Skip to content
esc close · switch
LYRA/ Tools/ Protection/ Auto-Apply Guard
Protection Agent-enabledAlways-on

Google's auto-apply does not get the keys.

Auto-Apply Guard sweeps your account once a day and disables the Google recommendation subscriptions you haven't whitelisted. When Google re-enables one — and it does — we disable it again and tell you. No campaign is changed on your behalf.

No credit card · Read-only audit available · Revert at Google level anytime
What Guard does · product behaviour, not analytics Tool v1.1.0 · daily cron
Sweep cadence Daily Runs once every 24h at 06:15 UTC across every connected account.
What we touch Subscriptions Google's recommendation_subscription API only. Your bids, budgets, and keywords are never edited by Guard.
Alert channel Slack Posts to your linked Slack channel whenever Google has re-enabled a previously disabled subscription since the last sweep.
Re-enable rescue Automatic If Google flips a subscription back on between sweeps, the next sweep turns it off again — no human action needed.

A receipt of every subscription we touched.

Each daily run writes a record of what Google proposed, what was on your whitelist, and what Guard disabled. No postmortems — the answer to 'what happened to my account overnight?' is already written.

Sample · one account · one week of sweeps
TimeTypeWhat happenedRule matchedAction
06:15 UTC · Mon Bid strategy Disabled subscription: KEYWORD_MATCH_TYPE Re-enabled by Google since last sweep Disabled
06:15 UTC · Mon Assets Left on: CALLOUT_EXTENSION On user whitelist Allowed
06:15 UTC · Wed Keywords Disabled subscription: ADD_KEYWORD Default block policy Disabled
06:15 UTC · Wed Budget Disabled subscription: CAMPAIGN_BUDGET Default block policy Disabled
06:15 UTC · Fri Assets Left on: SITELINK_EXTENSION On user whitelist Allowed
06:15 UTC · Fri Targeting Disabled subscription: TARGETING_DATA_EXCLUSION Default block policy Disabled
Anatomy · three moving parts

The rails are boringly specific.

Guard doesn't need ML to do its job. It needs a daily sweep, a whitelist, and a log that proves what it did. Everything else is plumbing.

01Sweep

Runs once a day at 06:15 UTC.

For every connected account, Guard reads the current recommendation_subscription list from Google Ads, compares it against your whitelist, and disables anything outside it. Takes seconds per account.

Cadence: daily cron · every connected account
02Whitelist

Block all by default. Opt in per-type.

Guard uses Google's native recommendation_subscription API — the same surface Google's own interface uses. You name the categories you trust (sitelinks, callouts, broken-URL fixes). Everything else stays off, sweep after sweep.

API surface: Google Ads API · recommendation_subscription
03Log

Every sweep writes a run record.

What was enabled before, what got disabled, what re-enabled since last sweep — stored per-account. No rollback needed: Guard didn't change your campaigns, only revoked consent. Re-enable anything you want in Google Ads in two clicks.

Storage: tool_execution_logs · queryable per account
Case · B2B SaaS · 4 accounts under one MCC · 90-day window
Guard blocked two Google-proposed budget increases that violated our lead-quality floor. The weekly postmortem we used to run is gone — I see everything the next morning.
IH In-house strategist · B2B SaaS 4 accounts under one MCC · Europe · anonymized
Budget-increase subscriptions interceptedFirst 90 days 2
Qualified lead ratevs. prior quarter +44%
Strategist time reclaimedPreviously spent on export-stitching ~4h/wk
Cross-account health viewReplaced a manual shared sheet Unified
Frequently asked

The questions we answer on every onboarding call.

How often does Guard actually check?

Once a day at 06:15 UTC. If Google re-enables a subscription at 06:16, we catch it the next morning. If you need tighter than daily, the real workaround is to have Google stop offering the category altogether — Guard's whitelist does that for you by leaving those subscriptions permanently disabled.

Does Guard change anything in my campaigns?

No. Guard only toggles Google's recommendation_subscription flags — a consent layer that sits above your campaigns. Your bids, budgets, keywords, and strategies are untouched. Nothing to roll back, because nothing was changed on your live account.

What if Google applies a recommendation anyway, before my next sweep?

Rare, but when it happens it lands in Change History. Pair Guard with Change History Alert: Guard stops the consent at the subscription layer, Change History Alert catches the change if Google slips past it.

Can I allow some categories and block others?

Yes. The default policy is block-all. You add categories — sitelinks, callouts, broken-URL fixes, optimisation-score nudges — to your whitelist. Guard leaves those on and disables everything else, every sweep.

What happens if Guard is offline for a day?

Not much. Guard is a daily sweep, not a firewall. If the cron misses a run, your subscription state carries over from the previous day. You lose one day of protection, not the account. The next successful sweep re-asserts the whitelist.

14-day free trial · No credit card · Cancel in one click

Run the audit.
Keep the findings.

Connect your account and let Lyra run its 18 tools for 14 days. If the projected waste recovery isn't worth at least 10× the $49, don't pay. You keep every insight either way.

Read-only connect · write access opt-in per tool · SOC 2 in progress · GDPR + CCPA compliant