1. Home
  2. Docs
  3. Atlas AI Connector
  4. Usage & Setup
  5. How to Limit What Claude or ChatGPT Can Do on WordPress by User Role

How to Limit What Claude or ChatGPT Can Do on WordPress by User Role

An AI client acts as the WordPress user who connected it. Access control decides which tools each role can use, so an editor connection cannot change settings or users even if the AI tries.

Access control screen assigning MCP abilities and workflows to WordPress user roles
Pick a role, then choose which groups and abilities it may use.

How to set access for a role

  1. Go to AtlasAI Connector → Access control.
  2. Keep the Abilities tab selected and click a role, for example Editor.
  3. Tick the groups this role may use, for example AI Content Steward and Media Manager.
  4. Click Save Abilities.

Roles with no assignments get no access. Every tool also runs its own WordPress permission check, so an AI can never do more than the user behind it.

Give a role access to workflows

Open the Workflows tab and choose which saved workflows each role can run.

Example: a safe setup

RoleSuggested access
AdministratorEverything you use
EditorAI Content Steward, Pages Manager, Media Manager
Shop managerAI Store Manager (WooCommerce)
Author, ContributorOnly the content tools they need, or nothing

Pro controls

Pro: Grant single abilities instead of whole groups. Choose how each ability is exposed: as a Tool, a Resource or a Prompt.

Pro: On the MCP Auth page, Per-role OAuth policy decides which roles may connect an AI client at all and which scopes (mcp:read, mcp:write, mcp:woocommerce) they can grant.

Related guides

How can we help?