For agencies · 10–100 client sites

Take on more client sites without taking on more risk.

Every risky AI change gets reviewed before it runs, with one evidence trail across every client site — no matter who hosts it.

The panic this solves

"Which site did the agent just change?"

That's the moment this exists to prevent. A change goes out, and nobody can say who approved it, what it touched, or what actually ran.

Economic job

Grow the client roster each operator can safely maintain — without a matching rise in incident risk or margin erosion.

Emotional job

Let a senior developer supervise more work without becoming the bottleneck for every harmless read. Give an owner real confidence to let the whole team run AI against production.

Built for agency structure

Separation of duties for a real team. Not a solo workflow with extra steps.

Requester and approver, separated

A developer, or the agent itself, can propose a change. A senior developer, technical director, or account owner reviews the exact preview and approves that digest. Assign the approver role to someone else, and no one signs off on their own work.

Works across mixed hosting

Most agencies don't run every client site on one host. WP MCP reaches sites over SSH+WP-CLI or a companion plugin, regardless of who hosts them. Mixed hosting and customer-owned hosting both included.

Fleet-wide policy and evidence

One rulebook, one evidence trail, for the whole client roster.

Policy templates & inheritance

Set the rules once — content, maintenance, WooCommerce, user and security — and apply them across site groups instead of reconfiguring per client.

Approval inbox across all sites

Approvers see every pending packet from every governed site in one place, instead of scattered across a dozen project chat threads.

Centralized evidence timeline

One packet ledger tracks proposal, approval, execution, and verification — across the fleet, instead of one-off logging per project.

Client-ready reporting
When a client asks "what did the AI change," the Agency tier's audit exports answer it directly. That turns AI-assisted maintenance from a sales pitch into something you can actually hand them.
Is this you?

A quick self-check before you book a review.

  • One or more AI coding tools already touch client WordPress sites.
  • The agent gets SSH, WP-CLI, application-password, or admin-level access.
  • It isn't always clear who's actually authorized to approve a production change.
  • The person prompting the agent can often also approve the action, today.
  • There's no reliable way to prove the payload that executed is the payload that was reviewed.
  • Clients sometimes ask what changed, and there's no clean evidence trail to hand them.
  • Reversing a bad settings, content, or plugin change would take longer than anyone would like.
  • Client sites are spread across multiple hosts, with no single dashboard tying them together.

Checked two or more? That's exactly the conversation an agency safety review is for.

Why guarded change beats raw agent access
Most tools can show a green "approve" button. What matters is whether that approval is exact: bound to the specific payload and pre-change state a human saw. And whether it's independently enforced, so it goes invalid the moment reality changes. Read the full security model →
Built for this tier

Agency — $79/month

Founding Agency — first 20 agencies only
50% off for 12 months ($39/month), price locked while continuously subscribed, a direct founder channel, and onboarding included.
Ask about founding pricing

See every plan

Book a 30-minute agency safety review.

We'll map how AI reaches your client sites, test one harmless dry run, and show you the evidence trail.