10 Sep 2026 · 4 min read
How to Write a Media Buying Mandate for an AI Agent
TL;DR: A media buying mandate is the document that governs what an AI agent is authorised to do on a buyer's behalf. Writing a good one requires clarity about five things: the scope of authorised inventory, the CPM range the agent can commit to, the audience parameters it can use, the approval thresholds that trigger human review, and the conditions under which the agent must stop rather than escalate. Vague mandates produce agents that drift. Specific mandates produce agents that are auditable.
A media buying mandate is not a strategy document. It does not describe campaign goals, target audiences, or creative approach. It is a governance document: it defines the boundaries within which an agent may act without human approval, the conditions under which it must seek approval, and the conditions under which it must stop. Its purpose is to make the agent's activity auditable after the fact.
The distinction matters because mandates that blend strategy with governance produce agents that are hard to audit. If the mandate says "focus on high-quality brand-safe inventory that supports awareness goals among 18-34 audiences," the agent has described intent but not scope. If the mandate says "CPM range £3.00-£8.50, domain list as per Appendix A, audience segment IDs [x, y, z], format: display 300x250 and 728x90, approval required for CPM above £8.50, stop if daily pacing exceeds budget by 5%," the agent has a testable set of parameters and the buyer has an auditable record.
What a mandate must contain
Authorised inventory scope. The mandate should specify which publishers, domains, or inventory packages the agent is authorised to buy. This may be a whitelist, a list of approved agentic marketplaces, or a set of brand safety requirements that define acceptable inventory categories. Agents operating without an inventory scope definition are empowered to buy anything the protocol can reach, which is rarely the buyer's intent.
CPM range. The mandate should state the minimum and maximum CPM the agent is authorised to commit to. This is the most direct financial control in the mandate. The minimum matters as well as the maximum: an agent without a minimum CPM will accept below-floor inventory that a human buyer would reject.
Audience parameters. The mandate should specify which audience data the agent is authorised to use in deal negotiation. This includes first-party segment IDs, permitted third-party data providers, and, for deployments where the sell-side agent is providing audience data, the conditions under which that data can be used. This section has data protection implications: it should be reviewed by the buyer's legal or compliance team before the mandate is issued.
Approval thresholds. The mandate should define the conditions under which the agent must pause and seek human approval before proceeding. Typical approval thresholds include: CPM above a stated rate, individual deal commitment above a stated value, new publisher or inventory source not on the authorised list, and audience data request outside the defined parameters. Each threshold should be stated as a testable condition, not a subjective judgement.
Stop conditions. The mandate should define the conditions under which the agent must stop entirely rather than escalate for approval. Stop conditions are the hardest fail-safes: pacing overage beyond a stated percentage, a total spend commitment beyond a stated cap, and a defined audit event such as a deal record inconsistency. Stop conditions should be fewer than approval thresholds and should represent genuinely unrecoverable situations rather than routine decisions.
What makes a mandate auditable
A mandate is auditable if a reviewer can evaluate any deal the agent completed and determine whether the deal was within mandate or outside it. This requires that each mandate parameter is expressed in terms that can be compared to deal record data.
"Premium quality inventory" is not auditable. "Domain list Appendix A, MFA-screened, minimum viewability 70% per IAS verification" is auditable.
The mandate should also include a version reference and an effective date. Mandates change as campaigns evolve, and the deal record should contain the mandate version reference at the time of execution. If a deal is later reviewed and found to be outside the current mandate parameters, the reviewer needs to know which version of the mandate was in effect when the deal was completed.
Who should review the mandate before it is issued
The mandate is a governance document with financial, legal, and data protection dimensions. Before it is issued to an agent, it should be reviewed by the person responsible for the campaign budget (for the CPM range and spend caps), the person responsible for data compliance (for the audience parameters), and the person responsible for brand safety (for the inventory scope). In agencies with formal governance processes, the mandate may also require a legal review for deployments where large commitments are possible.
The mandate should not be written by the person who will also audit it. The conflict of interest is the same as in any audit context: the writer should set the parameters, and the auditor should verify compliance against them.