Billing settings reference.
[{"route":"/docs/billing-finance-accounting/","slug":"billing-finance-accounting","title":"Connect QuickBooks Online","summary":"Connect QuickBooks Online.","text":"Connect WooCommerce order and payout data to QuickBooks Online (QBO), then confirm the result in both systems. Access and dependencies Use a Finance Admin, administrator, or other account with the WordPress manage_woocommerce capability. Create or select an Intuit app and have its Client ID, Client Secret, and the redirect URI shown by GymCore ready. Ask the bookkeeper which QBO account IDs should receive income, deposits, clearing amounts, shipping, and failed-retry notes. WooCommerce is the commerce record. QuickBooks is the accounting destination. Exact steps Safe stop: Save the mapping with Save Accounting Settings, but stop before Connect to QuickBooks Online or Queue Re-Sync until the company, date range, and destination accounts have finance approval. Open GymCore Admin \u0026gt; Integrations, then select the QuickBooks tab. Under API Credentials, enter Client ID and Client Secret. Copy the displayed Redirect URI into the Intuit app before connecting. Review Sync Options. New settings default to Sync Payments and Sync Payouts enabled; clear either checkbox if that data must not leave WordPress. Under QBO Account Mapping, enter the approved account IDs. Category → QBO Income Account overrides Default Income Account ID for mapped membership categories. Select Save Accounting Settings. Expected: GymCore displays Accounting settings saved. Saving changes configuration only; it does not start the OAuth connection or queue old orders. Select Connect to QuickBooks Online, sign in at Intuit, choose the correct company, and approve the connection. Expected: GymCore displays QuickBooks Online connected successfully. and shows the QBO Realm ID under Connection Status. To backfill a limited period, enter Date From and Date To under Manual Re-Sync, then select Queue Re-Sync. Expected: GymCore reports how many orders were scheduled. Only completed and processing orders in the range are queued, two seconds apart; an existing QBO record with the same document number is skipped. Verify the final result in both owning systems: review Sync Log for Success, Errors, and Skipped totals, then open one queued WooCommerce order and its matching QBO record. Expected: Customer, total, tax, line items, and destination accounts agree between the WooCommerce source order and the QuickBooks record. Defaults, effects, and reversal Item Current source behavior Sync Payments Enabled by default; sends completed/processing orders as QBO sales receipts. Sync Payouts Enabled by default; sends WooPayments payouts as QBO bank deposits. Account IDs and category map Empty until a finance owner supplies them. Manual re-sync Requires both dates and queues background jobs; it does not run synchronously. Disconnect Disconnect QBO revokes the refresh token when possible and removes stored OAuth tokens and the Realm ID. Saved client credentials and mappings remain. The Client ID and Client Secret are saved in WordPress options. OAuth tokens are encrypted with a key derived from the site’s WordPress authentication salt. Restrict database and backup access accordingly. Disconnecting stops future sync but does not delete entries already created in QuickBooks; a bookkeeper must correct those in QBO. If the connection or sync fails Invalid or expired callback: start Connect to QuickBooks Online again and confirm the redirect URI matches the Intuit app exactly. Token exchange failed: recheck the Client ID and Client Secret; do not send either value in a screenshot or support message. A queued order is skipped: look for the same document number in QBO before retrying. An account receives the wrong entry: stop re-syncing, correct the mapping, and ask the bookkeeper to decide how to reverse the existing QBO entry. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Defaults, effects, and reversal","If the connection or sync fails","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/accounting.md"},{"route":"/docs/billing-finance-failed-renewals/","slug":"billing-finance-failed-renewals","title":"Investigate a failed membership renewal","summary":"Investigate a failed membership renewal.","text":"Find the failed order, identify the system that owns the retry, and avoid creating a second charge. Access and dependencies Use a Finance Admin, administrator, or other account with manage_woocommerce. WooCommerce must be active. A recurring-billing extension and its gateway must also be active if the membership renews automatically. This repository does not contain WooCommerce Subscriptions or another recurring-billing extension, so it cannot verify a Subscriptions menu or retry-button label. Confirm the active extension under Plugins \u0026gt; Installed Plugins and follow its visible workflow. Exact steps Safe stop: Investigate through the WooCommerce order and subscription record, but stop before any visible retry or payment action if the gateway status is unknown. Open GymCore Admin \u0026gt; Finance Copilot and find Failed-payment recovery queue. Record the Order number, Last attempt, and Next attempt. Expected: The queue lists unpaid renewal attempts known to the installed WooCommerce billing stack. An empty queue displays No failed payments waiting on retry. Open the WooCommerce order list. GymCore keeps the wc-orders screen available to approved office and commerce roles; the installed WooCommerce version owns the exact menu presentation. Search for the recorded order number. Confirm the customer, total, gateway, status, and order notes before taking an action. GymCore’s receivables view treats failed, on-hold, and pending orders as unpaid. Under Plugins \u0026gt; Installed Plugins, identify the recurring-billing extension. Open the related subscription from the order only if that extension exposes one. Expected: The owning extension shows the current subscription status, related orders, and any next retry or next payment it has scheduled. If no recurring extension is active, stop; GymCore does not supply a replacement retry action. Resolve the cause in the owning system: the member updates their stored payment method, the gateway owner clears an account problem, or an authorized finance user uses the extension’s visible retry action. Do not create a manual order to imitate a retry. Expected: The gateway records at most one new authorization or charge, and WooCommerce adds a new order note or renewal order rather than overwriting the failed history. Verify the final result first in the gateway dashboard, then in the WooCommerce order and subscription record. Reload GymCore Admin \u0026gt; Finance Copilot last. Expected: The gateway transaction, WooCommerce status, next payment, and GymCore recovery queue agree. A successful order no longer appears as an unpaid receivable. Effects, reversal, and member data Finance Copilot is read-only for retries; it shows order IDs, customer names, amounts, and retry dates. The actual retry belongs to the installed subscription extension and gateway. A successful charge cannot be undone by changing a WooCommerce status; use the gateway-backed refund process. Preserve failed order notes because they are the audit trail, and share only the order ID—not card, email, or phone details—when escalating. If the record does not line up Order is absent from Finance Copilot: search WooCommerce directly and confirm its status is failed, on-hold, or pending. No subscription screen or retry action exists: verify installed extensions; do not invent a retry by changing the order status. Gateway shows a charge but WooCommerce still shows failure: stop further retries and give the gateway transaction ID and WooCommerce order ID to the payment owner. Two charges exist: do not delete either order. Ask finance to reconcile them and refund the duplicate through the gateway. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Effects, reversal, and member data","If the record does not line up","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/failed-renewals.md"},{"route":"/docs/billing-finance-finance-copilot/","slug":"billing-finance-finance-copilot","title":"Review receivables with Finance Copilot","summary":"Review receivables with Finance Copilot.","text":"Use Finance Copilot to review unpaid orders, draft recovery outreach, and run a recorded monthly-close checklist without treating a suggestion as a posted accounting entry. Access and dependencies Use a Finance Admin, administrator, or other account with manage_woocommerce. WooCommerce supplies orders, statuses, totals, and customer billing data. Finance Agent is the intended customer term. The current Finance Copilot source still renders the legacy Ask Pippin label; treat that label as product-source leakage, not as public GymCore AI taxonomy. The control needs the AI plugin’s finance endpoint. The page remains useful for receivables and monthly close when that endpoint is unavailable. Exact steps Safe stop: Review receivables and create an outreach draft, but stop before Run monthly close until the month and underlying WooCommerce records have finance approval. Open GymCore Admin \u0026gt; Finance Copilot. Review Accounts receivable aging. The source groups failed, on-hold, and pending orders into 0–30 days, 31–60 days, 61–90 days, and 90+ days. Open the corresponding WooCommerce order before acting on a row. Compare the customer, amount, issue date, currency, and status with the source order. To prepare a message, select Draft outreach beside the receivable. Expected: GymCore creates a draft with the default gentle tone and queues it as a pending action. It does not send a message or retry a payment. Review Failed-payment recovery queue for the order number and the installed subscription extension’s Last attempt and Next attempt values. Perform any retry only in that extension or gateway. If the Finance Agent question control is available, use the currently rendered Ask Pippin field and select Ask. Treat the older label as a current UI defect and the answer as a lead for investigation, not as a transaction or correction. Expected: The answer appears on the page. If the AI finance endpoint is not wired, the page says it is unavailable and leaves financial records unchanged. To run close, choose Month. The field defaults to the current UTC month. Select Run monthly close only after finance has approved the period. Expected: GymCore reconciles payout data, lists refunded subscriptions, writes a coach-payroll attendance CSV, requests sign-off through an action hook, and caches the result for that YYYY-MM month. A normal re-run returns Already closed for this month — re-running is safe. Verify the final result in the owning systems: open the referenced WooCommerce orders, payout records, and generated payroll CSV, then compare the close summary with the accounting system. Expected: The WooCommerce and accounting totals support the close result, and every exception has an owner. The Finance Copilot result alone is not final accounting approval. Effects, reversal, and sensitive data The aging and recovery panels are read-only. Draft outreach creates a pending communication; remove or reject it in the owning approval queue if it should not be sent. Run monthly close writes a CSV under WordPress uploads, saves a close result in a WordPress option, and can notify an installed approval-queue listener. There is no customer-facing undo control. Limit access to customer names, emails, balances, and payroll attendance, and delete exported files under the gym’s retention policy. If a panel is wrong Receivable is missing: confirm the WooCommerce order status is failed, on-hold, or pending and that its creation date is valid. Draft appears but no one can approve it: verify the installed AI approval-queue plugin; the draft endpoint intentionally never sends. Close uses the wrong month: do not force another run. Preserve the result and ask the finance owner to decide whether the cached close and CSV should be replaced. Accounting total differs: reconcile the source orders, refunds, and payouts; do not edit the displayed summary to force a match. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Effects, reversal, and sensitive data","If a panel is wrong","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/finance-copilot.md"},{"route":"/docs/billing-finance-membership-billing-renewals/","slug":"billing-finance-membership-billing-renewals","title":"Review a member\u0027s recurring billing","summary":"Review a member\u0027s recurring billing.","text":"Confirm the next payment and membership state in the extension that owns recurring billing before changing access in GymCore. Access and dependencies Use an administrator to verify plugins and an account with manage_woocommerce to review commerce records. WooCommerce must be active. Automatic renewals also require a recurring-billing extension and a compatible payment gateway. This repository contains neither WooCommerce nor a recurring-billing extension’s admin UI. It therefore does not prove that WooCommerce \u0026gt; Subscriptions, a Next payment field, or any particular change action exists on the installed site. Exact steps Safe stop: Compare the order, subscription, and gateway records without changing them; stop before any status, date, payment-method, or retry action until its financial effect is approved. Open Plugins \u0026gt; Installed Plugins and identify the active recurring-billing extension and payment gateway. Expected: Both extensions show as active and have an owner who can access their service accounts. If no recurring-billing extension is active, stop; GymCore does not create recurring charges by itself. Open the WooCommerce order list and search for the member’s latest order. GymCore source preserves the wc-orders screen for approved roles, while the installed WooCommerce version controls its visible menu label. Confirm the customer, membership product, total, status, gateway, and order notes. Record the order ID before following any link to the owning recurring-billing extension. In that extension’s record, compare the subscription status, next payment date, payment method, and related orders. Use only labels that are visible on the installed version. Expected: The subscription record and latest WooCommerce order refer to the same customer and product, with no unexplained duplicate renewal. If a date, status, product, or payment method must change, write down the financial effect and ask the recurring-billing owner to approve it. Use the extension’s documented action; GymCore source does not define or validate that action. Expected: The extension creates an audit note or related order and shows the approved new state. A status change must not silently create an extra charge. Verify the final state in the payment gateway and recurring-billing extension first. Then open the member in GymCore and confirm their intended access. Expected: Gateway transactions, the extension’s next payment and status, WooCommerce order history, and GymCore access agree. Effects, reversal, and member data Recurring-billing changes can charge money, stop future renewals, alter proration, or remove access. Their defaults and limits belong to the installed extension, not GymCore. Do not promise a retry schedule or proration rule without reading that configuration. Reverse a charge through the gateway-backed refund flow; reverse a schedule or status change through the same recurring-billing extension. Keep customer email, billing address, payment-token details, and order notes out of screenshots. If the renewal screen is missing No recurring-billing extension appears under Installed Plugins: the site has no source-backed automatic-renewal workflow; ask the site owner how memberships are billed. Order exists but no related subscription exists: confirm whether the product is actually recurring and whether the extension created the order. GymCore access differs from billing: preserve both records and give the member ID, order ID, and extension name to the site administrator. Gateway and WooCommerce disagree: stop changes and have the payment owner reconcile the gateway transaction before another retry. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Effects, reversal, and member data","If the renewal screen is missing","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/membership-billing-renewals.md"},{"route":"/docs/billing-finance-refunds-corrections/","slug":"billing-finance-refunds-corrections","title":"Refund a WooCommerce order safely","summary":"Refund a WooCommerce order safely.","text":"Return money through the gateway that captured it, preserve the order history, and review future billing and member access separately. Access and dependencies Use a Finance Admin, administrator, or other account with manage_woocommerce and authorized access to the payment gateway. Record the approved refund amount and reason before opening the order. The repository does not contain WooCommerce or gateway UI source. It cannot verify a particular Refund dialog, automatic-refund button, settlement time, or fee policy. Confirm those labels and rules in the installed versions. Exact steps Safe stop: Reconcile the WooCommerce order with the gateway transaction first; stop before Refund whenever the amount, currency, customer, provider status, or subscription effect is unclear. Open the WooCommerce order list and search for the approved order ID. GymCore source retains the wc-orders screen for approved roles; the installed WooCommerce version owns its visible menu label. Confirm the customer, captured total, amount already refunded, currency, gateway, order status, and any related recurring-billing record. Open the gateway dashboard in a separate tab and find the matching transaction. Expected: Gateway amount, currency, customer, and transaction reference match the WooCommerce source order. If they do not, stop before refunding. If the installed WooCommerce UI exposes Refund, select it only when the screen clearly identifies whether money will be returned through the gateway. Enter the approved amount and an internal reason; do not mark an order refunded merely to imitate a gateway refund. Expected: WooCommerce adds a refund/order note and the gateway creates one refund for the same amount. A manual record-only correction must not be described as money returned. Review the related recurring-billing record. A refund does not prove that future renewals are cancelled, paused, or rescheduled. Open the member in GymCore and decide separately whether access should change. Use the membership owner’s approved process rather than deleting the member or order. Verify the refund in the gateway first, then reload the WooCommerce order, recurring-billing record, and GymCore member. Expected: The gateway refund status and amount agree with WooCommerce, future billing has the intended state, and GymCore access reflects the approved policy. Effects, reversal, and financial data A submitted gateway refund may be impossible to cancel and may take time to settle. Deleting an order or changing its status does not recall it. If the amount is wrong, preserve both records and ask the gateway owner how to correct it. Share order and transaction IDs when escalating, but remove billing addresses, tokens, and other customer data. If the refund does not appear No refund action is visible: verify the active gateway extension and your role; do not install a replacement or edit the order status as a workaround. WooCommerce shows a refund but the gateway does not: determine whether a record-only refund was used and escalate with both IDs. Gateway shows a refund but WooCommerce does not: do not submit it again. Ask the payment owner to reconcile the original transaction and order notes. Membership renewed again: the refund did not change the recurring schedule; correct that record in its owning extension. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Effects, reversal, and financial data","If the refund does not appear","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/refunds-corrections.md"},{"route":"/docs/billing-finance-woocommerce-payments-setup/","slug":"billing-finance-woocommerce-payments-setup","title":"Connect WooPayments before launch","summary":"Connect WooPayments before launch.","text":"Meet GymCore’s payment-readiness checks, then verify a test transaction in WooPayments and WooCommerce before accepting live membership payments. Access and dependencies Use a WordPress administrator to install or activate plugins. Use an account with manage_woocommerce to connect and review payments. GymCore checks for active WooCommerce, active WooPayments, a connected WooPayments account, and enabled High-Performance Order Storage (HPOS). This repository does not contain the WooPayments extension UI. Its onboarding fields, supported countries, test-mode controls, fees, disputes, and payout settings must be verified on the installed extension. Exact steps Safe stop: Verify plugin readiness and review the WooPayments connection screen, but stop before entering business, identity, or bank details until the account owner and approved test plan are present. Open Plugins \u0026gt; Installed Plugins and confirm WooCommerce and WooPayments are active. Expected: GymCore’s Payment Processing readiness check can report WooCommerce is active. and WooPayments is active. If either plugin is absent, stop and use the site’s approved installation process. Open the WooPayments connection route from the Payment Processing step. Current GymCore source links to WooCommerce Admin’s /payments/connect screen; use the visible WooPayments labels on the installed version. Complete the WooPayments-owned account, business, bank, and identity steps. Do not paste account credentials into GymCore documentation, screenshots, or support messages. Expected: GymCore reports WooPayments is connected. The check calls the installed WooPayments account service; a saved setup-step value alone does not pass it. Enable HPOS through the installed WooCommerce settings if the readiness check says it is disabled. Expected: GymCore reports HPOS custom order tables are enabled. The fallback option value is no, so do not assume HPOS is active without the positive check. If the installed WooPayments version exposes a documented test mode, enable it and place one staff-controlled test order. Use only the test credentials and labels supplied by that extension. Expected: One test transaction appears in WooPayments and one matching order appears in WooCommerce with the expected status and amount. Use the extension’s documented test refund action, then verify the result in the WooPayments transaction and WooCommerce order. Expected: Both owning systems show one matching test refund. GymCore does not provide a separate refund engine. Leave test mode only after the business owner has verified checkout, order status, email, refund, and—when a separate recurring-billing extension is installed—one renewal scenario. Expected: The first live payment is not enabled until the WooPayments dashboard and WooCommerce order records agree with the approved configuration. Effects, reversal, and payment data Connecting WooPayments authorizes a third party to process charges and payouts. HPOS changes where WooCommerce stores orders. Disconnecting or disabling the extension stops future processing but does not erase settled payments, disputes, payout records, or orders. Use the WooPayments account owner for reversals. Never collect raw card numbers in WordPress fields or support diagnostics. If readiness stays incomplete WooPayments active but not connected: reopen the /payments/connect screen and check the account state in WooPayments. HPOS check remains disabled: ask the WooCommerce owner to verify extension compatibility before enabling it; do not change order storage on an untested production site. Test order appears in only one system: stop before live mode and reconcile the WooPayments transaction ID with the WooCommerce order ID. Recurring-payment controls are missing: verify the separate recurring-billing extension; WooPayments alone does not prove that subscriptions are available. Related guides Memberships Billing Renewals Audit Logs","headings":["Access and dependencies","Exact steps","Effects, reversal, and payment data","If readiness stays incomplete","Related guides"],"source_sha256":"","section":"Billing \u0026 Finance","source":"docs/user-guide/billing-finance/woocommerce-payments-setup.md"},{"route":"/docs/classes-attendance-capacity-waitlists/","slug":"classes-attendance-capacity-waitlists","title":"Set class capacity and validate waitlists","summary":"Set class capacity and validate waitlists.","text":"Use the class record to set the maximum enrollment for one recurring class. Gym Core 2.1.0 wires the waitlist setting into member, REST/MCP, storage, and cancellation-triggered paths, but the installed flow still needs verification from placement through roster change and notification. Access and dependencies To edit a class, use an account that can edit that gym_class post. Administrators and other roles with the applicable WordPress post-edit capability normally qualify. To change the site-wide default, use an account with gymcore_manage_settings, or the administrator fallback manage_options, then open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Schedule. Create the location, program, and class before testing capacity. Capacity is personal operational data only when combined with a roster. Limit roster access to staff who need it. Set the site-wide default Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Schedule. In Default class capacity, enter a whole number of at least 1. A new installation defaults to 30; the current settings control does not declare a maximum. Select Save changes. Expected: WordPress reports that the settings were saved. This changes the fallback for classes without their own usable capacity; it does not rewrite every existing class record. Set capacity for one class Open GymCore \u0026gt; Classes, then select the class. In Class Details, enter Capacity. The field minimum is 1, and an empty or zero stored value falls back to 30 in the editor. If public trial booking is in use, set Public Trial Spots from 0 through the class capacity. 0 keeps that class request-only for public trials. Select Update. Expected: The updated class reloads with the saved capacity. The change affects the recurring class definition and can affect future booking availability. Verify the source-wired waitlist end to end The Enable waitlist control under GymCore Admin \u0026gt; GymCore Settings \u0026gt; Schedule defaults to enabled. Current 2.1.0 source uses it to gate member waitlist UI, REST routes and mutations, MCP registration/execution, and cancellation-triggered auto-fill dispatch. Turning it off does not delete existing queue rows. The auto-fill source removes the first eligible active member, fires gym_core_waitlist_auto_enrolled, and attempts notification; source review alone does not prove a roster enrollment or provider delivery. Before relying on waitlisting in production, use a non-production class to verify all of the following in the installed site: Fill the class to its saved capacity. Attempt one additional registration from the same customer-facing path members will use. Confirm where the extra registration is stored and what the member sees. Cancel an enrolled registration. Confirm whether a waiting member is promoted and whether any message is actually delivered. Expected: Record the observed behavior for this installation. Do not call the workflow complete unless the member-visible state, waitlist row, roster/enrollment source, and provider result agree. If any stage is absent, keep that unproven outcome out of staff and member instructions. Reverse or recover Restore the prior Capacity and select Update to reverse a class change. Reducing capacity does not by itself remove or notify people already enrolled; compare the roster with the new limit and resolve over-capacity enrollment deliberately. Restore the prior site-wide default under Schedule if that setting was changed. Verify in the source systems Reopen the class in GymCore \u0026gt; Classes and confirm Capacity and Public Trial Spots in the gym_class record. Then inspect the actual dated occurrence or registration source used by your installed booking flow. A saved settings checkbox is not evidence that waitlist placement, promotion, or messaging ran.","headings":["Access and dependencies","Set the site-wide default","Set capacity for one class","Verify the source-wired waitlist end to end","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Classes \u0026 Attendance","source":"docs/user-guide/classes-attendance/capacity-waitlists.md"},{"route":"/docs/classes-attendance-check-in-kiosk/","slug":"classes-attendance-check-in-kiosk","title":"Check members in without duplicate attendance","summary":"Check members in without duplicate attendance.","text":"Use Quick Check-In on the Attendance screen to create an attendance record for a member and class. The documented control is staff-facing; confirm any separate public kiosk route on the installed site before directing members to it. Access and dependencies The staff account needs gym_check_in_member. Open GymCore Students \u0026gt; Attendance \u0026gt; Today. The member, class, and applicable location must already exist. Attendance reveals when and where a person was present. Keep the screen out of public view and do not leave a staff session unlocked at a front-desk device. Check in a member In Quick Check-In, use Search member… to select the correct person. Match more than a name when duplicates exist. Select the class the person is attending. Select Check In once. Expected: The Today view adds or refreshes the member’s attendance entry. When duplicate prevention is enabled, repeating the same check-in should be rejected rather than create a second record. Open History, find the member and class, and confirm the saved timestamp and location before checking in the next person. Expected: History shows the persisted attendance record. This is the source-system check; a transient success message alone is not sufficient. Know which settings are active Under GymCore Admin \u0026gt; GymCore Settings \u0026gt; Attendance: Prevent duplicate check-ins defaults to enabled and is intended to block repeated attendance for the same member and class occurrence. Check-in methods defaults to qr, search, and manual. Gym Core 2.1.0 uses the list to allow or reject REST check-ins and to show or hide name search in the current kiosk. Selecting a method does not create missing scanner/client hardware or prove that client works. Kiosk auto-logout defaults to 10 minutes and accepts 5 through 60, but current source applies it to the sales kiosk rather than the Attendance screen. Select Save changes after altering an active setting. Expected: WordPress reports that the settings were saved. Re-test the real check-in path and confirm disabled methods are rejected. Source review proves the setting has consumers, not that every installed QR/manual client works end to end. Secure a shared device Use a dedicated least-privilege staff account with gym_check_in_member, lock the operating system between shifts, and prevent browser password exposure. Do not grant manage_options or payment capabilities merely to run attendance. If your site exposes a /check-in/ route, verify authentication, member search visibility, duplicate handling, and session timeout on that exact route before deployment. Reverse or recover Do not click Check In again to fix a wrong member or class. The current History screen is read-only and does not provide a delete or correction action. Follow Record and correct attendance and have an authorized operator correct the stored record. Verify in the source system Finish on GymCore Students \u0026gt; Attendance \u0026gt; History. Confirm one—and only one—record for the member and occurrence, with the intended class, time, and location. If