Built for WordPress 7 & WooCommerce

Let AI agents run your store — without handing them the keys.

WordPress 7 lets Claude, Cursor and your own custom agents discover and run your store’s abilities. Raqvio Agent Guardrails decides what each agent may do, blocks the rest, and logs every move.

Free forever · No account required · Never sells or proxies AI access

< 5 ms
p95 policy overhead, asserted in tests
4 risk levels
read · write · financial · destructive
3 channels
agent traffic governed on MCP, REST and internal
100% local
the audit log stays in your database

Exposure is already solved by WordPress core. Control is not. That’s the gap Raqvio Agent Guardrails fills.

Free, on WordPress.org

Everything you need to govern agents safely — for free.

The free version is fully functional: no locked screens and no trialware. Here’s what ships in the box.

Ability inventory + risk levels

Every ability on your site — WordPress, WooCommerce, other plugins — classified as read, write, financial or destructive. Override any classification, or mark an ability “never log input”.

Agent profiles

Map an application password or a dedicated WordPress user to a named agent — as many agents as you need, plus a built-in “Site AI” for AI features running inside WordPress.

Per-agent allow / deny

Grant or block each ability per agent. Unknown agents get safe defaults with no setup: reads allowed, writes, financial and destructive actions denied.

Emergency kill switch

Block every agent action at once from the admin bar, the dashboard or Settings. “Block for 1 hour” turns itself off again.

Admin-bar toggle

Redacted audit log

Who ran what, through which channel, what was decided and the result. Values under password, token, key and card fields are removed; emails, phones and addresses are masked. You choose how long to keep it, up to a year.

Credential hardening check

Shows where your AI provider keys live — database, wp-config.php or environment — without reading them, plus exposed abilities and administrators with application passwords.

Catalog readiness audit

A 0–100 score per product and for the store: descriptions, images and alt text, SKU, GTIN/MPN/brand, attributes, variations, price and stock, titles — plus a Product JSON-LD check.

Abilities for agents

raqvio-ag/get-my-permissions lets an agent check what it may do before it tries. raqvio-ag/order-create-refund gives agents a refund tool that is always governed.

Works with WooCommerce MCP

Agents on WooCommerce’s MCP endpoint are identified by their API key’s user and governed like any other — every tool shows up in the permission matrix.

How it works

From exposed to governed in four steps.

01

Map your agents

Bind an application password or a dedicated “AI Agent” user to a named agent. In-site AI features resolve to the built-in Site AI.

02

Set permissions

Allow or deny each ability per agent. Anything unmapped gets safe defaults automatically — reads through, changes stopped.

03

Enforce & approve

On WordPress 7.1+ every call is decided before it runs: allow, deny — or, with Pro, wait for a human to approve.

04

Audit & roll back

Every action is logged with redacted input. With Pro, changes are snapshotted so you can undo one — or everything an agent did.

Enforcement needs WordPress 7.1.  On 6.9 & 7.0, Raqvio Agent Guardrails runs in audit-only mode — it logs what it would have decided.
Inside the plugin

A control room for agent activity — right in wp-admin.

Screens built with the WordPress component system. Nothing to log into elsewhere; everything lives on your site.

Agent Guardrails → Abilities
woocommerce/products-queryread
woocommerce/product-updatewrite
woocommerce/order-update-statusfinancial
raqvio-ag/order-create-refundfinancial
woocommerce/product-deletedestructive

Ability inventory. Every registered ability, classified by risk. Override any level you disagree with.

Agent Guardrails → Agents → Permissions
AbilityRiskPermission
products-queryreadAllow
product-updatewriteAllow
order-create-refundfinancialRequire approval
product-deletedestructiveDeny

Per-agent permissions. Default, Allow, Deny — or Require approval with Pro. Different agents, different reach.

Agent Guardrails → Audit Log
products-query · mcpAllowed
product-update · restAllowed
order-create-refund · mcpNeeds approval
product-delete · mcpDenied
order-update-status · restDenied

Audit log. Agent, channel, decision and result for every call — input redacted before it is stored.

Agent Guardrails → Readiness
78
Store score
How well AI shopping agents can read your catalog
Missing GTIN/MPN/brand312
Missing or short description147
Missing images or alt text89
Missing key attributes41

Catalog readiness. A score plus the issues holding your products back in AI-driven shopping.

Illustrations of the plugin screens; names, labels and decisions match the plugin, numbers are examples.

Pricing

Start free. Upgrade when you need rules, approvals and rollback.

