Docs / Tag
Permissions
Abilities (7) Add-ons (3) CLI (2) Embeds (1) FAQ (3) Getting Started (8) Installation (2) MCP (13) MCP Clients (1) Permissions (14) Security (1) Settings (2)
Who can access: WordPress Capability
Restrict a resource by capability — the fine-grained permissions behind roles, including ones added by other plugins.
Who can access: Users
Grant access to specific people by searching for them by username or email and adding them to the list.
Who can access: WordPress Role
Restrict a resource to one or more WordPress roles — Administrator, Editor, Author, Contributor, Subscriber or your own custom roles.
Who can access: Everyone (no restriction)
Open a resource to all users — including logged-out visitors — with no further checks.
Who can access: No user access added by admin
The default, locked state — the resource stays available to administrators only until you choose another option.
For developers: providers, REST API & React component
How the wpb-access-control library works under the hood — custom providers, the REST API, the drop-in React panel, and the one PHP call that gates a resource.
Pro: membership, LMS & community integrations (coming soon)
Coming soon in AcrossAI User Access Pro — gate any ability or MCP server by paid membership, LMS enrolment, or community profile type across 10 popular plugins.
How access is decided
The exact order the system uses to allow or deny a user — and where administrators and logged-out visitors fit in.
The “Who can access” options
Every option in the User Access dropdown, explained — from locking a resource to opening it to a role, capability, specific users, or a membership.
Choosing which tools & abilities to expose
Decide exactly what each MCP server offers AI clients using the Tools and Abilities tabs.