Review AI tools and external abilities

Review AI tools and external abilities.

Status: source-reviewed Section: GymCore AI

Search documentation

Type to search.

GymCore AI offers different functions for sales, coaching, members, finance, and administrators. Choosing a persona narrows what is offered, but WordPress still checks the signed-in user’s permission every time.

Owner flow

  1. Name the staff job to support and the minimum records it needs.

  2. Choose the narrowest persona, then verify the actual WordPress permission on every required function.

  3. Separate immediate reads from drafts and proposed writes. Reads can expose data; drafts do not send; writes must become pending before review.

  4. Test denial, one harmless read, one rejected proposal, and duplicate/retry handling with a least-privilege staging account.

    Expected: Unauthorized functions are denied, the read matches its source and has no commit button, the proposal remains pending until rejected, and retries do not create duplicate source records.

  5. Verify any completed action in the GymCore, WooCommerce, or provider source record.

    Expected: The source record contains the intended result exactly once. A successful tool return is not confused with provider delivery or settlement.

The technical permission names used below are WordPress capabilities. A persona can hide functions, but the capability on each endpoint remains authoritative.

Audited AI tool count: 55. A registered tool is not permission to use it and is not proof its dependency is configured.

Persona access

Persona Default gate Tool scope
Sales Agent gym_process_sale Sales, leads, pricing, schedules, CRM prospect work, SMS drafts/history, rosters, image generation.
Coaching Agent gym_view_briefing Training, attendance, ranks, Foundations, rosters, promotion recommendations, status-only subscriptions.
My Coach read Authenticated member progress, schedule, and subscription status.
Finance gym_view_finance Full admin data set and financial writes; no image generation.
Admin Agent manage_options Full admin set plus image generation.

Write approval rule

A tool definition with write=true queues an action for staff approval. Write families include order/lead creation, class-program assignment, SMS, promotions and Foundations updates, announcements/social actions, CRM notes, refunds, and monthly close. Read tools can still expose personal data immediately. Always verify the tool definition in the installed source because inventory risk labels are conservative and do not replace the write flag.

Complete registered tool catalogue

Stable ID Tool Source Inventory risk
INV-TOOL-0001 get_pricing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:342 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0002 calculate_pricing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:360 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0003 lookup_customer wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:382 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0004 create_kiosk_order wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:400 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0005 create_lead wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:458 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0006 get_schedule wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:496 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0007 get_classes wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:522 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0008 assign_class_program wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:589 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0009 get_locations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:611 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0010 draft_sms wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:623 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0011 get_trial_info wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:657 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0012 get_member_rank wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:673 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0013 get_rank_history wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:695 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0014 get_attendance wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:717 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0015 get_badges wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:751 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0016 get_streak wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:769 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0017 recommend_promotion wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:787 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0018 promote_member wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:809 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0019 get_briefing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:843 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0020 get_foundations_status wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:861 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0021 record_coach_roll wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:879 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0022 get_revenue_summary wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:905 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0023 get_subscriptions wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:948 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0024 get_subscriptions_summary wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:975 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0025 get_mrr wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:988 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0026 get_failed_payments wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1001 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0027 get_reports wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1023 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0028 get_today_attendance wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1039 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0029 get_promotion_eligible wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1061 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0030 draft_announcement wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1079 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0031 draft_social_post wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1126 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0032 generate_image wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1152 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0033 get_briefing_today wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1197 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0034 get_announcements wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1219 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0035 get_sms_templates wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1249 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0036 enroll_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1266 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0037 clear_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1284 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0038 get_active_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1302 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0039 get_social_pending wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1319 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0040 approve_social_post wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1332 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0041 search_crm_contacts wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1354 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0042 get_crm_contact wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1389 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0043 get_crm_contact_notes wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1407 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0044 add_crm_contact_note wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1433 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0045 get_crm_pipeline wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1455 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0046 get_member_orders wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1471 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0047 get_member_billing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1527 medium-high: sensitive access/configuration
INV-TOOL-0048 get_member_subscription_status wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1545 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0049 get_churn_metrics wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1603 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0050 issue_refund wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1621 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0051 get_sms_history wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1651 high: mutates data, sends communication, or crosses trust boundary
INV-TOOL-0052 get_class_roster wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1681 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0053 get_ar_aging wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1703 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0054 draft_dunning_message wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1715 medium: authenticated/operator surface; permission and side effects vary
INV-TOOL-0055 run_monthly_close wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1738 medium: authenticated/operator surface; permission and side effects vary

Connect an MCP client

MCP is a protocol an external client can use to discover approved AI functions. When WordPress Abilities API and the MCP adapter are installed, GymCore AI registers tool-backed abilities with MCP-public metadata. This means an authenticated adapter can advertise them; it does not mean anonymous public access. The gym_core_ai_mcp_public_ability filter can suppress individual abilities. Capability checks and pending-action controls still apply.

Before connecting an MCP client:

  1. Inventory every advertised ability and suppress everything the client does not need.

  2. Use a dedicated least-privilege service account; never an owner administrator account.

  3. Test read denial, write approval, rejection, duplicate/retry behavior, and audit records on staging.

    Expected: The client reads only approved data, every write is pending before review, rejection leaves the source unchanged, and retries do not duplicate the result.

  4. Set retention and access policy in the external MCP client because it may store prompts and results.

  5. Rotate credentials and revoke the account when the client, vendor, or operator is removed.

    Expected: The removed client can no longer authenticate or discover protected results, while the action/audit evidence required by policy remains available under its separate retention rules.

Need help?

Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.

Contact GymCore