a separate kiosk or QR route was used, verify the same record here rather than relying on the kiosk display.","headings":["Access and dependencies","Check in a member","Know which settings are active","Secure a shared device","Reverse or recover","Verify in the source system"],"source_sha256":"","section":"Classes \u0026 Attendance","source":"docs/user-guide/classes-attendance/check-in-kiosk.md"},{"route":"/docs/classes-attendance-curriculum/","slug":"classes-attendance-curriculum","title":"Assign curriculum to a class","summary":"Assign curriculum to a class.","text":"Add the technique, drill, or focus for a class to its Curriculum of the day field. Current source renders that value verbatim in a coach briefing curriculum card, so enter only content that the intended coaching audience may see. Access and dependencies Open GymCore \u0026gt; Classes with an account that can edit the selected post. Saving checks the WordPress edit_post capability for that class. Create the class first. A program term can help organize the class but is not required by the curriculum field. The current field accepts free text and preserves allowed Markdown or HTML. Do not paste secrets, private member notes, health information, or untrusted markup. Add the class focus Open GymCore \u0026gt; Classes and select the class. Find the Curriculum of the day panel. In What technique / drill / focus is this class teaching?, enter the coaching content. Keep it specific to the class definition you are editing. Select Publish for a new class or Update for an existing class. Expected: The class editor reloads with the curriculum text still present. Saving an empty field deletes the stored curriculum value. Check the coaching output Open the coach briefing surface used by the installed site for a date on which the class occurs. Find the curriculum card for the class and compare its content with the class editor. Expected: When coach briefings are enabled and that class is included, the card displays the saved content verbatim. Briefing availability and delivery are runtime-dependent; a saved class value does not prove a briefing was generated or sent. Reverse or recover Reopen the class, restore the prior text or clear the field, and select Update. Because the value can already have appeared in a generated briefing, removing it from the class does not retract screenshots, exports, or messages that have already left WordPress. Verify in the source systems Use the class editor as the source for the saved _gym_class_curriculum_today value. Use the dated coach briefing as the source for what staff actually received. Confirm both when the wording is consequential to instruction or safety.","headings":["Access and dependencies","Add the class focus","Check the coaching output","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Classes \u0026 Attendance","source":"docs/user-guide/classes-attendance/curriculum.md"},{"route":"/docs/classes-attendance-programs-classes-schedule/","slug":"classes-attendance-programs-classes-schedule","title":"Create a program and schedule classes","summary":"Create a program and schedule classes.","text":"Programs classify classes; class records hold the instructor, location, time, capacity, recurrence, and status used to build the schedule. Create the program first, then verify the resulting occurrences on the calendar. Access and dependencies Managing Programs and the Schedule requires gym_manage_curriculum. The calendar also recognizes manage_woocommerce for edit actions, although its menu is registered against gym_manage_curriculum. Editing a class directly requires the applicable WordPress post-edit capability. Create staff users and location terms before assigning them to a class. Changing a recurring definition can alter future customer-visible scheduling. Record the prior values before rescheduling a live series. Create or confirm a program Open GymCore \u0026gt; Programs. Use Add New Program to enter the program name, slug, parent, and description needed by the WordPress taxonomy screen. Select Add New Program. Expected: The program appears in the Programs table and becomes available to class records. GymCore also synchronizes its canonical program terms during admin requests, so inspect an existing term before creating a near-duplicate. Create the recurring class Open GymCore \u0026gt; Schedule and select Add Class, or open GymCore \u0026gt; Classes \u0026gt; Add New Class. Enter the class title and any public description or featured image. In Class Details, set Day of Week, Start Time, End Time, Capacity (minimum 1, default fallback 30), Public Trial Spots (0 through capacity), Instructor, Recurrence, and Status. Assign the applicable Program and Location taxonomy terms. Select Publish. Expected: WordPress creates a gym_class record. It should appear in GymCore \u0026gt; Classes with its instructor, program, schedule, capacity, recurrence, and status columns. Verify and adjust the calendar Open GymCore \u0026gt; Schedule and select the intended Location. Switch between Week and Month as needed and find the new occurrences. Select an occurrence to inspect or edit it. The calendar exposes Save Changes, Delete, and Edit full details ↗ to authorized users. Expected: The calendar shows the class at the saved location and time. Instructor or location conflicts should be surfaced by the current calendar runtime, but confirm the actual warning before depending on it operationally. Dragging an occurrence asks Move this class? (all future occurrences). Confirming changes the recurring series, not just an isolated date. Use Cancel if that is not the intended scope. Expected: After confirmation, future occurrences move and the class definition reflects the new schedule. Review all affected future dates. Reverse or recover Before editing, note the original day, times, recurrence, instructor, and location. Restore those values through Edit full details ↗ and select Update if a series was moved incorrectly. Deleting a class is more destructive than setting Status to inactive and can break links or history; prefer an inactive status when records must be retained. Verify in the source systems Confirm taxonomy membership in GymCore \u0026gt; Programs, the saved definition in GymCore \u0026gt; Classes, and dated occurrences in GymCore \u0026gt; Schedule. If the site publishes a front-end schedule, check the affected location there too; the admin class record alone does not prove the customer-facing cache or display refreshed.","headings":["Access and dependencies","Create or confirm a program","Create the recurring class","Verify and adjust the calendar","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Classes \u0026 Attendance","source":"docs/user-guide/classes-attendance/programs-classes-schedule.md"},{"route":"/docs/classes-attendance-record-correct-attendance/","slug":"classes-attendance-record-correct-attendance","title":"Record and correct attendance","summary":"Record and correct attendance.","text":"Record attendance from the Today tab, then verify it in History. Current source provides no correction or delete control in the Attendance UI, so a mistaken record requires an authorized data correction rather than another check-in. Access and dependencies Recording attendance requires gym_check_in_member. Open GymCore Students \u0026gt; Attendance. The member and class must already exist. Attendance can affect reports, streaks, badges, promotion eligibility, retention automation, and personal-data exports. Correct the source record rather than compensating in a report. Record attendance Open the Today tab. In Quick Check-In, use Search member… and select the intended member. Select the intended class. Select Check In once. Expected: Today shows the member as checked in. With Prevent duplicate check-ins enabled in Attendance settings—the default—a repeated submission should not create another attendance record. Open History and locate the member and class. Use the available filters to narrow the result. Expected: History shows the persisted attendance entry with its saved class, timestamp, and location. Correct a mistaken record There is no edit, delete, undo, or commit button on the current History tab. Do not create another check-in to offset an error. Record the member, class, occurrence date, displayed timestamp, location, and why the entry is wrong. Include a record identifier if the authorized data tool exposes one. Send the correction through your approved administrator or support path. The operator must be authorized to change the GymCore attendance data store and should preserve an audit note outside any member-visible field. Ask the operator to update or remove only the erroneous source record, then re-run any downstream process that your organization knows depends on attendance. Expected: After the authorized correction, History reflects the intended attendance state. If the UI still shows the old value, stop and have the operator verify the stored record and any cache before making another change. The exact database or support procedure depends on the installed environment and is intentionally not prescribed here. No installed customer-safe correction tool was found in the current Attendance UI. Privacy and recovery Share the minimum data needed to identify the record; do not post attendance details in a public channel. Before a direct data correction, the authorized operator should capture the original row or use the site’s approved backup/audit mechanism. Reversal means restoring that specific prior record—not restoring an entire site over unrelated newer activity. Verify in the source systems Finish on GymCore Students \u0026gt; Attendance \u0026gt; History and confirm the correct member, class, time, and location. Then check any consequential downstream source—such as the member’s promotion eligibility or attendance report—rather than assuming it recalculated. History is read-only, so there is no final Save button on this page.","headings":["Access and dependencies","Record attendance","Correct a mistaken record","Privacy and recovery","Verify in the source systems"],"source_sha256":"","section":"Classes \u0026 Attendance","source":"docs/user-guide/classes-attendance/record-correct-attendance.md"},{"route":"/docs/communication-retention-announcements/","slug":"communication-retention-announcements","title":"Publish an announcement to coach briefings","summary":"Publish an announcement to coach briefings.","text":"Create a dated announcement for the coach briefing audience. Current source includes announcements in coach briefings; it does not establish a general member-portal, email, or SMS announcement broadcast. Access and dependencies Open GymCore \u0026gt; Communications \u0026gt; Announcements with edit_posts. Viewing the optional Coach Briefings tab requires gym_view_briefing. Create any target location or program before selecting it. Announcements can be reproduced in briefings. Do not include member health, payment, disciplinary, credential, or other private information. Create the announcement Open GymCore \u0026gt; Communications \u0026gt; Announcements. Select Add announcement. If you are on the Communications summary, Manage announcements opens the same records. Enter the WordPress title and body. Set the visible target controls, including target type and, when applicable, Target Location or Target Program. Set Start Date and End Date for the intended briefing window, and choose the pinned option only when the item should receive that emphasis. Select Publish. Expected: WordPress creates the announcement and its editor reloads in published state. The target and date fields remain saved. Verify the audience output Open GymCore \u0026gt; Communications \u0026gt; Coach Briefings with an account that has gym_view_briefing. Select a relevant date, location, or program supported by the installed briefing view. Find the announcement and compare the title, body, target, and active dates. Expected: The announcement appears only in an applicable coach briefing while active. Briefing generation is runtime-dependent; publication alone does not prove an email, SMS, member notice, or external delivery occurred. Reverse or recover Use Update to correct the title, body, targeting, or dates. Change the WordPress status to draft or trash the announcement to stop future inclusion. That does not retract briefings, screenshots, exports, or messages already produced. Verify in the source systems Confirm the published post and targeting in Communications \u0026gt; Announcements, then confirm the rendered item in the applicable Coach Briefings view. If an external process distributes briefings, verify that separate provider or delivery record too.","headings":["Access and dependencies","Create the announcement","Verify the audience output","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Communication \u0026 Retention","source":"docs/user-guide/communication-retention/announcements.md"},{"route":"/docs/communication-retention-automated-retention/","slug":"communication-retention-automated-retention","title":"Enable retention automation one trigger at a time","summary":"Enable retention automation one trigger at a time.","text":"Review inactivity, streak, missed-class, and win-back runtime state without assuming the retired Retention form is editable. Some legacy option IDs remain as runtime or migration inputs, but Communications owns current workflow intent and status. Access and dependencies The legacy Retention Settings alias routes to the Communications member-outreach destination, which requires gymcore_manage_communications or the administrator fallback manage_options. SMS actions require global SMS enablement, provider credentials, registered sending infrastructure, and valid recipient consent. Coach-queue and win-back output depend on their own runtime consumers. The former 30-day MailPoet retention path is retired. Attendance, streak, membership, consent, and communication data feed these decisions. Restrict access and avoid placing sensitive explanations in templates. Review the legacy definitions The source field definitions default these proposed controls to enabled: 7-day inactive SMS streak-break SMS coach queue after 3 missed classes 90-day win-back action The churn-risk definition defaults to 70 and accepts 1 through 100. Templates can be blank. These are source defaults, not proof of stored, reachable, enabled, or tested configuration. Stage one automation Open Communications \u0026amp; Automations \u0026gt; Member Outreach and identify the workflow owner and reported readiness. Have an administrator or developer inspect any stored legacy options and runtime consumers read-only. Do not treat source defaults as current values. Choose one trigger and confirm its intended threshold, copy, recipient population, consent, and provider/queue owner. Stop unless the installed build supplies a supported, approval-gated control for disabling every untested path. Do not write the options directly. Expected: the current state and any missing owner control are recorded. No save, enablement, or safe disable is claimed from the unreachable legacy form. Use an approved non-production member whose data meets the chosen trigger, then run or wait for the actual scheduled process used by the installed site. Expected: Exactly one intended action is created for that trigger. Confirm whether it is a provider message, coach-queue item, or win-back record. Verify the event in its destination source and check the member’s communication history where applicable. Expected: Trigger data, consent, generated content, and provider or queue result agree. Only then enable the next automation. Reverse or recover Use the installed workflow owner’s supported emergency-disable path. If none exists, stop scheduling/dispatch through the authorized operational owner and record the product blocker; do not write legacy options directly. This does not recall queued or delivered messages. Verify in the source systems Confirm the inspected legacy option state, qualifying attendance/membership data, scheduled-job result, and final Twilio, coach-queue, or win-back record. A source default or stored option by itself is not evidence that retention automation works.","headings":["Access and dependencies","Review the legacy definitions","Stage one automation","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Communication \u0026 Retention","source":"docs/user-guide/communication-retention/automated-retention.md"},{"route":"/docs/communication-retention-configure-sms/","slug":"communication-retention-configure-sms","title":"Connect Twilio and test SMS delivery","summary":"Connect Twilio and test SMS delivery.","text":"Channels \u0026amp; providers contains the administrator-only Twilio credential form and an explicit Send test SMS action. Saving provider settings does not turn on SMS, enable an automation, or send a message. Do not write the underlying options directly. Access and dependencies Open GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers with gymcore_manage_communications or the administrator fallback manage_options. Name the Twilio account owner, approved credential workflow, sending number or Messaging Service, consented test destination, maintenance window, and rollback owner. Treat the Auth Token as a secret. Do not paste it into tickets, screenshots, lead notes, documentation, or test-message content. Current product boundary The old sms Settings alias redirects to Channels \u0026amp; providers. Only a site administrator with manage_options can view or change Twilio credentials. Other communications managers can see provider status but not credential values or the test control. The test action sends one real SMS to the billing phone on the current administrator profile after an explicit confirmation. It does not activate the SMS channel or any automation. A saved configuration or accepted test request is not proof of carrier delivery. Safe procedure Open Channels \u0026amp; providers as a site administrator and record the current provider status without exposing credentials. Enter the Twilio account SID, Auth Token, and either a Messaging Service SID or a From number, then select Save Twilio settings. Expected: The page confirms that settings were saved. This does not enable SMS or an automation. Rotate an exposed token at Twilio first. Keep the old/rollback path only as allowed by the provider owner and maintenance plan. Confirm the current administrator profile has a staff-owned billing phone, then select Send test SMS once and accept the explicit confirmation. Expected: GymCore reports the test request result. The action sends one real SMS only to that billing phone. Compare the GymCore result with Twilio’s message SID, destination, sender/service, timestamp, and final status. Expected: Channels \u0026amp; providers reports readiness and Twilio reports the final message status. A local accepted response is not carrier delivery. Recover Disable the approved sending workflow before investigating unexpected sends. Revoke an exposed token at Twilio. Do not repeatedly retry an ambiguous message, and do not claim rollback until both GymCore and Twilio show the intended state. Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. No installed provider delivery is claimed.","headings":["Access and dependencies","Current product boundary","Safe procedure","Recover"],"source_sha256":"","section":"Communication \u0026 Retention","source":"docs/user-guide/communication-retention/configure-sms.md"},{"route":"/docs/communication-retention-consent-templates-deliverability/","slug":"communication-retention-consent-templates-deliverability","title":"Verify consent, templates, and delivery","summary":"Verify consent, templates, and delivery.","text":"Audit a communication workflow before enabling it. GymCore stores consent and templates, while Twilio, MailPoet, WordPress mail, or another installed provider determines whether a message is accepted and delivered. Access and dependencies Lead consent and history are in GymCore Leads \u0026gt; Lead Pipeline and require the applicable lead access. The legacy SMS and Retention aliases route to Communications destinations guarded by gymcore_manage_communications, with manage_options as the administrator fallback. Confirm the organization’s lawful basis, opt-out handling, quiet hours, sender identity, and retention rules outside the plugin before enabling marketing or automation. Never copy provider credentials or large exports of contact data into templates or troubleshooting notes. Verify consent provenance Open the lead and inspect the separate SMS and email consent states, their source, and any withdrawal history. Compare the source with the action the person actually took. Current source recognizes provenance such as lead-board checkbox, sales kiosk, waiver, and import; imported or staff-entered consent still requires a defensible source. Expected: The intended channel has affirmative, current consent with a credible source. If the record is ambiguous, do not send while investigating. Review a retention template Open GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Member Outreach. Review the intended automation and owner. The current registry does not render the legacy retention template fields. If the installed workflow depends on a legacy template option, have an administrator or developer inspect it read-only and identify a supported owner control before proposing a change. Stop if no supported template editor exists; do not edit the option directly. Expected: the outreach destination reports current state without claiming that a template was saved. A blank or legacy value is not a verified message, and AI-composed output can vary by runtime. Test deliverability end to end Use a consented non-production recipient who can check inbox, spam, and phone delivery. Trigger the exact lead, trial, or retention workflow once. Expected: GymCore records the requested workflow result without duplicate sends. Check the provider event, then confirm what arrived and how links, sender identity, and opt-out text render. Expected: The provider and recipient observation agree on delivery. Fix bounces, suppression, registration, or authentication in the provider; editing a GymCore note does not repair delivery. Reverse or recover Disable the affected automation or global SMS before changing consent rules, provider credentials, or templates. Restore the prior approved template if needed. Messages already accepted by a provider generally cannot be recalled, and clearing a lead field does not remove provider logs. Verify in the source systems Confirm authorization in the lead’s consent history, the exact copy/configuration in its supported owner system, and final status in Twilio or the email provider. Keep these three checks distinct when investigating a complaint.","headings":["Access and dependencies","Verify consent provenance","Review a retention template","Test deliverability end to end","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Communication \u0026 Retention","source":"docs/user-guide/communication-retention/consent-templates-deliverability.md"},{"route":"/docs/communication-retention-send-email-sms/","slug":"communication-retention-send-email-sms","title":"Send a message from a supported workflow","summary":"Send a message from a supported workflow.","text":"Current GymCore source has no general-purpose Compose email or Compose SMS page. Send only from a visible lead, trial, retention, or provider-specific control that is implemented on the installed site; do not follow stale instructions to a nonexistent Communications composer. Access and dependencies Viewing GymCore \u0026gt; Communications requires read, but that page does not grant send authority. Lead SMS actions require the lead-management access used by the board and gym_send_sms where the action checks it. SMS requires enabled provider settings and affirmative SMS consent. Email requires the installed email provider or WordPress mail path and affirmative consent where required. A stored contact address does not authorize marketing. Check channel, consent status, source, scope, and withdrawal before sending. Send from a lead or trial control Open GymCore Leads \u0026gt; Lead Pipeline and select the intended person. Review the phone/email, channel consent state, consent source, and communication history. Stop if consent is absent, withdrawn, ambiguous, or for a different purpose. Use only the SMS or email action visible in that lead or trial detail. If no action appears, the account or installed runtime does not provide a supported send from that screen. Review the exact recipient and generated message. Remove unnecessary personal information, and do not include credentials, payment-card data, or sensitive health details. Select the displayed send action once. Expected: The workflow reports an accepted or failed request and adds the appropriate communication history when implemented. A saved note is not a sent message. Verify delivery Find the message in Twilio, the email provider, or the WordPress mail log used by the installed site. Match recipient, content or template, timestamp, and provider identifier. Expected: The provider shows its actual status. Queued, accepted, delivered, bounced, and failed are different outcomes; report the one the source shows. When there is no send control There is no commit button on GymCore \u0026gt; Communications for an arbitrary message. Use the organization’s approved external provider only if that process is authorized, then record a minimal factual note on the lead without copying secret links or full message content. Do not invent a GymCore delivery record. Reverse or recover Most email and SMS cannot be recalled after provider acceptance. Stop scheduled automation, correct consent, and send a correction only when policy and customer impact justify another message. Rotate any credential or secret link disclosed in message content. Verify in the source systems Use the lead’s consent and communication history to establish why and how the send was requested. Use Twilio or the email provider to establish delivery. Neither source alone proves both authorization and delivery.","headings":["Access and dependencies","Send from a lead or trial control","Verify delivery","When there is no send control","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Communication \u0026 Retention","source":"docs/user-guide/communication-retention/send-email-sms.md"},{"route":"/docs/gymcore-ai-action-approvals/","slug":"gymcore-ai-action-approvals","title":"Review and decide an AI-proposed action","summary":"Review and decide an AI-proposed action.","text":"Purpose Confirm exactly what GymCore AI proposes, then approve, revise, or reject it without confusing approval with completion. A proposal does not change a source record while its status is Pending. Audience and access For: Gym owners and administrators authorized to make the proposed change\u0026lt;br\u0026gt; Access needed: WordPress manage_options\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; Staff Dashboard \u0026gt; Pending Actions when the chat panel is available; use GymCore Admin \u0026gt; AI \u0026gt; Audit Log to review status history The Audit Log is read-only. It has a Filter button, but no approval or commit button. Approval controls are registered in the chat panel. Before you start Open the target member, order, class, message, or other source record in GymCore, WooCommerce, or the owning provider. Confirm that the action is still needed and that you are authorized to make it. For a payment, outbound message, promotion, order, or other high-impact action, record the approved amount, currency, recipient, content, target ID, and effective date. Do not proceed if the Pending Actions panel is absent. Confirm GymCore and Gym Core AI are active and validate the installed dashboard before approving any action. Exact visible steps Open GymCore Admin \u0026gt; Staff Dashboard and find Pending Actions. Expected: Each proposal shows an action ID, agent, action type, summary or content preview, and Approve, Approve with Changes, and Reject controls. If the panel is missing, stop and use the recovery guidance below. Match the action ID and target identifiers to the source record. Check amount, currency, product, rank, recipient, message body, consent, and requested date when they apply. Expected: Every value needed to execute the action is present and matches the approved source. If a value is missing or ambiguous, do not approve. Open GymCore Admin \u0026gt; AI \u0026gt; Audit Log, choose Pending under All Statuses, choose the relevant agent under All Agents, and select Filter. Expected: The same action ID appears as Pending. Filtering does not change the action. Return to Pending Actions and choose one decision: Select Approve only when the proposal is exact. Select Approve with Changes, enter clear instructions, then select Submit Changes when the target identity is correct but the proposed content or values need revision. Select Reject, optionally enter a reason, then select Confirm Rejection when evidence or authority is missing. Expected: Approve attempts the write immediately. A successful tool return becomes Completed; a failed execution remains Approved with an execution_error. Approve with Changes stores the instructions and becomes Approved with Changes; the approval request itself does not execute the revised action. Reject becomes Rejected and does not execute the proposal. Reopen GymCore Admin \u0026gt; AI \u0026gt; Audit Log, filter by the resulting status, and confirm the action ID, reviewer, and reviewed time. Expected: The audit row reflects the decision. Approved is not completion, and Approved with Changes still requires a separate revision-and-completion path. Open the owning source record and, when applicable, the payment, messaging, publishing, or CRM provider. Expected: The intended source value and downstream result are present exactly once. A Completed audit status means the tool returned successfully; it does not prove a gateway settled, a carrier delivered, or a third party published the result. Expected result The action has one recorded decision, the audit status matches that decision, and the final state has been verified in the system that owns the record. Do not repeat an approval because a notice disappears slowly. Defaults and limits Behavior Current source behavior New write proposal Stored as Pending; no source change yet Approve Changes status to Approved, then attempts immediate execution Successful approved execution Changes status to Completed and stores the execution result Failed approved execution Remains Approved and stores execution_error and failure time Approve with Changes Stores staff instructions as Approved with Changes; completion depends on a separate agent/worker path Reject Changes status to Rejected and stores an optional reason Action and audit retention No configurable automatic purge is registered Side effects and privacy Pending-action rows contain the persona, action type, action data, optional external run ID, status, reviewer, and timestamps. The action data may include names, phone numbers, message bodies, refund reasons, or financial details. The 1–365 day conversation-retention setting does not purge pending actions, completed actions, rejected actions, or the Audit Log view over those rows. Recover by symptom The Pending Actions panel is missing Open Plugins \u0026gt; Installed Plugins and confirm GymCore and Gym Core AI are active, then check GymCore Admin \u0026gt; AI \u0026gt; Settings for System Status. If Staff Dashboard says AI Chat is unavailable, do not use a direct REST request as a workaround. Record the installed versions and the missing legacy chat-availability constant for product support. Approval reports an error or the row remains Approved Do not approve again. Open Audit Log, capture the action ID and detail, then check the target source record and provider for an existing result. An Approved row with execution_error did not complete successfully. Approved