Let AI agents run your store — without handing them the keys.
WordPress 7 lets Claude, Cursor and your own custom agents discover and run your store’s abilities. Raqvio Agent Guardrails decides what each agent may do, blocks the rest, and logs every move.
Free forever · No account required · Never sells or proxies AI access
This action needs human approval. It has been queued as approval_id 1047; poll raqvio-ag/get-approval-status with that approval_id.
Exposure is already solved by WordPress core. Control is not. That’s the gap Raqvio Agent Guardrails fills.
Everything you need to govern agents safely — for free.
The free version is fully functional: no locked screens and no trialware. Here’s what ships in the box.
Ability inventory + risk levels
Every ability on your site — WordPress, WooCommerce, other plugins — classified as read, write, financial or destructive. Override any classification, or mark an ability “never log input”.
Agent profiles
Map an application password or a dedicated WordPress user to a named agent — as many agents as you need, plus a built-in “Site AI” for AI features running inside WordPress.
Per-agent allow / deny
Grant or block each ability per agent. Unknown agents get safe defaults with no setup: reads allowed, writes, financial and destructive actions denied.
Emergency kill switch
Block every agent action at once from the admin bar, the dashboard or Settings. “Block for 1 hour” turns itself off again.
Admin-bar toggleRedacted audit log
Who ran what, through which channel, what was decided and the result. Values under password, token, key and card fields are removed; emails, phones and addresses are masked. You choose how long to keep it, up to a year.
Credential hardening check
Shows where your AI provider keys live — database, wp-config.php or environment — without reading them, plus exposed abilities and administrators with application passwords.
Catalog readiness audit
A 0–100 score per product and for the store: descriptions, images and alt text, SKU, GTIN/MPN/brand, attributes, variations, price and stock, titles — plus a Product JSON-LD check.
Abilities for agents
raqvio-ag/get-my-permissions lets an agent check what it may do before it tries. raqvio-ag/order-create-refund gives agents a refund tool that is always governed.
Works with WooCommerce MCP
Agents on WooCommerce’s MCP endpoint are identified by their API key’s user and governed like any other — every tool shows up in the permission matrix.
From exposed to governed in four steps.
Map your agents
Bind an application password or a dedicated “AI Agent” user to a named agent. In-site AI features resolve to the built-in Site AI.
Set permissions
Allow or deny each ability per agent. Anything unmapped gets safe defaults automatically — reads through, changes stopped.
Enforce & approve
On WordPress 7.1+ every call is decided before it runs: allow, deny — or, with Pro, wait for a human to approve.
Audit & roll back
Every action is logged with redacted input. With Pro, changes are snapshotted so you can undo one — or everything an agent did.
A control room for agent activity — right in wp-admin.
Screens built with the WordPress component system. Nothing to log into elsewhere; everything lives on your site.
Ability inventory. Every registered ability, classified by risk. Override any level you disagree with.
| Ability | Risk | Permission |
|---|---|---|
| products-query | read | Allow |
| product-update | write | Allow |
| order-create-refund | financial | Require approval |
| product-delete | destructive | Deny |
Per-agent permissions. Default, Allow, Deny — or Require approval with Pro. Different agents, different reach.
Audit log. Agent, channel, decision and result for every call — input redacted before it is stored.
Catalog readiness. A score plus the issues holding your products back in AI-driven shopping.
Illustrations of the plugin screens; names, labels and decisions match the plugin, numbers are examples.
Start free. Upgrade when you need rules, approvals and rollback.
Free
WordPress.org- Ability inventory + risk classification
- Unlimited agents + the built-in Site AI
- Per-agent allow / deny, safe defaults
- Emergency kill switch
- Redacted audit log — keep it 1 to 365 days
- Credential & exposure hardening check
- Catalog readiness score (WooCommerce)
- Refund ability for agents, governed
Pro
14-day free trial · no card- “Require approval” permission for any ability
- Approval queue — approve or reject from email or Slack
- Policy rules — amounts, spending budgets, % price changes, rate limits, time windows, input values
- Test a rule on past agent activity before you save it
- Alerts when an agent is blocked repeatedly or unusually busy
- Snapshots + one-click & bulk rollback
- Tamper-evident audit log, filters, CSV export
- AI readiness fixer · Google Merchant Center feed
14-day money-back guarantee on every purchase and renewal — refund policy · terms.
Prices in USD, billed yearly. Every Pro and Agency plan includes all Pro features; they differ only in the number of sites.
Raqvio Agent Guardrails never sells or proxies AI access and never ships model keys. The readiness fixer uses the AI provider you configure in WordPress.
Questions, answered.
Does Raqvio Agent Guardrails work without WooCommerce?
Is the free version limited?
Are humans in wp-admin governed?
What does an agent see when it is blocked?
raqvio_ag_denied (HTTP 403), or raqvio_ag_blocked while the kill switch is on. With Pro, an action that needs approval returns raqvio_ag_approval_required (HTTP 202) with its approval id, which the agent can poll with raqvio-ag/get-approval-status.Which AI agents can I connect?
Can refunds be rolled back?
Can an agent change Raqvio Agent Guardrails’s own settings?
Does Raqvio Agent Guardrails read my AI API keys?
wp-config.php constant, or database. Database presence is checked with a LENGTH() query, so the value never leaves MySQL.What are the requirements?
More in the documentation.
Put a guardrail between agents and your store.
Install the free plugin, map your first agent, and watch the audit log fill up. Upgrade to Pro when you want rules, approvals and rollback.