A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.
What to expect
Connecting takes a couple of minutes. When you add the Campaign Manager 360 (CM360) integration in Medialake, you'll be redirected to the official Google sign-in screen — you pick the Google account that has your CM360 access, then Google shows a consent screen describing what Medialake is asking for. You approve it yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Google's site, and once you approve you're returned to Medialake.
> If your Google account has connected to Medialake before (for example, another Medialake integration), Google may show "medialakeAI already has some access" instead of re-listing the permissions. That's Google confirming what you previously granted — nothing new is being added.
We follow the principle of least privilege: CM360 is a trafficking, creative, and asset integration — we never create, edit, delete, traffic, or upload anything in your Campaign Manager 360 account. All data is read through Google's official Campaign Manager 360 API (v5), which uses the dfareporting.googleapis.com service endpoint.
You Medialake Google│ connect source │ ││────────────────────────▶│ ││ redirect to Google │ ││◀────────────────────────│ ││ sign in & grant access │ ││──────────────────────────────────────────────────▶││ redirect with code │ ││◀──────────────────────────────────────────────────││ │ exchange code ││ │────────────────────────▶││ │ access + refresh token ││ │◀────────────────────────││ source authorized │ ││◀────────────────────────│ ││ │ renews automatically ││ │────────────────────────▶│
Verifying it's really us
On Google's consent screen, check that the app requesting access is:
App name: MedialakeAI
If the app name doesn't match, stop and contact us. Never approve a Google access request you weren't expecting.
Who should do the connecting
The connection is tied to the Google account that signs in. Please have it done by someone who:
Has a Campaign Manager 360 user profile for the relevant account or subaccount, and whose CM360 account has Trafficking API access enabled. Google notes that CM360 API access follows the user profile's CM360 permissions — there are no separate API permissions.
Has view or read-only access to the CM360 objects we need to read: user profile, account/subaccount, advertisers, campaigns, ads, placements, sites, creatives, and creative metadata. CM360 permissions are controlled through user roles and role permissions.
Is a permanent member of your team. If the person who authorized us loses their CM360 access, the connection stops working and someone else will need to reconnect.
Their Google login is used only to authorize the connection — we get access to your CM360 account structure and creative metadata, never their email content or other Google services.
Limiting what we can access
We inherit exactly the connecting person's CM360 user profile access — nothing more, enforced by Google on every request. To keep the connection narrow, create or choose a CM360 user profile with the smallest role permissions needed for the advertisers, campaigns, placements, ads, sites, and creatives in scope.
CM360 also supports filters on user profiles. Filters can limit which advertisers, campaigns, sites, and user roles a profile can access. If the profile sits under a subaccount, Google limits it to that subaccount's data as well. Medialake can only see what that profile can see.
You choose what we sync
After you approve and are redirected back to Medialake, you select the CM360 account/profile and scope you'd like us to sync. Medialake only ever has access to what the connecting Google account can see in CM360 — everything outside their user profile, subaccount, role, or filters is invisible to us.
The permissions we request
Permission (scope) | What it lets us do | How we use it |
Access Campaign Manager 360 trafficking entities — advertisers, campaigns, ads, placements, sites, creatives, and related metadata. Google's CM360 API docs require this scope for read methods such as advertisers.list and creatives.list. | READ ONLY (see note) | |
See the name, email address, and profile photo of the Google account connecting. | READ ONLY |
>Why the consent screen sounds broader: Google's scope wording says CM360 trafficking access is read/write — for example, dfatrafficking is described as access to "view and manage" CM360 display ad campaigns. Google offers no read-only variant of this scope, so that wording is the only option. Medialake performs no write operations on your account — nothing is ever created, edited, deleted, trafficked, uploaded, or changed by us. Your real protection is CM360's own user profile and role system: where the connecting profile has read-only permissions for the relevant areas, Google rejects writes regardless of the scope.
Google's own description of every CM360 scope is in its OAuth 2.0 scopes reference (under "Campaign Manager 360 API"); the openid, email, and profile trio is documented in Google's OpenID Connect guide.
Verified by Google
Sensitive scopes like dfatrafficking aren't granted to apps just for asking. The MedialakeAI app has completed Google's OAuth app verification: our branding is verified (the name and identity you see on the consent screen are vetted by Google) and our data access is verified (Google has reviewed the scopes we request and why). Unverified apps show a warning screen and are capped by Google — you'll see neither when connecting to Medialake.
What we can't see or do
Regardless of the scope wording, we cannot:
See or store your password, or log in as you
Access Gmail, Google Drive, or any other Google service — only the CM360 API
Create, edit, delete, traffic, or upload anything in CM360, or export placement tags
Upload offline conversions
Access accounts, subaccounts, advertisers, campaigns, sites, or creatives the connecting profile can't see
Staying connected
Unlike some platforms, Google issues refresh tokens, so the connection renews itself — there's no fixed expiry to plan around. A connection only stops working if it goes unused for about six months, if the connecting person loses their CM360 access, or if access is revoked — the full list of cases is in Google's OAuth 2.0 documentation under "Refresh token expiration". If that happens, just reconnect from the CM360 integration in Medialake — it takes a minute.
Revoking access
You're in control at any time. To remove Medialake:
Google Account → Third-party apps & services → select the Medialake app → Remove access, or
Disconnect the CM360 source from its settings page in Medialake.
Revoking from the Google side invalidates the tokens and data collection stops without any action needed from us — Google notes it may take a short time for the revocation to take full effect.
Troubleshooting
Issues while connecting typically relate to the connecting Google account not having a CM360 user profile, the account not having Trafficking API access enabled, the user profile not having access to the relevant account/subaccount, advertisers, campaigns, sites, or creatives, or your organization's Google Workspace settings restricting third-party app access. If you get stuck, contact [email protected] and we'll walk you through it.
Further reading (Google documentation)
Campaign Manager 360 API — Authorize Requests — Google's OAuth flow and the CM360 scopes
Campaign Manager 360 API — REST reference — the API the connector reads from
CM360 user access — user profiles, roles, filters, and API access
CM360 user role permissions — what read-only, modify, and full access mean
OpenID Connect scopes — what
openid,email, andprofileexposeOAuth 2.0 — refresh token expiration — the cases where a connection stops renewing (see "Refresh token expiration")
OAuth 2.0 scopes reference — Google's description of every scope, including
dfatrafficking
You can review or withdraw access at any time from your Google Account's third-party access settings.
