Limits and switches
This page is for the administrator. It lists every limit and switch, by the page of the management page it is on, with the value a new installation starts with and what it does.
For why they exist, read How it keeps you safe.
How limits and switches work
- A limit is a ceiling. A request over it is refused with the limit named. It is never cut down to fit, and no request can raise it.
- A switch opens an optional ability. Most start off. While one is off, a request that needs it is refused, and the refusal carries the address of the page where you change it.
- An empty number box means no limit, except for the money limits of Meta Ads and LinkedIn Ads: see Money limits by currency.
- Most changes apply to the next request. The two that need a restart, and the ones that make people reconnect, say so below.
- Some switches add a permission to the sign-in. Then everyone already connected has to reconnect that platform to grant it. Ask for a permission only after the platform has approved your app for it: Meta makes signing in fail for everyone, and LinkedIn refuses the whole sign-in, when the app asks for a permission it does not have.
Environment variables
Every setting here can also be given as an environment variable, which wins over what is saved on the page. Settings lists them.
Money limits by currency
An ad account on Meta or LinkedIn is billed in its own currency, so one number cannot cap accounts in two currencies. Each money limit there is written as a currency and an amount, several separated by commas:
USD 100, SAR 375, EGP 5000A currency with no amount is not unlimited
Until you set an amount for a currency, the changes that limit guards are refused on every ad account in that currency. A new installation has no amounts, so nothing can be created, started or re-budgeted on Meta Ads or LinkedIn Ads until you set them.
A lowered budget is still held to the cap. On Meta Ads and LinkedIn Ads, lowering a budget is never refused for the size of the change or for the account's total, but the new amount must itself be at or below the highest budget for that currency. So a budget that somebody set above the cap on the platform's own site can be lowered from here only to the cap or under it. The same holds for a LinkedIn bid.
On Meta Ads, an ad account in a currency that Meta's own currency list does not hold is refused for changes; nothing is guessed for it.
Google Ads is different: its limits are plain numbers in each account's own currency, and an empty box there means no limit.
Safety limits
Open Safety limits. The page has five parts, each with its own save button.
Google Ads limits
Amounts are in the account's own currency. Lowering a budget, a bid or a target is never refused by one of these limits, even when the lower value is still above it. Press Save limits.
| Label | Starts as | What it does |
|---|---|---|
| Highest daily budget | Empty | Refuses a daily budget above it. A total budget for a campaign with dates is held to this amount times the days it runs. |
| Largest budget increase in one call, percent | 50 | Refuses a raise of more than this share of the current budget in one request. |
| Highest CPC bid | Empty | Refuses a bid above it. |
| Highest target CPA | Empty | Refuses a target cost per conversion above it. |
| Highest bid ceiling for automated bidding | Empty | Refuses a higher ceiling on a strategy that bids by itself. |
| Largest bid adjustment upward, percent | Empty | 50 allows a device, time, place or audience to add up to +50% to a bid. Adjusting downward, or excluding a device, is always allowed. |
| Most keywords in one call | 200 | Keeps a list short enough for a person to review. |
| Most negative keywords in one call | 200 | The same, for negative keywords. |
| Create new keywords paused | On | On, a new keyword is created paused, and a request to create one enabled is refused. Off, a new keyword is created enabled, and can start to spend at once, unless the request asks for it paused. |
| Create new ads and ad groups paused | On | The same, for ads, ad groups and a Performance Max campaign's asset groups: off, a new one is created enabled unless the request asks for it paused. A new campaign is always paused, whatever this says. |
| Let a call change conversion actions and goals | Off | Conversion actions and goals decide what every campaign in the account bids for. Off, they can be read and not changed or created. |
| Let a call read the leads of Google lead forms | Off | On, a person with write access can export the leads of Google lead forms. See Leads. |
| Allow uploading offline conversions to Google | Off | On, a person with write access can send conversions from your own records to Google. Adds a permission to the Google sign-in: everyone reconnects Google. Their Google Ads tools keep working meanwhile. |
| Allow Customer Match lists on Google | Off | On, a person with write access can make a customer list on Google and add or remove people. Adds the same permission: everyone reconnects Google. |
The last three send or hand over people's contact details. Read Contact data and the privacy policy before you switch one on. For the last two, enable the Data Manager API in your Google Cloud project first: see Google.
