Skip to content

Powerful enough to act.
Careful enough to trust.

Giving an AI agent access to a production WordPress site is only reasonable if you control what it can do. Talos makes that control explicit at five separate layers, each of which you configure yourself.

Modes set the ceiling

Ask is inspect-only, with no access to write or high-impact tools at all. Plan makes the agent propose a structured plan and wait for your approval. Agent gives it the full allowed tool set, still subject to every other control. You choose the site default.

Per-tool policy sets the detail

Each tool is independently disabled, set to always ask, or fully allowed. Disabled tools are hidden from the agent entirely. The editor is searchable and grouped by risk, so you can review the high-impact set on its own.

Confirmation gates catch the rest

Dangerous plugin operations, rollbacks and skill approval or replay stop for explicit confirmation in chat regardless of policy, with a capability mapping and a risk threshold above which approval is always required.

Roles decide who gets access

The floating chat appears only for the WordPress roles you list. Administrators are always included, and settings plus the management APIs require manage_options.

Budgets keep spend predictable

A default limit of 30 runs per hour and 200,000 tokens per run, both configurable, plus a list of protected option names the settings tools treat with extra care. Token usage is visible in the chat panel as you go.

The specifics.

Modes

Ask · Plan · Agent

Per-tool policy

Disabled · Always ask · Fully allowed

Risk levels

read → low → medium → high → critical

Approval threshold

Defaults to high

Rate limit

30 runs per hour (configurable)

Token budget

200,000 per run (configurable)

Good to know.

What is the safest way to start?

Set the default mode to Ask. The agent can then investigate and answer questions with no ability to change anything, because write and high-impact tools are unavailable in that mode. Move to Plan once you trust its reasoning.

Can an editor use Talos without gaining admin powers?

Yes. Chat access is role-based, but the capability mapping still checks the acting user’s own WordPress capabilities. An editor cannot use Talos to do something their role could not do directly.

Where do the API keys live?

In your WordPress site settings, and they are masked in API responses. You bring your own provider keys, so requests are billed to your account at your provider’s published rates.

What about prompt injection from site content?

It is treated as a real threat. Scopes are fixed at enable time and cannot be widened mid-run, email report recipients cannot be changed by the agent, high-impact tools need confirmation, and settings access is allowlisted with secrets redacted. Content the agent reads cannot grant it new permissions.

Put an agent to work in WordPress.

Spend less time clicking through admin and more time moving your site forward.