One control plane. Different operating realities.
Different teams use WordPress.
One boundary governs them all.
Give each team the access it needs—without turning a connection, credential, or automation into invisible authority.
Bounded accessOnly explicit Abilities
Human approvalAt consequence
Signed evidenceLocal and inspectable
Supported recoveryWhere it truly exists
Choose your operating context
Start with the outcome your team needs.
Each path uses the same governance foundation, tuned to a different kind of WordPress work.
01 Site owners
Control without becoming the bottleneck
Let agents help while your site remains in charge.
See every managed agent, the WordPress user behind it, the Abilities it may use, and the decisions waiting for you. Pause access or enable emergency restriction without losing the audit trail.
- One accountable identity per agent and purpose
- Default-deny Ability decisions
- Readiness and runtime health in plain language
Production siteNorthstar Media Control path healthy
Publishing Assistant6 abilities · restricted
ReadyStore Agent3 abilities · approval required
ReviewFind stale product referencesRead-only · allowed
Draft updated copyNo publish side effect
Update published pageHuman approval required
Waiting02 Content & SEO
Move quickly without publishing blind
Separate safe drafting from consequential publishing.
Let agents research, classify, and draft within narrow permissions. Put review at the point where public content, metadata, redirects, or bulk changes create real consequence.
Speed where risk is low. Judgment where risk rises. The same workflow can allow research, require approval for publishing, and block destructive operations.
03 WooCommerce
Bound business consequence
Let agents operate the store without gambling with the catalog.
Distinguish a single low-value edit from a high-volume price change. Evaluate scope, value movement, reversibility, environment, and preview coverage before execution.
- Product and order Abilities stay explicit
- Bulk and value-change thresholds
- One-time approval for exact requests
Allow within assigned scope
AllowHuman review with preview
ApprovalOutside permitted boundary
Blockacme/sync-release-notes{
"type": "write",
"risk": "medium",
"requires": ["edit_posts"],
"preview": true,
"recovery": "supported"
}acme/list-release-notesread · lowacme/archive-release-notedelete · high
04 Developers
A machine-readable contract
Expose useful Abilities without inventing a shadow authority.
Register bounded operations with input and output schemas, native capability requirements, risk metadata, preview support, recovery boundaries, and redaction rules. RuleFence governs the Ability; WordPress still authorizes it.
Build on WordPress, not around it. Providers describe what can be done and how it can be verified; they do not silently grant agent access.
05 Agencies
Standards across sites
Govern a fleet without erasing each site’s boundary.
Inventory sites, group them, deploy policy templates, surface approval work, report drift, and apply one-way emergency restriction—while each site keeps its own authority and evidence.
Northstar Media4 agents · policy current
ReadyMeridian StorePolicy drift detected
ReviewStudio Network2 approvals waiting
ReadyShared governance foundation
Different workflows. The same non-negotiable controls.
Every solution inherits the same control path rather than receiving a privileged shortcut.
Managed identity
One accountable agent, purpose, environment, WordPress user, connection, and session history.
Least privilege
Explicit decisions per Ability, default deny, contextual policy, and human approval where needed.
Signed evidence
Readable local events with redaction, linked integrity, outcome verification, and stated limits.
Recovery and stop
Supported snapshots, re-authorized restore, agent pause, session revocation, and emergency restriction.
One boundary, your operating context
Give each team useful access without invisible authority.
Start narrow. Keep consequence visible. Preserve WordPress control.
