How agents are identified
Every time an ability runs, Raqvio Agent Guardrails works out who is calling and through which channel.
Identity, in order
Section titled “Identity, in order”- Application password bound to an agent — the most specific match.
- WordPress user bound to an agent.
- Site AI — a call made by WordPress’s own AI Client inside the site.
- Unknown agent — not mapped, but clearly an agent, because it:
- authenticated with any application password, or
- came in over MCP, or
- was made by a user with the AI Agent (Raqvio Agent Guardrails) role, or
- “Govern all ability executions” is on (then every logged-in user counts).
- Otherwise the caller is a human using wp-admin: not governed and not logged.
Unknown agents follow Settings → Defaults for unknown agents (by default: reads allowed, everything else denied).
Channels
Section titled “Channels”| Channel | What it covers |
|---|---|
mcp |
Requests to an MCP server — the MCP Adapter’s servers, WooCommerce’s /woocommerce/mcp, and wp mcp-adapter serve over WP-CLI |
rest |
The Abilities REST API (/wp-abilities/v1/…) and other REST requests |
internal |
PHP calls inside WordPress, including the AI Client and actions run after an approval |
The channel is shown in the audit log for every call.
Agents can’t escape their identity
Section titled “Agents can’t escape their identity”- Raqvio Agent Guardrails’s own management API only accepts a nonce-verified wp-admin session from a user who can manage Raqvio Agent Guardrails (administrators, and shop managers if you allow it). Application-password requests are refused (“Raqvio Agent Guardrails settings cannot be changed with an application password.”).
- Revoking a bound application password, or deleting a bound user, pauses and unbinds the agent, so a new credential can’t inherit it.
- A paused agent is denied everything (“This agent is paused.”).