RuleFence knowledge base

Find the cause.
Follow the safest fix.

Resolve setup, permission, approval, evidence, and recovery issues without weakening the boundary that protects your WordPress site.

Task-first guidance Clear stop conditions Version-aware steps
Knowledge base navigator 48 verified guides
CURRENT STATEAgent is connected, request is blocked3 likely paths
FIRST CHECKConfirm native WordPress authority

A native denial cannot be overridden by agent policy.

THEN CHECKReview the Ability permission

Make sure the exact registered Ability is allowed.

IF REQUIREDOpen the approval record

Verify the request fingerprint and expiry before approval.

Never solve access by bypassing authorityObserve → Confirm → Correct → Verify

Browse by responsibility

Start where the request stopped.

Each collection maps to one part of the governed path, so you can narrow the issue before changing anything.

6 guides

Install & activate

Requirements, activation, updates, and first-run checks.

Open collection
8 guides

Agents & identity

Recognition, environment, status, and managed identity.

Open collection
12 guides

Abilities & permissions

Registration, native authority, scope, and policy.

Open collection
7 guides

Approvals

Review windows, request binding, expiry, and replay refusal.

Open collection
9 guides

Activity & evidence

Decision records, verification, redaction, and export.

Open collection
6 guides

Recovery & emergency

Snapshots, rollback limits, emergency stop, and restore.

Open collection

Guided troubleshooting

Diagnose the boundary before changing the boundary.

Begin with the visible state, preserve the request details, and test the narrowest explanation first.

  1. 01Capture the exact stateAgent, Ability, decision, timestamp, and request ID.
  2. 02Locate the stopping layerIdentity, native authority, agent policy, approval, or execution.
  3. 03Apply one bounded correctionChange only the setting supported by the evidence.
  4. 04Verify the outcomeConfirm both the decision and what WordPress actually changed.
Diagnostic summary Actionable
REQUEST STATUSBlocked before executionNo WordPress content changed
AgentManaged · Production
Abilityacme/update-post
Native authorityAllowed
Agent policyReview required
ApprovalNot found
Next safe action Review the request and create approval only if the exact consequence is acceptable.

Common starting points

Resolve the state you can see.

These guides begin with the operator-facing symptom and lead back to the responsible layer.

Identity

Agent not recognized

Confirm identity, environment, and registration state before reconnecting.

Read the guide
Authority

Permission denied

Separate native WordPress denial from agent policy or approval requirements.

Read the guide
Approval

Request waiting for approval

Review the exact action, input fingerprint, risk, and expiration window.

Read the guide
Evidence

Outcome unverified

Check provider support and evidence state without repeating the action.

Read the guide

Safe fixes

A successful fix preserves the authority model.

Troubleshooting should restore intended behaviour, not create a second path around WordPress or the managed request lifecycle.

  • Keep native authorization intact
  • Match approvals to the exact request
  • Change one policy or permission at a time
  • Verify the outcome before closing the issue
Review the security boundary
Fix validation Required
Native authorizationStill enforced
Agent identityStill explicit
Ability permissionNarrowly scoped
ApprovalRequest-bound
EvidenceRecorded
If a fix depends on broader authority, stop and reassess the diagnosis.

Before you change anything

Keep the evidence that explains the issue.

A clean diagnostic record prevents guesswork and helps support reproduce the same stopped path.

Environment

WordPress, PHP, RuleFence, and related plugin versions.

Managed identity

Agent name, environment, status, and registration state.

Request context

Ability name, decision, timestamp, and redacted request ID.

Outcome evidence

What was attempted, what was verified, and what remains unknown.

Share diagnostics, not secrets. Remove credentials, cookies, API keys, private content, and customer data before copying evidence.

When self-service ends

Escalate with a complete, redacted record.

Contact support when the documented path ends, a reproducible defect remains, or recovery evidence is incomplete.

SUPPORT HANDOFFInclude the evidence support needs
  • Product and WordPress versions
  • Steps to reproduce
  • Expected and actual decision
  • Redacted diagnostic export
Contact support

Knowledge base questions

Begin with the narrowest explanation.

Most issues become clearer when identity, authority, policy, approval, and execution are checked separately.

Why is a connected agent still blocked?+

Connection proves the agent can reach the site. It does not grant a WordPress Ability, satisfy policy, or create an approval.

Should I broaden permissions to test a problem?+

No. Use the activity record to identify the stopping layer, then change only the relevant permission or policy.

Can I retry an unverified write action?+

First confirm whether WordPress changed. Repeating an action before checking the outcome can create a duplicate or unintended change.

What should I send to support?+

Include versions, reproduction steps, expected and actual decisions, and a redacted diagnostic export. Never include credentials or private data.

Resolve inside the boundary

Find the stopping layer.
Make one safe correction.

Use verified guidance first, then bring complete evidence when you need support.