Support
Bring the request, not just the symptom.
Support starts faster when it starts with context: the site, the agent, the Ability, the decision, and the evidence. Everything below is arranged so you can answer the first three questions before you send anything.
- Self-serve first
- Context-led requests
- Security reports handled separately
Start here
Most operational questions have a documented answer, and finding it yourself is usually faster than describing the problem to someone else. Two links resolve the majority of them.
- DiagnoseGuided troubleshooting
Work from the symptom you can see back to the gate that stopped the request.
- Look upKnowledge base
Focused answers for setup, permissions, approvals, evidence, and recovery.
- Set upGetting started
Install, register one agent, grant one Ability, and inspect the first decision.
Default deny, a native WordPress denial, and a required approval are all working controls. Confirm which gate answered before treating it as a fault.
Where to get help
-
Open a ticket
The main route, for free and paid alike. Sign in first and your licence is attached to the ticket; file as a guest if you would rather not.
Go to the form -
Plugin support forum
For the free edition. Public, searchable, and the right place for questions other operators are likely to share.
Open the forum -
Licence and billing
Invoices, renewals, seat changes, and refunds under the published refund policy.
[email protected] -
Security
Suspected vulnerabilities go to the disclosure process, not to the support queue or the public forum.
Responsible disclosure
What to include
Send the request context. It is the difference between a first reply that asks questions and a first reply that answers one.
- Environment
- WordPress version, PHP version, RuleFence version, and whether the site is production or staging.
- Agent
- The managed identity involved, its state, and its environment.
- Ability
- The exact registered Ability name, for example
acme/update-post. - Decision
- What the activity record shows: the gate reached, the outcome, and the timestamp.
- Evidence
- The request identifier or fingerprint, and any linked evidence reference.
- Expected vs actual
- One sentence each. What you expected the boundary to do, and what it did.
A template you can copy
WordPress: 7.1.x PHP: 8.x RuleFence: 1.0.0
Environment: production | staging
Agent: <name> (state: active | restricted | paused)
Ability: <provider/ability-name>
Decision: <allowed | review required | blocked | failed closed>
Request ID: <identifier or fingerprint>
Timestamp: <site time zone>
Expected: ...
Actual: ...
Already tried: ...
Never include Application Passwords, licence keys in a public forum post, or unredacted request inputs. Evidence exports are redacted for exactly this reason — use them.
Open a ticket
One queue for everyone, free edition included. A paid licence changes how fast the first reply comes, not whether you get one.
Sign in first and your licence and sites are attached automatically. Filing as a guest is fine too — but the confirmation screen gives you a one-time tracking token, and that token is the only way back to the conversation, so keep it.
What to expect
| Plan | Channel | Target first response |
|---|---|---|
| Free | Ticket, or the public forum | Best effort, community and maintainers |
| Pro | Ticket, licence attached | Two business days |
| Agency | Ticket, licence attached, fleet context welcome | One business day |
Targets are for the first human response, not for a resolution. Business days are Monday to Friday, excluding public holidays. A well-formed request with the context above is consistently answered faster than the target; a request without it is consistently answered slower.
What support covers
In scope
- Installation, activation, and upgrade problems.
- Agent identity, connection health, and credential rotation.
- Ability discovery, classification, and permission decisions.
- Approvals, expiry, and binding behaviour.
- Activity, evidence, audit verification, and retention settings.
- Emergency modes, session termination, and recovery guidance.
- Licence activation, including a licence server that cannot be reached.
Out of scope
- Building or debugging your agent or the model behind it.
- General WordPress administration unrelated to a governed request.
- Custom development, bespoke integrations, and site migrations.
- Third-party plugin or host faults, beyond identifying the interaction.
- Any request to bypass native WordPress authorization or the governed request lifecycle. This is declined in every plan.
Plans differ in scale and optional features. If a support answer would require weakening the authority model, the answer is no regardless of what you pay.
Security reports
If you believe you have found a vulnerability, do not open a forum thread and do not put a working exploit in a support ticket. Follow the disclosure process, which sets out what to send, where, and what to expect in return.
Help with context
Start from the request that stopped.
Identity, Ability, decision, outcome, evidence — then the question.