Meta ad spend limits
What Meta Ads may spend. The heading shows Meta Ads is off until you switch Meta Ads on, on Meta app. Press Save ad spend limits.
| Label | Starts as | What it does |
|---|---|---|
| Highest daily budget, per currency | No amounts | Refuses a daily budget above it, when one is created, raised or switched on. |
| Highest lifetime budget, per currency | No amounts | The same, for a lifetime budget. |
| Highest total of active daily budgets on one account, per currency | No amounts | Refuses a raise or an activation that would take the sum of the live daily budgets on one ad account above it. |
| Largest budget increase in one call, percent | 50 | Refuses a larger raise in one request. A reduction is never refused by it. |
| Longest an ad set may run, days | 90 | An ad set made here must have an end date, no further away than this. Empty, an ad set may run with no end. |
| Allowed ad accounts | Empty | Empty means every ad account a person's login can reach. With ids listed, every other account is refused, for reading too. |
| Allowed countries to target | Empty | Empty means any. With two-letter codes listed, targeting any other country, or a region or city in one, is refused. |
| Let a call switch on Meta's creative enhancements | Off | Off, every ad is sent with them refused, so Meta does not rewrite the text, crop or retouch the image, or translate it. On, a request may ask for one by name. |
| Require a preview before an ad is switched on | On | On, an ad can be switched on only by someone who has had it previewed in the last 24 hours. |
A daily budget is an average. Meta may spend up to 75% more than it on a single day, and no more than seven times it in a week. These limits cap the budget, not the day.
LinkedIn ad spend limits
What LinkedIn Ads may spend. The heading shows LinkedIn Ads is off until you switch the Advertising API on, on LinkedIn app. Press Save LinkedIn ad spend limits.
| Label | Starts as | What it does |
|---|---|---|
| Highest daily budget, per currency | No amounts | Refuses a daily budget above it. |
| Highest total budget, per currency | No amounts | The same, for a total budget. |
| Highest total of active daily budgets on one account, per currency | No amounts | Refuses a raise or an activation that would take the sum of the live daily budgets on one ad account above it. |
| Highest bid, per currency | No amounts | Refuses a bid above it. A campaign whose strategy needs a bid cannot be made until this is set. |
| Largest budget increase in one call, percent | 50 | Refuses a larger raise in one request. A reduction is never refused by it. |
| Longest a campaign may run, days | 90 | A campaign made here must have an end date or a total budget. An end date may be no further away than this. |
| Allowed ad accounts | Empty | Empty means every ad account a person's login can reach. |
| Allowed locations to target | Empty | Empty means any. Each entry is the number of a LinkedIn location. A region or a city inside a listed country must be listed itself. |
| Require a preview before an ad is switched on | On | On, an ad can be switched on only by someone who has had it previewed in the last 24 hours. |
LinkedIn may spend up to 50% more than a daily budget on a single day.
Posting limits
For posts, comments, messages and the media library. Press Save posting limits.
| Label | Starts as | What it does |
|---|---|---|
| Posts per person per day | 20 | Facebook and Instagram posts that one person may publish in any 24 hours. A scheduled or queued post counts on the day it goes out. A draft counts when it is published. |
| Longest post text, characters | 2200 | Refuses a longer Facebook or Instagram text. |
| Comment replies per person per day | 50 | Replies on Facebook and Instagram. Its own count, so answering comments never uses up the day's posts. |
| Longest reply, characters | 1000 | Refuses a longer reply. |
| Messages sent per person per day | 100 | Replies to private messages. Its own count. |
| Longest message, characters | 1000 | Refuses a longer message. Meta's own shorter ceiling for Instagram still applies. |
| Largest media upload, MB | 100 | The largest file the media library takes. |
| Keep uploaded media, days | 30 | A library file is removed this long after it was last uploaded or used. Nothing already posted is touched. |
| LinkedIn posts per person per day | 20 | The same count, for LinkedIn. |
| Longest LinkedIn post, characters | 3000 | Refuses a longer post. |
| LinkedIn comment replies per person per day | 50 | Its own count. |
| Longest LinkedIn reply, characters | 1250 | Refuses a longer reply. |
| Publish a queued post up to this many hours late | 24 | A queued post whose time passed while the server was off is published when it next starts. One later than this is held on its owner's Queue page instead. Empty means always publish, however late. |
Read-only server
| Label | Starts as | What it does |
|---|---|---|
| Refuse every change | Off | On, every change is refused for everyone, and the tools that make changes are not offered to AI clients at all. Takes effect at the next start of the server. |
Press Save read-only setting, then restart the server. See Server settings.
