Governance artifacts
Governance files brought into scope by this page
This page is anchored to published surfaces that declare identity, precedence, limits, and the corpus reading conditions. Their order below gives the recommended reading sequence.
Canonical AI entrypoint
/.well-known/ai-governance.json
Neutral entrypoint that declares the governance map, precedence chain, and the surfaces to read first.
- Governs
- Access order across surfaces and initial precedence.
- Bounds
- Free readings that bypass the canon or the published order.
Does not guarantee: This surface publishes a reading order; it does not force execution or obedience.
Public AI manifest
/ai-manifest.json
Structured inventory of the surfaces, registries, and modules that extend the canonical entrypoint.
- Governs
- Access order across surfaces and initial precedence.
- Bounds
- Free readings that bypass the canon or the published order.
Does not guarantee: This surface publishes a reading order; it does not force execution or obedience.
LLMs.txt
/llms.txt
Short discovery surface that points systems toward the useful machine-first entry surfaces.
- Governs
- Discoverability, crawl orientation, and the mapping of published surfaces.
- Bounds
- Incomplete readings that ignore structure, routes, or the preferred markdown surface.
Does not guarantee: A good discovery surface improves access; it is not sufficient on its own to govern reconstruction.
Moving from an assistant that answers to one that acts changes the question we need to ask. It is no longer enough to decide whether the generated text sounds convincing. We also need to know where the assistant can act, what its authorization covers and how to verify what it actually did.
PAGUP Agent Control is a Pagup product I designed. I am presenting it here as a case of applying this thinking to WordPress, not as an independent evaluation of this product.
The starting point is deliberately concrete: prepare a new draft article from a published page selected as a reference. There is no need to begin by automating the entire website.
Intent is not permission
“Prepare an article and do not publish anything” expresses a goal. That sentence does not, by itself, define a connection’s technical permissions. It does not establish which content is accessible, which fields can be changed or when access ends.
I find it useful to separate three things: what the person requests, what the system authorizes and what can be observed after execution. Confusing them can create an impression of control without corresponding evidence.
In WordPress, the distinction must translate into a connection and task appropriate to the work. The prompt keeps its editorial role. It does not become a permission policy merely because it is precise.
Why begin with a draft?
A first draft provides an identifiable result: a new object on the intended site, with a title, identifier and status to check. It also makes it possible to distinguish the reference used from the target created.
In Agent Control’s documented guided workflow, a published page can be selected as the reference for a new article. The reference is not a page to rewrite. Work begins with the scope configured in WordPress and continues in the conversation using the corresponding connection.
The expected result is not “the AI says it is finished.” It is a draft found in WordPress and reviewed by a person. Its existence does not establish the truth of its claims. Technical success and editorial quality remain separate dimensions.
Distinctions a simple interface should preserve
A simple interface can hide complexity without hiding boundaries. Three distinctions are especially important in this case.
First, reading a public page is not necessarily access to private content. A site connection is not essential to every analysis of published material.
Second, preparing a draft, proposing an update and publishing are different operations. Presenting them as a single blanket consent would misrepresent the decision the user is making.
Third, ending a task is different from pausing or revoking a connection. Agent Control’s documentation distinguishes temporary task permissions from public reading that may remain available while a connection stays active.
These are not details that matter only during an audit. They affect what a user understands and decides before starting.
Keep technical workflows distinct
Agent Control documents guided tasks and advanced REST profiles. These should not be described as interchangeable presentations of the same control mechanism.
Their prerequisites and operating conditions belong in the relevant documentation. The Full Power Access add-on addresses a separate administrative need; it is not the required starting point for an article draft.
That distinction has a practical consequence: a demonstration must identify its workflow. A test in one environment does not automatically validate another interface, AI client or version.
What a demonstration should show
A useful demonstration makes the reference, authorization, request, resulting draft and final check visible. It identifies the version, client and environment. If a step was cut in editing, the edit should not suggest that the step does not exist.
A diagram explains an idea. A screenshot shows an interface. A recorded execution documents a scenario. All three can be useful, but they do not provide the same kind of evidence.
I am therefore not presenting this article as a test report. It explains a design rationale and points to the product documentation for the current workflow. A security qualification or independent evaluation must remain attached to its own scope and findings.
The connection with my work on the agentic web
A website can be readable without being ready to accept arbitrary actions. Likewise, an action can be technically possible without being relevant or authorized in its context.
PAGUP Agent Control provides a concrete example of the problem: connecting a user’s intent to defined WordPress work without turning a conversational instruction into a general guarantee. The product’s value can then be examined through the work it helps organize and the boundaries it makes understandable.
For me, the useful question is not “how far can we let AI act?” It is “what work do we want to entrust to it now, and how will we know that work was carried out correctly?”
Explore the agentic web hub · Understand PAGUP Agent Control