt-outConsent platform · GPC log
Preference and signal records

Agent

Marketing risk assessment

Reads the activities
Assembles the register
Holds for the executive

Records and case systemsPrivacy tooling · ticketing
Assessment and review records
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six gates between the model and the executive

Six gates set in order, the narrowest last. Whatever clears them all is drawn in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and trigger rules; on 3 December 2025 the CPPA fined ROR Partners for selling custom audiences while unregistered, which is why every destination is named.Track
L4TraceabilityRecord each activity, the assessment behind it, the register it feeds and every read of the file.Record
L3Executive releaseHold the summary for the attesting executive; the hold governs release, not whether an activity should ever have started.Gate
L2Scope guardrailsTest the register against 11 CCR §§ 7150–7157 as configured; behavioural advertising was cut from the final ADMT scope, which reaches significant decisions in finance, housing, education, employment and healthcare alone.Restrict
L1Confidence thresholdsRoute a thin assessment to a privacy read first; the PlayOn order of 3 March 2026 shows liability arising out of a single targeted campaign.Require review
Model coreEvidence assembled — the activities, their purposes, the safeguards and completeness
L1 – L2Test whether an assessment may stand
L3Puts the attestation in a person's hands
L4 – L5Keep the activity and the purpose behind it
L6Holds the assessment undrafted when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the register entry that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the summary a regulator reads
Depth of coverage ▼
E1Final-output evaluationDid the entry record what the activity actually does?
E2Step-level evaluationDid the agent read the right activity, the right purpose and the live destination?
E3Tool evaluationDid it read and write the correct activity and the correct assessment?
E4Confidence calibrationDo low-confidence assessments actually attract more privacy corrections?
E5Slice evaluationHow does performance change across specific activity types?
E6Business outcomeHow many entries needed a correction before the executive attested?
Floor — the register the business answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each placed at the stage where it first shows.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KD-03

Stale activity read

The destination read is not the one now in service.

Stage gathersThe tags, the purpose, the dates and the register
02 · Reasoning2 modes
KD-04

Trigger missed on launch

An activity starts before its assessment exists.

KD-06

ADMT scope read too widely

Ad targeting is worked as a significant decision.

Stage proposesActivities, their purposes and completeness
03 · Tool / write2 modes
KD-02

Thin assessment passed forward

An entry moves on without the privacy read.

KD-05

Bound to the wrong activity

An assessment is filed against the wrong tag.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KD-01

Attested, evidence unrecorded

The record shows an attestation but not what supported it.

Stage returnsThe summary an executive attests and a regulator reads
05 · Change / Version1 mode
KD-07

Silent trigger regression

A configuration change moves the trigger, not the register.

Stage tracksModel, prompt, trigger rules and register fields
Sev-1 · an activity live with no assessment Sev-2 · wrong evidence reaches the register Sev-3 · source degrades, entry held unattested

Affected slices

Third-party tags absorb the corrections

An activity-level assessment-coverage figure can read clean while third-party tags and SDKs carry most of the rework. Nestack reports the correction rate by activity type, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Third-party tags and SDKs10.4%3.6× Review
CTV and in-app integrations7.4%2.6× Review
Conversions APIs and server feeds4.6%1.6× Watch
First-party owned channels2.2%0.8× Normal
Bar: correction-rate lift vs. first-party channel baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What an unassessed activity costs

A cycle shuts when the unassessed pixel is a regression case. That suite is what the next register built is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Correction rate rises on third-party tags and SDKs.

02Diagnose

The pixel a campaign team added in an afternoon, three years before anyone had to describe it, is read back until one cause remains.

03Improve

The change ships numbered, and the activities that forced it ride with it.

04Verify

Nothing releases while one touched activity case is still red.

05Learn

It is retained for good, and the assessment rules are amended in that same commit.

Learn → DetectThe return edge. The next cycle is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, register assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Sell-or-share trigger discovery and boundary work.
02Tag, SDK and destination sources.
03Activity-to-assessment and re-review clock mapping.
04Activity and assessment ingestion.
05Activity, purpose and record binding.
06Completeness scoring and review routing.
07Executive attestation workflow.
08Tag and destination-system integration.
09Trigger and materiality cases.
10Guardrails and attestation controls.
11Activity-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne activity type, one cycle ProductionProduction assessment workflow AdvancedMultiple brands / entities
Introduced at Pilot
Register assembly to your activities
Attesting executive release
Sell-and-share inventory baseline
Introduced at Production
Reporting by processing activity
Attestation workflow in your systems
Approved write-back
Tag-and-SDK integration
Introduced at Advanced
Multi-brand registers
Cross-period evidence packs
Large tag estates
Multi-clock retention controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, activity volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your activities and the destinations each one feeds Activity inventory mapping and evidence captureWeek 1
02Representative tag, SDK and destination records Record binding, trigger logic and the register baselineWeek 2
03Your purposes and the safeguards behind them Activity mapping, trigger binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Tag, SDK and destination-source assessment, then integration setupWeek 2
05Registers you would not want examined Trigger cases and failure-mode testingWeek 4
06What no risk assessment may establish Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named executive to attest Attestation workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Every band below is worked time rather than drawn space, which is why the fifth of them holds two.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Privacy workflow discovery, activity mapping and the automation boundary W2Source integration and the assessment-coverage baseline W3Register assembly, trigger logic and release controls W4Evaluation suite, trigger cases and failure-mode testing W5Destination integration, pilot activities and targeted corrections W6One assessment cycle run under the privacy lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth takes a second because the work does.
At the end of W6Validation closes on live registers, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Marketing AI agent

Build a risk assessment agent around the activity running today that a 1 April 2028 filing has to count.

Show us one activity and the record behind it. If your opt-out is honoured per device rather than per account, then that is the fact pattern the Disney settlement of 11 February 2026 turned on. Cybersecurity audits sit with the CISO and are a different lane.

Nestack Agents · risk assessmentsAGT-MK-01 · Agent Care available after launch