# What AEBOT can do at each WordPress permission level

Source: https://auditae.app/docs/wordpress-permissions

The four AuditAE plugin permissions (read, draft, publish, Write SEO settings): what AEBOT and MCP agents can and can't change at each level.

Once the AuditAE plugin is paired, the site owner decides what AEBOT and any agent connected over MCP may do on the site. There are four switches, and every write is checked against them twice: by AuditAE before the request leaves our servers, and by the plugin on your site before it changes anything.

> [!NOTE]
> A new pairing starts with **read** and **draft** only. Publishing and SEO writes are opt-in.

## Where to change permissions

In WordPress admin, go to **Settings → AuditAE**, open the **Connect** tab, and find the **What AEBOT can do** card (it appears once the site is paired). Tick the permissions you want and click **Save permissions**. Only an administrator can change them.

AEBOT picks up a change the next time it tries: if a permission it needs is missing, it re-reads the plugin's live settings before giving up, so you don't need to re-pair. The connection page in AuditAE ([WordPress sites](https://auditae.app/dashboard/wp)) shows the current set; click **Refresh** there to sync it by hand.

## The four permissions

| Permission | Shown in AuditAE as | What it allows | Tools |
|---|---|---|---|
| `read` | Read site data (free) | Read posts and pages, SEO meta, schema, llms.txt, media, links, redirects, the AI crawler log and form leads | `wp_site_status`, `wp_get_seo_settings`, `wp_list_posts`, `wp_get_post`, `wp_get_post_seo`, `wp_get_faq_schema`, `wp_get_post_schema`, `wp_get_organization_schema`, `wp_probe_schema`, `wp_get_llms_txt`, `wp_read_page_blocks`, `wp_list_recent_posts` (AEBOT only), `wp_get_post_links` (AEBOT only), `wp_get_link_graph` (AEBOT only), `wp_list_crawler_hits` (AEBOT only), `wp_list_form_submissions` (AEBOT only), `wp_get_fields` (AEBOT only), `wp_list_media` (AEBOT only), `wp_get_media` (AEBOT only), `wp_list_redirects` (AEBOT only), `wp_suggest_redirects_from_404s` (AEBOT only) |
| `draft` | Create + update draft posts | Create and update drafts, upload media, insert internal links in drafts, save a designed page as a draft, trash a draft | `wp_create_post`, `wp_update_post`, `wp_trash_post`, `wp_design_page`, `wp_upload_media` (AEBOT only), `wp_insert_internal_link` (AEBOT only), `wp_edit` (AEBOT only) |
| `publish` | Publish posts directly | Publish or schedule posts and edit posts that are already live, including link inserts and designed pages | `wp_create_post`, `wp_update_post`, `wp_design_page`, `wp_insert_internal_link` (AEBOT only), `wp_add_record` (AEBOT only) |
| `write_seo` | Write SEO settings | Change SEO titles and descriptions, FAQ, post and organization schema, llms.txt, image alt text and captions, and redirects | `wp_set_seo_settings`, `wp_set_post_seo`, `wp_set_faq_schema`, `wp_delete_faq_schema`, `wp_set_post_schema`, `wp_delete_post_schema`, `wp_set_organization_schema`, `wp_delete_organization_schema`, `wp_set_llms_txt`, `wp_reset_llms_txt`, `wp_update_media` (AEBOT only), `wp_rename_media` (AEBOT only), `wp_add_redirect` (AEBOT only), `wp_delete_redirect` (AEBOT only) |

`wp_list_sites` lists your paired sites from AuditAE itself and needs no permission. Tools marked "AEBOT only" are available in the AEBOT chat but not over MCP.

## What AEBOT does at each level

### Not paired

AEBOT can't touch the site. It gives you paste-ready edits (copy, meta tags, JSON-LD) and points you to [pairing the plugin](https://auditae.app/docs/wordpress-pairing).

### Read only

AEBOT reads your posts, SEO meta, schema, llms.txt, media, links, redirects and the AI crawler log, so its advice is about your real pages. It won't offer to create a draft or change anything.

### Read and draft (the default)

AEBOT can create new drafts and update drafts, upload media, insert internal links into drafts, and save a designed page as a draft for you to review and publish yourself. Editing a post that is already published needs **publish**.

### Publish

AEBOT can publish or schedule posts and edit live content, always after you confirm. Scheduling a post for later counts as publishing, because it goes live without another check. Trashing a live post needs **publish** too; trash is reversible from the WordPress Trash.

### Write SEO settings

AEBOT can apply SEO fixes directly: titles and meta descriptions (Yoast or Rank Math), FAQ schema, post and organization schema, llms.txt, image alt text and captions, and 404 → 301 redirects. Schema is validated before it reaches the site.

Without **Write SEO settings**, AEBOT shows you the exact edits instead of applying them, and names the switch that would let it apply them. On an audit, the fix buttons read **Show me the exact edits** for a paired site without it, and **Apply with AEBOT** once it's on.

## Good to know

- **Elementor pages:** AEBOT edits text in place with exact find-and-replace edits (`wp_update_post` with `replacements`). Whole-page rewrites are refused there, and fields bound to Elementor Pro dynamic tags are skipped. On block-editor pages the same edits also update the text blocks keep in their settings (Yoast or Rank Math FAQ blocks, for example), so edited blocks stay valid in the editor.
- **AuditAE AI Autopilot theme:** `wp_edit` changes page fields and site-wide brand settings (needs **draft**), and `wp_add_record` adds services, locations, FAQs and other records that pages loop over (needs **publish**).
- **Every action is logged** on the plugin's **Activity** tab in WordPress admin, and you can disconnect at any time from the **Connect** tab.

## What it costs

Reads are free. Each standard write costs 5¢, billed per write from your AuditAE balance. `wp_design_page` (the Page Composer) costs 25¢. AEBOT's own reply is billed on top; see [Credits, prices and top-ups](https://auditae.app/docs/credits).