with Changes never completes The visible approval stores instructions but does not dispatch the revised action in that request. Confirm that the site has a registered handler for the approved-with-changes event. If not, reject and recreate a correct proposal after the product path is fixed; do not edit action JSON in the database. The source record does not match Completed Capture the action ID, tool name, completion time, stored result, source record ID, and provider request ID. Do not repeat the action until the owning system proves no duplicate or delayed result exists. Related guides Chat safely with GymCore AI Configure approval notifications Protect AI data and connections Troubleshoot GymCore AI Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. The visible approval flow still requires installed-version validation after the Staff Dashboard chat integration is corrected.","headings":["Purpose","Audience and access","Before you start","Exact visible steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","The Pending Actions panel is missing","Approval reports an error or the row remains Approved","Approved with Changes never completes","The source record does not match Completed","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/action-approvals.md"},{"route":"/docs/gymcore-ai-agents/","slug":"gymcore-ai-agents","title":"Choose AI personas and access","summary":"Choose AI personas and access.","text":"A persona changes what the assistant is told to do and which functions it may offer. It never gives a staff member permission they do not already have. Owner flow Start with the staff job: sales, coaching, member self-service, finance, or site administration. Choose the narrowest matching persona and enable it only for the people who need that work. With a non-administrator staging account, request one harmless read and compare the answer with its source record. Request one harmless proposed change and confirm it remains pending until an administrator decides it. Expected: The proposal appears as Pending, and the owning source record is unchanged. If it writes immediately or does not appear for review, stop the test and remove access until the path is corrected. After an approved test reports completion, reopen the owning GymCore, WooCommerce, or provider record. Expected: The account sees only the intended persona and data, a read has no commit button, a draft remains unsent, and the final source record proves whether the approved action finished exactly once. The technical access checks below are WordPress capabilities. A persona narrows the catalogue, but it does not bypass the capability on a tool endpoint. Persona Default display name Persona gate Scope sales Sales Agent gym_process_sale Pricing, leads, kiosk orders, schedules, CRM prospect work, SMS drafts, rosters, image generation. It must not be used as a source for member training or finance data. coaching Coaching Agent gym_view_briefing Ranks, attendance, badges, streaks, Foundations, rosters, promotion recommendations, and subscription status without amounts. member-coaching My Coach read The authenticated member’s rank, rank history, attendance, badges, streak, schedule, and subscription status. finance Finance Agent gym_view_finance Full admin data-tool set for operations, training, sales, CRM, billing, receivables, refunds, and monthly close; no image generation. Set this customer-facing display name before launch because older source defaults may contain a legacy character name. admin Admin Agent manage_options Full admin tool set plus image generation. Agent overrides Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; Agents. Each registered agent has: Display Name: cosmetic label. Description: staff-facing summary. Capability: read, gym_view_briefing, gym_process_sale, gym_view_finance, gym_use_gandalf, edit_posts, or manage_options. System Prompt Override: replaces the built-in prompt completely when nonblank. {{gym_name}} inserts the AI Gym Name. Enabled: removes the persona from normal availability when off. Changing a persona gate can expose sensitive tools to more people. Use the strongest capability that still supports the role, then test with a real non-admin test account. A prompt override can remove built-in restrictions, grounding rules, and role boundaries; keep it blank unless the replacement has been security-reviewed in full. Capability layers Staff Access edits only four newer gymcore_* capabilities. AI personas and tools also use legacy gym_*, manage_options, manage_woocommerce, edit_posts, and read. Always verify the effective role with the complete permissions reference; do not assume the Staff Access checkbox table controls every AI path. Related guides GymCore AI overview GymCore AI settings reference AI troubleshooting Roles and capabilities Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. No installed persona or permission test is asserted.","headings":["Owner flow","Agent overrides","Capability layers","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/agents.md"},{"route":"/docs/gymcore-ai-chat/","slug":"gymcore-ai-chat","title":"Chat safely with GymCore AI","summary":"Chat safely with GymCore AI.","text":"Purpose Ask for a narrow answer or draft, verify it against the source record, and recognize when a request has become a proposed write. Reading, drafting, approving, completing, and verifying are separate states. Audience and access For: Signed-in staff using an approved AI persona\u0026lt;br\u0026gt; Access needed: Permission to open Staff Dashboard, the selected persona, and the requested data; only administrators with manage_options can approve actions\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; Staff Dashboard The canonical GymCore Admin \u0026gt; AI hub does not register a Chat tab in the checked-out source. Do not direct staff to AI \u0026gt; Chat. Before you start Confirm GymCore and Gym Core AI are active and GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General shows the required runtime dependencies. Use your own staff account and a persona appropriate for the task. Prepare a narrow date range or source record ID and begin with fictional, non-sensitive data. Do not paste payment-card data, credentials, API keys, webhook secrets, medical details, legal documents, or bulk member exports. Stop if Staff Dashboard shows “AI Chat is not available.” Confirm GymCore and Gym Core AI are active before troubleshooting providers or credentials. Exact visible steps Open GymCore Admin \u0026gt; Staff Dashboard. Expected: A chat panel contains Select an agent, a Type your message… field, and Send. If only an unavailable notice appears, stop and follow the recovery guidance. Choose the authorized persona from Select an agent. Expected: The message field and Send become available. Changing the persona clears the visible message panel and starts without a selected conversation ID. Enter one task with the record ID or narrow date range, the requested result, and the format you need. Select Send. Expected: The panel shows the staff message and an assistant response. Tool details label a successful read as ok, a proposed write as queued for approval, and a failed call as error. If the response is a read, open the owning GymCore, WooCommerce, CRM, or provider record and compare the identifiers, dates, totals, and status. Expected: The source record supports the answer. A read-only result has no commit button; nothing needs to be saved or approved. If the response is a draft, check names, dates, prices, claims, consent, and tone. Keep it in draft form unless an authorized write is separately proposed and reviewed. Expected: Draft text is visible, but it has not been sent, published, or written to a source record. If the response proposes a write, open Pending Actions and confirm the proposal is Pending before reviewing it. Expected: The source record is unchanged. The proposal waits for an administrator to choose Approve, Approve with Changes, or Reject. After any approved action reports completion, reopen the source record and any downstream provider. Expected: The intended result exists exactly once in the system that owns it. Chat text and a Completed action row are evidence of processing, not substitutes for source-record verification. Expected result You have a source-verified answer or an explicitly uncommitted draft. Any proposed change remains pending until an administrator reviews it, and any completed change is verified in its owning system. Defaults and limits Behavior Current source behavior Message field Disabled until a persona is selected Conversation ownership Stored with the WordPress user ID; ordinary access checks ownership Conversation retention Default 30 days; configurable from 1–365 days Read result Returns immediately when capabilities allow; no commit button exists Draft result Text only until a write path is proposed, approved, and executed Write result Queued as Pending for administrator review Approve with Changes Stores revision instructions; the approval request does not execute the revision, so a separate handler must complete it Action/audit retention Not purged by conversation retention Side effects and privacy Conversations and messages store user ID, persona, timestamps, message content, token counts, and tool-call details. Read tools can expose personal or financial data immediately. Model/provider systems may keep their own copies under separate contracts and settings. Administrators and database operators can have broader access than the conversation owner. Recover by symptom Staff Dashboard says AI Chat is not available Confirm both plugins are active and capture their versions. The dashboard checks GYM_CORE_AI_VERSION; if the notice remains, inspect the plugin requirement notice and server logs rather than adding an undocumented constant. Send stays disabled Select a persona. If no personas appear, ask an administrator to check GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; Agents, the persona’s Enabled value, and your effective capability. The answer has no source support Do not refine the prompt to force agreement. Narrow the record/date range, inspect tool details for error, and use the owning system as the source of truth. A write is missing from Pending Actions Treat the write as not approved and do not assume it ran. Capture the conversation time, persona, tool name, and tool details, then check GymCore Admin \u0026gt; AI \u0026gt; Audit Log for the action ID before retrying. The interface looks slow after approval Do not click twice. Check the action status, source record, order notes, and provider logs first to prevent duplicate sends, orders, refunds, or promotions. Related guides Review and decide an AI-proposed action Configure GymCore AI Choose AI personas and access Troubleshoot GymCore AI Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. A successful installed chat session has not been claimed; the current Staff Dashboard gate requires product correction and staging validation.","headings":["Purpose","Audience and access","Before you start","Exact visible steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","Staff Dashboard says AI Chat is not available","Send stays disabled","The answer has no source support","A write is missing from Pending Actions","The interface looks slow after approval","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/chat.md"},{"route":"/docs/gymcore-ai-install-configure/","slug":"gymcore-ai-install-configure","title":"Install and configure GymCore AI","summary":"Install and configure GymCore AI.","text":"Purpose Install the staff-facing AI companion, configure an approved provider through WordPress AI Client, and verify the configuration screens without claiming that write execution has passed an installed-version test. Audience and access For: Site owners and WordPress administrators\u0026lt;br\u0026gt; Access needed: activate_plugins to install or activate; manage_woocommerce to open the AI hub; manage_options to configure GymCore AI\u0026lt;br\u0026gt; Open after activation: GymCore Admin \u0026gt; AI \u0026gt; Settings Before you start Confirm the site runs WordPress 7.0 or later and PHP 8.0 or later. Install and activate GymCore first. GymCore AI stops initialization when GymCore is unavailable. Install the approved WordPress AI provider plugin and configure it under Settings \u0026gt; Connectors. GymCore AI never reads or stores its credential. Take a current database backup because activation creates or updates GymCore AI tables, options, and agent accounts. Use staging for the first activation and prepare individual least-privilege test accounts. Exact visible steps Migrate sites from the retired HMA AI Chat plugin Back up the database and plugin files. Stage the reviewed Gym Core AI source at wp-content/plugins/gym-core-ai while leaving hma-ai-chat active and installed; on Pressable, deploy with Delete extra files: OFF. Verify the staged plugin reports version 0.5.6, then run wp –skip-plugins=hma-ai-chat eval-file wp-content/plugins/gym-core-ai/migrate-from-hma-ai-chat.php from the WordPress root. Do not activate Gym Core AI manually before the command. Continue only after Migration complete. No errors. and verification that migrated data, activation scopes, schedules, legacy-owned state, accounts, and the hma-ai-chat directory were retired. Restore the backup on any failure. New installs In WordPress, open Plugins \u0026gt; Add Plugin \u0026gt; Upload Plugin, select the approved Gym Core AI ZIP, and choose Install Now. Expected: WordPress reports that the plugin installed. Do not activate an unreviewed ZIP or overwrite a different plugin folder to resolve a name mismatch. Choose Activate Plugin. Expected: Gym Core AI appears as active under Plugins \u0026gt; Installed Plugins. A requirement notice must not report an unsupported WordPress version or an inactive Gym Core plugin. Open Settings \u0026gt; Connectors, configure the approved provider plugin, and confirm that provider reports connected. Expected: The secret is owned by WordPress and the provider plugin. It is never pasted into GymCore AI settings or stored in a support ticket. Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General and read System Status. Expected: GymCore and WordPress AI Client are active. Provider configuration remains under Settings \u0026gt; Connectors. On an upgraded site, confirm the provider is connected under Settings \u0026gt; Connectors, then use Clear stale key from database to delete the retired GymCore AI option without inspecting it. Expected: WordPress reports Deprecated API key cleared from the database. The current resolver does not use the old database option. Set Gym Name and Conversation retention (days), then select Save Changes. Use Connections \u0026amp; Security to discover, test, and activate an exact provider/model pair. Expected: The settings page reloads with the saved values. A blank Gym Name falls back to the WordPress site title; retention accepts 1–365 days and defaults to 30. Open Settings \u0026gt; Agents, review each persona’s Enabled, Display Name, and Capability, then select Save Changes. Expected: The saved agent values reload. These persona gates do not replace the capability checks on individual tools. Open GymCore Admin \u0026gt; Staff Dashboard. Expected: A working installation shows the AI chat panel when GYM_CORE_AI_VERSION is available. If the unavailable notice appears, confirm both plugins are active and stop; configuration status alone is not proof that chat is usable. On staging, use a fictional read request, then compare the result with its GymCore or WooCommerce source record. Expected: The answer matches the source record. A read-only request has no commit button. Do not run a production write as the installation test. Expected result Gym Core AI is active, its status screen detects GymCore and WordPress AI Client, and its saved General and Agents settings reload correctly. Provider/model discovery, readiness, activation, and rollback remain bound to the official WordPress AI Client registry. Defaults and limits Setting or dependency Current source behavior WordPress 7.0 or later required PHP 8.0 or later required GymCore Required and active AI runtime WordPress AI Client only Provider credentials and transport Owned by WordPress and the registered provider plugin Deprecated database API-key option Cleanup only; never read for runtime execution Effective model Exact activated provider/model from the official registry Conversation retention 30 days by default; 1–365 days WooCommerce and service extensions Needed only by tools that consume their data or services Side effects and privacy Activation creates local AI data stores and provisions agent users. Prompts, tool inputs, and provider responses can contain personal or financial data, so configure provider retention and access before production use. Conversation cleanup applies only to conversations and messages; it does not purge pending actions, completed actions, rejected actions, or audit history. Recover by symptom Activation shows a WordPress or GymCore requirement notice Do not suppress the notice. Confirm WordPress 7.0+, PHP 8.0+, and that Gym Core is active. Correct the dependency on staging, then activate once. System Status cannot find an AI provider Verify that WordPress AI Client and the approved provider plugin are active, then check the provider under Settings \u0026gt; Connectors. Do not add a GymCore AI API-key option, constant, or environment fallback. Settings is missing The AI overview uses gym_view_ai_hub; legacy manage_woocommerce remains a compatibility source. Administrative AI destinations use their own policies with the administrator fallback. Test with the intended role, then correct that role rather than sharing the administrator account. Staff Dashboard says AI Chat is not available Confirm both GymCore and Gym Core AI are active, record their versions, and inspect the requirement notice. Do not define an undocumented compatibility constant on production to bypass the check. Migrate from the retired AI Chat plugin Follow Migrate sites from the retired HMA AI Chat plugin above. The reviewed 0.5.6 migration script copies only allowlisted non-secret settings and verified table rows, activates Gym Core AI in corresponding site/network scopes, removes the complete legacy-owned state inventory, and deletes retired executable files without executing legacy plugin code. Any error blocks the cutover; do not delete hma-ai-chat manually or copy credential values into GymCore AI. A green status row is mistaken for a full test System Status checks dependency presence only. It does not prove Twilio, Slack, WooCommerce Subscriptions, CRM, notifications, external automation, approval execution, or source-record updates work. Related guides Chat safely with GymCore AI Review and decide an AI-proposed action Configure approval notifications Troubleshoot GymCore AI Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-08-06. Exact-commit PHPUnit, multisite, and browser evidence is produced only after the reviewed source is committed.","headings":["Purpose","Audience and access","Before you start","Exact visible steps","Migrate sites from the retired HMA AI Chat plugin","New installs","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","Activation shows a WordPress or GymCore requirement notice","System Status cannot find an AI provider","Settings is missing","Staff Dashboard says AI Chat is not available","Migrate from the retired AI Chat plugin","A green status row is mistaken for a full test","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/install-configure.md"},{"route":"/docs/gymcore-ai-knowledge/","slug":"gymcore-ai-knowledge","title":"Manage AI knowledge and runtime context","summary":"Manage AI knowledge and runtime context.","text":"GymCore’s canonical knowledge manager is GymCore Admin \u0026gt; AI \u0026gt; AI Knowledge. It requires manage_woocommerce. It is provided by the core GymCore plugin and is distinct from conversation history and the AI plugin’s persona prompts. The current rollout uses reviewed knowledge only for the staff Coaching assistant. It does not publish authored knowledge to member-facing chat. Choose a Program before asking a discipline-specific question; General / all programs uses only genuinely cross-program entries. Knowledge entry fields Field Type Default/limit Effect and safety Title Required text Maximum 255 characters Used in search/retrieval. Make it specific and stable. Body Required textarea Plain text content May be injected into model context. Never store credentials, payment data, medical details, or private staff notes. Tags Text Comma-separated Used with title/body for keyword retrieval and publishing scope. Keep a controlled vocabulary. Topic Select One of general, pricing, schedule, policies, programs, faq, staff, facilities Supports filtering and organization. Unknown CSV topics become general. The list supports search, topic filter, edit, delete, pagination, and CSV import. CSV must have title, body, tags, topic headers; rows without a title are skipped. Import on staging first and review every row because a successful import can add incorrect policy or pricing context in bulk. What belongs in authored knowledge Use AI Knowledge for durable, owner- or head-coach-approved material: gym curriculum and teaching sequence; coaching cues and common errors; safety and stop conditions; class norms and stable policies; gym-specific exceptions; and reviewed, licensed discipline guidance. Do not store volatile or personal data here. Schedules, prices, ranks, attendance, rosters, subscriptions, CRM state, and pending actions must come from GymCore’s live tools and APIs. Live results override static knowledge. Never include member names, personal information, credentials, private URLs, secrets, or raw conversations in titles, tags, bodies, or source labels. Source and authority order When sources conflict, use this order: Live GymCore operational data. Owner/head-coach-approved gym doctrine. Reviewed discipline guidance. Reviewed general coaching guidance. General model knowledge for low-risk explanations only. For authored entries, use one authority tag: authority:gym, authority:discipline, or authority:general. For entries with the same stable key, exact program/persona scope wins over all; gym authority then wins over discipline authority, which wins over general authority. Conflicting active sources at the same authority level require review rather than silent combination. Required publishing metadata Tags are comma-separated, lowercase, exact tokens. Every runtime-ready row requires exactly one tag from each required field: key:\u0026lt;stable-slug\u0026gt; status:published persona:\u0026lt;current-persona\u0026gt; or persona:all program:\u0026lt;program-slug\u0026gt; or program:all authority:gym or authority:discipline or authority:general source:\u0026lt;non-secret-slug\u0026gt; reviewed:YYYY-MM-DD Optional descriptive tags may include type:* and level:*. Example for a gym-specific Adult BJJ coaching entry: key:adult-bjj-closed-guard-posture, status:published, persona:coaching, program:adult-bjj, authority:gym, source:head-coach-curriculum, reviewed:2026-07-27, type:technique, level:beginner Use program:all only for genuinely cross-program material. Use persona:all only when the entry is safe for every entitled assistant. Missing, duplicated, malformed, draft, archived, unscoped, or unpublished metadata fails closed: the entry remains editable but is not used by assistants. One entry, one concept Each row should answer one coherent question or teach one atomic concept. For technique and curriculum entries, use this body template where applicable: Summary: Applies when: Prerequisites: Teaching steps: Coaching cues: Common errors: Safety and stop conditions: Age/rank adaptations: Gym-specific exceptions: Policy and FAQ entries may omit irrelevant sections, but they must identify the governing source and escalation owner. Retrieval and staff program scope The store searches title, body, and tags, scores words longer than two characters, and returns up to the top five matches by default. Keyword retrieval is not semantic certainty: a similarly worded stale entry can outrank the correct one. Archive or update replaced policies instead of adding conflicting active versions. In staff chat, choose the Coaching assistant and then select the program. A selected program can use matching program:\u0026lt;slug\u0026gt; entries plus program:all. General / all programs uses only program:all entries. Other staff assistants are forced to the neutral all scope. Changing the assistant or program starts a new conversation so history cannot cross scope boundaries. Gym- and program-specific claims must cite retrieved sources as [KB-\u0026lt;id\u0026gt;]. Retrieved entry text is evidence, not an instruction, and cannot grant tools, change scope, authorize writes, or bypass pending-action review. If no approved source supports a gym-specific answer, the assistant should say it does not know and refer the question to the owner or head coach. Live runtime context GymCore AI separately assembles persona-specific data through internal REST dispatch and caches context for 5 minutes: Sales: pricing, trials, schedule, announcements, pipeline, recent leads. Coaching: schedule, Foundations, promotion candidates, today’s rosters, optional member context. My Coach: authenticated member context and schedule. Finance: subscriptions, MRR, failed payments, signups, churn, pipeline. Admin: attendance summary, announcements, pending social, pipeline, churn. Context is wrapped as data-only content, but it can still contain member names, CRM notes, announcements, billing, ranks, and attendance. A five-minute cache means a recent correction may not appear immediately. Verify the source record before acting. Prompt and naming precedence Built-in persona prompt, unless an agent System Prompt Override replaces it completely. AI Gym Name and {{gym_name}} substitution. Global Response Style instructions. Topic/runtime/knowledge context selected for the request. Tool results returned during the request. Retained conversation messages. Core Brand voice and core Organization name are separate. WordPress Site Title is the AI Gym Name fallback. White Label Brand Name is another presentation-only value. Author, test, and publish Create or import the entry without status:published. Add its stable key, persona, program, authority, source, and review metadata. Have the owner or head coach review accuracy, audience, safety language, conflicts, and source rights. Test supported, cross-program, unsupported, and prompt-injection questions. Add status:published only after review passes. Archive a bad release with status:archived; do not delete review evidence just to roll back a published entry. Maintenance procedure Name an owner for each policy/pricing entry and include an effective date in the body. In Search entries…, search for the subject before adding another entry. Select Edit for the canonical entry, or select Add Entry only when no current entry exists. Expected: Edit Knowledge Entry opens with the saved values, or Add Knowledge Entry opens blank with Topic set to general. No record changes until Save is selected. Complete Title, Body, Tags (comma-separated), and Topic, then select Save. Expected: The dialog reports Saved. and the refreshed list shows the intended title, topic, tags, and updated time. Reopen Edit and compare the saved body before relying on it. For a confirmed duplicate, select Delete and confirm Delete this knowledge entry? Expected: The row disappears from the refreshed list. This deletes the knowledge-table row; there is no undo control in this screen, so restore from a database backup if the deletion was wrong. Before a bulk import, create a recoverable database backup and validate a CSV with the title, body, tags, topic header on staging. In Bulk Import (CSV), choose the file and select Import. Expected: The screen reports Imported N entries. Review the inserted rows on staging. Missing titles are skipped and unknown topics become general; an import success message does not prove the content is correct or retrievable. After the site’s actual AI conversation surface is confirmed available, test one prompt that should retrieve the entry and one unrelated prompt that should not. Compare the answer with the reopened knowledge entry and the live policy, schedule, price, or member record that owns the fact. Expected: The relevant prompt uses current information, the unrelated prompt does not pull the entry inappropriately, and the final source record matches the answer. If the chat surface is absent or blocked, stop at the saved-entry check and use Chat safely with GymCore AI to diagnose the runtime path; do not claim an end-to-end test. The audited AI Settings UI contains code for topic overrides but does not register Topics as one of the four active nested settings tabs. Do not tell customers to edit hidden topic options directly. Rollout boundary The code path alone does not authorize content import or runtime rollout. Owner/head-coach review, source rights, and installed-version testing are still required. Member-facing grounding remains a separate privacy-reviewed rollout. Related guides GymCore AI overview Agent personas Chat Security, privacy, and retention","headings":["Knowledge entry fields","What belongs in authored knowledge","Source and authority order","Required publishing metadata","One entry, one concept","Retrieval and staff program scope","Live runtime context","Prompt and naming precedence","Author, test, and publish","Maintenance procedure","Rollout boundary","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/knowledge.md"},{"route":"/docs/gymcore-ai-notifications/","slug":"gymcore-ai-notifications","title":"Configure approval notifications","summary":"Configure approval notifications.","text":"Purpose Alert authorized staff when an AI-proposed action is waiting for review. Notifications do not approve, execute, or verify the action. Audience and access For: Gym owners, site administrators, and the staff owner for Slack or Twilio\u0026lt;br\u0026gt; Access needed: WordPress manage_options; access to the private Slack channel/app or the GymCore Twilio configuration\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General Before you start Choose a private staff-only Slack channel and/or current on-call phone numbers. Review who can read channel history, exports, guest access, notification previews, and managed mobile devices. Review Twilio readiness under GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers. A site administrator can save Twilio credentials and send one explicit test SMS to that administrator’s staff-owned billing phone. This does not validate AI notification delivery. Use staging and fictional action data for notification validation. The settings screen has no notification test button. Exact visible steps Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General and find Notify on pending action. Expected: The checkbox is on by default. The in-admin pending notice is separate and remains visible to administrators even when external notification delivery is off. To use Slack, paste the restricted incoming-webhook URL into Slack incoming webhook URL. Expected: Only an HTTPS hooks.slack.com URL can be saved. Leave the field blank to disable Slack. To use SMS, enter one authorized E.164 number per line under SMS admin numbers (one per line). Expected: Formatting is reduced to digits and a leading +. A blank list disables SMS delivery. Leave Include action summary in Slack off unless the channel is approved for member-related content. Expected: Slack receives routing metadata without the optional description. SMS is always metadata-only and does not include the action description. Select Save Changes. Expected: The General tab reloads with the saved checkbox, masked or stored URL value, recipient list, and standard WordPress settings confirmation. On staging, create one fictional proposal through the supported AI