PlugPress

Permissions and Access Levels: Control What AI Can Do on Your Site

Saddle never gives an AI app blanket admin rights. Access is controlled in three layers — a global pause switch, a site-wide access level, and per-tool toggles — and every one of them is set by you in the WordPress dashboard. If any layer says no, the AI’s request is refused.

What are the three layers of control?

  1. The pause switch — one setting in Saddle → Settings that suspends all AI access instantly, across every connection. Nothing gets through while it’s on. Use it any time you want the site frozen — during a launch, an audit, or just for peace of mind.
  2. Access level — set in Saddle → Permissions, this decides how much a connection can do overall: from read-only browsing up to full content management. Start low and raise it as you build trust in your workflow.
  3. Per-tool toggles — also in Saddle → Permissions, every individual tool (create page, upload media, edit blocks, and so on) can be switched off independently. Want an AI that can draft posts but never touch pages? Turn off the page tools and you’re done.

What happens when the AI tries something that isn’t allowed?

The tool call is refused with a permission error, and a well-behaved assistant will tell you which control blocked it rather than retrying. Nothing partial happens — a refused call makes no changes at all. To allow the action, check (in order): the pause switch in Settings, the access level in Permissions, and that specific tool’s toggle in Permissions.

Do permissions apply per connection?

Every connection you create in Saddle → Connections has its own sign-in key, so you can revoke one app’s access without touching the rest. Permission controls apply to whatever connects — there is no side door around them, and destructive actions carry their own extra safeguard on top (see Safe Deletions and the Approval Gate).

Is there a record of what AI apps changed?

Yes. Saddle keeps an activity log of what connected AI apps changed and when — creations, edits, and deletions, newest first. Connected assistants also receive this log as context, so they know what already happened on the site before making new changes.

  • Start with a conservative access level and only the tools you expect to use.
  • Create a separate connection per app or per person, named clearly.
  • Raise permissions gradually — you can change them at any time without reconnecting.

New to Saddle? Begin with Getting Started: Connect Your First AI App.