Review AI tools and external abilities.
GymCore AI offers different functions for sales, coaching, members, finance, and administrators. Choosing a persona narrows what is offered, but WordPress still checks the signed-in user’s permission every time.
Owner flow
-
Name the staff job to support and the minimum records it needs.
-
Choose the narrowest persona, then verify the actual WordPress permission on every required function.
-
Separate immediate reads from drafts and proposed writes. Reads can expose data; drafts do not send; writes must become pending before review.
-
Test denial, one harmless read, one rejected proposal, and duplicate/retry handling with a least-privilege staging account.
Expected: Unauthorized functions are denied, the read matches its source and has no commit button, the proposal remains pending until rejected, and retries do not create duplicate source records.
-
Verify any completed action in the GymCore, WooCommerce, or provider source record.
Expected: The source record contains the intended result exactly once. A successful tool return is not confused with provider delivery or settlement.
The technical permission names used below are WordPress capabilities. A persona can hide functions, but the capability on each endpoint remains authoritative.
Audited AI tool count: 55. A registered tool is not permission to use it and is not proof its dependency is configured.
Persona access
| Persona | Default gate | Tool scope |
|---|---|---|
| Sales Agent | gym_process_sale |
Sales, leads, pricing, schedules, CRM prospect work, SMS drafts/history, rosters, image generation. |
| Coaching Agent | gym_view_briefing |
Training, attendance, ranks, Foundations, rosters, promotion recommendations, status-only subscriptions. |
| My Coach | read |
Authenticated member progress, schedule, and subscription status. |
| Finance | gym_view_finance |
Full admin data set and financial writes; no image generation. |
| Admin Agent | manage_options |
Full admin set plus image generation. |
Write approval rule
A tool definition with write=true queues an action for staff approval. Write families include order/lead creation, class-program assignment, SMS, promotions and Foundations updates, announcements/social actions, CRM notes, refunds, and monthly close. Read tools can still expose personal data immediately. Always verify the tool definition in the installed source because inventory risk labels are conservative and do not replace the write flag.
Complete registered tool catalogue
| Stable ID | Tool | Source | Inventory risk |
|---|---|---|---|
| INV-TOOL-0001 | get_pricing |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:342 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0002 | calculate_pricing |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:360 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0003 | lookup_customer |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:382 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0004 | create_kiosk_order |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:400 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0005 | create_lead |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:458 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0006 | get_schedule |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:496 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0007 | get_classes |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:522 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0008 | assign_class_program |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:589 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0009 | get_locations |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:611 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0010 | draft_sms |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:623 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0011 | get_trial_info |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:657 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0012 | get_member_rank |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:673 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0013 | get_rank_history |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:695 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0014 | get_attendance |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:717 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0015 | get_badges |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:751 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0016 | get_streak |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:769 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0017 | recommend_promotion |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:787 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0018 | promote_member |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:809 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0019 | get_briefing |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:843 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0020 | get_foundations_status |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:861 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0021 | record_coach_roll |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:879 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0022 | get_revenue_summary |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:905 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0023 | get_subscriptions |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:948 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0024 | get_subscriptions_summary |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:975 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0025 | get_mrr |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:988 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0026 | get_failed_payments |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1001 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0027 | get_reports |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1023 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0028 | get_today_attendance |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1039 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0029 | get_promotion_eligible |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1061 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0030 | draft_announcement |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1079 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0031 | draft_social_post |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1126 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0032 | generate_image |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1152 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0033 | get_briefing_today |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1197 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0034 | get_announcements |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1219 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0035 | get_sms_templates |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1249 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0036 | enroll_foundations |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1266 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0037 | clear_foundations |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1284 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0038 | get_active_foundations |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1302 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0039 | get_social_pending |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1319 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0040 | approve_social_post |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1332 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0041 | search_crm_contacts |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1354 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0042 | get_crm_contact |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1389 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0043 | get_crm_contact_notes |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1407 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0044 | add_crm_contact_note |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1433 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0045 | get_crm_pipeline |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1455 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0046 | get_member_orders |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1471 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0047 | get_member_billing |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1527 |
medium-high: sensitive access/configuration |
| INV-TOOL-0048 | get_member_subscription_status |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1545 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0049 | get_churn_metrics |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1603 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0050 | issue_refund |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1621 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0051 | get_sms_history |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1651 |
high: mutates data, sends communication, or crosses trust boundary |
| INV-TOOL-0052 | get_class_roster |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1681 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0053 | get_ar_aging |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1703 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0054 | draft_dunning_message |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1715 |
medium: authenticated/operator surface; permission and side effects vary |
| INV-TOOL-0055 | run_monthly_close |
wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1738 |
medium: authenticated/operator surface; permission and side effects vary |
Connect an MCP client
MCP is a protocol an external client can use to discover approved AI functions. When WordPress Abilities API and the MCP adapter are installed, GymCore AI registers tool-backed abilities with MCP-public metadata. This means an authenticated adapter can advertise them; it does not mean anonymous public access. The gym_core_ai_mcp_public_ability filter can suppress individual abilities. Capability checks and pending-action controls still apply.
Before connecting an MCP client:
-
Inventory every advertised ability and suppress everything the client does not need.
-
Use a dedicated least-privilege service account; never an owner administrator account.
-
Test read denial, write approval, rejection, duplicate/retry behavior, and audit records on staging.
Expected: The client reads only approved data, every write is pending before review, rejection leaves the source unchanged, and retries do not duplicate the result.
-
Set retention and access policy in the external MCP client because it may store prompts and results.
-
Rotate credentials and revoke the account when the client, vendor, or operator is removed.
Expected: The removed client can no longer authenticate or discover protected results, while the action/audit evidence required by policy remains available under its separate retention rules.
Related guides
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.