Review what AI assistants did on your site
Agent activity lists every ability call on your WordPress site, refused ones too: who made it, how it came in and how it ended.
The screen is under BetterShield › Activity › Agent activity. In WordPress, an ability is a named action a plugin offers to AI assistants and other tools, such as reading the score; each use of one is a call. This screen shows the calls that were made, where Agents › Surface shows what callers are able to do.
Note: Recording needs WordPress 7.1 or newer. On an earlier version the screen says agent activity is not recorded on this version, and nothing is listed.
What is recorded
Every time an ability is called on the site, whichever plugin registered it and however the call came in, including calls that were refused. Each record keeps the ability name, the time, the account it ran as, how the call came in, and the outcome. The input is kept only as a digest, never its contents, because an input can carry a secret.
Refusals also reach the site activity log: Ability refused once per ability per request, and Abilities refused repeatedly when ten requests within an hour carry a refusal. Another plugin can stop the recording, and BetterShield cannot prevent that, but it writes Agent activity recording stopped to the log, at most once an hour.
Turn recording on or off
Record what agents do on this site is on by default. The same switch appears in two places: the Recording agent activity card under Settings › General, and the same card under Agents › Permissions. Turning it off asks for your password first when Ask for my password before an action that removes a protection is on. Rows already recorded stay, and a note above the list says recording is off.
The figures at the top
| Figure | What it shows |
|---|---|
| Recording | On, Off or Unavailable. |
| Calls | Calls kept, or calls matching your filters. |
| Refused | Calls that asked for more than the account was allowed. |
| Completed | Calls that ran and answered. |
Filters
- Outcome, as chips with counts: All, Refused, Completed, Input rejected, Input unreadable, Output rejected, Answered early, Failed and Did not finish.
- Namespace: the first part of an ability name, with counts. WordPress does not record which plugin registered an ability, so a namespace is a naming convention, not proof of who is behind it.
- Came through: Any door, MCP (a connected assistant), REST, WP-CLI or PHP.
- Clear filters resets all three.
Reading a row
Each row shows the time, the ability name, the account it ran as, how it came in (over MCP, over REST, via WP-CLI or in PHP), how long it took when that is measurable, and the outcome with any error code. A refused call is highlighted.
- Everything this account did narrows the list to that account. Show every account goes back.
- Agent surface, at the top, opens Agents › Surface, which shows what agents are able to do.
- Show older entries loads more.
How long rows are kept
As long as the activity log: 30 days, or 90 days (Ultra). The note at the foot says which applies. The screen has no export; use wp bettershield agents --format=csv (WP-CLI commands).