Are Google Ads scripts safe to run?
What a Google Ads script can access, the real risks, and the checks worth doing before you schedule one.
A script runs with the permissions of the person who authorized it. In practice that means it can read and change the account it runs in, and use the Google services it was granted — Sheets, Drive, Gmail, external URLs. It cannot reach other accounts that person has no access to, and it cannot change billing or users.
The real risks
- A bug that changes too much. A wrong condition can pause the wrong campaigns or set the wrong bids. This is by far the most common problem.
- A script that silently stops. Authorization lapses, a spreadsheet is deleted, Google changes an API field — and the job you thought was running is not.
- Code you did not read. A script copied from the internet does whatever its author wrote, including sending data elsewhere.
Checks before you schedule a script
- Read what it does. At least the description and the settings; ideally the code. Marketplace scripts in chiliad show their full code before you install.
- Run a preview. Preview shows the changes the script would make without applying them. Note that emails and spreadsheet writes do happen in preview.
- Start narrow. Run it on one account, or filter it to one campaign, before rolling it out.
- Authorize with the right login. The script acts as the user who authorized it. If that person leaves, the script stops.
How chiliad helps
- Every code change is a saved version with an author, and you can restore an earlier one.
- At manager level the loader runs only the accounts assigned to the script, and skips the run if it cannot confirm the list.
- Failed, stopped and unusually short runs raise alerts, so a quiet failure does not stay quiet. See Monitoring and alerts.