The Access Control screen lets you control which WordPress roles can use AtlasMCP modules, abilities, and workflows.
You can assign access at the role level, giving each WordPress role access only to the capabilities you want them to use. Roles without any assignments receive no AtlasMCP access.
To allow or disallow abilities based on user roles follow the below instruction:
Navigate to AtlasMCP plugin dahsboad → click Access Control tab.
Access Control Overview #
AtlasMCP provides separate access controls for:
- Abilities — Control which abilities each WordPress role can use.
- Workflows — Control which workflows each role can access.
Use the Role selector to choose the WordPress role you want to configure.
Available roles can include:
- Administrator
- Editor
- Author
- Contributor
AtlasMCP Modules #
The AtlasMCP section can include modules such as:
- AI Content Steward — 22/22
- Media Manager — 7/7
- Users Manager — 7/7
- Custom Post Types Manager — 6/6
- Pages Manager — 5/5
- Site Info & Diagnostics — 4/4
- REST API Tools — 3/3
- Settings Manager — 3/3
The numbers show how many abilities from each module are currently assigned to the selected role.
For example, AI Content Steward 22/22 means all 22 available abilities from that module are granted to the selected role.
Other Plugins #
Abilities provided by WordPress core or other plugins are also listed separately.
For example:
- WordPress Core — 3/3
This allows you to control access to abilities that do not originate from AtlasMCP’s built-in modules.
Managing Access by Role #
Access Control lets you configure each WordPress role independently.
For example:
- Administrator can be given access to all available abilities.
- Editor can be limited to content-related abilities.
- Author can be given access only to abilities required for creating and managing their content.
- Contributor can receive a more restricted set of abilities.
The exact access available to each role depends on the abilities you assign.
Removing Access #
To remove an ability from a role:
- Select the WordPress role you want to modify.
- Find the module or ability you want to restrict.
- Deselect the ability.
- Save the changes.
You can also use Deselect all to remove all currently assigned abilities from the selected role.
Access Control and AI Clients #
Access Control works together with the permissions of the connected WordPress user.
When an AI client connects through AtlasMCP, the available actions are determined by the user’s WordPress role and the abilities assigned to that role.
This allows you to control what different users and their connected AI clients can access without giving every role access to every AtlasMCP ability.