Define, document and maintain segments, lookalikes and suppression lists with the permission behind every input on file — a named person clears the legal basis and any restricted category before an audience ships.
Read the segment brief, the fields available in the CDP and the permission recorded against each one.
02
Pull the consent, preference and opt-out state for every source, stamped with the date it was read.
Reason
03
Draft inclusion and exclusion rules from fields the client is permitted to use for advertising, and no others.
04
Test every rule for proxies — the neutral-looking field that reconstructs a protected attribute.
05
Size the segment, model any lookalike from a named seed, and state how far the model sits from it.
Decide
06
Hold anything that reads as housing, employment or credit, or that rests on a sensitive-category inference.
07
Route every segment to a named approver with its inputs, permission record and proxy result attached.
Out
08
Push only the approved definition, apply the suppression list, and record the match rate as it came back.
09
Retain the brief, the rules, the permission evidence, the approver and the composition actually delivered.
→Product statement
The agent proposes and documents audiences. It does not clear a legal basis, does not decide a restricted category, and does not control how a platform delivers.
Example workflow
One segment, end to end
AgentHuman
1Brief receivedA segment brief from a planner, or a scheduled refresh of an audience already running
2Permission checkedEvery field the segment would use, set beside the consent, contract and stated purpose behind it
3Rules drafted and sizedInclusion and exclusion rules, the seed for any lookalike, projected size and overlap with what is already live
4Proxy and category screenEach rule tested for proxies of a protected attribute, and the brief tested against the restricted-category list
No human action required
Stages 1 to 4 run without a person in the loop — the sourcing, the rule draft and the proxy screen are finished before anyone is asked to sign anything.
5DecisionSplits on restricted category and permission coverage
Category clear, permission covered
Reaches the approver ready to sign.
Restricted category or permission gap
Held with the field named, not built.
Audience approver and privacy reviewer
A named approver confirms the legal basis for every input and clears any restricted category. Nothing reaches a platform before that.
Approve · Narrow the rule · Send back
Approved — handed back▼
6Activated and suppressedPushed only to the platform and account the approver named, with the suppression list applied and the match rate recorded
7Delivery reviewedDelivered composition against intended, reach and frequency, and the slices where the two diverge
Rule changes
Every rule the approver narrows or removes is counted.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Shipping any audience in a restricted category.
Deciding the legal basis for a segment's inputs.
Adding a field the client cannot use for advertising.
Building a lookalike from an unapproved seed.
Automation boundaryAgent acts unaided
✓Draft segment rules from fields already cleared for advertising.
✓Check consent, purpose and opt-out state per input.
✓Test each rule for proxies of a protected attribute.
✓Size the segment, apply suppression and record the match rate.
Write actions run only inside the approval boundaries agreed during implementation. Pushing an audience to a platform is not among them.
Inferring health, religion, politics or sexual orientation.
Targeting an audience that may contain known minors.
Changing or switching off a suppression list.
Onboarding first-party data to a new platform or partner.
Example output
One segment definition, annotated
Everything the agent proposes is attached to the brief it came from.
Audience output · single segmentIllustrative example
Segment brief
Sources
Permission
Category
Confidence
Status
Renters near new listings
CDP plus a partner list
Read today
Housing — restricted
91%
Held, not built
As receivedThe brief as the planner wrote it, the sources it would draw on, and the date the consent and opt-out state were read.
Evidence usedConsent record, datedStated purpose on filePartner list, unpermitted
Why it is heldIt is a housing brief, and one source has no advertising permission. Both are named.
ActionApproveNarrow the ruleSend back
What the score decidesIt decides how hard the approver reads the rule set — not whether the audience is lawful to run.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every segment requestFrom planners, the CDP and scheduled refreshes
03Permission & purpose
Carry the permission with the field
Every field in a segment arrives with the consent, contract and stated purpose behind it, read at build time and stamped with the date.
01Approved path
Cut the sourcing and sizing work
Sourcing, rule drafting, sizing and overlap are finished before a person opens the brief, so the approver reads a definition instead of building one.
02Human review
Surface the proxy before the push
Rules that reconstruct a protected attribute, and briefs that fall in a restricted category, are held now instead of found in a delivery report later.