flow and leave it Pending. Expected: The admin notice appears. Configured external channels receive one approval alert; no action is approved or executed. If the current Staff Dashboard chat integration is unavailable, there is no customer-facing test control—record the configuration as saved but not delivery-validated. Open the Slack message or SMS, then follow its admin link or open GymCore Admin \u0026gt; AI \u0026gt; Audit Log and filter for Pending. Expected: The notification’s action ID, agent, and action type match the pending audit row. The source record remains unchanged until a separate approval succeeds. Remove fictional external messages according to the Slack, Twilio, carrier, and device policies. Expected: The local pending row and audit history remain; deleting an external message or expiring conversation history does not purge action history. Expected result Authorized recipients receive a minimal alert for a new pending action, the linked action ID exists in the local Audit Log, and no notification is mistaken for approval, completion, or source-record verification. Defaults and limits Control or behavior Current source behavior Notify on pending action On by default; gates Slack and SMS dispatch In-admin pending notice Always shown to administrators when pending actions exist Slack URL Blank by default; HTTPS hooks.slack.com only Include action summary in Slack Off by default SMS recipients Blank by default; one E.164 number per line Slack rate limit At most 10 posts in 5 minutes; later alerts are skipped and logged SMS rate limit One message per recipient per minute; sends are asynchronous Built-in test control None Side effects and privacy Slack, Twilio, carriers, and recipient devices keep copies under their own retention and access policies. A Slack summary can include a trimmed action description containing names, phone fragments, or refund reasons. The SMS body carries only action ID, agent, and action type, but those values still reveal operational activity. Conversation retention does not delete any notification already sent or the local action/audit row. Recover by symptom Slack does not receive an alert Confirm Notify on pending action is on, the saved URL is an HTTPS hooks.slack.com URL, the Slack app still belongs to the intended channel, and fewer than 10 alerts were attempted in the last 5 minutes. Check the WooCommerce or PHP log source gym-core-ai; delivery failures do not block action creation. SMS does not receive an alert Confirm the recipient is saved in E.164 format, GymCore Twilio credentials are current, WordPress cron or Action Scheduler is running, and no message was sent to that number in the last minute. Check Twilio delivery status; the local queue does not prove carrier delivery. An alert contains too much personal data Turn off Include action summary in Slack, select Save Changes, remove the exposed message where possible, review channel access, and rotate the Slack webhook if it was exposed. The already-sent copy remains subject to Slack exports and retention. Saved settings exist but delivery cannot be tested Do not claim notification validation. Record the exact saved values without secrets, the unavailable pending-action creation path, and the installed versions. Test after the Staff Dashboard chat integration is corrected. Related guides Review and decide an AI-proposed action Protect AI data and connections Manage credentials and webhooks Troubleshoot email and SMS Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. Notification delivery is not described as tested unless an installed staging flow produces the pending action and provider result.","headings":["Purpose","Audience and access","Before you start","Exact visible steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","Slack does not receive an alert","SMS does not receive an alert","An alert contains too much personal data","Saved settings exist but delivery cannot be tested","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/notifications.md"},{"route":"/docs/gymcore-ai-overview/","slug":"gymcore-ai-overview","title":"Understand GymCore AI\u0027s current boundaries","summary":"Understand GymCore AI\u0027s current boundaries.","text":"GymCore AI is a staff-facing companion plugin. It registers data tools, proposed-action storage and review, an audit log, notifications, connection security, and optional external-client abilities. It is not a public website chatbot. Owner flow Give each staff member only the persona and records needed for their job. Treat an answer as a lead to verify, not as the source record. Keep generated text as a draft until an authorized person chooses to send or publish it. Require every proposed change to appear as pending before an administrator reviews it. After a change reports completion, reopen the owning GymCore, WooCommerce, or provider record and check the result there. Expected: Reads have no commit button, drafts remain uncommitted, pending actions do not change source records, and a completion status is not accepted without final source verification. Current product boundary Configuration and history: WordPress admin at GymCore Admin \u0026gt; AI. Chat: available from GymCore Admin \u0026gt; Staff Dashboard, not an AI \u0026gt; Chat tab. The dashboard checks the current GYM_CORE_AI_VERSION bootstrap constant; installed-version validation still determines whether the panel and provider runtime work together. Users: signed-in staff and, for the My Coach persona, authenticated users with the required capability. Data: current WordPress, GymCore, WooCommerce, CRM, attendance, rank, communication, and finance records, limited by the selected persona and tool capability. AI output: may be wrong. A response is not a source record. Writes: tools marked as writes enter the pending-action flow and require administrator review before normal approval execution. No public widget: current source does not register a public visitor chatbot. White-label values are consumed by their settings/configuration preview, but no separate runtime interface consumer was found; do not advertise a website bot or a verified staff-interface rebrand. Canonical navigation The core plugin owns GymCore Admin \u0026gt; AI. Available hub tabs are filtered by capability and installed modules. Current tabs can include AI Knowledge, Audit Log, Settings, and license-gated White Label. No Chat tab is registered in the current hub. Inside Settings, use Agents, Webhook \u0026amp; Security, Response Style, and General. Old standalone AI URLs redirect and should not appear in new instructions. Safety model The signed-in user must be allowed to see the persona. Every tool has its own WordPress capability requirement. Read tools may return sensitive records immediately. Write tools queue a proposed action with Pending status; the source record should remain unchanged. An administrator reviews it in Pending Actions when the chat panel is available. The Audit Log is read-only and has no approval button. Approve attempts the write immediately. Success becomes Completed; failure remains Approved with an execution error. Approve with Changes stores staff instructions as Approved with Changes and depends on a separate revision/completion handler. Reject does not execute the proposal. Audit Log records action, status, reviewer, created time, reviewed time, and a detail summary. Staff verify the final GymCore, WooCommerce, or provider source record. Completed is a successful tool return, not proof of provider settlement, delivery, or publication. Conversation retention does not delete pending-action or audit records. External model, Slack, SMS, MCP, and hosting systems may keep their own copies. Related guides GymCore AI overview GymCore AI settings reference AI troubleshooting Roles and capabilities Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. No installed-version chat or write success is asserted.","headings":["Owner flow","Current product boundary","Canonical navigation","Safety model","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/overview.md"},{"route":"/docs/gymcore-ai-security-privacy-retention/","slug":"gymcore-ai-security-privacy-retention","title":"Protect AI data and connections","summary":"Protect AI data and connections.","text":"Owner flow Decide which staff roles may use each persona and which member, finance, attendance, or communication data they need. Keep prompts narrow, use fictional data for tests, and verify every answer or completed action in the owning source system. Set the conversation-retention period, then separately document retention for action history, the model provider, Slack, SMS, external clients, hosting, and backups. Keep an external automation connection off until its owner, secret-transfer method, allowed source addresses, staging test, and rollback are approved. Expected: The owner can name who has access, which data may leave the site, how long each system keeps it, and where the final source record will be verified. Only then should a technical operator configure the connection below. Webhook security An inbound webhook lets an approved external automation send a request into GymCore AI. “Egress IP” means the network address that automation uses when it leaves the provider. Obtain those exact production addresses before opening GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; Webhook \u0026amp; Security. Webhook Secret: generated on activation; shown masked. Rotation creates a new secret and accepts the previous one for 5 minutes. IP Allowlist: one source IP per line. Enforce IP allowlist: when on, an empty list denies all webhook traffic. When off, an empty list accepts any IP that passes signature authentication. Supported new-deployment authentication: HMAC over timestamp and raw body. The header name in current source is legacy-named X-HMA-Signature; treat that as a wire identifier, not customer-facing branding. Replay window: HMAC timestamps outside 5 minutes are rejected. Bearer path: still present but deprecated because it has no timestamp replay protection. Do not use it for new connections. Before turning enforcement on, obtain the exact production egress IPs from the external automation operator and test them on staging. Rotate the secret after exposure, staff/vendor offboarding, or integration ownership changes. Update the external sender within the five-minute grace period. Expected: One installed staging request from an allowed address with the current signature creates the intended local status or record; a stale, altered, or disallowed request is rejected. Do not report this result unless the request was actually run. Data retention matrix Data Storage Current automatic retention Conversations/messages GymCore AI conversation/message tables Configurable 1–365 days; default 30; daily purge. Pending/approved/rejected/completed actions Pending-action table with JSON payload/results No configurable automatic purge found. Audit log View over action records Same as action records; not covered by conversation retention. External model/provider data Provider systems Provider contract/settings, not GymCore retention. Slack/SMS notifications Slack/Twilio/carrier/recipient devices External policies, not GymCore retention. MCP client transcripts External MCP client Client policy, not GymCore retention. Privacy rules Use least-privilege accounts, narrow prompts, and fictional tests. Do not paste credentials or payment-card data into chat. Treat attendance, rank, billing, lead, communication, waiver, family, and churn data as personal data. A WordPress personal-data erasure request does not automatically prove removal from AI action history, model providers, Slack, SMS, backups, or MCP clients; review each store. Related guides GymCore AI overview GymCore AI settings reference AI troubleshooting Roles and capabilities Source review: checked-out gym-core-ai and gym-core PHP on 2026-07-13. Connection behavior must still be validated on the installed staging version.","headings":["Owner flow","Webhook security","Data retention matrix","Privacy rules","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/security-privacy-retention.md"},{"route":"/docs/gymcore-ai-tools-abilities-reference/","slug":"gymcore-ai-tools-abilities-reference","title":"Review AI tools and external abilities","summary":"Review AI tools and external abilities.","text":"GymCore AI offers different functions for sales, coaching, members, finance, and administrators. Choosing a persona narrows what is offered, but WordPress still checks the signed-in user’s permission every time. Owner flow Name the staff job to support and the minimum records it needs. Choose the narrowest persona, then verify the actual WordPress permission on every required function. Separate immediate reads from drafts and proposed writes. Reads can expose data; drafts do not send; writes must become pending before review. Test denial, one harmless read, one rejected proposal, and duplicate/retry handling with a least-privilege staging account. Expected: Unauthorized functions are denied, the read matches its source and has no commit button, the proposal remains pending until rejected, and retries do not create duplicate source records. Verify any completed action in the GymCore, WooCommerce, or provider source record. Expected: The source record contains the intended result exactly once. A successful tool return is not confused with provider delivery or settlement. The technical permission names used below are WordPress capabilities. A persona can hide functions, but the capability on each endpoint remains authoritative. Audited AI tool count: 55. A registered tool is not permission to use it and is not proof its dependency is configured. Persona access Persona Default gate Tool scope Sales Agent gym_process_sale Sales, leads, pricing, schedules, CRM prospect work, SMS drafts/history, rosters, image generation. Coaching Agent gym_view_briefing Training, attendance, ranks, Foundations, rosters, promotion recommendations, status-only subscriptions. My Coach read Authenticated member progress, schedule, and subscription status. Finance gym_view_finance Full admin data set and financial writes; no image generation. Admin Agent manage_options Full admin set plus image generation. Write approval rule A tool definition with write=true queues an action for staff approval. Write families include order/lead creation, class-program assignment, SMS, promotions and Foundations updates, announcements/social actions, CRM notes, refunds, and monthly close. Read tools can still expose personal data immediately. Always verify the tool definition in the installed source because inventory risk labels are conservative and do not replace the write flag. Complete registered tool catalogue Stable ID Tool Source Inventory risk INV-TOOL-0001 get_pricing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:342 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0002 calculate_pricing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:360 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0003 lookup_customer wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:382 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0004 create_kiosk_order wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:400 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0005 create_lead wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:458 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0006 get_schedule wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:496 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0007 get_classes wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:522 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0008 assign_class_program wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:589 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0009 get_locations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:611 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0010 draft_sms wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:623 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0011 get_trial_info wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:657 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0012 get_member_rank wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:673 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0013 get_rank_history wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:695 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0014 get_attendance wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:717 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0015 get_badges wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:751 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0016 get_streak wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:769 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0017 recommend_promotion wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:787 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0018 promote_member wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:809 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0019 get_briefing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:843 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0020 get_foundations_status wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:861 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0021 record_coach_roll wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:879 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0022 get_revenue_summary wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:905 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0023 get_subscriptions wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:948 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0024 get_subscriptions_summary wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:975 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0025 get_mrr wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:988 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0026 get_failed_payments wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1001 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0027 get_reports wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1023 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0028 get_today_attendance wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1039 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0029 get_promotion_eligible wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1061 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0030 draft_announcement wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1079 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0031 draft_social_post wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1126 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0032 generate_image wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1152 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0033 get_briefing_today wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1197 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0034 get_announcements wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1219 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0035 get_sms_templates wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1249 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0036 enroll_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1266 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0037 clear_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1284 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0038 get_active_foundations wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1302 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0039 get_social_pending wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1319 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0040 approve_social_post wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1332 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0041 search_crm_contacts wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1354 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0042 get_crm_contact wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1389 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0043 get_crm_contact_notes wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1407 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0044 add_crm_contact_note wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1433 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0045 get_crm_pipeline wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1455 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0046 get_member_orders wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1471 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0047 get_member_billing wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1527 medium-high: sensitive access/configuration INV-TOOL-0048 get_member_subscription_status wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1545 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0049 get_churn_metrics wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1603 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0050 issue_refund wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1621 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0051 get_sms_history wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1651 high: mutates data, sends communication, or crosses trust boundary INV-TOOL-0052 get_class_roster wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1681 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0053 get_ar_aging wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1703 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0054 draft_dunning_message wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1715 medium: authenticated/operator surface; permission and side effects vary INV-TOOL-0055 run_monthly_close wp-content/plugins/gym-core-ai/src/Tools/ToolRegistry.php:1738 medium: authenticated/operator surface; permission and side effects vary Connect an MCP client MCP is a protocol an external client can use to discover approved AI functions. When WordPress Abilities API and the MCP adapter are installed, GymCore AI registers tool-backed abilities with MCP-public metadata. This means an authenticated adapter can advertise them; it does not mean anonymous public access. The gym_core_ai_mcp_public_ability filter can suppress individual abilities. Capability checks and pending-action controls still apply. Before connecting an MCP client: Inventory every advertised ability and suppress everything the client does not need. Use a dedicated least-privilege service account; never an owner administrator account. Test read denial, write approval, rejection, duplicate/retry behavior, and audit records on staging. Expected: The client reads only approved data, every write is pending before review, rejection leaves the source unchanged, and retries do not duplicate the result. Set retention and access policy in the external MCP client because it may store prompts and results. Rotate credentials and revoke the account when the client, vendor, or operator is removed. Expected: The removed client can no longer authenticate or discover protected results, while the action/audit evidence required by policy remains available under its separate retention rules. Related guides Complete MCP ability catalogue Complete REST route catalogue Action approvals Security, privacy, and retention AI troubleshooting","headings":["Owner flow","Persona access","Write approval rule","Complete registered tool catalogue","Connect an MCP client","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/tools-abilities-reference.md"},{"route":"/docs/gymcore-ai-white-label/","slug":"gymcore-ai-white-label","title":"Configure the GymCore AI brand preview","summary":"Configure the GymCore AI brand preview.","text":"Purpose Save staff-interface branding values and review them in the built-in Live Preview. These settings do not create or publish a public website chatbot. Audience and access For: Gym owners, brand owners, and WordPress administrators\u0026lt;br\u0026gt; Access needed: WordPress manage_options and an AI license tier that allows white_label\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; AI \u0026gt; White Label On the canonical AI hub, the White Label tab is omitted when either access check fails; a locked page is not guaranteed to appear. Before you start Approve one brand name, logo asset, primary color, and short staff-facing welcome message. Compare the proposed name with GymCore Organization name, WordPress Site Title, and AI Gym Name; these are separate values and can disagree. Use an HTTPS logo from an approved media location and check that its use complies with your privacy, accessibility, and brand policies. Plan to validate contrast and display behavior manually. The checked-out source has no verified consumer of these values outside the settings page and its preview. Exact visible steps Open GymCore Admin \u0026gt; AI \u0026gt; White Label. Expected: White Label Settings shows Brand Name, Logo URL, Primary Color, Hide Branding, Custom Welcome Message, and Live Preview. If the tab is missing, follow the recovery guidance. Enter Brand Name. For a logo, paste its HTTPS URL or use the media picker, choose the asset under Select Logo, then choose Use this image. Expected: Live Preview updates immediately. A blank brand name previews GymCore AI; a blank logo URL hides the preview image. Set Primary Color and review text, controls, focus indicators, and adjacent backgrounds for readable contrast. Expected: The preview header and footer use the selected color. Clearing or submitting an invalid color returns to #1a1a2e. Choose Hide Branding only if your license and brand policy allow the “Powered by GymCore AI” credit to be hidden. Expected: The credit disappears from Live Preview while the checkbox is selected. Enter a short Custom Welcome Message for signed-in staff. Do not address anonymous website visitors or promise a public chatbot. Expected: The preview message updates. A blank value previews “Hello! How can I help you today?” Select Save White Label Settings. Expected: WordPress shows White label settings saved. and redirects back to the white-label page. Reopen GymCore Admin \u0026gt; AI \u0026gt; White Label and compare every field with the approved brand record. Expected: The saved values and Live Preview match the approved source exactly. This verifies persistence and preview only; current source does not prove that chat or another runtime surface consumes the configuration. Expected result The approved brand values persist and the built-in preview renders them. Do not report a production interface change until an installed runtime surface is identified and verified separately. Defaults and limits Field Current default or behavior Brand Name GymCore AI Logo URL Blank Primary Color #1a1a2e; invalid input falls back to this value Hide Branding Off Custom Welcome Message Blank; preview fallback is “Hello! How can I help you today?” Media picker Images only; one selection Public website chatbot Not registered by current source Verified runtime consumer None found outside settings/config and Live Preview Side effects and privacy Saving updates one GymCore AI configuration option. A remote logo URL can disclose visitor or staff requests to the asset host if a future runtime surface loads it. Do not put member data, credentials, support promises, or regulated claims in the welcome message. Branding changes do not change AI capabilities, approval requirements, data retention, or provider privacy. Recover by symptom The White Label tab is missing Confirm the user has manage_options and the current AI license allows white_label. The canonical hub hides the tab when either check fails. Core licensing is managed separately under GymCore Admin \u0026gt; GymCore Settings \u0026gt; License; do not paste a license key into an undocumented AI field. A field reverts after saving Confirm White label settings saved. appeared, then reopen the tab. For the color field, use a valid six-digit hex value. For the logo, choose a stable HTTPS media URL. Capture the visible notice and field value before escalation. Live Preview changes but the staff interface does not That is consistent with the checked-out source: no runtime consumer was found outside the configuration and preview code. Do not clear caches or repeatedly save. Record the installed versions and request product confirmation of the intended consumer. The tab advertises a public chat widget Treat that text as legacy product copy. Current source does not register a public website chatbot. Do not publish customer promises based on the upgrade message. Related guides GymCore AI overview Configure GymCore AI Protect AI data and connections Troubleshoot GymCore AI Source review: checked-out gym-core-ai PHP/JavaScript on 2026-07-13. Persistence and preview are source-backed; no installed runtime brand-consumer test is asserted.","headings":["Purpose","Audience and access","Before you start","Exact visible steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","The White Label tab is missing","A field reverts after saving","Live Preview changes but the staff interface does not","The tab advertises a public chat widget","Related guides"],"source_sha256":"","section":"GymCore AI","source":"docs/user-guide/gymcore-ai/white-label.md"},{"route":"/docs/integrations-calendars-google/","slug":"integrations-calendars-google","title":"Connect Google Calendar for attendance-triggered events","summary":"Connect Google Calendar for attendance-triggered events.","text":"Connect a service account to one Google Calendar and verify the narrow event behavior that the current GymCore source actually implements. Access and dependencies Use a WordPress administrator with manage_options and a Google Workspace or Google Cloud owner who can manage a service account and calendar sharing. Prepare the full service-account JSON key and the destination Google Calendar ID. Share the destination calendar with the service-account email and grant the minimum permission needed to create events. Current source subscribes only to GymCore’s class_attended event. It does not expose a general class-schedule sync, date range, direction, or daily-sync control. Exact steps Safe stop: Save and test the connection, but stop before producing a class_attended event until the destination calendar and fictional staging records are confirmed. Open GymCore Admin \u0026gt; Integrations and find the Google Calendar card. Select Connect. Enter Service Account JSON (paste full JSON key file) and Google Calendar ID (e.g. primary or [email protected]). Select Save \u0026amp; Connect. Expected: The card changes to Connected only after GymCore obtains a Google access token. Credentials are stored encrypted in the site’s WordPress database. Select Test Connection. Expected: The card reports Healthy when GymCore can obtain another access token. This check does not create a calendar event. On a staging site, use a staff-controlled class and member to produce the GymCore class_attended event once. Expected: GymCore posts one Google event using the class post title, _gym_class_start, _gym_class_end (or the start value when end is empty), and the WordPress site timezone. Verify the final result in the owning systems: open the destination Google Calendar and compare its event title, start, end, and timezone with the GymCore class record. Expected: The Google Calendar event matches the GymCore source class. If no event appears, do not describe the integration as ready. Effects, limits, and credential safety The current implementation sends a new Google Calendar events request when class_attended fires; it does not search for an existing event before posting. Repeating the source event may therefore create duplicates. Disconnect removes the encrypted service-account configuration and cached token