Authority

Review permissions you no longer need

Every permission was granted for a reason. The useful question months later is whether that reason still exists.

  • Abilities & permissions
  • 4 min read

Why boundaries drift

Grants are made under pressure, to unblock something. Nothing ever generates pressure to remove one. Left alone, an agent’s boundary only widens — and the widest it has ever been is the boundary that applies the day something goes wrong.

Use the evidence you already have

  • Per-Ability invocation summaries show whether an Ability has actually been used on this site. A permission granted six months ago and never exercised is the easiest thing you will remove all year.
  • The activity timeline shows what each agent actually does, as opposed to what it was set up to do.
  • Readiness flags weaknesses in the current posture and links to the screen that fixes each one.

A workable cadence

  1. Quarterly, or after any significant change to what an agent is used for.
  2. For each agent, list its allowed Abilities and mark any never invoked.
  3. Remove those, or move them to require approval if you are not certain.
  4. Re-check every high and critical risk allow against the four questions.
  5. Revoke agents that are no longer used at all, and delete their WordPress users.
Removing a permission is cheap to undo

If you remove one and a real workflow breaks, the activity record will tell you exactly which Ability and which agent within minutes. That asymmetry is why it is safe to be aggressive here.

Abilities & permissions

Keep the boundary while you fix the problem.

A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.