Quick start
This walkthrough connects one agent over an application password, the most precise way to identify an agent. For WooCommerce’s MCP endpoint (API keys) see Connect an agent.
1. Look at what agents can already do
Section titled “1. Look at what agents can already do”Open Agent Guardrails → Abilities. This is every ability registered on your site, with its risk level (Read, Write, Financial, Destructive) and whether it is exposed publicly or to MCP (“Public / MCP”). Out of the box, agents you have not mapped get the unknown-agent defaults: reads allowed; writes, financial and destructive abilities denied.
2. Create a dedicated WordPress user for the agent
Section titled “2. Create a dedicated WordPress user for the agent”Don’t let an agent act as you. Go to Users → Add New User and create a user for the agent.
Raqvio Agent Guardrails can only narrow what a WordPress user is allowed to do — the ability’s own permission check still applies. So give the user the capabilities the agent genuinely needs:
- The AI Agent (Raqvio Agent Guardrails) role has only the
readcapability. It is a safe starting point for agents that only read; add capabilities with a role editor as needed. - For an agent that should manage products or orders, a role such as Shop Manager grants the WooCommerce capabilities, and Raqvio Agent Guardrails then limits which abilities it may use.
If an agent calls an ability its user lacks the capability for, WordPress refuses it and Raqvio Agent Guardrails records the attempt as “permission denied”.
3. Create an application password
Section titled “3. Create an application password”Edit the new user (Users → All Users → Edit), scroll to Application Passwords, enter a name (for example “Claude Desktop”) and click Add New Application Password. Copy the password — WordPress shows it once. Raqvio Agent Guardrails never stores it; it only records which application password (by its ID) belongs to the agent.
4. Add the agent in Raqvio Agent Guardrails
Section titled “4. Add the agent in Raqvio Agent Guardrails”Go to Agent Guardrails → Agents → Add agent:
- Name — for example “Claude Desktop”.
- Identity — choose A specific application password (recommended), find the user, and pick the application password you just created.
- Abilities not listed in the matrix — keep Deny unlisted abilities (recommended).
- Status — Active.
- Click Save agent.
Add one agent like this for each AI client you use. There is no limit on the number of agents.
5. Allow exactly what the agent needs
Section titled “5. Allow exactly what the agent needs”On the agent’s card click Permissions. For each ability choose Allow or Deny (or leave Default, which follows the agent’s setting from step 4). For example, allow woocommerce/products-query and woocommerce/orders-query, and leave everything else on Default. Click Save permissions.
With Pro you can also choose Require approval, so a human confirms the action first.
6. Connect the agent and watch the audit log
Section titled “6. Connect the agent and watch the audit log”Point your AI client at the site with the user name and application password — see Connect an agent for tested configurations. Then open Agent Guardrails → Audit Log: every call the agent makes appears with its decision (Allowed, Denied, Needs approval), channel (mcp, rest, internal) and redacted input.
When something goes wrong, use the kill switch in the admin bar (Agents → Turn kill switch on (block all agents)) to stop every agent at once.
Next steps
Section titled “Next steps”- Kill switch — including “Block for 1 hour”.
- Hardening checklist — find risky credentials and exposed abilities.
- Policy rules and approvals (Pro) — for example, refunds over an amount wait for a human.