Authority

Understand a blocked Ability

WordPress allowed the action and agent policy did not. The record names which decision applied; the correction follows from that and nothing else.

  • Abilities & permissions
  • 4 min read

What the record says, and what to do

RecordMeaningCorrection
BlockedThis Ability is set to block for this agent.Change the decision deliberately, or leave it and change the integration.
Review requiredApproval is required and none was claimable.Approve the specific request, or move the Ability to allow if it never warrants review.
No permission recordDefault deny. It was never granted.Grant it explicitly in the permission matrix.
Unregistered AbilityThe requested name is not in the registry.Register it, or correct the name the agent sends.
Site modeRead-only or paused is active site-wide.Return to normal once the reason for the mode is resolved.

Allowed in the matrix but still stopped

An Ability set to allow can still be escalated to review by the contextual risk engine, which reads the request itself. The record shows the escalation and its reason.

This is working as intended: the matrix expresses your general decision, and the engine can only make a specific call stricter. If a particular shape of request escalates every time and you are comfortable with it, the honest fix is to narrow the input the agent sends, not to look for a way to disable the escalation.

Change one thing, then retry

Change a single decision and retry the original request. Changing several at once means the next result will not tell you which change was responsible — and one of those changes is likely to be one you did not need to make.

When blocked is the right answer

A refusal is often the product working

Default deny, a native denial and a required approval are all controls. Before treating a block as a fault, check whether the agent has simply been asked to do something you already decided it should not do.

Abilities & permissions

Keep the boundary while you fix the problem.

A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.