Kiến trúc đề xuất · Triển khai · 2026-10-08
Giám đốc Marketing vẫn trò chuyện với AI trên máy của mình, nhưng máy chủ Google Ads MCP (tự host) và mọi kết nối tới Google nằm trên server của doanh nghiệp: nơi giữ token, giới hạn scope, ghi nhật ký và xếp hàng đề xuất chờ duyệt. Chạy theo lịch không phụ thuộc laptop đang bật hay tắt.
Recommended architecture · Deployment · 2026-10-08
The Marketing Director still talks to the AI on their own machine, but the self-hosted Google Ads MCP server and every connection to Google sit on the company server: that is where tokens are kept, scopes are limited, calls are logged and proposals queue for approval. Scheduled runs do not depend on whether a laptop is on.
推荐架构 · 部署 · 2026-10-08
市场总监仍在自己的电脑上与 AI 对话,但自托管的 Google Ads MCP 服务器以及所有通往 Google 的连接都放在企业服务器上:令牌保存在那里、权限范围受限、调用被记录、建议排队等待审批。定时运行不依赖笔记本是否开机。
Architecture recommandée · Déploiement · 2026-10-08
Le directeur marketing continue de dialoguer avec l'IA sur sa propre machine, mais le serveur MCP Google Ads auto-hébergé et toutes les connexions vers Google résident sur le serveur de l'entreprise : c'est là que les jetons sont conservés, les scopes limités, les appels journalisés et les propositions mises en file d'approbation. Les exécutions planifiées ne dépendent pas d'un portable allumé.
| Tiêu chí | Máy cá nhân (laptop CMO) | Server riêng + laptop (đề xuất) | Cloud quản trị (Google Cloud, Anthropic) |
|---|---|---|---|
| Thời gian bắt đầu | Vài giờ: cài pipx, chạy google-ads-mcp, đăng nhập ADC bằng tài khoản có quyền MCC. | 1–3 tuần: host google-ads-mcp dạng Streamable HTTP (OAuth proxy) sau cổng, lưu token, bật nhật ký. | 1–3 tuần, ít việc vận hành hơn server riêng. |
| Ai giữ credential | Token OAuth của CMO nằm trên laptop; mất máy là mất kiểm soát. | Secret manager trên server; người dùng chỉ đăng nhập SSO. | IAM và secret manager của cloud; dễ xoay vòng, dễ thu hồi. |
| Nhật ký và kiểm toán | Gần như không; chỉ lịch sử chat. | Ghi mọi lời gọi tool: ai, lúc nào, ghi gì vào Google Ads. | Có sẵn audit log, tích hợp SIEM. |
| Chạy theo lịch, chạy nền | Không: laptop tắt là dừng. | Có: báo cáo sáng, cảnh báo CPI/ROAS, job hàng giờ. | Có, tự co giãn. |
| Nhiều người dùng | Mỗi người tự cấu hình, không đồng nhất. | Một cấu hình, phân quyền theo vai trò. | Như server, cộng thêm quản trị tập trung của nhà cung cấp. |
| Rủi ro ghi nhầm | Thấp hôm nay vì máy chủ chính thức chỉ đọc; sẽ cao khi Google mở quyền ghi. | Thấp: khi Google mở quyền ghi, bật trong tools_config.yaml chỉ ở server, mọi thay đổi xếp hàng chờ duyệt. | Thấp, cùng cơ chế với server. |
| Chi phí | Chỉ phí thuê bao AI. | Một VPS hoặc máy nội bộ + công vận hành. | Phí dịch vụ theo mức dùng, thường cao hơn khi quy mô nhỏ. |
pipx run google-ads-mcp ngay trong Claude Desktop/Code (đường nét đứt dưới cùng) với ADC của mình và GOOGLE_ADS_LOGIN_CUSTOMER_ID = MCC. Máy chủ chỉ đọc nên rủi ro thấp; dùng giai đoạn này để học cách hỏi và kiểm tra chất lượng câu trả lời.tools_config.yaml), chỉ bật ở server, mọi thay đổi xếp hàng chờ người duyệt; cho tới lúc đó, người áp dụng thay đổi trong giao diện Google Ads như sơ đồ Google Ads MCP.| Criterion | Personal machine (the director's laptop) | Own server + laptop (recommended) | Managed cloud (Google Cloud, Anthropic) |
|---|---|---|---|
| Time to start | Hours: install pipx, run google-ads-mcp, sign in to ADC with an account that has MCC access. | 1–3 weeks: host google-ads-mcp as Streamable HTTP (OAuth proxy) behind a gateway, store tokens, enable logging. | 1–3 weeks, less operations work than an own server. |
| Who holds credentials | The director's OAuth token lives on the laptop; a lost machine means lost control. | A secret manager on the server; users only sign in with SSO. | The cloud's IAM and secret manager; easy to rotate and revoke. |
| Logging and audit | Almost none; only chat history. | Every tool call logged: who, when, what was written to Google Ads. | Audit logs built in, SIEM integration. |
| Scheduled and background runs | No: laptop off means nothing runs. | Yes: morning reports, CPI/ROAS alerts, hourly jobs. | Yes, auto-scaling. |
| Multiple users | Everyone configures their own setup, inconsistently. | One configuration, role-based permissions. | Same as a server, plus the vendor's central administration. |
