Skip to content

Choosing a Permission Level for Your AI

30 views · Updated 1 month ago

How much should your AI be allowed to do?

You pick this when you connect, and you can change it whenever you like by reconnecting. Start low. You can always raise it once you have seen how it behaves.

Read only

It can look, and change nothing.

Checks whether your site is up, why it might be slow, when your SSL certificate expires, how much disk you are using, what your DNS records say.

Good for: almost everyone, to begin with. There is nothing it can break.

Manage

Everything above, plus safe changes.

Create an email account, add a DNS record, request an SSL certificate, clear your cache.

Every change here is recorded with an Undo button in your panel for 30 days.

Good for: day to day admin you would otherwise do yourself in the panel.

Edit content

Everything above, plus your WordPress pages and posts.

Read your pages, rewrite them, and write new ones. New pages are saved as drafts unless you specifically ask for them to be published - so nothing appears on your site without you deciding.

Needs one extra step: see Letting your AI edit your WordPress pages.

Good for: keeping content up to date without opening WordPress.

Full access

Everything above, plus files and databases.

Read and write the files of your website, and run queries against your own databases.

This is the most powerful level and it behaves differently on purpose:

  • Anything that deletes or overwrites describes what it is about to do and stops, and only acts after you say yes.
  • Files holding passwords - wp-config.php, .env and similar - stay closed even here. Nothing you grant opens them.
  • It cannot reach outside your own website's folder.

Good for: when you are comfortable, and want real help with a problem.

Whatever you choose

  • Your AI only ever sees your own account.
  • Pause stops everything at once.
  • The activity list shows what it has been doing, in plain language, including anything it tried and was refused.