Security

A built-in audit log for AI writes

A built-in audit log for AI writes

Letting an agent write to your WordPress install without a paper trail is reckless. NIBWP records every MCP call in a built-in audit log, so there is always an answer to the question: what did the AI actually do?

Every call, on the record

Each entry captures the tool name, the status, the latency, the calling user, and the originating IP. Reads and writes alike are logged, so you can reconstruct exactly what happened and when.

Debugging becomes trivial

When something looks off, you do not guess. You open the log, filter to the window, and see the precise sequence of calls — including the one that returned a 409 and the retry that followed.

  • Status and latency for every call.
  • User and IP for attribution.
  • Error-rate and timing metrics at a glance.
  • Exportable for compliance and review.
If an agent can write to your site, you should be able to see what it wrote.

Pairs with least privilege

The log is the second half of a safety model whose first half is permissions. Scope a token narrowly, force writes to draft, cap the rate — then review the log to confirm the agent stayed inside the lines.

Trust, but verify

The audit log is what lets teams say yes to AI on production content. Read the security docs or book a demo to see it live.

More reading

From the blog

See it run on a live site.

Book a demo and watch an agent work through these abilities.