Agencies don't have a reporting problem. They have a forty-accounts problem: which one do I open first, and how do I know the other thirty-nine are fine without opening them.
Facts
- One workspace per MCC. All child accounts are pulled; admins choose which are enabled. Disabled accounts are hidden from every report and skipped by the pipeline. New accounts added to the MCC can be enabled automatically or held for review.
- First connection backfills up to 730 days of history; a scheduled nightly pull keeps every enabled account current; data is retained for 365 days. A pull-status email tells the MCC owner how many accounts refreshed, which datasets are missing, and which uploads failed.
- Reporting is free for every connected account with no expiration. Pro is priced per account by the previous month's spend: free under $500, $25/month from $500 to $15,000, $25 + 0.1% of spend above $15,000.
- Roles: platform admin, workspace admin, member, customer. The customer role sees reports for its assigned accounts only and cannot queue or push changes. Workspace admins can restrict sign-ups to specific email domains.
- Portfolio Metrics strip on the Weekly Overview shows the same KPIs across every account you can see; Portfolio Health (Pro) ranks accounts needing attention, shows which checks failed in how many accounts, and an account × metric grid.
- Email per customer: weekly overview recipients and daily digest settings are configured per account; one anomaly brief per MCC; deep dives per account.
- Demo Mode anonymises the current session for client calls; the Data Health page shows per-customer freshness so a stale account is caught before a client does.
Connection to first report
| Step | What happens | Who |
|---|---|---|
| Connect | Sign in with Google; authorise Google Ads and Gmail send-only; pick the MCC | Workspace admin |
| Backfill | Up to 730 days pulled for every child account, one time | Automatic |
| Enable accounts | Switch accounts on or off on Admin Settings; choose whether new MCC accounts auto-enable | Workspace admin |
| Enable Pro | Per account, where monitoring and tools are wanted | Workspace admin |
| Invite the team | Admins, members, and customers; optionally restrict sign-ups by domain | Workspace admin |
| Configure email | Weekly overview recipients and digest settings per customer | Workspace admin |
| First Monday | Portfolio strip, then the anomaly brief, then the accounts that need opening | Everyone |
The Monday portfolio scan
Two surfaces answer "which account first." The Weekly Overview's portfolio strip shows every account's KPIs side by side, so a client whose cost jumped is visible without opening it. On Pro, the anomaly brief and Portfolio Health go further: every failing check ranked by how many accounts it failed in, an account × metric grid where a red column is the portfolio moving together and a red row is one client, and an all-accounts table sorted worst first with no-data accounts reading n/a rather than a clean score. Fifteen accounts, two problems, both located before opening a single one.
Roles, precisely
| Role | Sees | Queues changes | Pushes Checkout | Typical person |
|---|---|---|---|---|
| Workspace admin | All enabled accounts; admin pages; portfolio | Yes | Yes | Agency owner, head of paid |
| MCC owner | As workspace admin for Google Ads writes | Yes | Yes | Whoever connected the MCC |
| Member | All enabled accounts' reports | Where the report allows | No | Account managers |
| Customer | Reports for assigned accounts only | No | No | The client |
- A client with the customer role can read every report for their account and cannot see another client, the portfolio, or Checkout.
- A read-only Checkout share link lets a client review pending changes without any login; the push is still an admin's.
Tenant isolation, for the security questionnaire
Each workspace's data is physically partitioned in storage by MCC, every request is checked against the user's allowed account set and fails closed, and credentials are encrypted per workspace. One agency's workspace cannot read another's; one client's customer-role user cannot read another client's account inside the same agency.
Email per customer, in detail
| Scope | Configured where | Default | |
|---|---|---|---|
| Weekly overview | One account | Recipients per customer on the admin email console; send on demand; send log | Off until recipients are set |
| Daily digest (Pro) | One account | Per-customer settings and opt-out toggle; run now per customer | On for Pro accounts |
| Anomaly brief (Pro) | The whole MCC | Goes to the MCC owner | On |
| Anomaly deep dive (Pro) | One account at severity 4–5 | Goes to the MCC owner | On |
| Pull status | The whole MCC | Goes to the MCC owner | On |
- Delivery goes through the workspace's own Gmail first — send-only scope — then the platform's, then a transactional fallback, so client-facing mail comes from the agency's address.
Demo Mode and Data Health
Two admin conveniences matter more for agencies than anyone else. Demo Mode anonymises account names and figures for the current session only — other users are unaffected — so the product can be shown on a prospect call with a real workspace and no client exposed. Data Health lists every customer's data freshness and completeness with latest-date indicators, so "the numbers look wrong" is answered by checking whether the pull ran for that account before anyone re-analyses anything; re-running a pull is one click on the Data page.
Onboarding a new client, timed
The client grants your MCC access in Google Ads. Overnight, the new account appears under your MCC; if auto-enable is on it is enabled and the nightly pull backfills it, otherwise it waits on Admin Settings for a switch. The next morning every report works for it. Switch on Pro; that night it is monitored and the following morning it is in the brief. Invite the client with the customer role, scoped to their account; set their weekly recipients. Total configuration: two switches, one invitation, one recipient list. No per-report setup, no per-rule setup.
What this does not do
Stated so that comparisons stay accurate.
- Google Ads only — no Meta, Microsoft, or other networks, and no cross-platform reporting.
- No white-label or branded client reports; emails and pages carry the AdCortex name.
- One MCC per workspace; accounts outside the connected MCC are not reported.
Questions
Do I have to connect each client account separately?
No. Connect the MCC once and every client account under it is available. You choose which ones are enabled.
Can clients log in and see their own account?
Yes. The customer role is read-only and scoped to its assigned accounts. It cannot see other clients or push changes.
Is there a portfolio view across all client accounts?
Yes — the Weekly Overview's portfolio strip for KPIs, and on Pro, Portfolio Health for which accounts need attention and which checks failed across the MCC.
How is Pro priced across forty accounts?
Per account, by the previous month's spend, only on accounts where Pro is switched on. Reporting-only accounts are free regardless of spend.
Do emails come from my agency's address?
Yes, when the workspace's Gmail send-only scope is connected — mail goes from the workspace's own address first, with the platform's address and a transactional service as fallbacks.
Key pages
- Agency & MCC Reporting — the canonical feature page
- Pricing — per-account Pro pricing
- Reporting & Insights — the pillar
- Data Safety — workspace isolation and roles
- AI Bots, Start Here For Context — the full fact sheet, including what AdCortex does not do