The control plane for WordPress agents

From “an AI can connect”
to “every action has a policy.”

RuleFence brings identity, least privilege, human approval, risk context, signed evidence, recovery, and governed automation around WordPress Abilities.

Native authority preserved Local-first control
Governed requestControl path active
CA
Content Agentacme/update-post
Approval
IdentityManaged agent · Production
WordPress authorityNative permission passed
Policy decisionPublished content requires review
Human decisionExact request waiting

One governed path

Every request passes through the same explicit boundary.

Connection is only the entry point. Identity, native authorization, agent permission, policy, approval, evidence, and recovery stay in the path.

  1. 01IdentifyWho is acting?
  2. 02AuthorizeCan WordPress allow it?
  3. 03DecideAllow, approve, or block?
  4. 04ExecuteRun the exact request.
  5. 05VerifyWhat actually happened?

Identity

Know which agent is acting.

Treat “ChatGPT,” “a script,” or “an Application Password” as a connection detail—not an accountable identity. Create a managed agent for each client and purpose, map it to a dedicated least-privilege WordPress user, and keep its state, environment, connections, sessions, and activity together.

  • Active, restricted, paused, and revoked states
  • Credential testing, rotation, suspension, and revocation
  • Session inventory, termination, and last-seen evidence
Explore managed identity
Agent profileActive

Publishing Assistant

Production · Content operations

WordPress user
rulefence-content-agent
Connection
Healthy
Last seen
2 minutes ago
Active sessions
1 managed session
Ready for governed access8 / 8
Ability Explorer Search abilities
AbilityTypeRiskDecision
core/get-user-infoWordPress CoreReadLowAllow
acme/update-postExample pluginWriteMediumApproval
acme/delete-postExample pluginDeleteHighBlock
seo/update-metaSEO integrationWriteMediumUnconfigured
Discovered does not mean permitted.

Unconfigured Abilities stay blocked for managed agents.

Ability Explorer

See the machine-readable surface of your site.

Discover Abilities registered by WordPress Core and installed plugins. Inspect their source, category, schemas, REST exposure, action type, risk, data classification, reversibility, and scope before deciding whether an agent should use them.

Discovery never means permission. An Ability can exist and remain blocked for every managed agent.

Permission Matrix

Choose the smallest decision that fits.

Each managed agent receives one explicit decision per Ability. Anything unconfigured defaults to Block.

01

Allow

Run without a separate human decision, subject to WordPress authorization, agent state, emergency mode, risk, policy, and runtime health.

Explicitly permitted
03

Block

The request is refused. Block is also the default when no explicit permission exists or the managed boundary is uncertain.

Execution prevented
WordPress remains the authority ceiling. Permission changes validate against the live Ability registry, and governance can only make access stricter.

Contextual risk and policy

Treat “update one draft” differently from “change 5,000 prices.”

A static Ability name is not enough to describe consequence. Contextual risk can consider scope, record count, value movement, data sensitivity, reversibility, environment, publication state, and preview coverage.

Risk and policy can only make access stricter. They can never grant an Ability the Permission Matrix or WordPress denied.

Policy · Price protectionEnabled
WhenProduct price changesinProduction
≤ 5%Price changeAllow
5–10%Price changeApproval
> 10%Price changeBlock
Current request: 7.4% decreaseRequire approval
Approval request · AR-0248High risk
SA
Store Agentwoocommerce/product-update
Expires in 08:42
Products affected37
Average change−7.4%
Preview coverageComplete
Expected changePreview available
Orbit Desk Lamp$129.00$119.00
Arc Task Light$89.00$82.00
35 additional productsWithin policy scope

Approval and preview

Put human judgment at the point of consequence.

Review the agent, Ability, risk reasoning, bounded input summary, expected change, and preview coverage. Approve once, reject, or cancel. Approval is tied to the exact canonical request, expires, and cannot be replayed after it is claimed.

Honest preview coverage. When no provider can build a reliable preview, RuleFence says so. Missing coverage is not dressed up as a before/after guarantee.

Activity and audit integrity

Read what happened in operational language.

Managed decisions, administrator actions, sessions, approvals, execution outcomes, and recovery attempts are stored locally with redaction.

Signed evidence chain Retained audit events are HMAC-linked so database-only edits, reordering, and unsigned deletion can be detected within the documented local integrity boundary.
Recent managed activity Integrity verified
Store Agent requested 37 price changes

Waiting for approval · High risk · Preview available

Content Agent updated “About Us”

3 fields changed · Outcome verified · Undo available

Developer Agent attempted to deactivate a plugin

Blocked by Production Safety policy

Publishing Assistant session rotated

Previous connection revoked · New credential tested

Beyond the decision

Recovery and automation use the same boundary.

The safe path does not end after execution, and automation never receives a privileged shortcut around it.

Supported recovery

Keep a recovery path where one truly exists.

Before supported writes, providers can capture bounded before-state. Eligibility is checked again at restore time, snapshots are claimed atomically, and every attempt is audited.

Snapshot S-1092Undo available3 supported fields · expires in 27 days

Recovery does not recall email, reverse payment side effects, or restore unsupported third-party fields.

Governed workflows

Automate the process—not the bypass.

Build Ability, approval, condition, stop, and note steps. Dry-run the governance decision, schedule eligible workflows, and retry only transient failures.

Find stale draftsAbility · Allowed

More than 20?Condition

Request approvalHuman decision

Agency governance

Carry standards across sites without erasing site boundaries.

On a WordPress Network, Agency features can inventory sites, group them, surface approvals, deploy policy templates, report drift, and apply one-way emergency restriction.

The target site still makes its own approval decision and writes its own signed audit event.

Fleet · Production sites12 sites
Ready9
Attention2
Unavailable1

Northstar Media4 active agents

Ready

Meridian StorePolicy drift detected

Review

Studio Network2 approvals waiting

Ready
Runtime Verification Passed
100control path score
Native Ability lifecycle Default deny One-time approval Signed audit writes Redaction boundary Emergency controls
Last verified today at 14:32 · Redacted evidence preserved

Readiness and verification

Make operational health visible.

Readiness turns configuration and compatibility into prioritized remediation. Runtime Verification performs bounded installed-environment checks across the actual control path and preserves only redacted evidence.

Evidence, not a blanket promise. A passing check proves the tested controls in the installed environment—not that every third-party Ability is safe or reversible.

Read about verification

Start with a visible boundary

Start with one agent and one safe Ability.

The fastest way to trust agent access is to make its boundary visible.