from WordPress but does not delete events already created in Google Calendar. Rotate the Google key if it was exposed, and never paste it into a ticket, chat, or screenshot. Owner handoff: Tell the site administrator the source event is class_attended, not “class schedule changed.” Give them the GymCore class ID, event time, calendar ID, and Google event link—never the JSON key. If the calendar result is wrong Connect fails: confirm the JSON is complete, the Calendar API is enabled, and the service-account key is still active. Healthy but no event appears: confirm a class_attended event actually fired and the class has _gym_class_start data. Event appears in the wrong calendar: disconnect, confirm the Calendar ID, reconnect, and delete the incorrect event in Google Calendar. Duplicate events appear: stop repeating the attendance event and remove duplicates in Google Calendar; disconnecting does not clean them up. Related guides Credentials Webhooks Integrations API Scheduled Jobs Automation","headings":["Access and dependencies","Exact steps","Effects, limits, and credential safety","If the calendar result is wrong","Related guides"],"source_sha256":"","section":"Integrations","source":"docs/user-guide/integrations/calendars-google.md"},{"route":"/docs/integrations-mailpoet-automatewoo/","slug":"integrations-mailpoet-automatewoo","title":"Verify MailPoet or AutomateWoo before creating a workflow","summary":"Verify MailPoet or AutomateWoo before creating a workflow.","text":"Confirm which messaging extension is installed and what GymCore exposes before building an automation with member data. Access and dependencies Use a WordPress administrator with manage_options; include the staff owner of outbound email or SMS. The current repository’s plugin directory contains neither MailPoet nor AutomateWoo, and GymCore Admin \u0026gt; Integrations registers no MailPoet or AutomateWoo card. GymCore contains conditional AutomateWoo trigger and action code that loads only when an installed AutomateWoo extension supplies its base classes. Current source contains no MailPoet bridge. Exact steps Safe stop: Keep the test workflow disabled after reviewing its recipient, consent, trigger, and exit rules; enabling it is the first step that can contact someone. Open Plugins \u0026gt; Installed Plugins and look for MailPoet and AutomateWoo. Expected: Only extensions actually installed on the site appear. If either is missing, stop; a GymCore source class is not proof that the customer can use that product. Open GymCore Admin \u0026gt; Integrations and confirm there is no MailPoet or AutomateWoo connection card in the current build. Expected: The page shows registered services such as Google Calendar or Twilio, plus the separate QuickBooks tab. Do not invent a MailPoet or AutomateWoo connect action. If AutomateWoo is installed and approved, open its own workflow editor and look for the Gym group. Current GymCore source can register these triggers: Gym – Belt Promotion, Gym – Foundations Cleared, Gym – Class Check-In, Gym – Attendance Milestone, and Gym – Referral Converted. For SMS workflows, confirm Send SMS (Twilio) appears and review the administrator-owned credential form, readiness, and Send test SMS action under Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers. The action offers Message Template and Custom Message; a custom message overrides a selected template. Expected: AutomateWoo displays the source-backed Gym trigger/action labels. If it does not, record the installed AutomateWoo version and hand the mismatch to the site administrator. Build one disabled workflow using staff-controlled data. Check consent, entry rules, recipient, delay, and exit conditions before enabling it. Enable the workflow only for the staff test record and fire its GymCore source event once. Expected: AutomateWoo records one workflow run. A Twilio action logs a send or a specific skip reason, such as missing phone, empty message, or SMS opt-out. Verify the final result in the owning delivery service: check email delivery in the installed email service or SMS delivery in Twilio, then compare the recipient and source event with the GymCore member record. Expected: The owning delivery service and AutomateWoo log agree. Do not rely on a moved lead card or saved workflow alone as proof of delivery. Effects, reversal, and consent Enabling a workflow can send messages from membership, attendance, rank, referral, and billing-phone data. A sent message cannot be recalled. Disable the workflow to stop future entries, but preserve its run log for investigation. Honor SMS opt-outs and the email extension’s suppression list; never add a recipient merely to make a test pass. Owner handoff: If MailPoet is installed, ask the email owner to document its lists, consent source, suppression behavior, and delivery log. GymCore source does not define those screens or a MailPoet data sync. If the Gym group is missing Verify AutomateWoo is active and supplies its AutomateWoo\\Trigger and AutomateWoo\\Action classes. Confirm GymCore is active after AutomateWoo, then reload the workflow editor. If labels still do not appear, do not recreate them manually; give the administrator the extension versions and expected source-backed labels above. Related guides Credentials Webhooks Integrations API Scheduled Jobs Automation","headings":["Access and dependencies","Exact steps","Effects, reversal, and consent","If the Gym group is missing","Related guides"],"source_sha256":"","section":"Integrations","source":"docs/user-guide/integrations/mailpoet-automatewoo.md"},{"route":"/docs/integrations-overview/","slug":"integrations-overview","title":"Choose and verify an integration","summary":"Choose and verify an integration.","text":"Use only services registered by the installed GymCore build, start with the smallest safe data flow, and verify the destination before using live member data. Access and dependencies Use a WordPress administrator with manage_options and include an owner who can sign in to the third-party service. Have a staging site, the provider’s approved credential, and a staff-controlled test record. Current GymCore source registers cards for Zapier, Slack, Mailchimp, Google Calendar, and Twilio SMS. QuickBooks is a separate tab on the same page. MailPoet and AutomateWoo are not registered cards. Their plugins are also absent from this repository; verify installed extensions before planning either workflow. Exact steps Safe stop: Complete and test the provider connection without using member data; stop before the provider-specific end-to-end test until its account, recipient, and rollback are approved. Open GymCore Admin \u0026gt; Integrations. Find the service by its visible card label. If the label is absent, open Plugins \u0026gt; Installed Plugins and verify whether an approved companion extension supplies a different workflow. Expected: A supported built-in service appears as a card with Connect or the connected actions Test Connection and Disconnect. Do not infer availability from a PHP class name alone. Ask the service owner for the minimum credential and destination needed by that card. Do not use a personal password when the provider offers a token, service account, or authorization flow. Select Connect, complete every required field, and select Save \u0026amp; Connect. Expected: GymCore stores the configuration encrypted and changes the card to Connected only when that integration’s connect check passes. Select Test Connection and read the result in the card. Expected: The card shows Healthy or Unhealthy. This is not always an end-to-end test: for example, the current Twilio card checks only that three fields are non-empty. Run one provider-specific test with staff-controlled data. Verify both the GymCore or WooCommerce source record and the destination record, message, or event. Expected: One source action produces one intended destination result, with the correct account, recipient, fields, and timestamp. Record the integration owner, credential-rotation date, data shared, and removal procedure before using member data. Verify the final result in both owning systems: reopen the GymCore or WooCommerce source record and the provider’s destination record. Expected: Source and destination still agree on account, recipient, fields, status, and timestamp after a fresh reload. Defaults, effects, and reversal Built-in cards are disconnected until encrypted configuration exists. Disconnect deletes GymCore’s stored credential and calls the integration’s disconnect handler. It does not recall messages, delete calendar events, remove CRM contacts, or reverse accounting entries already created at the provider. Rotate an exposed credential at the provider as well as disconnecting it in WordPress. Owner handoff: Tell the administrator the card label, source event, destination account, and failed test time. Give the provider only redacted record IDs; never include tokens, service-account JSON, member messages, or payment data. If the card and service disagree Card is missing: verify the active GymCore version and installed companion extensions; do not install an unrelated substitute on production. Connected but unhealthy: reconnect with a fresh least-privilege credential and confirm the provider account is active. Healthy but no destination result exists: inspect the provider’s delivery or audit log; the card’s health check may validate credentials only. Wrong destination received data: disconnect immediately, rotate the credential, and have the provider owner remove or correct the copied record. Related guides Credentials Webhooks Integrations API Scheduled Jobs Automation","headings":["Access and dependencies","Exact steps","Defaults, effects, and reversal","If the card and service disagree","Related guides"],"source_sha256":"","section":"Integrations","source":"docs/user-guide/integrations/overview.md"},{"route":"/docs/integrations-twilio/","slug":"integrations-twilio","title":"Connect and test Twilio SMS","summary":"Connect and test Twilio SMS.","text":"Save Twilio in the settings screen used by GymCore’s sending client, send one test to an authorized staff phone, and verify it in Twilio. Access and dependencies Use a WordPress administrator with manage_options and a Twilio account owner. Complete sender registration and obtain an Account SID, Auth Token, and either a Messaging Service SID or Twilio phone number. Put an authorized E.164-format billing phone on the administrator’s own user profile for the test. GymCore Admin \u0026gt; Integrations \u0026gt; Twilio SMS is not sufficient for launch: its current Test Connection checks only that Account SID, Auth Token, and From Number (E.164) are non-empty. The runtime sending client uses the settings below. Exact steps Safe stop: Save the approved sender configuration, but stop before Send test SMS until the current user’s billing phone, consent, test cost, and Twilio account are confirmed. Open GymCore Admin \u0026gt; GymCore Settings, then select SMS. Enter Twilio Account SID and Twilio auth token. The token is encrypted after saving; leave the masked value unchanged unless rotating it. Enter Twilio messaging service SID or Twilio phone number. A Messaging Service SID is optional but takes precedence when both are set; a phone number must use E.164 format. Set Rate limit from 1 to 10 messages per contact per hour. The default is 1. Save the settings before testing. Expected: The SMS section reloads with saved non-secret values and a masked auth token. No message has been sent yet. Select Send test SMS. This action sends a one-line Twilio test to the current user’s billing phone. Expected: GymCore displays Test SMS sent. and Twilio records one message SID. If the user has no billing phone, GymCore says so instead of choosing another member. Verify the final result in Twilio: open the message log and compare sender, recipient, body, time, and final delivery status with the current WordPress user’s billing phone. Expected: The Twilio log and WordPress profile agree. A GymCore success notice without a matching Twilio message is not final verification. If the site also uses the Twilio SMS integration card, connect it only after the SMS settings test passes. Its event listener can send fixed messages for rank_promoted, badge_earned, subscription_created, and subscription_cancelled to the member’s gym_phone value. Effects, reversal, and consent The test sends a real SMS and may incur a Twilio charge; it cannot be recalled. The runtime retries once only for Twilio HTTP 429 or 503 responses. Keep the default rate limit unless the messaging owner approves more. Sender registration, consent, quiet hours, opt-out handling, and retention remain the gym’s responsibility. Rotate the Auth Token in Twilio immediately if it is exposed, then replace the saved token. Owner handoff: Give the administrator the Twilio message SID, redacted sender/recipient, GymCore event, and timestamp. Do not send the Auth Token or full message content in a general support channel. If the test fails Save settings before sending a test: save the SMS section, then retry once. No billing phone is set: add an approved phone to the testing administrator’s own billing profile; do not borrow a member’s number. Twilio credentials are not configured: confirm Account SID, token, and at least one sender setting in the SMS section—not only the Integrations card. Twilio rejects the request: use the Twilio error and message log to check sender registration, destination format, balance, and regional permissions. Related guides Credentials Webhooks Integrations API Scheduled Jobs Automation","headings":["Access and dependencies","Exact steps","Effects, reversal, and consent","If the test fails","Related guides"],"source_sha256":"","section":"Integrations","source":"docs/user-guide/integrations/twilio.md"},{"route":"/docs/integrations-webhooks-rest-api/","slug":"integrations-webhooks-rest-api","title":"Define a webhook or REST integration for a developer","summary":"Define a webhook or REST integration for a developer.","text":"Describe the business outcome and data boundary first, then let a developer confirm whether the installed site exposes a safe source-backed endpoint or event. Access and dependencies The gym owner approves the data purpose and destination. A WordPress administrator with manage_options verifies installed integrations. A developer owns authentication, validation, retries, logging, and deployment. Current GymCore source exposes administrator-only REST operations for listing, connecting, disconnecting, and checking registered integration cards under /wp-json/gym/v1/admin/integrations. Those endpoints manage built-in cards; they are not a customer-facing webhook builder. GymCore Admin \u0026gt; Integrations contains no generic Webhook, Add endpoint, or REST API key control in current source. Exact steps Safe stop: Approve the plain-language data flow and synthetic staging case, but stop before deployment or any member-data payload until engineering verifies authentication, authorization, duplicate handling, and redacted logging. Write the outcome in plain language: “When this GymCore event happens, send these fields to this named system for this business owner.” Include the consent basis and retention period. Open GymCore Admin \u0026gt; Integrations and check for a card that already owns the destination. Expected: Use the built-in card when it exists. If no matching card appears, do not invent a webhook screen or reuse another provider’s credential. Open Plugins \u0026gt; Installed Plugins and check for an approved companion extension. Record its name and version if it supplies the workflow. Hand the developer the source event or record, required fields, destination, frequency, acceptable delay, duplicate rule, failure owner, and a staff-controlled test case. Owner handoff: Avoid endpoint jargon in the approval request. Say what leaves the gym, who receives it, why it is needed, and how to stop it. The developer can translate that into routes, signatures, and payloads. The developer confirms authentication and authorization in source. The active integration-management routes require manage_options; they must not be exposed as public ingestion endpoints. Deploy only to staging and send one synthetic payload that contains no member, payment, credential, or message content. Expected: The destination accepts one request, logs one result, and a repeated request follows the agreed duplicate rule. Verify the final result in both owning systems: trigger one staff-controlled source event and compare the GymCore source record with the destination record and both systems’ timestamps. Expected: The owning source and destination agree on fields and status, and a failed request produces a redacted log with a named owner. Defaults, effects, and reversal There is no default generic webhook URL, secret, retry policy, payload, or customer UI in current GymCore source. Treat all of those as implementation requirements. Disabling custom code or deleting a credential can stop future delivery, but it cannot recall a payload already received by another system. Rotate secrets at both ends and ask the destination owner to delete copied test data. If the implementation claim cannot be verified Documentation names a control that is absent: trust the installed source and UI; record the mismatch and verify extensions rather than creating a substitute. Request returns 401 or 403: have the developer check WordPress authentication, REST nonce handling, and the required capability; do not weaken the permission callback. Destination receives duplicates: stop the integration and add an idempotency rule before another live test. A secret or member payload reached logs: rotate the secret, restrict the log, and follow the gym’s incident process. Related guides Credentials Webhooks Integrations API Scheduled Jobs Automation","headings":["Access and dependencies","Exact steps","Defaults, effects, and reversal","If the implementation claim cannot be verified","Related guides"],"source_sha256":"","section":"Integrations","source":"docs/user-guide/integrations/webhooks-rest-api.md"},{"route":"/docs/leads-sales-capture-create-leads/","slug":"leads-sales-capture-create-leads","title":"Capture a lead with valid consent","summary":"Capture a lead with valid consent.","text":"Create a prospective-customer record from the Lead Pipeline or verify one created by an installed form or sales flow. Contact details and permission to communicate are separate facts: a phone number or email address is not consent. Access and dependencies Manual creation uses GymCore Leads \u0026gt; Lead Pipeline and requires gym_manage_leads; current page and API checks also allow manage_woocommerce as an administrative fallback. Create locations, programs, and staff accounts before assigning those values. Public forms, imports, waiver capture, and the sales kiosk are runtime-specific lead sources. Test the exact path installed on the site. Lead records can contain identity, contact details, consent provenance, notes, appointments, and sales outcomes. Limit access and apply the site’s retention and deletion policy. Create a lead manually Open GymCore Leads \u0026gt; Lead Pipeline and select + New Lead. In New Lead, enter the visible name and contact fields. Choose the actual lead source. If the source is Other, record the requested explanation rather than choosing a convenient but false category. Set location, program interest, assignee, and next follow-up when those values are known. Record SMS or email consent only when the person took the corresponding affirmative action. Preserve the displayed consent source; do not overwrite it with a note. Select Create Lead. Expected: The lead appears on the board. Its detail shows the saved source, contact details, consent state and provenance, assignment, and follow-up values. Verify an automatically captured lead Submit the exact installed form, waiver, or /sales/ flow using approved non-production contact data. Open GymCore Leads \u0026gt; Lead Pipeline and locate the resulting record. Compare every captured value with the submission, especially source, location, program, SMS/email consent, and consent source. Expected: One lead exists with accurate provenance. A successful form screen is not proof that the pipeline write succeeded, and multiple records indicate that deduplication needs operational review. If the source triggers an email or SMS, verify delivery in that provider and the communication history. Expected: The provider reports the actual send result. Lead creation alone does not authorize or prove delivery. Reverse or recover Correct an inaccurate field in the lead detail and add a short factual note when the correction is operationally important. Do not manufacture retroactive consent. For duplicates, erasure, or consent withdrawal, use the organization’s approved privacy process and preserve only the audit information the policy allows. Verify in the source system Finish in the lead detail on GymCore Leads \u0026gt; Lead Pipeline. Confirm the lead ID, identity and contact fields, source, consent state and source, assignee, location, program, next follow-up, and history. For form or sales capture, compare that record with the originating submission or WooCommerce order.","headings":["Access and dependencies","Create a lead manually","Verify an automatically captured lead","Reverse or recover","Verify in the source system"],"source_sha256":"","section":"Leads \u0026 Sales","source":"docs/user-guide/leads-sales/capture-create-leads.md"},{"route":"/docs/leads-sales-lead-pipeline/","slug":"leads-sales-lead-pipeline","title":"Advance a lead through the pipeline","summary":"Advance a lead through the pipeline.","text":"Use the Lead Pipeline board to assign follow-up, record outcomes, and move a prospect between stages. The board is a JavaScript application; current PHP renders only its mount point, so a blank page is an application failure—not an empty pipeline. Access and dependencies Open GymCore Leads \u0026gt; Lead Pipeline with gym_manage_leads. Current page and API checks also allow manage_woocommerce as an administrative fallback. The lead must already exist. Create locations, programs, staff users, and class occurrences before assigning them. A card can expose contact, consent, communication, appointment, note, and sales data. Give access only to staff who need that history. Record work and change the stage Open the intended lead card and confirm the lead identity before changing it. Review the assignee and Next follow-up value. Update them using the controls present in the detail when responsibility or timing changes. Add a factual note and select Save Note. Avoid payment-card, health, credential, or unrelated personal information. Expected: The note appears in the lead history with its saved author and time. Use the applicable contact, trial, or sales outcome control to record what actually happened. Choose the destination under Move Stage only after the corresponding work is complete. Expected: The card moves to the selected column and the detail history reflects the outcome. Stage changes can affect funnel reporting and follow-up queues; they do not prove that a message was delivered, a trial occurred, or a payment settled. Export the current lead view Set the board filters to the exact population you intend to export and verify the displayed count. Select Export. Include contact details only when the recipient and purpose require them and your account has the privacy-export capability. Confirm the explicit private-data warning, wait for the asynchronous export to become ready, and download it once. Expected: The export reflects the bounded board query. It expires after 24 hours, is available only to its owner, and the download is consumed after one successful use. Store or transmit the CSV only in an approved private location. If preparation fails, expires, or is cancelled, create a new export from the verified board filters. Do not reuse an old download link or broaden access to work around a permission error. Diagnose a blank board The current server-rendered page has no useful no-JavaScript, loading-failure, or API-error fallback. If no columns, cards, or notice render: Stop rather than recreating leads elsewhere. Reload once and confirm that the account still has gym_manage_leads or the administrative fallback. Have an administrator inspect the browser console and the gym/v1/leads response. Record the error without copying customer data into a public ticket. Resolve the script, nonce, permission, or API failure, then reload. Expected: Stage columns and cards load. A completely blank mount area is not confirmation that no leads exist. Reverse or recover If a stage was changed incorrectly, restore the prior stage with Move Stage and add a correction note. Do not erase legitimate history. Correct consent provenance through the approved privacy process; a stage movement cannot grant or withdraw consent. Verify in the source systems Finish in the lead detail and confirm the lead ID, consent state, assignee, next follow-up, current stage, and history. For trials or sales, also verify the appointment or WooCommerce order in its own source rather than treating the pipeline column as proof.","headings":["Access and dependencies","Record work and change the stage","Export the current lead view","Diagnose a blank board","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Leads \u0026 Sales","source":"docs/user-guide/leads-sales/lead-pipeline.md"},{"route":"/docs/leads-sales-referrals/","slug":"leads-sales-referrals","title":"Configure and verify referral rewards","summary":"Configure and verify referral rewards.","text":"GymCore stores referral rewards as versioned, mode-specific configurations. A new or migrated configuration remains off until an owner enables it and all delivery-readiness checks pass. New referral attributions snapshot the effective revision; later edits do not change existing decisions. Access and dependencies Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Referrals with gymcore_manage_settings; WordPress administrators with manage_options also qualify. manage_woocommerce alone does not grant access. WooCommerce and Action Scheduler must be available before any reward mode can be enabled. WooCommerce fixed-cart coupon snapshots the current WooCommerce store currency on every save. A later enable save creates another revision using the currency current at that save; GymCore does not present a separate changed-currency review gate. Integer outbound-message credits require an external PHP integration that registers the version 1 credit ledger, a credit-aware sender, and ready Twilio transport. Core provides no ready registration. Credits are message units, not money, Twilio balance, or carrier segments. Registered receipt-based custom handler requires an external PHP integration that registers a matching contract version, idempotency, reconciliation, readiness, and durable delivery callbacks. Core provides no handler registration. Activation trusts the descriptor’s declared readiness; the delivery worker rejects missing callbacks later. Referral records connect two customers and purchase activity. Restrict access and never disclose one person’s order details to another. Use fictional people and a non-production site until the complete reward path has passed. Save a disabled revision first Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Referrals. Clear Program enabled. Choose Reward mode. Enter only the selected mode’s values: Coupon amount: a positive store-currency decimal no greater than 100000. Message-credit units: a whole number from 1 through 10000. Custom: a registered reward identifier, owner description, handler key, and matching handler contract version. Add an optional Configuration note without member data or secrets. Select Save changes, reload the page, and confirm the preview and values. Expected: GymCore stores a new disabled revision. A stale browser tab, invalid field, unregistered custom handler, or mismatched handler version rejects the save without replacing the current revision. Enable only after readiness passes Confirm the selected mode’s dependencies are installed, configured, and tested. Select Program enabled. Select Save changes. Expected: Saving with Program enabled creates a new enabled revision only when the save-time readiness result is ready; it does not activate the earlier disabled revision. If that check fails, GymCore preserves the prior revision and reports that the reward program remains unchanged. Readiness is checked during the enabled save, not continuously when a referral is attributed. Recheck dependencies after any provider, currency, scheduler, ledger, sender, or handler change. Clearing Program enabled creates a disabled copy of the current revision without revalidating a degraded mode dependency; save and reload to confirm it is off. Enabling affects only referral attributions created while that revision is effective. It does not add a promise or backfill a decision for older referrals. Test attribution, qualification, and delivery Submit a fictional referral through the exact installed capture path. Confirm the referral record identifies the intended fictional referrer and referred customer. Confirm the decision records the expected configuration revision and selected mode. For a non-subscription fixture, complete the first eligible paid order. Do not treat a subscription renewal as qualification evidence yet: current source compares the subscription’s total payment count with 1, while WooCommerce Subscriptions normally includes the paid parent order in that count. The first-renewal path remains blocked until renewal-only behavior has an installed WCS regression. Allow the scheduled worker to run, then inspect the decision, attempt, and source-system evidence. Expected for a supported fixture: One immutable decision progresses from pending to qualified and then to succeeded. Delivery evidence is mode-specific: Coupon: one opaque, non-stackable fixed-cart coupon, one use, no sale items, and 183-day expiry. Delivery rejects a missing or invalid recipient; verify the coupon has the fictional referrer’s non-empty referrer email restriction and passes exact coupon policy readback. initial_order_only is recorded as coupon metadata, so verify that the installed checkout/subscription stack actually enforces it before customer use. Message credits: one unique committed positive ledger entry for the promised integer units. Custom: one durable handler receipt or authorized manual-fulfilment record. A hook firing or request acknowledgement is not delivery proof. Do not manually replay a failed or unknown delivery. GymCore reconciles bounded batches every five minutes and terminalizes delivery as exhausted after five delivery attempts. An unknown coupon reconciliation can remain issuing; escalate immediately with safe decision/attempt identifiers instead of retrying it. Reverse or recover Clear Program enabled, save, reload, and confirm the active revision is off to stop new reward decisions. This disable path preserves the current mode values and does not require a missing or changed custom handler. Existing decisions and delivered rewards remain unchanged. Correct or void an issued benefit in its owning source system, preserve an audit note, and follow the approved customer-impact policy. Verify in the source systems Confirm the active revision under GymCore Settings \u0026gt; Referrals, the relationship and decision in GymCore referrals, the qualifying order in WooCommerce or the subscription provider, the scheduled action result, and the issued benefit in WooCommerce coupons, the message-credit ledger, or the custom handler’s durable records. This guide is verified against Gym Core 2.2.0.","headings":["Access and dependencies","Save a disabled revision first","Enable only after readiness passes","Test attribution, qualification, and delivery","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Leads \u0026 Sales","source":"docs/user-guide/leads-sales/referrals.md"},{"route":"/docs/leads-sales-sales-kiosk/","slug":"leads-sales-sales-kiosk","title":"Complete