Skip to content

How agents are identified

Every time an ability runs, Raqvio Agent Guardrails works out who is calling and through which channel.

  1. Application password bound to an agent — the most specific match.
  2. WordPress user bound to an agent.
  3. Site AI — a call made by WordPress’s own AI Client inside the site.
  4. Unknown agent — not mapped, but clearly an agent, because it:
    • authenticated with any application password, or
    • came in over MCP, or
    • was made by a user with the AI Agent (Raqvio Agent Guardrails) role, or
    • “Govern all ability executions” is on (then every logged-in user counts).
  5. Otherwise the caller is a human using wp-admin: not governed and not logged.

Unknown agents follow Settings → Defaults for unknown agents (by default: reads allowed, everything else denied).

Channel What it covers
mcp Requests to an MCP server — the MCP Adapter’s servers, WooCommerce’s /woocommerce/mcp, and wp mcp-adapter serve over WP-CLI
rest The Abilities REST API (/wp-abilities/v1/…) and other REST requests
internal PHP calls inside WordPress, including the AI Client and actions run after an approval

The channel is shown in the audit log for every call.

  • Raqvio Agent Guardrails’s own management API only accepts a nonce-verified wp-admin session from a user who can manage Raqvio Agent Guardrails (administrators, and shop managers if you allow it). Application-password requests are refused (“Raqvio Agent Guardrails settings cannot be changed with an application password.”).
  • Revoking a bound application password, or deleting a bound user, pauses and unbinds the agent, so a new credential can’t inherit it.
  • A paused agent is denied everything (“This agent is paused.”).