Change many permissions safely
Bulk editing is available because reviewing forty Abilities one at a time is how boundaries stop getting reviewed. It is deliberately narrow about what it will touch.
- Abilities & permissions
- 4 min read
Selection is explicit
A bulk change applies to the items you actually selected — not to “everything matching the current filter”. That distinction is the whole safety property. A filter you forgot you had applied cannot silently widen the set.
Writes are atomic: the whole set applies, or none of it does. You will not end up half-way through a change you cannot describe.
A workflow that works
- Filter by action and risk first. “All delete actions” and “all critical risk” are the two most useful starting sets.
- Read the list before selecting. If anything in it surprises you, stop and open that Ability.
- Select explicitly, and set the decision.
- Re-run the filter afterwards to confirm the result is what you intended.
Good uses of bulk
- Blocking every delete action for an agent that has no business deleting anything.
- Moving every high and critical risk Ability from allow to require approval.
- Applying a reviewed standard to a newly created agent.
- Tightening a fleet-wide standard on the Agency plan.
Where to be careful
Bulk tightening is nearly always safe. Bulk granting is how an agent ends up with permissions nobody consciously decided on. If you are about to bulk-allow, ask whether you could name the consequence of every item in the selection.
High and critical risk allows still require confirmation individually and are recorded as administrative decisions, so bulk does not become a way around that.
Abilities & permissions
Keep the boundary while you fix the problem.
A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.