a staffed sale","summary":"Complete a staffed sale.","text":"Use the full-screen sales flow at /sales/ to select a WooCommerce product, capture the customer, create an order, and continue to payment. This is a staff sales terminal, not a self-service public checkout. Access and dependencies Sign in with gym_process_sale or manage_woocommerce, then open your site’s /sales/ URL. WooCommerce, at least one eligible published product, taxes, currency, and a working payment gateway must be configured. Pricing customization appears only for products with GymCore pricing rules; otherwise the flow skips to customer information. The kiosk handles contact, order, and payment information. Use a secured device and never put full card data in notes or lead fields. Create the sale Confirm the kiosk’s location before selecting a product. Select the intended membership or product. If no products are available, fix product eligibility in WooCommerce rather than improvising another item. Expected: A configured product opens pricing customization; an unconfigured product proceeds to customer information with its subscription price. If pricing controls appear, choose the permitted down payment and review the server-returned recurring payment, effective total, discount, and billing label. Enter the required customer details. Select the real lead source; when Other is selected, enter the required source note. Record communication consent only when the customer actually gave it through the displayed control. Continue to review and compare the product, price, customer, source, and consent details with what the customer approved. Use the displayed order action to create the order and continue to WooCommerce payment. Expected: GymCore creates a kiosk-origin WooCommerce order for the selected customer and opens the order-pay form. It can also save or update a related lead; verify the association. Complete payment through the configured gateway and wait for the WooCommerce result. Expected: A successful payment returns to /sales/ with completed-order context. A redirect is not proof of settlement. Know the current location limitation The legacy Filter products by location definition defaults to enabled and has an archive/shortcode runtime consumer, but the current Locations owner does not render that control. It is not a Sales Kiosk, cart, or checkout guard. Staff must inspect actual installed behavior and confirm that a product is valid for the sale location. Kiosk auto-logout under Attendance defaults to 10 minutes and accepts 5 through 60; current source applies it to this sales flow. Re-test the timeout after changing it. Reverse or recover Do not repeat a sale after an ambiguous payment response. Find the order first. Refund, cancel, or edit the WooCommerce order under your payment and accounting policy; changing the lead stage does not reverse money. Correct a wrongly linked lead separately. Verify in the source systems Open WooCommerce \u0026gt; Orders and confirm the order ID, customer, items, totals, gateway, and paid/order status. Then confirm the lead and sales outcome in GymCore Leads \u0026gt; Lead Pipeline, and check the payment provider when settlement matters. This guide does not assume an installed end-to-end payment test.","headings":["Access and dependencies","Create the sale","Know the current location limitation","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Leads \u0026 Sales","source":"docs/user-guide/leads-sales/sales-kiosk.md"},{"route":"/docs/leads-sales-trials-conversion/","slug":"leads-sales-trials-conversion","title":"Schedule a trial and record conversion","summary":"Schedule a trial and record conversion.","text":"Manage a prospect’s trial from their Lead Pipeline detail. A trial appointment and an introductory product are separate records: the appointment belongs to the lead workflow, while a paid offer belongs to WooCommerce. Access and dependencies Open GymCore Leads \u0026gt; Lead Pipeline with gym_manage_leads or the current manage_woocommerce fallback. Create the location, program, class, and dated occurrence before scheduling the trial. Sending SMS additionally requires gym_send_sms, valid consent, and working provider configuration. Trial records contain contact, consent, schedule, waiver, and attendance information. Show only the details staff need. Schedule the appointment Open the lead card and confirm the person, location, program interest, communication consent, and assignee. Use the visible trial scheduling control to choose the actual class occurrence and date. Save or confirm the appointment with the displayed action. Expected: The lead detail shows a trial appointment in scheduled state with the intended occurrence. Verify its date and time; a general lead Trial date is not a substitute for the appointment record. If the workflow creates a waiver link, review its status. Use Open waiver link only for the intended prospect. Expected: The detail reports the actual waiver state, such as pending or complete. A generated link does not mean a waiver was signed. Record the real outcome Use only actions allowed for the appointment’s current state: Confirmation can move an active appointment through confirmed_24h or confirmed_day_of. Attendance is valid from scheduled, confirmed, waiver-pending, or waiver-complete states. No-show, reschedule, and cancel represent different outcomes; choose the one that occurred. Expected: The appointment and lead detail show the new trial status. Recording attendance can affect funnel reporting and follow-up, but does not create a paid membership. Record a paid conversion separately Configure an introductory offer as an eligible WooCommerce product and sell it through /sales/ or WooCommerce checkout. Current source does not define one universal intro-offer object with a fixed discount or duration. Expected: A paid offer has its own WooCommerce order and gateway result. Move the lead to a converted stage only after verifying that source record. Reverse or recover Use reschedule or cancel only while the current state permits it. If a wrong outcome has no reversal control, preserve the appointment ID and history and use the authorized support/data-correction path; do not create a second appointment to hide the mistake. Refund paid products in WooCommerce and the gateway. Verify in the source systems Confirm the occurrence, appointment status, waiver state, and history in the lead detail; confirm attendance under GymCore Students \u0026gt; Attendance \u0026gt; History when marked attended; and confirm any paid offer in WooCommerce \u0026gt; Orders and the gateway. These records must agree before treating the lead as converted.","headings":["Access and dependencies","Schedule the appointment","Record the real outcome","Record a paid conversion separately","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Leads \u0026 Sales","source":"docs/user-guide/leads-sales/trials-conversion.md"},{"route":"/docs/members-families-add-edit-member/","slug":"members-families-add-edit-member","title":"Add or edit a member account","summary":"Add or edit a member account.","text":"Purpose Create one WordPress/WooCommerce customer account and verify that GymCore shows the same person without inventing a second member record. Access and dependencies For: Manager or administrator\u0026lt;br\u0026gt; Capabilities: gym_view_attendance to view GymCore Students \u0026gt; Students; WordPress create_users and edit_users to create or edit accounts\u0026lt;br\u0026gt; Dependencies: A unique email address and the approved member identity/contact details The GymCore Students screen is a roster and profile view. The reviewed source does not provide an add-member form there. Add a member Open GymCore Students \u0026gt; Students, use Search students…, and search the email address before creating anything. Expected: One matching profile opens, or the roster shows no existing account. Stop and reconcile multiple matches. If no match exists, open Users \u0026gt; Add New. Enter the approved username and email, choose the intended WooCommerce customer/member role, and select Add New User. Expected: WordPress shows one new user with the intended role. Account email behavior follows the checkbox and mail configuration on that form. Return to GymCore Students \u0026gt; Students and search again. Expected: The new user appears once in the roster. If it does not, verify the assigned role and current roster filters instead of creating another user. Edit a member Open the member in GymCore Students \u0026gt; Students. If your account has edit_users, select the pencil action whose tooltip is Edit in WP Admin. Expected: WordPress opens Edit User for the same numeric user ID. Change only the approved identity/contact fields and select Update User. Expected: WordPress reports that the user was updated and the values persist after reload. Reopen the GymCore profile and any related WooCommerce customer, order, or subscription. Expected: The same user ID owns the intended records. GymCore rank, attendance, notes, and billing are not silently rewritten by an identity edit. Impact, recovery, and privacy User edits are reversible by restoring recorded prior values. Deleting or merging users can orphan attendance, ranks, orders, subscriptions, waivers, and relationships; this guide does not authorize either action. Collect only the identity/contact information the gym needs. Keep medical details, consent evidence, payment data, and credentials in their approved dedicated systems—not general user fields or screenshots. Troubleshooting If the roster omits an existing user, record the user ID, assigned roles, filters, and exact search term; do not create a duplicate. If Edit in WP Admin is absent, the current account lacks edit_users. Ask an administrator to perform the edit with their own account. If WooCommerce billing details disagree, correct the customer/order/subscription source record separately; do not create a replacement member. Verify in the source systems Reopen Users, GymCore Students \u0026gt; Students, and any linked WooCommerce customer/order/subscription. Match them by numeric user/customer ID and email. Related guides Import members from CSV Create and verify a membership product Verify parent and child access Source-verified: src/Admin/StudentRoster.php and templates/admin/student-profile.php for roster access and Edit in WP Admin. WordPress user-form labels can vary by installed version.","headings":["Purpose","Access and dependencies","Add a member","Edit a member","Impact, recovery, and privacy","Troubleshooting","Verify in the source systems","Related guides"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/add-edit-member.md"},{"route":"/docs/members-families-families-guardians/","slug":"members-families-families-guardians","title":"Verify parent and child access","summary":"Verify parent and child access.","text":"Purpose Confirm an existing parent-child relationship and avoid promising a relationship editor that the current customer UI does not provide. Access and dependencies For: Parent/guardian, manager, or administrator\u0026lt;br\u0026gt; Access: A signed-in user can read only their own linked children; manage_woocommerce can query another parent’s family summary through the authenticated API\u0026lt;br\u0026gt; Dependencies: Separate WordPress accounts for the adult and each child, plus an existing relationship in GymCore’s ContactRelationships store Current product limit: The reviewed GymCore admin and member UI reads parent-child relationships but exposes no customer-facing screen to create, change, or remove them. Do not tell staff to use a nonexistent “family” section. Relationship maintenance requires the approved site-specific integration or product/developer workflow. Verify a relationship Confirm the adult and child each have a distinct WordPress user ID. Do not share the child’s login with adults. Expected: Each person has one account and the adult is not substituted for the child on attendance or rank records. Ask the adult to sign in through WooCommerce My Account. Expected: My Kids appears only when GymCore already finds one or more linked children. Open My Kids and compare the child’s name, Belt Rank, Total Attendance, and Eligible for Promotion with the child’s GymCore source records. Expected: The portal shows only linked children and read-only summary values. There is no save button. If My Kids is absent or the wrong child appears, stop. Record the adult and child user IDs and route the relationship change to the approved integration/developer owner. Expected: No account or relationship is created by guesswork. Impact, privacy, and recovery A relationship controls access to a child’s name, email, rank, attendance total, and promotion-eligibility summary. Treat it as an authorization record. Never attach a child based only on a shared surname, address, or payer. Because the reviewed UI has no relationship commit or rollback control, recovery must use the same approved system that created the relationship. Preserve the prior adult/child IDs and audit evidence. Troubleshooting If a linked child is missing, verify that both user accounts still exist and capture the authenticated parent’s ID. Do not recreate either account. If an adult sees an unrelated child, treat it as a privacy incident: remove access through the authorized relationship owner, preserve logs, and do not send screenshots containing the child’s details. Promotion eligibility in this portal inherits the current rank-threshold mismatch; use coach review and the promotion source screen. Verify in the source system After an authorized relationship change, sign in as the adult again and reopen My Kids. Then compare the child user ID with the family API/source store and the child’s GymCore profile. Related guides Use member and parent portals Add or edit a member account Publish and collect a waiver version Source-verified: src/Member/ParentPortal.php and src/API/ParentPortalController.php. No customer-facing relationship editor was found in the reviewed PHP/JS source.","headings":["Purpose","Access and dependencies","Verify a relationship","Impact, privacy, and recovery","Troubleshooting","Verify in the source system","Related guides"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/families-guardians.md"},{"route":"/docs/members-families-import-members/","slug":"members-families-import-members","title":"Import members from CSV","summary":"Import members from CSV.","text":"Purpose Preview a CSV, import new WordPress customer accounts, and reconcile every skipped or failed row. Access and dependencies For: Site administrator\u0026lt;br\u0026gt; Capability: manage_options\u0026lt;br\u0026gt; Menu: GymCore Admin \u0026gt; Setup \u0026gt; Import Members\u0026lt;br\u0026gt; Dependencies: Untouched source export, approved field mapping, and a restorable site backup This import is additive and has no bulk rollback button. Existing users are skipped by matching email; valid rows continue even when other rows fail. Prepare the file Use a CSV header row with required columns first_name, last_name, and email. Supported optional headers are phone, join_date, membership_tier, belt_rank, and notes. Normalize and deduplicate email addresses before upload. Remove columns GymCore does not need, especially payment data, passwords, medical details, and provider tokens. Preview and import Open GymCore Admin \u0026gt; Setup \u0026gt; Import Members, choose the CSV, and select Upload \u0026amp; Preview. Expected: Preview \u0026amp; Confirm reports the total row count, recognized mapping, errors, and a five-row sample. No user has been created yet. Review Column Mapping, Sample Data, and Preview Errors. Select Back and correct the source CSV if any required header, email, or mapping is wrong. Expected: The corrected preview contains the intended row count and no unexplained errors. Compare preview emails with Users and GymCore Students \u0026gt; Students. Existing emails will be skipped, not updated. Expected: You know which rows will create new accounts and which will remain unchanged. Select Import Members once. Expected: The result screen reports imported, skipped, and failed rows. The importer attempts every row rather than rolling back the entire file. Select Download Error Report (CSV) when errors exist and store it in the approved restricted location. Expected: Every failed row has a row number and reason for correction; do not rerun successful rows as a second full file. Verify a small sample plus every exception in Users and GymCore Students \u0026gt; Students. Expected: Each imported email exists once and its supported profile metadata matches the CSV. Impact, recovery, and privacy Imported rows create WordPress users and apply supported member metadata. The importer does not migrate gateway tokens, orders, subscriptions, family relationships, consent evidence, or every field from another platform. Do not delete imported users as an automatic rollback. If the mapping was wrong, stop and reconcile by user ID with an approved correction plan; deletion can orphan downstream data. The CSV contains personal data. Restrict access, use encrypted transfer/storage approved by the gym, and retain the source/error files only for the documented migration period. Troubleshooting and final verification Missing required column(s) means the header names do not exactly match the required lowercase names after trimming. An invalid email row is reported and skipped; other valid rows may still import. A high skipped count usually means those emails already exist. Compare IDs rather than changing emails to force duplicates. Reopen Users, GymCore Students \u0026gt; Students, and the saved result/error report. Those are the final sources; the five-row preview is not full post-import evidence. Related guides Add or edit a member account Verify the site before launch Create and verify a membership product Verify in the source systems Reopen GymCore Setup \u0026gt; Import Members for the final import summary and error report, then verify sampled users in Users and in the GymCore student roster. The CSV preview is not the final source after import. Source-verified: src/Members/MemberImportPage.php, ImportController.php, and MemberImporter.php for access, labels, headers, five-row preview, skip, and error behavior.","headings":["Purpose","Access and dependencies","Prepare the file","Preview and import","Impact, recovery, and privacy","Troubleshooting and final verification","Related guides","Verify in the source systems"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/import-members.md"},{"route":"/docs/members-families-member-parent-portals/","slug":"members-families-member-parent-portals","title":"Use member and parent portals","summary":"Use member and parent portals.","text":"Purpose Read the signed-in user’s training, badges, pause, and family summaries without exposing another account’s data. Access and dependencies For: Member or parent/guardian\u0026lt;br\u0026gt; Access: Signed-in WooCommerce My Account user\u0026lt;br\u0026gt; Dependencies: WooCommerce My Account endpoints registered; GymCore source records linked to the current WordPress user This is primarily a read-only workflow. A portal summary has no commit button; Pause My Membership is the separate consequential exception. Read the portal Sign in through WooCommerce My Account with your own account. Expected: My Account shows only endpoints registered for this user and the active extensions. Open the installed training/dashboard endpoint and My Badges to review rank, attendance, schedule, streak, and badges. Expected: The summaries belong to the signed-in numeric user ID. Labels can vary with the installed theme/build. If you are an adult with linked children, open My Kids. Expected: Each linked child card shows Belt Rank, Total Attendance, and Eligible for Promotion; no relationship can be edited here. If Pause My Membership is available, stop and read Pause or cancel a membership safely before submitting it. Expected: Merely opening the pause page does not change a subscription or pause record. Ask staff to compare any disputed value with the GymCore member/rank/attendance record or WooCommerce subscription. Expected: The owning source—not the portal card—determines the correction. Limits and privacy Portal endpoints depend on current plugin/theme routing and the user’s linked records. My Kids is conditional; its absence does not prove the child was deleted. Promotion eligibility inherits the current threshold-store mismatch and is advisory. Never ask a member or parent to share a password. Use account-recovery controls and numeric user IDs. A wrong-child display is an access incident, not a cache issue; preserve evidence without circulating the child’s personal details. Troubleshooting If an endpoint returns 404 after activation/update, ask an administrator to verify permalinks and the current endpoint registration; do not create a duplicate page or user first. If data belongs to another person, sign out immediately and report the two user IDs through the privacy process. If rank, attendance, badge, or subscription status is stale, capture the portal label/time and compare the source record before clearing caches or changing data. Verify in the source systems Staff should reopen the matching GymCore profile, attendance/rank history, family relationship store, or WooCommerce subscription. Portal display alone is not final proof. Related guides Verify parent and child access Pause or cancel a membership safely Verify badges, streaks, and milestones Source-verified: current src/Member portal classes and My Account templates. Endpoint availability and theme labels require installed-version verification.","headings":["Purpose","Access and dependencies","Read the portal","Limits and privacy","Troubleshooting","Verify in the source systems","Related guides"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/member-parent-portals.md"},{"route":"/docs/members-families-memberships/","slug":"members-families-memberships","title":"Create and verify a membership product","summary":"Create and verify a membership product.","text":"Purpose Create the WooCommerce product that owns membership price and billing terms, then verify any GymCore access metadata shown by the installed build. Access and dependencies For: Gym owner or commerce manager\u0026lt;br\u0026gt; Capability: manage_woocommerce plus WooCommerce product-edit capability\u0026lt;br\u0026gt; Dependencies: WooCommerce active; WooCommerce Subscriptions active only when recurring billing is required; approved price, tax, terms, program, and location Create the product Open Products \u0026gt; Add New, enter the Product name, and choose the product type that matches the approved terms. Expected: The editor shows WooCommerce fields for that type. Recurring fields appear only when the installed subscription extension supplies them. In Product data \u0026gt; General, enter Regular price or the installed subscription price/billing fields. Configure tax, purchase, trial, and sign-up-fee fields only when they are part of the approved offer. Expected: The on-screen totals/terms match the written offer before publication. Set any GymCore program or location fields exposed on this product, then select Publish. Expected: WooCommerce reports that the product was published and assigns one product ID. Reopen the product and verify status, catalog visibility, price, billing interval, tax, program, and location metadata. Expected: The saved product is the source for checkout. A legacy location-filter option may affect covered archive/shortcode queries, but its control is not rendered by the current Locations owner; checkout and custom query enforcement still require installed verification. Use only the gateway/provider’s approved non-production verification method. If no such test is installed, review the live configuration without placing a charge. Expected: Any executed test has one WooCommerce order and provider result; otherwise the untested runtime claim is recorded honestly. Impact, recovery, and privacy Publishing makes the product eligible for catalog/checkout behavior defined by WooCommerce. Editing is reversible, but changing price or billing terms does not necessarily rewrite existing subscriptions. Trashing a product can affect checkout links and reports; record the product ID and prior values first. Do not store card details, gateway keys, or private contract notes in product content. Public product pages must state recurring terms, trial/sign-up fees, cancellation rules, and location limits clearly. Troubleshooting If recurring fields are absent, verify WooCommerce Subscriptions is installed and active; do not label a simple product as recurring in prose alone. If the wrong location sees the product, inspect the active location, product taxonomy assignments, and whether the member-facing surface uses a covered WooCommerce archive/shortcode query. Test cart and checkout separately. If checkout and the product editor disagree, stop sales and compare product ID, variation, tax, currency, and extension/provider logs. Verify in the source systems Reopen the WooCommerce product and, if an approved test was executed, its order, subscription, and gateway event. GymCore access should then be checked with the same test member ID. Related guides Pause or cancel a membership safely Set your gym profile and locations Know which system owns the change Source-reviewed: WooCommerce remains the commerce source; Gym Core 2.1.0 location filtering covers archive/product-shortcode queries only. Installed extension, cart/checkout, custom-query, and gateway behavior remains runtime-dependent.","headings":["Purpose","Access and dependencies","Create the product","Impact, recovery, and privacy","Troubleshooting","Verify in the source systems","Related guides"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/memberships.md"},{"route":"/docs/members-families-pauses-cancellations/","slug":"members-families-pauses-cancellations","title":"Pause or cancel a membership safely","summary":"Pause or cancel a membership safely.","text":"Purpose Separate a GymCore pause request from WooCommerce subscription status so access and billing do not drift. Access and dependencies For: Member using self-service, or staff with commerce responsibility\u0026lt;br\u0026gt; Access: Signed-in member for My Account \u0026gt; Pause My Membership; manage_woocommerce for staff-side pause and subscription review\u0026lt;br\u0026gt; Dependencies: An active WooCommerce subscription for the pause form, plus an approved pause/cancellation policy Pause a membership Open the matching record under WooCommerce \u0026gt; Subscriptions and note its ID, status, next payment date, and gateway state. Expected: One subscription is identified before any pause request. In My Account \u0026gt; Pause My Membership, select Subscription, Reason for pausing, and an Expected return date from tomorrow through December 31, within the remaining annual allowance. Expected: The form shows the used/allowed days and accepts a date within the configured limit. Select Pause My Membership once. Expected: The page reports Your membership has been paused and Pause History shows an Active record. Reopen the WooCommerce subscription and the member’s GymCore access. Expected: Billing and access show the intended state. Do not assume the pause message alone proves the gateway or subscription changed. Resume or cancel To end an active pause, select Resume My Membership Now and confirm Resume your membership now? Expected: Pause History shows Resumed; verify the subscription status and next payment date separately. To cancel recurring billing, use the authorized action on WooCommerce \u0026gt; Subscriptions, not a GymCore note or pause status. Expected: WooCommerce records the new subscription status and an order/subscription note. Gateway timing and refunds remain provider-dependent. Defaults, impact, and recovery Annual freeze limit (days) defaults to 60 and accepts 1–365 under GymCore Settings \u0026gt; Billing. The return date cannot be earlier than tomorrow or later than the current year in the member form. Pause/resume actions are recorded in GymCore and can affect access; cancellation affects recurring commerce. A resumption or reactivation may not undo gateway timing or charges. Preserve subscription notes and pause history instead of deleting them. Reasons can reveal health, travel, or family information. Limit access and do not copy free-text explanations into broad staff notes or messages. Troubleshooting and source verification If no subscription is listed, compare the signed-in user ID with the WooCommerce subscription customer ID. If the annual allowance is exhausted, do not change dates or user IDs to bypass it; route the exception through policy and an authorized administrator. If GymCore and WooCommerce disagree, stop retries and capture pause ID, subscription ID, statuses, next-payment date, timestamp, and provider event. Final evidence is the combination of Pause History, the WooCommerce subscription/order notes, member access, and any gateway event—not the success banner alone. Related guides Create and verify a membership product Use member and parent portals Know which system owns the change Verify in the source systems Confirm the pause or cancellation in Pause History, the WooCommerce subscription or order, member access, and the payment provider when billing changed. A portal confirmation alone is not proof of a gateway-side result. Source-verified: src/Admin/Settings.php, src/Admin/MemberPauseAdmin.php, templates/my-account/pause-membership.php, and assets/js/member-pause.js. Gateway effects require installed-provider verification.","headings":["Purpose","Access and dependencies","Pause a membership","Resume or cancel","Defaults, impact, and recovery","Troubleshooting and source verification","Related guides","Verify in the source systems"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/pauses-cancellations.md"},{"route":"/docs/members-families-waivers/","slug":"members-families-waivers","title":"Publish and collect a waiver version","summary":"Publish and collect a waiver version.","text":"Purpose Draft counsel-approved waiver text, preview its impact, deliberately publish one immutable version, and verify current signature evidence. Access and dependencies For: gym owner plus authorized legal/operations reviewer\u0026lt;br\u0026gt; Capabilities: gymcore_view_waiver_versions to view; gymcore_manage_waiver_drafts to draft/preview; gymcore_publish_waiver_versions to publish or prepare a forward rollback\u0026lt;br\u0026gt; Dependencies: approved text/policy, named publication reason, reviewed affected/unknown cohort counts, fictional non-production acceptance fixtures, and a rollback owner Publishing changes the active immutable publication. Saving a draft never does. GymCore Settings \u0026gt; Waiver redirects to Waiver Versions and has no save action; internal legacy options are guarded compatibility projections. Draft and preview Open GymCore Students \u0026gt; Waiver Versions. Record the active publication ID and pointer revision. Enter the approved Version label, Waiver text, Acknowledgement version, Signature mode, optional Form fields (JSON), and Change summary. Select Save draft. Expected: the draft revision advances and the active publication remains unchanged. Select Generate impact preview. Expected: GymCore reports affected and unknown-identity counts, validates the draft/current pointer, and provides a short-lived preview only when publication is ready. Stop if impact is unavailable, unknown identities remain, the cap is exceeded, or the draft/pointer changed. Publish Review the exact rendered waiver/policy and cohort evidence with the publication owner. Enter the required publication reason and the displayed PUBLISH \u0026lt;version label\u0026gt; phrase. Select Publish immutable version once. Expected: one immutable publication becomes active, prior publications remain unchanged, and audit/outbox evidence records