High-impact Abilities
High-impact Abilities include operations such as executing PHP, running unrestricted WP-CLI, accessing files, and irreversible changes. Some are reads: reading a file can expose sensitive data even when it changes nothing.
Enable only the operation you need
Open Abilities, find the Toolkit, and choose Manage. Expand the relevant Integration and review the individual Ability marked High impact before enabling it.
Recommended excludes high-impact Abilities. Selecting a Toolkit does not enable all its high-impact operations. Enable all includes them only after the warning and explicit confirmation.
The Agent and website must also permit the operation. Workspace enablement alone does not bypass narrower access.
Before allowing a change
Identify the exact website, operation, and expected result. For work that changes content or configuration, have an appropriate backup and a way to verify the result. MoraWP does not provide a universal sandbox or automatic rollback for every Ability.
A dry run is available only when the Ability's current description says it supports one. Do not assume PHP execution, deletion, or another high-impact operation can be previewed.
Usage and notifications
High-impact Abilities use the same AI Actions allowance as other Abilities. There is no separate high-impact plan quota.
Each active Workspace member receives a notice once per website when high-impact access first becomes effective there. Individual executions appear in Activity, rather than creating a new inbox notification each time.
Remove access afterwards
Turn off the individual Ability when it is no longer needed, or narrow the Agent's access. Disconnect the Agent if it should no longer reach the Workspace. Removing access does not undo completed changes.
Continue with Access modes or Unknown execution outcome.