Abilities & permissions
The largest collection, because this is where most operating questions land. Native WordPress authority is one gate and agent policy is another — most confusion comes from reading a refusal from one as a refusal from the other.
- 12 guides
- 49 min to read all
- Authority
Guides in this collection
- 3 min readWhat an Ability is, and what it is not
An Ability is a registered, named action with a schema — the vocabulary of what an agent may ask for. It is not a permission.
- 4 min readFind the Abilities registered on your site
Use the Ability Explorer to browse by provider with filters for action, risk, category, exposure and source, and read the detail view before deciding anything.
- 5 min readRead an Ability’s risk classification
Action, risk, reversibility, scope, bulk and exposure — what each means, and why an Ability that cannot be classified is treated as more dangerous.
- 4 min readGrant your first permission
Pick one narrow, reversible, non-public Ability, set it to allow, run one real request, and read the decision it produced before granting anything else.
- 5 min readPermission denied
Separate a native WordPress denial from an agent policy decision before changing anything. They look alike to the caller and have different fixes.
- 6 min readCheck the WordPress authority ceiling
Native WordPress roles and capabilities are checked independently of agent policy, and a native denial is final. How to check the ceiling safely.
- 4 min readUnderstand a blocked Ability
Blocked, review required, no permission record, unregistered, or site mode — five outcomes that look identical to the agent and need different fixes.
- 4 min readChange many permissions safely
Bulk changes apply only to an explicit selection and are written atomically. How to build that selection without catching something you did not mean to.
- 4 min readAllow a high or critical risk Ability
Why allowing a high-risk Ability asks for confirmation and is recorded as an administrative decision, and four questions to answer before you confirm.
- 3 min readThe requested Ability is not registered
The requested name is not in the WordPress registry, so there is nothing to evaluate. Usually a typo, a deactivated plugin, or a version mismatch.
- 3 min readWhy two agents behave differently
Permissions are per agent, not global. Two agents on the same WordPress user can hold different decisions for the same Ability, and that is the design.
- 4 min readReview permissions you no longer need
Boundaries drift wider, never narrower, unless someone revisits them. A short periodic review using invocation summaries and the audit trail.
Other collections
- 6 guidesInstall & activate
Requirements, activation, updates, and first-run checks.
- 8 guidesAgents & identity
Recognition, environment, status, and managed identity.
- 7 guidesApprovals
Review windows, request binding, expiry, and replay refusal.
- 9 guidesActivity & evidence
Decision records, verification, redaction, and export.
- 6 guidesRecovery & emergency
Snapshots, rollback limits, emergency stop, and restore.
Still stuck?
Bring the request, not just the symptom.
Identity, Ability, decision, outcome, evidence — then the question.