| Risk of accidental writes | Low today because the official server is read-only; rises once Google opens write access. | Low: when Google opens write access, enable it in tools_config.yaml on the server only, and queue every change for approval. | Low, same mechanism as the server. |
| Cost | Only the AI subscription. | One VPS or on-premise machine + operations time. | Usage-based service fees, usually higher at small scale. |
pipx run google-ads-mcp straight in Claude Desktop/Code (the dashed line at the bottom) with their own ADC and GOOGLE_ADS_LOGIN_CUSTOMER_ID = MCC. The server is read-only, so the risk is low; use this phase to learn how to ask and to check answer quality.tools_config.yaml), enable them on the server only and queue every change for a person to approve; until then, people apply changes in the Google Ads UI as in the Google Ads MCP diagram.| 标准 | 个人电脑(总监的笔记本) | 自有服务器 + 笔记本(推荐) | 托管云(Google Cloud、Anthropic) |
|---|---|---|---|
| 启动时间 | 数小时:安装 pipx,运行 google-ads-mcp,用有 MCC 权限的账号登录 ADC。 | 1–3 周:在网关后以 Streamable HTTP(OAuth 代理)托管 google-ads-mcp,保存令牌,开启日志。 | 1–3 周,运维工作少于自有服务器。 |
| 谁持有凭据 | 总监的 OAuth 令牌存在笔记本上;丢了电脑就失去控制。 | 服务器上的密钥管理器;用户只需 SSO 登录。 | 云平台的 IAM 与密钥管理器;易于轮换和吊销。 |
| 日志与审计 | 几乎没有;只有聊天记录。 | 记录每次工具调用:谁、何时、向 Google Ads 写了什么。 | 内置审计日志,可对接 SIEM。 |
| 定时与后台运行 | 不行:笔记本关机即停止。 | 可以:晨报、CPI/ROAS 告警、按小时任务。 | 可以,自动伸缩。 |
| 多用户 | 各自配置,难以统一。 | 一套配置,按角色授权。 | 同服务器,另有厂商的集中管理。 |
| 误写风险 | 目前较低,因官方服务器只读;Google 开放写权限后会升高。 | 低:Google 开放写权限后,只在服务器的 tools_config.yaml 中启用,所有更改排队待审批。 | 低,与服务器机制相同。 |
| 成本 | 仅 AI 订阅费。 | 一台 VPS 或内部机器 + 运维工时。 | 按用量计费,小规模时通常更高。 |
pipx run google-ads-mcp(底部虚线),使用自己的 ADC 并设置 GOOGLE_ADS_LOGIN_CUSTOMER_ID = MCC。服务器只读,风险低;用这一阶段学习提问方式并检验回答质量。tools_config.yaml 启用)时,只在服务器上启用,所有更改排队由人审批;在此之前,人按 Google Ads MCP 图在 Google Ads 界面中应用更改。| Critère | Poste personnel (portable du directeur) | Serveur propre + portable (recommandé) | Cloud managé (Google Cloud, Anthropic) |
|---|---|---|---|
| Délai de démarrage | Quelques heures : installer pipx, lancer google-ads-mcp, se connecter à ADC avec un compte ayant accès au MCC. | 1 à 3 semaines : héberger google-ads-mcp en Streamable HTTP (proxy OAuth) derrière une passerelle, stocker les jetons, activer la journalisation. | 1 à 3 semaines, moins d'exploitation qu'un serveur propre. |
| Qui détient les identifiants | Le jeton OAuth du directeur est sur le portable ; machine perdue, contrôle perdu. | Un gestionnaire de secrets sur le serveur ; les utilisateurs se connectent seulement en SSO. | IAM et gestionnaire de secrets du cloud ; rotation et révocation faciles. |
| Journalisation et audit | Quasi inexistants ; seulement l'historique de chat. | Chaque appel d'outil journalisé : qui, quand, ce qui a été écrit dans Google Ads. | Journaux d'audit intégrés, intégration SIEM. |
| Exécutions planifiées et en arrière-plan | Non : portable éteint, rien ne tourne. | Oui : rapports du matin, alertes CPI/ROAS, tâches horaires. | Oui, avec mise à l'échelle automatique. |
| Plusieurs utilisateurs | Chacun configure de son côté, sans cohérence. | Une seule configuration, droits par rôle. | Comme le serveur, plus l'administration centrale du fournisseur. |
| Risque d'écriture accidentelle | Faible aujourd'hui car le serveur officiel est en lecture seule ; augmentera quand Google ouvrira l'écriture. | Faible : quand Google ouvrira l'écriture, l'activer dans tools_config.yaml sur le serveur seulement et mettre chaque changement en file d'approbation. | Faible, même mécanisme que le serveur. |
| Coût | Seulement l'abonnement IA. | Un VPS ou une machine interne + temps d'exploitation. | Facturation à l'usage, souvent plus élevée à petite échelle. |
pipx run google-ads-mcp directement dans Claude Desktop/Code (ligne pointillée en bas) avec son propre ADC et GOOGLE_ADS_LOGIN_CUSTOMER_ID = MCC. Le serveur est en lecture seule, donc le risque est faible ; cette phase sert à apprendre à poser les questions et à vérifier la qualité des réponses.tools_config.yaml), ne les activer que sur le serveur et mettre chaque changement en file pour validation humaine ; d'ici là, les personnes appliquent les changements dans l'interface Google Ads comme sur le schéma MCP Google Ads.