A client logo in a report header does not prove that the numbers below belong to that client. A copied dashboard can retain its previous account filter. An export can contain a hidden worksheet from another project. A correctly prepared PDF can still be attached to the wrong delivery message.
For an agency managing ChatGPT advertising, client separation is a chain of checks across data selection, transformation, presentation and delivery. The useful question is not simply whether the report looks right. It is whether the same client identity survives each handoff in that chain.
Establish an account-to-client register
Maintain a controlled mapping between the agency’s client reference and the advertising account identifiers used for reporting. Include the effective dates when an account moves into or out of scope. A brand can have several accounts, and a client name can change without the underlying account changing.
Do not use a familiar campaign name as the boundary. Two clients can both have a campaign called Spring launch. The relevant identity includes the account as well as the campaign. When preparing combined data, retain those identifiers long enough to verify where every row belongs.
Make exceptions explicit. A group-level report may intentionally combine several brands, while a local report may cover only one account. The authorized scope should be visible in the reporting brief. An analyst should not have to infer that scope from last month’s spreadsheet or a folder name.
Check the selected data before formatting it
At extraction time, record the requested account, selected entities, period and retrieval time. Compare the account scope with the register before calculating totals. An attractive chart is a poor place to discover that the wrong population entered the report.
Use positive and negative controls in an internal test dataset. The expected client’s rows should appear; rows assigned to a different client should not. For example, a synthetic fixture containing two accounts with identically named campaigns tests whether a transformation relies on names instead of identifiers. It should contain invented data, not another client’s confidential results.
Check joins as carefully as filters. A lookup table keyed only by campaign name can attach another client’s category or account manager even when the metric rows were selected correctly. The guide to campaign identifiers in reports explains why stable identity matters through renames and enrichment.
Treat the final file as a separate object
The dashboard view, downloaded workbook and rendered PDF are different artifacts. Review the exact file that will be delivered. A browser filter does not establish what the export function included, and a screenshot of one page does not establish the contents of the remaining pages.
For a workbook, inspect sheet names, hidden sheets, comments, formulas and linked data where applicable. For a presentation, check appendix slides and speaker notes. For a PDF, inspect the complete page range, bookmarks and embedded attachments if the workflow can create them. These are checks on the chosen format, not claims that every export contains these features.
| Boundary | Useful evidence |
|---|---|
| Account to dataset | Requested account and retained row identifiers |
| Dataset to report | Scope filter and checked summary totals |
| Report to export | Exact delivered file and full-page review |
| Export to recipient | Approved client destination matched to that file |
Use a filename that helps distinguish the client, period and revision, but never treat the filename as proof of the contents. Renaming a file cannot correct a mistaken data selection.
Verify delivery context without exposing the report
Match the intended recipients or shared location against the current delivery agreement. A former contact can remain in an autocomplete suggestion. A copied message can retain the previous client’s address. Review the destination independently of the report’s title. Use a reporting service-level agreement to define that delivery scope, its timing and who receives notices when figures are revised.
Where a shared link is used, check which audience can open it and whether that audience matches the intended delivery. Do not assume that moving a file into a client folder changes an already existing sharing link. Apply the access controls available in the actual storage system.
A second reviewer should be able to complete the check from a short evidence record: client reference, account scope, reporting period, file revision and intended destination. Avoid placing complete client datasets in a central checklist merely to demonstrate that a review happened.
One client, end to end
- Account → data
Does the account identifier match the reporting brief?
- Data → file
Does the entire export contain only the agreed scope?
- File → recipient
Is this revision matched to the correct client's destination?
Checkpoint
Stop a mismatch before explaining performance
If the account identity or recipient mapping is uncertain, hold the delivery while the ambiguity is resolved. Performance commentary cannot compensate for a report whose ownership is unclear. Record the suspected boundary failure so the investigation starts at the relevant step.
If a report has already reached the wrong destination, follow the agency’s incident process and involve the responsible people. Preserve the known facts and avoid inventing assurances about who has or has not accessed the material. The response depends on the actual exposure and organizational obligations.
Keep the approved artifact through the agency’s report snapshot process. Review continued access through a separate report access review. OpenAI’s reporting documentation describes the source reporting interface; the client-separation controls here are an internal agency workflow around that source.
Sources and scope
Verify the mapping from advertising account to dataset, exported file and recipient before an agency delivers reports for multiple clients.
Working methods and examples are editorial suggestions. Check current platform requirements and available features before implementation.
