Email + password, or the master password alone.
Ad creative → which images, videos and headlines bring in Pipedrive leads and won cases, and which ad each lead clicked.
Paste or upload a Google Ads CSV/TSV (title rows and "Total:" rows handled), or pull Microsoft Ads search terms live. The rule engine routes each term (order is semantics), dedups against the synced ground truth with blocking evidence, and sends only genuinely unclear terms to Gemini.
| Status | Search term | Negative | Match | Block in | Home | Revenue | Spend | Reason |
|---|
| Term | Negative | Match | Blocked by |
|---|
One collapsed row per (keyword, match type, account, source) with the groups it blocks. 'partial' = a shared list not attached to every enabled+serving campaign of any group — blocks nothing, so leaks keep surfacing. Live sync happens on the Integrations tab; manual CSV is the fallback layer.
| Account | Source | Rows |
|---|
One phrase per line. Blank list = the built-in default (ported verbatim from WP — the enforcement→HC rule can never silently no-op). Everything else (Gemini keys/model, Pipedrive fields, HC valuation, advisory thresholds, write-back settings, dashboard code) lives in the portal settings page under the nks module.
Fair-trial threshold = 3× account CPA (servable economics; HC valued at realised Ethos averages, unvalued HC excluded).
| Keyword | Spend | Clicks | Deals | Revenue | ROI | Last won |
|---|
| Keyword | Spend | Deals | Revenue | ROI | Last won |
|---|
Critical = blocks a revenue keyword in its home group · High = blocks its own home traffic / KEEP language · Medium = over-broad 1-2-word phrase/broad.
True per-week figures (GAQL segments.week), most recent COMPLETE week vs the one before — the running week is excluded because a part-week always reads as a collapse. CPC and ROAS are derived per week (spend÷clicks, value÷spend), never averaged from averages.
| Campaign / ad group | Spend | Δ spend | CPC | Δ CPC | ROAS | Δ ROAS | Clicks | Conv. | Impr. share | Abs. top |
|---|---|---|---|---|---|---|---|---|---|---|
| Open this tab to load. | ||||||||||
Pick a campaign, type a theme (e.g. section 8, s8), tick the keywords, write or generate the ad, Validate (Google’s own dry-run — nothing is written), then Create. One atomic batch: new ad group + keywords + responsive search ad; originals paused (never removed); the theme added as negatives to the source ad group (phrase match where possible — broad or exact when the phrase form is already a keyword there, since Google can’t hold a keyword and a negative of the same form in one ad group) so the traffic actually routes to the new group. Every create is undoable from the history below.
| Keyword | Match | Ad group | Status | QS | Clicks | Spend | Conv. | Value |
|---|
| When | Summary | Status | |
|---|---|---|---|
| — | |||
Research — Gemini, grounded in live Google Search, lists the firms competing for this account’s services (minus names already in the NKS competitor rule list). Variations — each name is expanded into the forms searchers type (core brand token, run-together, hyphenated, website slug, aliases, misspellings), then checked against the live list and, critically, against our own keywords — anything that would block traffic we bid on is a conflict and can never be added. Add — members go into the chosen shared list; names are merged into the rule list so the analyser recognises them. Undoable.
| Competitor | Website | Why |
|---|
| Negative | Match | Competitor | Kind | Status |
|---|
| When | Summary | Status | |
|---|---|---|---|
| — | |||
| When | Action | Summary | Status |
|---|
One read-only bundle for an outside audit: Google Ads (campaigns with settings, ad groups, keywords with quality scores, search terms, every negative, ads, conversion actions, monthly trend, device / hour / region, ad schedules, the last 30 days of change history with masked emails) and Pipedrive (deals with origin, campaign, keyword, stage and outcome — no names, phones or emails), plus the call log and the portal's own state. Campaigns are tagged by department from their prefix (1 - = DR pre-court). Nothing is written to any platform.
For pulling the same sections directly instead of downloading a file. The token is shown once, only its hash is stored, it reaches nothing but the export, and it dies after 24 hours — or now, with Revoke. Minting a new one replaces the old.
Long syncs run as resumable jobs on the 5-minute cron tick (no browser loop to babysit). The weekly history snapshot also runs itself every Tuesday 02:00 UTC.
| Kind | Key | Status | Attempts | State / error | Updated |
|---|
| Job | Started | Outcome | Summary |
|---|