Review permissions you no longer need
Every permission was granted for a reason. The useful question months later is whether that reason still exists.
- Abilities & permissions
- 4 min read
Why boundaries drift
Grants are made under pressure, to unblock something. Nothing ever generates pressure to remove one. Left alone, an agent’s boundary only widens — and the widest it has ever been is the boundary that applies the day something goes wrong.
Use the evidence you already have
- Per-Ability invocation summaries show whether an Ability has actually been used on this site. A permission granted six months ago and never exercised is the easiest thing you will remove all year.
- The activity timeline shows what each agent actually does, as opposed to what it was set up to do.
- Readiness flags weaknesses in the current posture and links to the screen that fixes each one.
A workable cadence
- Quarterly, or after any significant change to what an agent is used for.
- For each agent, list its allowed Abilities and mark any never invoked.
- Remove those, or move them to require approval if you are not certain.
- Re-check every high and critical risk allow against the four questions.
- Revoke agents that are no longer used at all, and delete their WordPress users.
Removing a permission is cheap to undo
If you remove one and a real workflow breaks, the activity record will tell you exactly which Ability and which agent within minutes. That asymmetry is why it is safe to be aggressive here.
Abilities & permissions
Keep the boundary while you fix the problem.
A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.
