# Owner approval

Authorize one exact plan and one lifetime media budget.

## Review before spending

Agents return approval_url to the owner. The owner signs in and reviews the image, copy, destination, Facebook Page, targeting geography, schedule, and lifetime media budget. No agent scope can authorize campaign activation or advertising spend. Paid creative generation is a separate explicit operation available to live campaigns:write keys; it does not debit the ad balance.

For live campaigns, POST /api/v1/campaigns/{id}/approve is owner-only and requires:

```json
{
  "approved_budget_cents": 50000,
  "approved_plan_hash": "THE_64_CHARACTER_HASH_RETURNED_WITH_THE_PLAN",
  "acknowledge_live_spend": true
}
```

The server verifies the unchanged provider hierarchy, including that no extra ad or group has been added. It checks the advertiser binding and consent, pixel health and objective event, future schedule, deployment launch gate, verified funds, and operator allowance. A locked database transaction reserves the full lifetime budget before provider activation.

## Budget boundaries

The lifetime media budget is the provider spend boundary. Funding balance and operator spending allowance are separate checks. The approval does not authorize a higher budget, a new creative, another Page, or another destination. target_cac_cents does not automatically stop a campaign. Refunds/disputes can place funding on hold; operator review may be required.

A successful activation request is not proof of traffic. Read delivery_status and reconcile provider metrics. Network review and billing setup may prevent delivery. Pause does not refund money already spent and does not immediately free the reserved budget.

## Sandbox approval

A sandbox campaign instead uses {"approved_budget_cents":50000,"acknowledge_sandbox":true}. This permits local sandbox event recording and never authorizes future live spending. Sandbox approval and live approval are distinct schemas.

## Unknown outcome

If approval times out, retain the campaign ID. Reconcile and inspect it before retrying the same approved plan. Do not create another campaign to work around an uncertain activation. An expired provider retry window requires operator investigation.