Change-History Forensics: What Broke the Campaign Last Tuesday
The 60-second version
Performance breaks have authors: edits, budget moves, auction shifts. Correlating the change log with the break before touching anything else.
- What happened, in one line
- What to do about it this week
- What you can safely ignore
CAC doubled on Tuesday. Nothing in the market explains it — no festival, no competitor sale, no site outage. The team spends a week theorising about auctions and audiences. Then someone opens the change history: Monday 4 PM, daily budget halved on the two best campaigns to "test efficiency"; Monday 5 PM, three exact keywords paused as "redundant". The campaign did not break. It was broken, on schedule, by its own team.
Most performance breaks have authors. Change-history forensics is the discipline of checking the log before theorizing: correlating when performance moved with what changed, ruling out self-inflicted causes in minutes instead of debugging phantoms for weeks.
The short version: the log before the theory
Forensics Before Theories
Data JourneyMark the break
Pin the day (and intraday hour, if data allows) the metric moved, on matured data. Vague breaks produce vague suspects.
List the changes
Budget edits, bid/target changes, keyword and creative pauses, geo and audience edits, site deploys — 7 days back from the break.
Correlate and revert-test
Match change timestamps to break onset, check mechanism plausibility, revert or isolate to confirm. Theories without reverts are stories.
The principle is borrowed from incident response: recent changes are guilty until proven innocent. Ad accounts, like production systems, are changed far more often than markets move — so the base rate favours self-inflicted causes overwhelmingly. Forensics just makes the base rate operational.
Matured data only. Conversion lag makes fresh windows look broken (Tuesday always "collapses" on Wednesday morning). Confirm the break on settled data first — half of all forensics cases close at this step, with no suspect and no crime.
The suspect lineup: changes that break campaigns
| Change | Typical break signature | Onset delay |
|---|---|---|
| Budget cut/raised >30% | Learning reset: CPA volatile 3–7 days, volume step-change | 1–3 days |
| tROAS/tCPA target tightened | Volume collapse with stable-ish efficiency | 2–5 days |
| Hero keyword/creative paused | Impression share cliff on exact queries, spillover to worse queries | Same day |
| Match-type or structure migration | Query-mix shift: n-gram profile changes before CPA does | 3–7 days |
| Geo/audience narrowed | Reach cliff, frequency spike (mini-saturation, self-inflicted) | Same day |
| Site/checkout deploy | CVR drop with CPM and CTR flat — the "clean" signature of a broken funnel | Hours |
| Tracking/tag change | Conversions vanish while clicks hold — always suspect the plumbing first | Same day |
| Competitor sale entry | CPM surge + share loss, no account change at all (the innocent verdict) | Days |
The Tuesday doubling, solved in 20 minutes
The forensics query: breaks annotated with changes
Show query
Read it as a detective: a CAC step-change with a same-week flag is a suspect with means and opportunity. A break with no flag is when market theories (competitor moves, seasonality, auction shifts) earn their hearing — and not before.
The change discipline that makes forensics possible
Changes You Can Debug
Process FlowOne variable at a time, dated
Budget and bids never change the same day. Simultaneous edits create unsolvable cases — the log shows two suspects and no way to convict either.
Annotate the why with the what
'Budget −30% — testing efficiency hypothesis' beats 'budget updated' by the entire future investigation. The author writes one sentence; the detective saves a week.
Freeze before big reads
No structural edits during festive peaks or test windows. A frozen account is a clean experiment; a churned one is anecdote soup.
Revert-test before theorising
Suspect identified? Revert in a controlled way and watch. Recovery confirms; non-recovery exonerates and points outward to market causes.
Automated rules and scripts are changes too. A bid rule firing nightly, a budget script rebalancing weekly — these author breaks exactly like humans do, but nobody remembers them at 9 AM. Log automation actions into the same change history, or forensics will keep acquitting the guiltiest suspect in the account.
Frequently Asked Questions
How far back should the change log go?
Seven days before the break for direct causes; thirty for slow-burn ones (audience narrowing that saturated gradually, Quality Score decay from a landing change). Beyond thirty days, causes need a mechanism story, not just a timestamp — correlation without mechanism is superstition.
What if two changes coincide with the break?
Revert the most plausibly causal one first (mechanism ranking: tracking > funnel > budget > bids > structure), hold the other, and watch. If recovery is partial, revert the second. Sequential reverts are slower than parallel ones but produce knowledge; parallel reverts produce relief and no learning.
When is it genuinely the market, not us?
After forensics exonerates the log: no flags, mechanism absent, and external corroboration present (CPM surge across untouched campaigns, share loss with flat bids, known competitor event). "The market did it" is a verdict earned by eliminating suspects, never an opening hypothesis.
Summary & Next Steps
Performance breaks are guilty-until-proven-innocent recent changes. Mark the break on matured data, list the log's suspects, rank by mechanism, revert-test to convict — and theorise about markets only after the log is clean.
- Use dynamic baselines to mark breaks objectively instead of by gut.
- Use freshness and lag awareness so phantom breaks never open cases.
- Use conversion-lag discipline so the break date itself is trustworthy.
Chinmay Raibagkar
About author →Founder of DataLens AI. He helps non-technical teams read their ad and database numbers with confidence — which number to trust, what to do next, and what to ignore.