Skip to content

Agents & permissions

An agent is an AI client you govern. You map an application password or a dedicated WordPress user to it, then choose what it may do. Calls from application passwords and MCP clients you have not mapped are treated as unknown agents and follow the defaults in Settings.

Agent Guardrails → Agents → Add agent opens the agent editor:

Field Options
Name Required.
Description Optional.
Identity A specific application password (recommended) — pick the user, then one of their application passwords. Any request made by a dedicated WordPress user — every call made as that user, whatever the credentials — unless the application password used is bound to another agent, which takes precedence.
Abilities not listed in the matrix Deny unlisted abilities (recommended) (the default), Use risk defaults (allow read, deny the rest), or Allow unlisted abilities.
Status Active, or Paused (all actions denied).

Click Save agent. Each identity can belong to only one agent (“Another agent already uses this identity.”).

Which identity should I use?

  • Application password is the most precise: one credential, one agent. Only the password’s ID is stored, never the password. If the application password is revoked, the agent is paused and unbound.
  • WordPress user is needed when the client authenticates some other way — for example WooCommerce’s MCP endpoint, which uses WooCommerce REST API keys: bind the user who owns the key. If the user is deleted, the agent is paused and unbound.

Click Permissions on an agent card. Each governed ability is listed with its risk and a permission:

Permission Effect
Default Follows the agent’s “Abilities not listed in the matrix” setting (shown at the top of the panel).
Allow The agent may run the ability.
Deny Blocked with raqvio_ag_denied.
Require approval (Pro) The call waits in Approvals until a human approves it.

Click Save permissions. Policy rules (Pro) are checked before these permissions, and the kill switch before everything.

Site AI (“In-site AI Client calls”) is created automatically. It covers AI features running inside WordPress through the core AI Client — not external agents. It uses the risk defaults, can be paused, and cannot be deleted (“The built-in Site AI agent cannot be deleted. Pause it instead.”).

There is no limit. Add one agent per AI client, so each one has its own permissions and its own entries in the audit log.

Delete asks “Delete agent “…”? Its calls will then be treated as an unknown agent.” The agent’s past audit entries stay, shown as “(deleted agent)”.

Raqvio Agent Guardrails treats a call as coming from an agent when it:

  1. uses an application password or user bound to an agent;
  2. is an in-site AI Client call (Site AI);
  3. otherwise, as an unknown agent, when it is authenticated with any application password, arrives over MCP, is made by a user with the AI Agent (Raqvio Agent Guardrails) role, or when “Govern all ability executions” is on.

Everything else — a logged-in human in wp-admin — is not governed or logged. See How agents are identified.