Skip to content

Troubleshooting

My approval rules don’t create anything in Approvals

Section titled “My approval rules don’t create anything in Approvals”

Approval requests are only created when an agent attempts a matching action. Check:

  1. Who the rule applies to. A rule scoped to Site AI (in-site AI features only) only covers AI features running inside WordPress — not Claude Desktop or any other external agent. Set Applies to to All agents or the agent that calls. The Rules screen warns you when every rule is scoped to Site AI.
  2. Whether the agent is calling at all. Look for its calls in the Audit Log.
  3. Whether the call matches. For example “Approve refunds over 100” only matches refunds above 100.
  • Check the WordPress version: below 7.1 Raqvio Agent Guardrails is in audit-only mode and only logs. The audit log shows “(not enforced)”.
  • Check that the caller is governed. A logged-in human in wp-admin isn’t, unless Govern all ability executions is on.
  • Check the agent’s Abilities not listed in the matrix setting and its explicit permissions.

The call wasn’t matched to one of your agents. Bind the exact credential it uses: the application password it authenticates with, or — for WooCommerce MCP, which uses API keys — the WordPress user that owns the key. See How agents are identified.

The audit log says “permission_denied”

Section titled “The audit log says “permission_denied””

Raqvio Agent Guardrails allowed the call, but the ability’s own WordPress permission check refused it: the agent’s user doesn’t have the capability (for example editing products). Give that user the capabilities it needs; Raqvio Agent Guardrails still limits which abilities it may use.

The action ran after approval but returned an error (for example the refund amount was no longer available), or didn’t finish within 15 minutes. Open the request to see the result, and the related audit entry for details.

“Verify integrity” reports changed entries (Pro)

Section titled ““Verify integrity” reports changed entries (Pro)”

If many or all older entries show as changed at once, the most likely cause is a changed key, not tampering. The seals are keyed from RAQVIO_AG_ENCRYPTION_KEY in wp-config.php if you define it, otherwise from the WordPress security keys. Rotating the security keys, or restoring the database on another site, makes older seals unverifiable. If you rotate security keys regularly, define RAQVIO_AG_ENCRYPTION_KEY once and keep it. See Verify integrity.

If only a few entries are reported, check who has database access and when those entries were changed.

Check Settings → Alerts: a threshold of 0 turns that alert off, and the unusual-activity alert is off by default. Each alert is sent at most once per agent per period. Alerts are sent by a background job, so Action Scheduler must be running (Tools → Scheduled Actions). If approval emails don’t arrive either, the problem is your site’s email delivery. See Alerts.