
內容簡介
ControlPact Governance 外掛將 WordPress 連接至外部的 ControlPact AI-agent 治理服務,提供安全的內容發布決策。透過此外掛,管理員可依據 ControlPact 的評估結果,決定是否允許、批准或阻擋特定操作,確保網站內容的合規性。
【主要功能】
• 連接 ControlPact 外部治理服務
• 根據治理評估結果決定內容發布
• 支援 REST API 自動化操作
外掛標籤
開發者團隊
原文外掛簡介
ControlPact Governance connects WordPress to the external ControlPact AI-agent governance service.
Each WordPress administrator supplies their own scoped ControlPact API credential. No shared or developer-owned production credential is bundled with the plugin.
ControlPact evaluates governed actions and returns one of three decisions:
ALLOW
APPROVE
BLOCK
Version 0.1.0 includes a real governed WordPress operation for REST-based automation: an authenticated client can request publication of an existing draft post through the ControlPact endpoint. The post is published only when ControlPact returns ALLOW. APPROVE and BLOCK leave the post unpublished.
Governed endpoint:
POST /wp-json/controlpact/v1/posts/{id}/publish
The endpoint uses normal WordPress REST authentication and WordPress capability checks. The ControlPact API key remains stored server-side.
External Service
This plugin connects to the external ControlPact governance service.
ControlPact service website:
https://ctrlpact.com
Privacy Policy:
https://ctrlpact.com/privacy
Terms of Service:
https://ctrlpact.com/terms
Current API service endpoint:
https://controlpact-backend.onrender.com
The external service is required for governance evaluations. The plugin does not perform ControlPact policy evaluation locally.
When a governance evaluation is requested, the plugin may send:
The requested action name.
The governed resource.
A unique reference ID.
Context associated with the request.
The WordPress site URL.
For governed post publication: the post ID, post type, requested status and current WordPress user ID.
The configured ControlPact API credential in the HTTP Authorization header.
The governed post-publish endpoint does not send the post title or post content to ControlPact.
The API credential is used only to authenticate requests to ControlPact.
No governance request is sent until a WordPress administrator has configured the plugin with a ControlPact API credential and uses functionality that requires a ControlPact decision.
Privacy
The ControlPact API key is stored server-side in the WordPress options database and is not printed back into the administration interface after it has been saved.
The option is configured not to autoload with ordinary WordPress requests.
ControlPact Governance does not include advertising or unrelated tracking.
When governance functionality is used, information necessary to evaluate the requested action is transmitted to the external ControlPact service as described in the External Service section above.
Site administrators are responsible for ensuring that the contextual data they send through governed actions is appropriate for their organisation and applicable privacy requirements.
