Support

Bring the request, not just the symptom.

Support starts faster when it starts with context: the site, the agent, the Ability, the decision, and the evidence. Everything below is arranged so you can answer the first three questions before you send anything.

  • Self-serve first
  • Context-led requests
  • Security reports handled separately

Start here

Most operational questions have a documented answer, and finding it yourself is usually faster than describing the problem to someone else. Two links resolve the majority of them.

If a request was refused, that may be the correct outcome

Default deny, a native WordPress denial, and a required approval are all working controls. Confirm which gate answered before treating it as a fault.

Where to get help

  • Open a ticket

    The main route, for free and paid alike. Sign in first and your licence is attached to the ticket; file as a guest if you would rather not.

    Go to the form
  • Plugin support forum

    For the free edition. Public, searchable, and the right place for questions other operators are likely to share.

    Open the forum
  • Licence and billing

    Invoices, renewals, seat changes, and refunds under the published refund policy.

    [email protected]
  • Security

    Suspected vulnerabilities go to the disclosure process, not to the support queue or the public forum.

    Responsible disclosure

What to include

Send the request context. It is the difference between a first reply that asks questions and a first reply that answers one.

Environment
WordPress version, PHP version, RuleFence version, and whether the site is production or staging.
Agent
The managed identity involved, its state, and its environment.
Ability
The exact registered Ability name, for example acme/update-post.
Decision
What the activity record shows: the gate reached, the outcome, and the timestamp.
Evidence
The request identifier or fingerprint, and any linked evidence reference.
Expected vs actual
One sentence each. What you expected the boundary to do, and what it did.

A template you can copy

WordPress: 7.1.x   PHP: 8.x   RuleFence: 1.0.0
Environment:   production | staging
Agent:         <name> (state: active | restricted | paused)
Ability:       <provider/ability-name>
Decision:      <allowed | review required | blocked | failed closed>
Request ID:    <identifier or fingerprint>
Timestamp:     <site time zone>

Expected: ...
Actual:   ...
Already tried: ...
Redact before you send

Never include Application Passwords, licence keys in a public forum post, or unredacted request inputs. Evidence exports are redacted for exactly this reason — use them.

Open a ticket

One queue for everyone, free edition included. A paid licence changes how fast the first reply comes, not whether you get one.

Sign in first and your licence and sites are attached automatically. Filing as a guest is fine too — but the confirmation screen gives you a one-time tracking token, and that token is the only way back to the conversation, so keep it.

Open a ticket Your tickets

What to expect

PlanChannelTarget first response
FreeTicket, or the public forumBest effort, community and maintainers
ProTicket, licence attachedTwo business days
AgencyTicket, licence attached, fleet context welcomeOne business day

Targets are for the first human response, not for a resolution. Business days are Monday to Friday, excluding public holidays. A well-formed request with the context above is consistently answered faster than the target; a request without it is consistently answered slower.

What support covers

In scope

  • Installation, activation, and upgrade problems.
  • Agent identity, connection health, and credential rotation.
  • Ability discovery, classification, and permission decisions.
  • Approvals, expiry, and binding behaviour.
  • Activity, evidence, audit verification, and retention settings.
  • Emergency modes, session termination, and recovery guidance.
  • Licence activation, including a licence server that cannot be reached.

Out of scope

  • Building or debugging your agent or the model behind it.
  • General WordPress administration unrelated to a governed request.
  • Custom development, bespoke integrations, and site migrations.
  • Third-party plugin or host faults, beyond identifying the interaction.
  • Any request to bypass native WordPress authorization or the governed request lifecycle. This is declined in every plan.
Every security control is identical in every edition

Plans differ in scale and optional features. If a support answer would require weakening the authority model, the answer is no regardless of what you pay.

Security reports

If you believe you have found a vulnerability, do not open a forum thread and do not put a working exploit in a support ticket. Follow the disclosure process, which sets out what to send, where, and what to expect in return.

Read the disclosure policy

Help with context

Start from the request that stopped.

Identity, Ability, decision, outcome, evidence — then the question.