04Build an evidence trail
Retain the brief, the rules, the permission evidence, the proxy result, the approver, the match rate and the composition delivered — on both paths.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
An aggregate failure rate can look acceptable while a small number of brief types carry nearly all of the proxy findings, the permission gaps and the audiences pulled after sign-off. Nestack reports performance by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Housing, employment and credit briefs
6.2%
3.9×
Review
Onboarded partner and second-party data
4.3%
2.7×
Review
Lookalikes built from small seeds
2.9%
1.8×
Watch
Repeat first-party refreshes
1.0%
0.6×
Normal
Bar: failure-rate lift vs. first-party refresh baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
An approved audience does not stay approved
Consent is withdrawn, opt-outs arrive and platforms change what a category may target. A segment nobody re-checks drifts out of permission while it runs.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
A proxy finding, a permission gap or a delivery skew shows up in one kind of brief.
02Diagnose
Traced to a source field, a rule, the seed, the suppression list or a platform policy change.
03Improve
The field, rule or list is changed, re-cleared by the named approver and version-linked.
04Verify
Re-run against held-out briefs, including the audiences that were pulled after sign-off.
05Learn
The pulled audience becomes a regression case and the rule enters the targeting standard.
Learn → DetectThe return edge. Every cycle also re-reads consent, opt-outs and the platforms' category rules — an audience cleared last quarter is not cleared now.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, permission mapping, rules and proxy testing, evaluation, activation, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Workflow discovery and automation-boundary definition.
02CDP, warehouse and source assessment.
03Permitted-use, consent and contract mapping.
04Restricted-category rules and named approvers.
05Segment rule drafting and sizing logic.
06Proxy audit and protected-attribute testing.
07Suppression, opt-out and preference wiring.
08Approval workflow and sign-off record.
09Evaluation suite, slices and regression briefs.
10Platform audience APIs and clean-room joins.
11Match-rate and composition reporting.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne platform, one segment setProductionProduction CDP integrationAdvancedMulti-platform / multi-brand
Introduced at Pilot
Segment definition and sizing✓✓✓
Permitted-use and consent checks✓✓✓
Restricted-category flagging✓✓✓
Named-approver sign-off✓✓✓
Baseline evaluation✓✓✓
Introduced at Production
Proxy audit on every rule—✓✓
Suppression and opt-out enforcement—✓✓
Platform audience APIs — approver pushes—✓✓
Match-rate and composition reporting—✓✓
Introduced at Advanced
Clean-room joins and identity resolution——✓
Multi-brand and enterprise controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on platforms and data sources in scope, consent and preference systems, clean-room and identity integrations, segment volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01The platforms and segment types you want in scope→Platform audience APIs and activation scopingWeek 1
02Your data sources and what each was collected for→Permitted-use, consent and contract mappingWeek 1
03Access to the CDP, warehouse and consent platform→Source assessment, consent and preference wiringWeek 2
04Suppression lists, opt-outs and do-not-target rules→Suppression, opt-out and preference enforcementWeek 3
05The proxies and protected attributes you already watch→Proxy audit and protected-attribute testingWeek 3
06Segments you have had to pull, and the reason→Evaluation suite, regression briefs and slice reportingWeek 4
07Named approvers for legal basis and restricted briefs→Approval workflow, then activation under sign-offWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Phases are drawn over the weeks they actually occupy. Week 5 carries the first audiences pushed under sign-off.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Platforms and segment types in scope; who clears a restricted briefW2Source assessment, permitted-use mapping and consent wiringW3Segment rules, proxy audit and suppression enforcementW4Approval workflow, evaluation suite and slice reportingW5Platform APIs, first audiences pushed under sign-offW6Live audiences under approval, then Agent Care monitoring
Reading the bandThe proxy audit and the suppression wiring land in week 3, before any audience can be pushed in week 5. The bars show that dependency, not a smooth ramp.
At the end of W6Audiences have gone live under sign-off with the permission behind every field on file, then Agent Care takes over monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Advertising AI agent
Build an audience-targeting copilot around your data stack.
Show us the segments you build most often, where their data comes from and what each source was collected for, and who signs off a restricted brief today. We'll rebuild one live audience from its brief, show you the permission behind every field and the proxies it would have carried, then scope from there.