The control plane for WordPress agents
From “an AI can connect”
to “every action has a policy.”
RuleFence brings identity, least privilege, human approval, risk context, signed evidence, recovery, and governed automation around WordPress Abilities.
acme/update-postOne governed path
Every request passes through the same explicit boundary.
Connection is only the entry point. Identity, native authorization, agent permission, policy, approval, evidence, and recovery stay in the path.
- 01IdentifyWho is acting?
- 02AuthorizeCan WordPress allow it?
- 03DecideAllow, approve, or block?
- 04ExecuteRun the exact request.
- 05VerifyWhat actually happened?
Identity
Know which agent is acting.
Treat “ChatGPT,” “a script,” or “an Application Password” as a connection detail—not an accountable identity. Create a managed agent for each client and purpose, map it to a dedicated least-privilege WordPress user, and keep its state, environment, connections, sessions, and activity together.
- Active, restricted, paused, and revoked states
- Credential testing, rotation, suspension, and revocation
- Session inventory, termination, and last-seen evidence
Publishing Assistant
Production · Content operations
- WordPress user
- rulefence-content-agent
- Connection
- Healthy
- Last seen
- 2 minutes ago
- Active sessions
- 1 managed session
Unconfigured Abilities stay blocked for managed agents.
Ability Explorer
See the machine-readable surface of your site.
Discover Abilities registered by WordPress Core and installed plugins. Inspect their source, category, schemas, REST exposure, action type, risk, data classification, reversibility, and scope before deciding whether an agent should use them.
Discovery never means permission. An Ability can exist and remain blocked for every managed agent.
Contextual risk and policy
Treat “update one draft” differently from “change 5,000 prices.”
A static Ability name is not enough to describe consequence. Contextual risk can consider scope, record count, value movement, data sensitivity, reversibility, environment, publication state, and preview coverage.
Risk and policy can only make access stricter. They can never grant an Ability the Permission Matrix or WordPress denied.
Approval and preview
Put human judgment at the point of consequence.
Review the agent, Ability, risk reasoning, bounded input summary, expected change, and preview coverage. Approve once, reject, or cancel. Approval is tied to the exact canonical request, expires, and cannot be replayed after it is claimed.
Honest preview coverage. When no provider can build a reliable preview, RuleFence says so. Missing coverage is not dressed up as a before/after guarantee.
Activity and audit integrity
Read what happened in operational language.
Managed decisions, administrator actions, sessions, approvals, execution outcomes, and recovery attempts are stored locally with redaction.
Waiting for approval · High risk · Preview available
3 fields changed · Outcome verified · Undo available
Blocked by Production Safety policy
Previous connection revoked · New credential tested
Beyond the decision
Recovery and automation use the same boundary.
The safe path does not end after execution, and automation never receives a privileged shortcut around it.
Supported recovery
Keep a recovery path where one truly exists.
Before supported writes, providers can capture bounded before-state. Eligibility is checked again at restore time, snapshots are claimed atomically, and every attempt is audited.
Recovery does not recall email, reverse payment side effects, or restore unsupported third-party fields.
Governed workflows
Automate the process—not the bypass.
Build Ability, approval, condition, stop, and note steps. Dry-run the governance decision, schedule eligible workflows, and retry only transient failures.
Find stale draftsAbility · Allowed
More than 20?Condition
Request approvalHuman decision
Agency governance
Carry standards across sites without erasing site boundaries.
On a WordPress Network, Agency features can inventory sites, group them, surface approvals, deploy policy templates, report drift, and apply one-way emergency restriction.
The target site still makes its own approval decision and writes its own signed audit event.
Northstar Media4 active agents
ReadyMeridian StorePolicy drift detected
ReviewStudio Network2 approvals waiting
ReadyReadiness and verification
Make operational health visible.
Readiness turns configuration and compatibility into prioritized remediation. Runtime Verification performs bounded installed-environment checks across the actual control path and preserves only redacted evidence.
Evidence, not a blanket promise. A passing check proves the tested controls in the installed environment—not that every third-party Ability is safe or reversible.
Start with a visible boundary
Start with one agent and one safe Ability.
The fastest way to trust agent access is to make its boundary visible.