Free

WordPress.org
$0
Fully functional agent governance for every WordPress and WooCommerce site. No card, no account.
Download free
  • Ability inventory + risk classification
  • Unlimited agents + the built-in Site AI
  • Per-agent allow / deny, safe defaults
  • Emergency kill switch
  • Redacted audit log — keep it 1 to 365 days
  • Credential & exposure hardening check
  • Catalog readiness score (WooCommerce)
  • Refund ability for agents, governed

Pro

14-day free trial · no card
$99 /year · 1 site
Everything in Free, plus the policy engine, human approvals and rollback.
  • “Require approval” permission for any ability
  • Approval queue — approve or reject from email or Slack
  • Policy rules — amounts, spending budgets, % price changes, rate limits, time windows, input values
  • Test a rule on past agent activity before you save it
  • Alerts when an agent is blocked repeatedly or unusually busy
  • Snapshots + one-click & bulk rollback
  • Tamper-evident audit log, filters, CSV export
  • AI readiness fixer · Google Merchant Center feed

14-day money-back guarantee on every purchase and renewal — refund policy · terms.

Prices in USD, billed yearly. Every Pro and Agency plan includes all Pro features; they differ only in the number of sites.

Raqvio Agent Guardrails never sells or proxies AI access and never ships model keys. The readiness fixer uses the AI provider you configure in WordPress.

FAQ

Questions, answered.

Does Raqvio Agent Guardrails work without WooCommerce?
Yes. Governance covers every ability registered through the WordPress Abilities API. WooCommerce-only features — catalog readiness, the readiness fixer, the Merchant Center feed and the refund ability — appear when WooCommerce is active.
Is the free version limited?
No. The free plugin has no limits on agents, abilities or audit log entries, and no trial period. You choose how long the audit log is kept, from 1 to 365 days. Raqvio Agent Guardrails Pro is a separate plugin that adds human approvals, policy rules with spending budgets, alerts, rollback and a tamper-evident audit log.
Are humans in wp-admin governed?
Not by default. Only agent traffic is governed: application-password and MCP calls, users with the “AI Agent (Raqvio Agent Guardrails)” role, and the built-in Site AI. The “Govern all ability executions” setting extends the unknown-agent defaults to logged-in humans too.
What does an agent see when it is blocked?
A standard error with a readable reason that starts “Blocked by Raqvio Agent Guardrails:”. The code is raqvio_ag_denied (HTTP 403), or raqvio_ag_blocked while the kill switch is on. With Pro, an action that needs approval returns raqvio_ag_approval_required (HTTP 202) with its approval id, which the agent can poll with raqvio-ag/get-approval-status.
Which AI agents can I connect?
Any MCP client that can send your site’s API key or application password, or any HTTP client that calls the WordPress Abilities API. The docs have step-by-step setups for Claude Desktop, Claude Code and Cursor. ChatGPT can’t connect yet: it only supports OAuth sign-in, which WordPress’s MCP servers don’t offer (details). Raqvio Agent Guardrails identifies each agent by its application password or its dedicated WordPress user.
Can refunds be rolled back?
No. Refunds and payments are final, and Raqvio Agent Guardrails says so on every screen where it matters. Use an approval rule (Pro) such as “Approve refunds over X” to stop them before they happen. Rollback covers products, prices, stock and order statuses — and coupons, posts, pages and terms changed by abilities that follow the standard naming.
Can an agent change Raqvio Agent Guardrails’s own settings?
No. The management API only accepts a nonce-verified wp-admin session from an administrator (or a shop manager, if you allow it in Settings); requests authenticated with an application password are refused, even for administrators. A request made with a user’s own account must be approved by a different administrator.
Does Raqvio Agent Guardrails read my AI API keys?
No. The hardening check only reports where a key is configured — environment variable, wp-config.php constant, or database. Database presence is checked with a LENGTH() query, so the value never leaves MySQL.
What are the requirements?
WordPress 6.9+ and PHP 8.1+. Enforcement needs WordPress 7.1+; on 6.9 and 7.0 Raqvio Agent Guardrails runs in audit-only mode and logs what it would have decided. Store features need WooCommerce 10.0+ (the refund ability needs 10.9+). HPOS custom order tables are supported. Multisite: activate per site, not network-wide.

More in the documentation.

Put a guardrail between agents and your store.

Install the free plugin, map your first agent, and watch the audit log fill up. Upgrade to Pro when you want rules, approvals and rollback.

✓ Requires WP 6.9+✓ PHP 8.1+✓ HPOS compatible✓ Translatable & RTL-ready