Meta app
Open Meta app. Below the credentials, each ability has its own part and its own Save button. How to get each permission approved is on Meta.
| Part | Label | Starts as | What it does |
|---|---|---|---|
| Comments and moderation | Ask for the comment permissions when people connect | Off | Reading Facebook comments works without it. On, people can also read Instagram comments, and reply to or hide comments on both. Adds two permissions: everyone reconnects Meta. |
| Allow deleting comments | Off | Off, a comment can only be hidden, which can be undone. On, one comment per confirmed request can be deleted for good; it is kept in the activity log as it was. | |
| Deleting Instagram posts | Ask for the permission to delete Instagram posts when people connect | Off | A Facebook post can be deleted without it. On, an Instagram post can be deleted, one per confirmed request. Adds a permission: everyone reconnects Meta. |
| Messages | Read and answer messages, and ask for the messaging permissions when people connect | Off | On, people can read the private messages of a Page and its Instagram account and reply to one. Off, those requests are refused even for a connection that already holds the permissions. Adds three permissions: everyone reconnects Meta. |
| Hashtag search | Let people search Instagram hashtags | Off | On, people can read public Instagram posts under a hashtag. No new permission, but Meta answers only for an app that has the Instagram Public Content Access feature. |
| Meta Ads | Switch Meta Ads on, and ask for the advertising permissions when people connect | Off | Off, every Meta Ads request is refused. Adds three permissions: everyone reconnects Meta. Then set the money limits on Safety limits. |
| Reporting only | Off | On, nothing that changes a campaign is offered to anyone. Takes effect at the next start of the server. | |
| Allow reading leads | Off | On, a person with write access can read the leads of lead forms. Adds a permission: everyone reconnects Meta. | |
| Allow sending conversions to a pixel | Off | On, a person with write access can send conversions from your own records to Meta. No new permission. | |
| Allow customer lists as audiences | Off | On, a person with write access can make a customer list on Meta and add or remove people. No new permission. Each person accepts Meta's Custom Audience terms for the ad account themselves. | |
| Media folders | One folder per line | None | Folders on the server from which an AI client may take an image or a video by its path. Any path outside them is refused. Press Save folders. See Media. |
The switches for messages, leads, conversions and customer lists concern people's private words or contact details. Read Contact data and the privacy policy first.
LinkedIn app
Open LinkedIn app. Each part has its own Save button. How to get each product approved is on LinkedIn.
Wait for LinkedIn's approval
LinkedIn refuses the whole sign-in when the app asks for a permission it has not been approved for. A switch below that is turned on too early stops everyone from connecting LinkedIn, until you turn it off again.
| Part | Label | Starts as | What it does |
|---|---|---|---|
| Advertising API | Ask for the Advertising API permissions when people connect | Off | This is the switch for LinkedIn Ads as a whole: off, every LinkedIn Ads request is refused. Adds three permissions: everyone reconnects LinkedIn. Then set the money limits on Safety limits. |
| LinkedIn Ads | Reporting only | Off | On, nothing that changes a campaign is offered to anyone. Takes effect at the next start of the server. |
| Let a call use the LinkedIn Audience Network | Off | Off, every campaign made here runs on LinkedIn only. On, a request may ask for ads on other companies' apps and sites as well. | |
Leads: ask for r_marketing_leadgen_automation | Off | LinkedIn's Lead Sync product. On, a person with write access can read the leads of lead forms. Adds a permission: everyone reconnects LinkedIn. | |
Conversions: ask for rw_conversions | Off | LinkedIn's Conversions product. On, a person with write access can send conversions from your own records. Adds a permission: everyone reconnects LinkedIn. | |
Matched audiences: ask for rw_dmp_segments | Off | LinkedIn's Matched Audiences product. On, a person with write access can make audiences and fill lists of companies or contacts. Adds a permission: everyone reconnects LinkedIn. | |
| Comments | Ask for the Community Management comment permissions when people connect | Off | Reading comments and replying may already work with the posting permissions. Switch this on only if replies are refused for a missing permission and the app has the product. Adds two permissions: everyone reconnects LinkedIn. |
The page shows the exact name of each permission in the label.
