From request to reviewed change

How Agent Composer protects WordPress page structure

A safe editing flow needs more than permission to call an operation. It also needs rules for what that operation may change inside the page.

Request → permission check → page rules → draft or proposal → validation → human review

The control path

Three boundaries are checked separately

Agent Composer treats access, page structure and publication as separate decisions instead of relying on one instruction to cover all three.

1. Identity and operation
   ↓
2. WordPress permission / exposed action
   ↓
3. Managed page structure
   ├─ protected sections stay in place
   ├─ editable fields may change
   └─ extra blocks only in allowed insertion points
   ↓
4. Draft or update proposal
   ↓
5. Validation
   ↓
6. Human review before published content changes

Why this matters A user may be allowed to edit content without being allowed to reshape the whole page. Keeping those two decisions separate makes the rule enforceable in the application rather than dependent on model behaviour.

Example

What happens when an agent edits a managed page?

The same sequence can be tested with ordinary content changes and with requests that cross the protected boundary.

  1. Change permitted content — The agent can rewrite text in an editable area or replace an approved image where the page rules allow it.
  2. Reject a structural violation — A request to delete a required section, reorder protected sections or replace them with an arbitrary block is rejected by the page rules.
  3. Keep additions separate — New blocks can be allowed only in declared insertion points. Blocks added there remain removable or movable without exposing the protected structure.
  4. Review before publication — Changes to published content are prepared as a separate proposal. The live source remains unchanged until an authorized person reviews and applies it.

What each part is responsible for

Application checks

Machine-enforced boundaries

  • Identity and operation permissions are checked before an edit is accepted.
  • Managed page rules decide which parts may change and which must remain.
  • Validation checks the resulting document before it can move forward.

Human review

A separate publication decision

  • A reviewer sees the prepared change rather than relying on the agent’s description of it.
  • The published source is not rewritten while the proposal is still under review.
  • Approval remains distinct from the rules that constrain what the agent can prepare.

Practical questions

What the structure rules do and do not cover

Can an editor change the wording of a protected section?

Yes, if its text field is declared editable. Protecting the section does not require freezing every value inside it.

Can the site structure still evolve later?

Yes. The managed structure can be changed deliberately in its shared definition, while page-specific values remain separate from that definition.

Does this depend on the AI model following instructions?

No. The important boundaries are checked by the WordPress-side application. Instructions still help describe the task, but they are not the enforcement mechanism.

Does human approval replace these checks?

No. Approval decides whether a prepared change is applied. Permission and structure checks limit what can be prepared in the first place.

Compare the layers

See why permissions and structure are separate controls

The comparison page shows where MCP permissions stop and where page-structure rules begin.