Understand a blocked Ability
WordPress allowed the action and agent policy did not. The record names which decision applied; the correction follows from that and nothing else.
- Abilities & permissions
- 4 min read
What the record says, and what to do
| Record | Meaning | Correction |
|---|---|---|
| Blocked | This Ability is set to block for this agent. | Change the decision deliberately, or leave it and change the integration. |
| Review required | Approval is required and none was claimable. | Approve the specific request, or move the Ability to allow if it never warrants review. |
| No permission record | Default deny. It was never granted. | Grant it explicitly in the permission matrix. |
| Unregistered Ability | The requested name is not in the registry. | Register it, or correct the name the agent sends. |
| Site mode | Read-only or paused is active site-wide. | Return to normal once the reason for the mode is resolved. |
Allowed in the matrix but still stopped
An Ability set to allow can still be escalated to review by the contextual risk engine, which reads the request itself. The record shows the escalation and its reason.
This is working as intended: the matrix expresses your general decision, and the engine can only make a specific call stricter. If a particular shape of request escalates every time and you are comfortable with it, the honest fix is to narrow the input the agent sends, not to look for a way to disable the escalation.
Change one thing, then retry
Change a single decision and retry the original request. Changing several at once means the next result will not tell you which change was responsible — and one of those changes is likely to be one you did not need to make.
When blocked is the right answer
Default deny, a native denial and a required approval are all controls. Before treating a block as a fault, check whether the agent has simply been asked to do something you already decided it should not do.
Abilities & permissions
Keep the boundary while you fix the problem.
A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.