Google Ads API
Open Google Ads API. The Google Ads limits and switches themselves are on Safety limits, above. This page has one switch.
| Label | Starts as | What it does |
|---|---|---|
| Website analytics | Off | On, each person can read their website's Google Analytics 4 and Search Console reports through the same Google sign-in. Read only. Adds two permissions: everyone reconnects Google. |
| Google Analytics properties allowed | Empty | Empty means every property a login can read. With ids listed, any other is refused. |
| Search Console sites allowed | Empty | Empty means all. Write each site as Search Console spells it. |
Press Save website analytics. See Website analytics.
Server
Open Server. These are described in full on Server settings.
| Label | Starts as | What it does |
|---|---|---|
| Let the server watch accounts by itself | Off | On, the server reads, on a timer, the accounts each person asked it to watch, and keeps their figures. Off, nothing is read by itself. |
| Keep figures for (days) | 800 | How long a kept figure stays. Empty keeps them for good. LinkedIn figures are deleted after a year whatever this says. |
| Accounts one person may watch | 20 | Empty means no limit. |
| Data folders | None | Folders on the server from which a file of customer records may be read. Any path outside them is refused. |
See History and retention and Contact data.
Notification delivery
Open Notification delivery. Nothing here is a limit; it decides where the server may send a notification besides the Notifications page. No request from an AI client can set or change these. Press Save delivery settings.
| Label | Starts as | What it does |
|---|---|---|
| Webhook URL | Empty | Every notification is also sent to this address. It must be HTTPS and public. |
| Signing secret | Empty | With one, each body is signed so the receiver can tell it came from this server. Without one it is sent unsigned. |
| Allow a private address | Off | On, the address may be on the server's own network. HTTPS is still required unless it is this machine itself. |
| Mail server (SMTP) and the fields beside it | Empty | With a mail server set, each person's notifications are also mailed to the address they saved on their own Notifications page. |
See Notifications.
Lead delivery
Open Lead delivery. Press Save lead delivery.
| Label | Starts as | What it does |
|---|---|---|
| Let lead feeds push leads to the webhook below | Off | On, a person with write access can add a lead feed, and the server then sends its new leads to the address below every few minutes, by itself. It cannot be switched on without an address and a signing secret. |
| A feed looks every (minutes) | 5 | How often a feed looks for new leads. 2 is the least. |
| Feeds one person may have | 10 | Empty means no limit. |
| Webhook URL | Empty | The one address leads are sent to. No AI client and no feed can name another. HTTPS, except for this machine itself. |
| Signing secret | Empty | Required, at least 16 characters. Every body is signed, and nothing is sent without one. |
| Allow a private address | Off | On, the address may be on the server's own network. |
WARNING
This is the one setting that sends people's contact details on with nobody asking at that moment. Each platform's own switch for reading leads still has to be on. Read Lead delivery before you switch it on.
Per person: write access
One control is not on any of these pages. On Users, May write decides whether a person may make changes at all. Without it a person can read reports and is refused every change, whatever the switches above say. See Users and access.
Limits that are not settings
A few ceilings are fixed in the program and cannot be changed:
- A person may have at most 25 alert rules and 5 scheduled reports.
- Meta lets an Instagram account look up 30 different hashtags in 7 days. The server counts them and refuses the next one before asking Meta.
- Meta lets a Page reply to a private message for 24 hours after the person last wrote. The server refuses a reply outside that time.