the transition. A stale or repeated mismatched request fails closed. Open GymCore Students \u0026gt; Waivers \u0026gt; Missing Current Waiver. Expected: the page identifies the active publication and subjects without current evidence. On approved non-production infrastructure, have a fictional member/guardian complete the exact signing flow. Expected: the signature source records the signer, active publication/version evidence, timestamp, and required drawn signature or acknowledgement. The portal confirmation alone is not proof. Forward rollback Under Forward rollback preview, enter a prior publication ID and reason. GymCore copies that publication into a new draft; it does not rewrite history or directly move the pointer backward. Generate a new impact preview and use the normal typed publish gate. Privacy and recovery Waiver text, identity links, and signatures are sensitive legal records. Restrict exports/screenshots and never paste signatures into support messages. Do not delete evidence or edit legacy options to repair one member. Preserve publication IDs, pointer revisions, draft revisions, and audit records when investigating. Verify in source systems Reopen Waiver Versions, Missing Current Waiver, and the fictional signature record. Confirm the active publication/pointer, rendered policy, subject status, and signature evidence agree. Related guides Waiver settings reference Verify parent and child access Use member and parent portals Verify the site before launch Source-reviewed: current immutable waiver owner, REST capability boundaries, publication service, repository, and evidence screen on 2026-07-28. No production publication or signature is claimed.","headings":["Purpose","Access and dependencies","Draft and preview","Publish","Forward rollback","Privacy and recovery","Verify in source systems","Related guides"],"source_sha256":"","section":"Members \u0026 Families","source":"docs/user-guide/members-families/waivers.md"},{"route":"/docs/privacy-security-access-audit-logs/","slug":"privacy-security-access-audit-logs","title":"Review AI action history and source records","summary":"Review AI action history and source records.","text":"Purpose Trace an AI proposal from creation through review and execution, then confirm the result in the system that owns the record. GymCore does not provide one consolidated audit screen for every feature. Audience and access For: Gym owners, site administrators, and authorized reviewers\u0026lt;br\u0026gt; Access needed: manage_woocommerce to open the AI hub and manage_options to see Audit Log\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; AI \u0026gt; Audit Log The AI Audit Log is read-only. Filter changes the displayed rows; no commit, edit, approval, or retry button exists on this page. Before you start Record the approximate event time and timezone, affected source record ID, staff account, and expected result. Decide which system owns the final truth: GymCore for attendance/ranks, WooCommerce for orders/subscriptions, or the relevant messaging, payment, CRM, or publishing provider. Do not use an audit row as permission to expose the member or financial data it contains. Exact steps Safe stop: This investigation has no commit button. Filter and compare records without approving, rejecting, replaying, or editing the underlying action. Open GymCore Admin \u0026gt; AI \u0026gt; Audit Log. Expected: The page shows All Statuses, All Agents, Filter, and a table with ID, Agent, Action, Status, Detail, Reviewer, Created, and Reviewed. It displays 20 rows per page by default. Choose the relevant status and agent, then select Filter. Expected: The table reloads with matching rows only. Available statuses are Pending, Approved, Approved with Changes, Completed, and Rejected. Match the action ID, Created time, action type, and detail to the event you are investigating. Expected: One row identifies the proposal. Filtering or opening the page does not change it; there is no commit button. Interpret the status conservatively: Pending has not been approved. Approved may still contain an execution error. Approved with Changes stores staff instructions and still needs a separate completion path. Completed means the tool returned successfully. Rejected was not executed through the approval path. Expected: The reviewer and reviewed time appear only after a decision. A status does not prove a downstream provider result. Open the owning source record and any related provider log or transaction. Expected: The record ID, value, amount, recipient, and provider outcome match the intended action exactly once. If they do not, preserve the action ID and stop before retrying. For non-AI activity, use the feature’s own history: for example, a member profile’s audit/rank/attendance tabs, WooCommerce order notes, waiver rows, consent events, or provider logs. Expected: The feature-specific history and source record agree. Current source does not register a general GymCore audit-log page that combines all of these records. Expected result You can explain who reviewed the AI proposal, its recorded status, and what the owning source system shows. No read-only inspection has changed a record. Defaults and limits Behavior Current source behavior Access Administrator-only manage_options tab inside an AI hub gated by manage_woocommerce Page size 20 rows Default filters All Statuses and All Agents Data source Pending-action table, including reviewed and completed rows Automatic retention No configurable purge for action/audit rows General GymCore audit screen Not registered Side effects and privacy Reading the page does not mutate records, but rows can expose names, message content, refund reasons, target IDs, and operational details. Limit screenshots and exports to the incident owner. Conversation retention does not purge the action rows shown in this Audit Log. Recover by symptom Audit Log is missing Confirm GymCore and Gym Core AI are active. The AI hub requires manage_woocommerce; the Audit Log tab additionally requires manage_options. Correct the user’s role instead of sharing an administrator login. No actions are found Reset to All Statuses and All Agents, check the event timezone, and move through pagination. If the task never created a pending action, inspect chat tool details and the source system rather than inventing an audit ID. The row is Approved but the source did not change Treat it as incomplete. Capture the action ID and detail, check for execution_error in the stored action or logs, and confirm the source record before any retry. The row is Completed but a provider shows no result Use the provider as the source of truth for settlement, delivery, or publication. Collect the provider request/transaction ID, action ID, timestamps, and stored tool result for escalation. Related guides Review and decide an AI-proposed action Protect AI data and connections Collect diagnostics and contact support Review roles and permissions Source review: checked-out gym-core-ai and gym-core PHP on 2026-07-13. The page structure is source-backed; no installed-version task success is asserted.","headings":["Purpose","Audience and access","Before you start","Exact steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","Audit Log is missing","No actions are found","The row is Approved but the source did not change","The row is Completed but a provider shows no result","Related guides"],"source_sha256":"","section":"Privacy, Security \u0026 Access","source":"docs/user-guide/privacy-security-access/audit-logs.md"},{"route":"/docs/privacy-security-access-backup-deactivate-uninstall/","slug":"privacy-security-access-backup-deactivate-uninstall","title":"Back up, deactivate, or remove GymCore","summary":"Back up, deactivate, or remove GymCore.","text":"Purpose Create a recoverable copy before an outage or removal, understand what deactivation preserves, and avoid treating WordPress deletion as a complete privacy purge. Audience and access For: Gym owners, site administrators, hosting administrators, and database/CLI operators\u0026lt;br\u0026gt; Access needed: WordPress activate_plugins to deactivate or delete; host backup access; server shell access only for the optional GymCore backup command\u0026lt;br\u0026gt; Open: Plugins \u0026gt; Installed Plugins Before you start Name the decision owner, maintenance window, restore owner, and rollback deadline. Obtain a full host-level database and wp-content backup. The GymCore CLI archive covers GymCore custom-table rows only; it is not a full WordPress, uploads, WooCommerce, user-meta, or provider backup. Inventory active memberships, scheduled payments, check-in/kiosk use, outbound jobs, integrations, and reports that will stop or change. Test the restore on staging before deleting production data. Exact steps Safe stop: Complete and test the backup restore first; stop before Deactivate or Delete until the inventory, maintenance window, retention decision, and restore owner are approved. Create a full site backup in the hosting or approved backup system and record its ID, completion time, storage location, and retention date. Expected: The backup system reports success and the restore owner can locate the database and files. A backup job merely starting is not verification. Ask the restore owner to restore that backup to staging and compare a sample member, order, attendance row, rank history, uploaded file, and scheduled job. Expected: The restored source records match production at the backup time. If the restore has not been tested, stop before deletion. Optionally, have a server operator run wp gymcore backup \u0026lt;tenant_id\u0026gt; for an additional GymCore custom-table archive. Expected: WP-CLI reports Backup written to: followed by a .gymcore path under wp-content/uploads/gymcore-backups/\u0026lt;tenant_id\u0026gt;/. Keep the archive and its encryption requirements with the restore plan. On staging, open Plugins \u0026gt; Installed Plugins and select Deactivate for Gym Core. Expected: Gym Core becomes inactive. Current source removes the four custom GymCore roles, unschedules named GymCore cron events, and flushes rewrite rules; custom-table data remains. Verify staging sign-in, WooCommerce orders/subscriptions, member accounts, front-end pages, scheduled actions, integrations, and any process that depended on a removed GymCore role. Expected: The outage and access effects match the approved plan. Reactivate on staging and confirm required roles and schedules return before touching production. If only a temporary stop is required, select Deactivate on production during the approved window and stop there. Expected: Runtime behavior stops as above, but data is preserved for reactivation. Deactivation is not erasure. If permanent removal is approved and the restore test passed, select Delete for the inactive Gym Core plugin and confirm WordPress’s deletion prompt. Expected: WordPress runs uninstall.php, which drops GymCore custom tables and deletes only gym_core_settings, gym_core_version, gym_core_activated, and gym_core_db_version in the checked-out source. Do not assume every GymCore-prefixed option, user-meta value, WooCommerce record, upload, backup, or third-party copy is removed. Compare the final site and database inventory with the approved removal checklist and preserve the restore evidence. Expected: The intended plugin files and source-handled tables are gone, required WordPress/WooCommerce data remains, and any residual data has an explicit retention or follow-up owner. Expected result The site has a tested restore point. Deactivation is reversible and data-preserving; deletion is destructive for source-handled custom tables but is not documented as a complete site-wide or privacy erasure. Defaults and limits Operation Current source behavior Deactivate Preserves data, removes GymCore custom roles, unschedules named jobs, flushes rewrite rules CLI backup Encrypted per-tenant archive of GymCore custom tables only CLI restore Upserts archive rows; tenant ID must match Delete through WordPress Runs uninstall handler and drops GymCore custom tables Options explicitly deleted Four named options only User meta, WooCommerce, uploads, providers Not comprehensively removed by the uninstall handler Side effects and privacy Backups and CLI archives contain sensitive member and operational data. Restrict access, encrypt storage, and set a deletion date. Removing custom roles can immediately change staff access. Deleting the plugin removes source-handled custom-table records and may be irreversible after backup expiration. Recover by symptom A backup completed but cannot be restored Do not deactivate or delete production. Capture the backup ID and restore error, verify encryption keys and storage access, and create a new tested full-site backup. Staff lose access immediately after deactivation This matches the source’s removal of gym_head_coach, gym_coach, gym_finance, and gym_sales. Reactivate Gym Core through an administrator account, then verify role assignments and capabilities before reopening the site. Scheduled work continues after deactivation Check WooCommerce Scheduled Actions and WordPress cron for the exact hook. GymCore deactivation clears a named list, but third-party and WooCommerce jobs have separate owners. Do not delete jobs until their source and retry behavior are known. Data is missing after Delete Stop writes and restore the tested backup to staging first. Use wp gymcore restore \u0026lt;tenant_id\u0026gt; \u0026lt;file\u0026gt; only for a matching GymCore CLI archive and only with a server operator; it does not restore the rest of WordPress. A privacy owner expects complete erasure Review WordPress users/meta, WooCommerce orders, uploads, AI action history, backups, and third-party systems separately. The current uninstall handler is not a complete personal-data eraser. Related guides Process a privacy request Collect diagnostics and contact support Troubleshoot installation and setup Review product boundaries Source review: checked-out gym-core PHP on 2026-07-13. Restore steps are requirements for the operator; this source review did not execute an installed-site restore.","headings":["Purpose","Audience and access","Before you start","Exact steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","A backup completed but cannot be restored","Staff lose access immediately after deactivation","Scheduled work continues after deactivation","Data is missing after Delete","A privacy owner expects complete erasure","Related guides"],"source_sha256":"","section":"Privacy, Security \u0026 Access","source":"docs/user-guide/privacy-security-access/backup-deactivate-uninstall.md"},{"route":"/docs/privacy-security-access-credentials-webhooks/","slug":"privacy-security-access-credentials-webhooks","title":"Manage credentials and webhooks safely","summary":"Manage credentials and webhooks safely.","text":"Purpose Put each secret in its owning settings area, test only the connection you changed, and rotate access without exposing the value. In plain language: decide who owns the service, save its credential in the supported place, confirm one harmless connection, and revoke the old access. Audience and access For: Gym owners coordinating the change, WordPress administrators, and the technical owner of each provider\u0026lt;br\u0026gt; Access needed: manage_options for Integrations and GymCore AI settings; gymcore_manage_communications or manage_options for the SMS provider destination; server access only for wp-config.php or environment secrets\u0026lt;br\u0026gt; Common paths: GymCore Admin \u0026gt; Integrations, GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers, and GymCore Admin \u0026gt; AI \u0026gt; Settings Before you start Name the credential owner, provider account, affected production connection, maintenance window, and rollback credential. Use staging and a harmless provider account or destination where possible. Obtain the exact provider fields and, for inbound AI webhooks, the sender’s production network addresses before changing enforcement. Keep secrets out of chat, screenshots, browser-console captures, tickets, and command history. Exact steps Safe stop: Enter or review new credentials only in the approved admin field, but stop before Save \u0026amp; Connect, Save changes, secret rotation, or enforcement changes until the provider owner and rollback credential are ready. Connect a registered GymCore integration Open GymCore Admin \u0026gt; Integrations and locate the provider card. Expected: The card shows Connected or Not Connected and one of Connect, Test Connection, or Disconnect. If the page says no integrations are registered, no customer form exists for that provider. For a new connection, select Connect, complete the provider-labelled fields, and select Save \u0026amp; Connect. Expected: The card changes to Connected. Password-type fields are determined by the registered provider schema; do not assume every field is a secret. Select Test Connection. Expected: The card reports Healthy or Unhealthy. Connected means configuration was saved; only Healthy reports the current health response, and neither proves a future delivery or sync. When revoking access, disable or rotate the credential at the provider first, then select Disconnect and confirm Disconnect this integration? Expected: The card returns to Not Connected. Verify the provider no longer accepts the old credential. Update Twilio credentials Open GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers as a site administrator. The current owner renders the Twilio credential form, rate limit, readiness result, and explicit Send test SMS action. Expected: The page masks the stored token and separates saved configuration, readiness, test acceptance, and carrier delivery. Rotate or enter credentials only through that approval-gated owner workflow. Never edit the old options directly. Use the installed test action at most once with the current administrator’s staff-controlled billing phone. Expected: GymCore and Twilio show the same message SID and destination. Provider acceptance is not carrier delivery; verify Twilio’s final status. Configure the AI provider and Slack Configure the approved provider through Settings \u0026gt; Connectors. GymCore AI does not read or copy the provider credential. Expected: GymCore Admin \u0026gt; AI \u0026gt; Connections \u0026amp; Security \u0026gt; Provider and model lists only configured providers. Refresh the catalog, save the exact model draft, run readiness, and activate it. Do not restore the retired GymCore AI credential option. For approval alerts, enter the restricted URL under Slack incoming webhook URL, choose whether to enable Include action summary in Slack, and select Save Changes. Expected: Only an HTTPS hooks.slack.com URL is accepted. This credential sends alerts; it does not authenticate inbound AI actions. Protect the inbound AI webhook First, tell the external automation owner that you are rotating its shared secret and restricting the network addresses allowed to connect. Agree on the five-minute cutover and rollback owner. Expected: The owner has the correct production sender addresses and is ready to update the secret immediately. Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; Webhook \u0026amp; Security. Enter one sender address per line under IP Allowlist and select Enforce IP allowlist. Expected: With enforcement on, an empty list blocks all webhook traffic. The screen uses the server-observed source address; a reverse proxy must set that address correctly. Select Generate Secret for a first connection or Rotate Secret for an existing one, then confirm the prompt. Expected: The new secret is shown once in an admin notice. During rotation, the previous and new secrets are accepted for five minutes. Transfer the new secret through the approved secret channel, update the external sender, and select Save Changes for the allowlist settings. Expected: A staging request from an allowed address with a current signature succeeds; a stale, altered, or disallowed request is rejected. Do not claim this test unless the installed staging request was actually run. After five minutes, repeat one staging request using only the new secret and verify the intended source record or action status. Expected: The old secret no longer authenticates after cleanup, and the new request produces the expected local record exactly once. Expected result Each service uses one supported credential location, the old access is revoked, a harmless connection check has a recorded result, and the final provider or source record confirms what happened. Defaults and limits Area Current source behavior Integration cards Administrator-only; registered provider schema controls fields Twilio token Legacy option may exist, but the current customer UI does not render a supported replacement field AI provider key Owned by WordPress and the registered provider plugin under Connectors; Gym Core AI does not read or store it Slack URL HTTPS hooks.slack.com only; blank disables Slack Inbound webhook secret 64 hexadecimal characters when generated Secret rotation overlap 5 minutes IP enforcement On by default in current validator; on + empty list denies all Client address Server REMOTE_ADDR; forwarded headers are not trusted by the validator Technical handoff The inbound automation signs the timestamp and raw request body with the shared secret and sends the result in X-HMA-Signature. This HMAC signature expires after five minutes and is separate from a WordPress REST nonce, which protects actions taken by a signed-in administrator. A legacy bearer-token path remains in source but lacks timestamp replay protection and should not be used for new connections. “Egress IP” means the network address the external sender uses when it leaves its service; it belongs in IP Allowlist. Side effects and privacy Saving a credential can grant access to messages, accounting, AI prompts, or member records. Connection tests can create provider logs, billable requests, or external messages. Secret rotation can interrupt automation; leaving enforcement off with an empty allowlist accepts any source address that has a valid signature. Provider retention is separate from GymCore retention. Recover by symptom Connect saves but Test Connection is Unhealthy Do not reconnect repeatedly. Confirm the provider account, required fields, network access, clock, and provider status. Capture only the sanitized health error and provider request ID. A Twilio test succeeds locally but no phone receives it Check Twilio’s message status, sender selection, destination E.164 value, account restrictions, consent, and carrier rejection. The local response is not delivery proof. The webhook returns 401 or 403 after rotation Confirm the external sender uses the new secret, its clock is within five minutes, the raw body is unchanged after signing, and the server-observed source address is allowed. Do not turn off enforcement on production as a diagnostic shortcut. The new secret was exposed Rotate again, update the sender within the five-minute overlap, revoke screenshots/logs where possible, and review webhook requests during the exposure window. A credential field is missing Use the owning surface above. A provider absent from Integrations has no registered customer form. Do not write options directly or add secrets to an undocumented field. Related guides Configure approval notifications Protect AI data and connections Troubleshoot integrations and APIs Collect diagnostics and contact support Source review: checked-out gym-core and gym-core-ai PHP/JavaScript on 2026-07-13. Connection outcomes must be recorded from the installed staging environment; none are fabricated here.","headings":["Purpose","Audience and access","Before you start","Exact steps","Connect a registered GymCore integration","Update Twilio credentials","Configure the AI provider and Slack","Protect the inbound AI webhook","Expected result","Defaults and limits","Technical handoff","Side effects and privacy","Recover by symptom","Connect saves but Test Connection is Unhealthy","A Twilio test succeeds locally but no phone receives it","The webhook returns 401 or 403 after rotation","The new secret was exposed","A credential field is missing","Related guides"],"source_sha256":"","section":"Privacy, Security \u0026 Access","source":"docs/user-guide/privacy-security-access/credentials-webhooks.md"},{"route":"/docs/privacy-security-access-privacy-requests/","slug":"privacy-security-access-privacy-requests","title":"Export or erase a member\u0027s GymCore data","summary":"Export or erase a member\u0027s GymCore data.","text":"Purpose Use WordPress’s personal-data workflow to export or erase the GymCore data associated with a verified email address, then review records that GymCore does not remove. Audience and access For: The approved privacy-request owner and site administrator\u0026lt;br\u0026gt; Access needed: WordPress privacy-tool access (manage_privacy_options); gym_manage_data_privacy, or the administrator fallback manage_options, to use the GymCore Settings \u0026gt; Data \u0026amp; Privacy destination\u0026lt;br\u0026gt; Open: Tools \u0026gt; Export Personal Data or Tools \u0026gt; Erase Personal Data Before you start Verify the requester’s identity outside the email address being searched and record the approved scope. Check legal, tax, payment, safeguarding, and dispute-retention requirements with the responsible owner. Identify the WordPress account email and related WooCommerce, CRM, AI, messaging, payment, backup, and provider records. Export before erasing when policy permits. Erasure cannot be undone from the live source without a restore, and backups follow their own expiry schedule. Exact steps Safe stop: Create and review an export request first; stop before the visible erasure action until identity, scope, required retention, and the owning systems outside GymCore are approved. Export the data Open Tools \u0026gt; Export Personal Data in WordPress. Expected: WordPress opens its personal-data export tool. GymCore Admin \u0026gt; GymCore Settings \u0026gt; Data \u0026amp; Privacy manages retention policies and is not the person-specific export screen. Enter the verified username or email and use the visible WordPress control to send or add the export request. Expected: WordPress creates a request for that identity. Confirmation and row-action labels are controlled by the installed WordPress version; record the exact visible status rather than assuming completion. After the request is confirmed or otherwise authorized under your site’s process, run the available download/email action. Expected: The package includes GymCore groups named Gym Profile, Attendance Records, Rank History, and Billing History when matching data exists. GymCore completes its exporter in one page. Review the package against the member profile, attendance history, rank history, and WooCommerce orders. Expected: The exported source IDs and values match the live records. Separately collect data from CRM, GymCore AI action history, Slack, Twilio, payment providers, and other systems when the request covers them. Erase the data Open Tools \u0026gt; Erase Personal Data in WordPress. Expected: WordPress opens its erasure tool. No data has been erased yet. Enter the verified username or email and create the WordPress erasure request. Complete the required confirmation/authorization step. Expected: WordPress records a pending or confirmed erasure request according to the installed version. Stop if the identity or approved scope does not match. Run the visible erasure action for the confirmed request. Expected: GymCore changes attendance rows to user ID 0 to keep aggregate counts, deletes current-rank and rank-history rows, and deletes its listed member user-meta keys. It does not erase WooCommerce orders through the GymCore eraser. Reopen the member’s GymCore profile/history and inspect the WordPress request result. Expected: Personal links are absent from the GymCore data handled by the eraser, attendance aggregates remain anonymized, and any error is recorded before another attempt. Review WooCommerce orders, the WordPress account, CRM records, AI conversations and action history, Slack/SMS copies, payment/provider data, exports, and backups under their own retention rules. Expected: Every in-scope store is either erased/anonymized, retained under a documented basis and expiry, or assigned a follow-up owner. GymCore conversation retention does not prove removal of pending actions or audit history. Expected result The requester receives a source-checked export or the approved GymCore data is erased/anonymized as the current eraser defines. Remaining systems and retained records have explicit dispositions. Defaults and limits Area Current source behavior Lookup key WordPress username/email workflow; GymCore callback resolves by email GymCore exporter One page; returns profile, attendance, rank history, and WooCommerce billing history Attendance erasure Anonymizes user_id to 0; retains aggregate row Rank erasure Deletes current rank and rank-history rows Profile erasure Deletes the eraser’s listed GymCore user-meta keys WooCommerce orders Exported by GymCore, not erased by the GymCore eraser AI actions/audit, providers, backups Separate review required Side effects and privacy Exports consolidate sensitive profile, medical/coach-note, attendance, rank, and billing data into a portable package. Restrict the download, delivery address, storage, and expiry. Erasure is destructive, while anonymized attendance still preserves non-personal class totals. Never attach the full package to an ordinary support ticket. Recover by symptom The WordPress privacy tool is missing Use an account with manage_privacy_options, normally a WordPress administrator. GymCore Admin \u0026gt; GymCore Settings \u0026gt; Data \u0026amp; Privacy is a separate retention-policy surface and does not replace the WordPress export or erasure tools. The export contains no GymCore groups Confirm the email belongs to the intended WordPress user and GymCore is active so its exporter is registered. Compare the user ID with member, attendance, rank, and order sources before creating a duplicate account. Erasure reports success but orders remain That is expected from the GymCore eraser: it does not delete WooCommerce orders. Apply the approved WooCommerce/legal retention process and document the result separately. Attendance counts remain after erasure GymCore anonymizes attendance rows instead of deleting them. Verify the rows no longer identify the member; do not delete aggregates merely to make counts fall. AI action history still contains personal data Conversation cleanup does not purge pending-action or audit rows. Restrict access, document the retention decision, and escalate a separate action-history remediation; do not edit production action JSON directly. Related guides Review AI action history Back up, deactivate, or remove GymCore Protect AI data and connections Collect diagnostics and contact support Source review: checked-out gym-core GDPR PHP on 2026-07-13. WordPress row-action labels must be confirmed on the installed version; no completed customer request is fabricated.","headings":["Purpose","Audience and access","Before you start","Exact steps","Export the data","Erase the data","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","The WordPress privacy tool is missing","The export contains no GymCore groups","Erasure reports success but orders remain","Attendance counts remain after erasure","AI action history still contains personal data","Related guides"],"source_sha256":"","section":"Privacy, Security \u0026 Access","source":"docs/user-guide/privacy-security-access/privacy-requests.md"},{"route":"/docs/privacy-security-access-roles-capabilities/","slug":"privacy-security-access-roles-capabilities","title":"Assign and verify staff access","summary":"Assign and verify staff access.","text":"Purpose Give each staff member the smallest role and GymCore permission set needed for their work, then verify both allowed and forbidden screens with that role. Audience and access For: Gym owners and WordPress administrators responsible for staff access\u0026lt;br\u0026gt; Access needed: gymcore_manage_staff, or the administrator fallback manage_options, to view or save GymCore Settings \u0026gt; Staff Access\u0026lt;br\u0026gt; Open: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access Before you start Use an individual WordPress account for each staff member; never share an owner account. List the exact tasks, records, locations, and end date the person needs. Keep a separate administrator available for recovery and prepare a non-production test account for the target role. Review the complete permissions reference because Staff Access controls only four newer permissions, not every GymCore, WordPress, or WooCommerce check. Exact steps Safe stop: Configure and test the target role on staging first; stop before applying Save Role Permissions on production until the approved task list and recovery administrator are confirmed. Open Users \u0026gt; All Users, edit the staff account, and choose the closest role: Administrator, Shop manager, Head Coach, Coach, Finance Admin, or Sales. Save the user. Expected: The user profile reloads with the selected role. Do not choose Administrator solely to make a missing GymCore menu appear. Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access. Expected: A matrix lists WordPress roles against Manage Members, Manage Billing, View Reports, and Manage Staff. Administrator checkboxes are selected and disabled because administrators always receive all four. For each role, select only the four permissions required by the approved task list. Use the preset buttons only when the complete preset matches the role; the current preset control asks for the role slug. Expected: The matrix reflects the intended grants before anything is saved. Presets change the visible checkboxes only until the form is submitted. Select Save Role Permissions. Expected: WordPress reports Role permissions saved. The saved map applies to every user with each edited role. Sign in to staging with the target test account and open every required menu and action. Then try at least one member, billing, report, staff, credential, and communication screen that should be forbidden. Expected: Required work is available and forbidden work is denied. A hidden menu alone is not proof of denial; test the action or direct page with the least-privilege account. Compare any unexpected access with the complete permissions reference and the screen’s source-backed capability. Expected: Legacy gym_*, manage_options, manage_woocommerce, edit_posts, edit_users, and other checks explain access that the four-column matrix does not control. Reopen Staff Access with the administrator and compare the saved matrix with the approved access record. Expected: The source configuration matches the approval, the test account has the intended role, and no extra capability was added merely to bypass a product defect. Expected result Each staff account has one appropriate role, the four Staff Access permissions match the approved task list, and staging verifies both required and forbidden behavior. Defaults and limits Role Factory default in the four-column matrix Administrator All four; cannot be cleared on this screen Shop manager Manage Members, Manage Billing, View Reports, Manage Staff Head Coach Manage Members, View Reports, Manage Staff Coach View Reports Finance Admin Manage Billing, View Reports Sales Manage Members The four permissions are gymcore_manage_members, gymcore_manage_billing, gymcore_view_reports, and gymcore_manage_staff. These technical names are useful for an access review, but owners should decide access by job task and data sensitivity first. Side effects and privacy Saving a role row affects every account assigned to that role. Access can expose member identities, attendance, billing, reports, staff records, credentials, or outbound communication. Role changes take effect on capability checks immediately, although a user may need to reload or sign in again to see menu changes. Recover by symptom Staff Access is missing The Settings destination requires gymcore_manage_staff, or the administrator fallback manage_options. Use an approved access owner; do not grant broad access to the affected staff member just so they can edit their own permissions. A required menu is still missing after save Look up that menu/action’s actual capability. The screen may use a legacy gym_*, WordPress, or WooCommerce permission outside the four-column matrix. Grant only the exact approved capability through a supported role path. A staff member can see too much Remove the unnecessary grant, select Save Role Permissions, end active sessions if the risk warrants it, and retest the direct page/action. Review all users assigned to the changed role. A custom GymCore role disappears after deactivation Current deactivation removes Head Coach, Coach, Finance Admin, and Sales roles. Reactivate GymCore with an administrator, then verify role assignments and permissions before staff resume work. A preset changes the wrong role Do not save. Restore the intended checkboxes manually or reload the page, then apply the preset only after entering the exact role slug shown in the permissions reference. Related guides Roles permissions matrix Review AI action history Choose AI personas and access Collect diagnostics and contact support Source review: checked-out gym-core roles, capability, and settings PHP on 2026-07-13. Role behavior still requires installed-version testing with non-administrator accounts.","headings":["Purpose","Audience and access","Before you start","Exact steps","Expected result","Defaults and limits","Side effects and privacy","Recover by symptom","Staff Access is missing","A required menu is still missing after save","A staff member can see too much","A custom GymCore role disappears after deactivation","A preset changes the wrong role","Related guides"],"source_sha256":"","section":"Privacy, Security \u0026 Access","source":"docs/user-guide/privacy-security-access/roles-capabilities.md"},{"route":"/docs/ranks-gamification-badges-streaks-milestones/","slug":"ranks-gamification-badges-streaks-milestones","title":"Verify badges, streaks, and milestones","summary":"Verify badges, streaks, and milestones.","text":"Use the Badges screen to review earned achievements and use Gamification settings for the small set of stored controls. Current source does not provide an administrator button to award every badge manually. Access and dependencies Open the Badges screen with gym_view_achievements. Administrative badge actions, where present, can require manage_options. Change gamification settings under GymCore Admin \u0026gt; GymCore Settings \u0026gt; Gamification with gymcore_manage_settings, or the administrator fallback manage_options. Attendance and other source events must already be accurate; badge and streak output can be wrong when their inputs are wrong. Achievements expose member activity and progress. Share them only with the member, authorized guardians, and staff who need the information. Configure the stored controls Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Gamification. Set Streak freezes from 0 through 4. A new installation defaults to 1. Review Notify members when they earn a badge, which defaults to enabled. Current source stores this value, but no notification consumer was verified; do not promise a message based on the checkbox. Review Enable targeted content, which defaults to enabled and controls targeted-content evaluation rather than badge calculation. Select Save changes. Expected: WordPress reports that settings were saved and the values remain after reload. No badge, streak, or notification should be inferred from this save. Verify an earned achievement Identify the attendance or other source event expected to qualify the member. Open the Badges screen and locate the member or achievement using the installed view. Compare the earned badge, streak, or milestone with the source attendance and its timestamp. Expected: The achievement reflects the intended member and qualifying data. If it does not, correct the source event before attempting a recalculation or support action. If notification is enabled, inspect the actual communication provider or member-facing destination. Expected: Record the runtime behavior observed. A checked Notify members setting is not evidence that a notification was generated or delivered. Reverse or recover Restore the prior gamification settings and select Save changes to reverse configuration. That does not retract achievements or external notifications already produced. For a wrong badge or streak, preserve the member, badge, and source-event identifiers and use the approved correction or recalculation path; do not add false attendance to compensate. Verify in the source systems Use Attendance History or the applicable event store for the qualifying action, the Badges view for the earned achievement, and the communication provider for any notification. All relevant sources must agree; there is no final commit button on the read-only achievement view.","headings":["Access and dependencies","Configure the stored controls","Verify an earned achievement","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Ranks \u0026 Gamification","source":"docs/user-guide/ranks-gamification/badges-streaks-milestones.md"},{"route":"/docs/ranks-gamification-belt-tests/","slug":"ranks-gamification-belt-tests","title":"Record belt-test results safely","summary":"Record belt-test results safely.","text":"Use the Belt Tests workflow to record each participant as Promoted, Not Yet, or Absent. Choosing Promoted calls the rank store and can change the member’s rank immediately. Access and dependencies Open the Belt Tests view under GymCore Students with gym_promote_student. Confirm each participant’s identity, program, current rank, and intended destination rank before the event. Correct Attendance History and rank history first if those sources are inaccurate. Test rosters and results are personal progress records. Restrict access and keep evaluative notes factual and relevant. Prepare the roster Open the intended belt test and review every participant. Match duplicate names using a stable member identifier and verify the program and current rank. Remove or escalate a participant whose identity or eligibility is unclear before recording results. Expected: The roster contains only the intended members with accurate starting ranks. Reviewing the roster does not promote anyone. Record results For each participant, select the result that occurred: Promoted, Not Yet, or Absent. Review the full set of selections before submitting the displayed result action. Submit once. Expected: GymCore stores the test results. Each Promoted result creates the corresponding rank change and can trigger celebration output; Not Yet and Absent must not advance rank. Reopen the belt test and inspect the saved result for every participant. Expected: The saved roster matches the submitted decisions without duplicate promotions. Reverse or recover Do not submit a second promotion to offset an error. Preserve the belt-test ID, member ID, prior and destination ranks, result, operator, and timestamp. Use an authorized rank-history correction process when the UI has no safe reversal, then correct the belt-test result if that control is available. External notifications or celebration screens cannot necessarily be recalled. Verify in the source systems Use the Belt Tests record for the assessment result and the member’s rank history for the actual promotion event. Then check the member profile and Promotions view. A success animation alone is not proof that the correct rank was stored.","headings":["Access and dependencies","Prepare the roster","Record results","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Ranks \u0026 Gamification","source":"docs/user-guide/ranks-gamification/belt-tests.md"},{"route":"/docs/ranks-gamification-promotion-workflow/","slug":"ranks-gamification-promotion-workflow","title":"Review and record a promotion","summary":"Review and record a promotion.","text":"Use the Promotions view to inspect eligibility, then record a promotion only after a coach confirms the member’s rank, program, and supporting history. Eligibility is a recommendation; viewing the queue does not change a member record. Access and dependencies Viewing Promotions requires gym_view_ranks. The action that records a promotion requires gym_promote_student. A staff member may be able to see the page without being allowed to promote. Attendance and rank history must be accurate, and the member must be assigned to the intended program. Promotion decisions and coach notes are personal progress records. Limit access and avoid unrelated sensitive information. Review eligibility Open the Promotions view under GymCore Students. Filter or locate the intended member and confirm the program, current rank, attendance counts, time or class thresholds, and any coach-review indicator shown by the installed screen. Compare those values with Attendance History and the member’s rank history. Expected: The queue and source records identify the same member and current rank. If a source value is wrong, correct it before promotion. The belt-system settings screen and the eligibility store are separate in current source. Do not infer that a recently edited threshold is active merely because it saved; validate the member at the actual boundary. Record the promotion With gym_promote_student, open the promotion action for the verified member. Confirm the destination rank and any visible effective-date or note field. Select the displayed promotion action once. Expected: GymCore adds a rank-history event and the member’s current rank changes to the intended value. A celebration or success notice is secondary to the stored record. Reopen the member and Promotions view. Expected: The new rank appears in member history and the prior recommendation is removed or updated according to the runtime. Reverse or recover Do not promote again to correct a mistaken rank. Preserve the member ID, previous rank, new rank, promotion event, operator, and time, then use the approved rank-history correction path. If no safe UI reversal is available, escalate to an authorized administrator or support operator and verify the corrected source record afterward. Verify in the source systems Confirm the new current rank and dated event in the member’s rank history, then confirm the Promotions queue recalculated. Check any member-facing progress card separately; its display can be cached or governed by targeted-content settings.","headings":["Access and dependencies","Review eligibility","Record the promotion","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Ranks \u0026 Gamification","source":"docs/user-guide/ranks-gamification/promotion-workflow.md"},{"route":"/docs/ranks-gamification-rank-systems-thresholds/","slug":"ranks-gamification-rank-systems-thresholds","title":"Configure a belt system without assuming eligibility changes","summary":"Configure a belt system without assuming eligibility changes.","text":"Use Belt Systems to edit the visible rank structure for a program. Current source keeps these settings separate from the rank eligibility store, so changing a belt or threshold here is not verified to change the Promotions queue. Access and dependencies Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Belt Systems with gymcore_manage_settings, or the administrator fallback manage_options. Confirm the program taxonomy and the organization’s approved rank policy before editing. Export or record the current belt-system values from this screen before a broad change. Do not restore an entire site merely to reverse one threshold. Rank data is member progress information. Limit edits and exports to authorized staff. Review the defaults and stored values GymCore’s Foundations settings default to enabled, with these initial minimums: Phase 1 classes: 10, minimum 1 Coach rolls: 2, minimum 1 Total classes: 25, minimum 1 These are settings-layer values. Do not state that they are the active promotion formula until an eligible-member result proves the eligibility engine consumes them. Change one system deliberately Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Belt Systems. Select the intended program or belt system. Record the current rank order, labels, colors, and threshold values displayed by the installed screen. Change only the approved values. Keep every numeric minimum within the control’s displayed range. Select Save changes. Expected: WordPress reports that settings were saved and the same belt-system values remain after reload. This confirms configuration storage only. Test the eligibility boundary Identify controlled member records just below, at, and above the changed threshold using accurate attendance and rank history. Open the Promotions view and compare their eligibility results with the expected policy. Expected: Record the actual result. Current source separates the visible settings/custom belt systems from the eligibility store; if the queue does not change, stop and treat the setting as non-authoritative for promotions. Check member-facing rank labels or progress output for the same controlled records. Expected: Presentation and eligibility may differ. Do not launch the new policy until both have an approved, source-backed outcome. Reverse or recover Restore the recorded prior values and select Save changes. Recheck both presentation and Promotions; reverting the settings does not necessarily reverse rank-history events or promotions already recorded. Correct those in their own source through the approved rank-data process. Verify in the source systems Confirm saved structure in Belt Systems, eligibility in the Promotions queue, and actual member rank in rank history or the student profile. A belt-system settings screen cannot by itself establish which thresholds the eligibility engine enforced.","headings":["Access and dependencies","Review the defaults and stored values","Change one system deliberately","Test the eligibility boundary","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Ranks \u0026 Gamification","source":"docs/user-guide/ranks-gamification/rank-systems-thresholds.md"},{"route":"/docs/ranks-gamification-targeted-content/","slug":"ranks-gamification-targeted-content","title":"Show content to a defined member segment","summary":"Show content to a defined member segment.","text":"Use the Targeted Content block or GymCore shortcodes to change presentation for a matching member. Targeting is not authorization: hidden content can still exist in the page response, cache, REST output, or editor and must never protect secrets or privileged actions. Access and dependencies Editing the WordPress page requires the applicable page/post capability. Enable targeted content under GymCore Admin \u0026gt; GymCore Settings \u0026gt; Gamification defaults to enabled and requires gymcore_manage_settings, or the administrator fallback manage_options, to change. Matching can depend on login state, role, membership, Foundations state, program, rank, class count, streak, or location. Those source records must be accurate. Do not place credentials, private notes, payment links, health data, or staff-only controls inside content that is protected only by a targeting rule. Add a targeted block Edit the intended WordPress page and add the Targeted Content block. Add the content to the block. Configure only the rules needed for the segment. Current rule types include logged-in users, members, Foundations, program, minimum or maximum rank, minimum classes, minimum streak, role, and location. Select Update or Publish. Expected: WordPress saves the block and its rule attributes. This confirms page storage, not every runtime match. Use a shortcode only when required The current source also registers [gym_targeted], [gym_member_greeting], and [gym_progress_card]. Use the block when it exposes the needed rule; if a shortcode is required, copy its supported attributes from the installed editor or maintained developer reference rather than inventing names. Expected: After Update, WordPress preserves the shortcode without displaying it as plain text. If it renders literally, stop and verify that GymCore registered it on that request. Test both sides of every rule View the page with a controlled account that should match. Expected: The targeted content appears with the intended greeting or progress data. View with a controlled account that should not match, and while signed out when login state matters. Expected: The content is not presented in the normal page view. Check full-page caching, edge caching, and any preview or REST exposure used by the installed site. Expected: One member’s personalized output is not served to another. If caching leaks a match, remove the block from production until the cache varies safely or bypasses personalized content. Reverse or recover Remove the block or shortcode and select Update to stop future rendering. Disable Enable targeted content and save only when the site-wide effect is intended. Purge only the relevant approved caches afterward; changing a rule does not erase copies already indexed, exported, or cached externally. Verify in the source systems Confirm the rules in the WordPress page, the matching member attributes in their source records, and the rendered result for matching and nonmatching sessions. Use real access controls outside targeted content for anything confidential or consequential.","headings":["Access and dependencies","Add a targeted block","Use a shortcode only when required","Test both sides of every rule","Reverse or recover","Verify in the source systems"],"source_sha256":"","section":"Ranks \u0026 Gamification","source":"docs/user-guide/ranks-gamification/targeted-content.md"},{"route":"/docs/glossary/","slug":"glossary","title":"GymCore glossary","summary":"GymCore glossary.","text":"Plain-language definitions for terms used in GymCore customer documentation. Product labels can change; verify visible menu and field names before publishing a procedure. A Academy\u0026lt;br\u0026gt; A martial arts gym. Customer documentation may use “gym” or “academy,” based on the reader’s context. Action approval\u0026lt;br\u0026gt; A review step shown before an AI-proposed or sensitive change is applied. An approval is not the same as an AI response or draft. Active membership\u0026lt;br\u0026gt; A membership that is currently valid under its WooCommerce subscription, order, and GymCore status rules. Do not use this term as a substitute for a specific billing status. Administrator\u0026lt;br\u0026gt; A WordPress role with broad site access. GymCore also defines or uses task-specific roles and capabilities. Staff should receive the least access needed for their work. Agent\u0026lt;br\u0026gt; A configured GymCore AI persona with instructions and access to a defined set of tools. An agent is part of the GymCore AI companion plugin. Announcement\u0026lt;br\u0026gt; A message created for staff briefing or gym communication, depending on the surface where it appears. API (application programming interface)\u0026lt;br\u0026gt; A way for software to exchange data or request an action. API work belongs in technical/admin or developer documentation. Audit log\u0026lt;br\u0026gt; A record of an action, proposal, approval, error, or security-relevant event when the corresponding feature records one. B Badge\u0026lt;br\u0026gt; A recognition item awarded through GymCore gamification rules or staff action. Belt test\u0026lt;br\u0026gt; A scheduled or tracked evaluation related to rank progression. It is distinct from applying a promotion. Block\u0026lt;br\u0026gt; A WordPress editor component that places content or functionality on a page. C Capability\u0026lt;br\u0026gt; A WordPress permission checked before a user can view a surface or perform an action. A role is a named collection of capabilities. Check-in\u0026lt;br\u0026gt; An attendance event connecting a member to a class or visit. Class\u0026lt;br\u0026gt; A scheduled training session. A class may belong to a program and can have capacity, curriculum, and attendance. Companion plugin\u0026lt;br\u0026gt; A separate WordPress plugin that works with GymCore but must be installed and configured independently. GymCore AI is a companion plugin. Consent\u0026lt;br\u0026gt; A person’s permission for a defined use of their data or for receiving communication. A phone number or email address alone is not proof of consent. Cron / scheduled job\u0026lt;br\u0026gt; A background task run by WordPress or the server on a schedule. Scheduled work may not happen immediately after a button is selected. Curriculum\u0026lt;br\u0026gt; The techniques, themes, or lesson content assigned to a program or class. D Dashboard\u0026lt;br\u0026gt; A summary or work area in WordPress admin. Use the full visible name, such as Staff Dashboard or Analytics \u0026amp; Reports, when more than one dashboard exists. Default\u0026lt;br\u0026gt; The value GymCore uses before a customer changes a setting. A default is not automatically a recommendation. Developer\u0026lt;br\u0026gt; A reader expected to work with code, APIs, webhooks, WP-CLI, logs, or data storage. Developer content must be labelled and kept out of beginner flows. E Endpoint\u0026lt;br\u0026gt; A URL or route used by a portal, rewrite rule, webhook, or API. An endpoint is not necessarily a customer-facing page. Entitlement\u0026lt;br\u0026gt; Access granted by a license, plan, role, or other verified condition. F Family / guardian relationship\u0026lt;br\u0026gt; A connection that lets an authorized adult manage or view information for one or more members, subject to current portal and access rules. Finance Copilot\u0026lt;br\u0026gt; The current GymCore finance work area or assistant label where present in the product. It handles sensitive finance information and should be available only to authorized staff. Front desk\u0026lt;br\u0026gt; Staff who handle arrivals, member records, basic sales, communications, and daily operations. It describes work, not a guaranteed WordPress role. G Gamification\u0026lt;br\u0026gt; GymCore features such as badges, streaks, milestones, and targeted content. Rank progression is documented separately even where the features interact. GymCore\u0026lt;br\u0026gt; The self-hosted WordPress and WooCommerce plugin for gym operations. The customer or hosting provider controls the site and hosting environment. GymCore Admin\u0026lt;br\u0026gt; A current top-level WordPress admin menu for GymCore operational and settings pages. GymCore AI\u0026lt;br\u0026gt; The separate companion plugin that adds AI chat, agents, tools, proposed actions, and related settings where configured. GymCore Classes\u0026lt;br\u0026gt; A current top-level WordPress admin menu for programs, classes, schedules, and related work. GymCore Leads\u0026lt;br\u0026gt; A current top-level WordPress admin menu for leads, pipeline, referrals, and sales-related work. GymCore Students\u0026lt;br\u0026gt; A current top-level WordPress admin menu for member, attendance, rank, promotion, badge, belt-test, and waiver work. Documentation may say “member” in prose while preserving “Students” in the exact menu label. H HPOS (High-Performance Order Storage)\u0026lt;br\u0026gt; WooCommerce’s order storage system. Compatibility and migration checks are technical/admin topics. Human review\u0026lt;br\u0026gt; A person checks a draft or proposed action before it is sent or applied. Documentation must not imply review occurred only because content was generated. I iCal feed\u0026lt;br\u0026gt; A calendar feed that another calendar application can subscribe to. It is not necessarily a two-way calendar sync. Integration\u0026lt;br\u0026gt; A connection between GymCore and another plugin or service, such as Twilio, MailPoet, AutomateWoo, a calendar, or an API client. Inventory ID\u0026lt;br\u0026gt; A stable maintainer identifier such as INV-SET-0035 used to connect audited source behavior to one primary documentation article. Customers do not need these IDs to use GymCore. K Kiosk\u0026lt;br\u0026gt; A focused check-in or sales screen intended for a shared front-desk or member-facing device. Kiosk access and timeout settings should be reviewed before use. L Lead\u0026lt;br\u0026gt; A prospective member whose contact, source, status, and follow-up activity may be tracked in GymCore. Legacy\u0026lt;br\u0026gt; An old name, URL, setting, plugin, or data shape retained for migration or compatibility. Legacy does not mean the surface should be taught as the current workflow. Location\u0026lt;br\u0026gt; A gym site used to organize products, classes, members, reports, or access where supported. A WordPress site can represent one or more gym locations. M MCP (Model Context Protocol)\u0026lt;br\u0026gt; A protocol that can expose approved abilities to compatible AI clients. MCP setup is a developer/admin topic and does not make every internal ability a customer-facing feature. Member\u0026lt;br\u0026gt; A person whose gym relationship is managed in GymCore. The visible WordPress admin menu may use GymCore Students. Member portal\u0026lt;br\u0026gt; A signed-in front-end area where a member can access the information and actions currently exposed to them. Membership\u0026lt;br\u0026gt; The gym product or access relationship assigned to a member. Billing may be handled through WooCommerce orders or subscriptions. Migration\u0026lt;br\u0026gt; Moving supported data or configuration from an older system, plugin, URL, or storage format to the current one. O Option\u0026lt;br\u0026gt; A value stored in WordPress settings. Customer instructions should lead with the visible field label, not the internal option name. P Parent portal\u0026lt;br\u0026gt; A signed-in front-end area for an authorized parent or guardian to work with connected family members. Personal data\u0026lt;br\u0026gt; Information that identifies or relates to a person, including contact, attendance, membership, waiver, billing, and communication data. Plan gate\u0026lt;br\u0026gt; A verified license or product-plan condition that controls access to a feature. “No explicit local gate found” does not prove a feature is included in every plan. Plugin\u0026lt;br\u0026gt; Software installed into WordPress. GymCore and GymCore AI are plugins; they do not include hosting by themselves. Portal\u0026lt;br\u0026gt; A front-end signed-in area. A portal is different from WordPress admin. Program\u0026lt;br\u0026gt; A category or grouping for classes, such as Adult BJJ or Kids BJJ. Promotion\u0026lt;br\u0026gt; A recorded change to a member’s rank or level. Readiness, belt tests, recommendations, notifications, and published posts may be related but are separate behaviors. Proposed action\u0026lt;br\u0026gt; A change prepared by GymCore AI for a person to review. A proposed action has not necessarily been applied. PWA (progressive web app)\u0026lt;br\u0026gt; A website configured to behave more like an installed app on supported devices. Setup depends on the site, browser, and current GymCore implementation. R Rank\u0026lt;br\u0026gt; A member’s current belt, level, stripe, or other progression state within a configured rank system. Read-only action\u0026lt;br\u0026gt; An operation that retrieves or summarizes data without intentionally changing stored information. It may still expose sensitive data and require access control. REST API\u0026lt;br\u0026gt; A set of web routes used by authorized software clients. Route existence does not imply public or anonymous access. Retention\u0026lt;br\u0026gt; Features intended to identify or contact members based on activity, missed classes, churn risk, or time away. Messaging still requires correct consent and delivery configuration. Rewrite rule\u0026lt;br\u0026gt; A WordPress rule that maps a friendly URL to an internal handler. It is a technical implementation detail unless a customer must visit or configure the URL. Role\u0026lt;br\u0026gt; A named WordPress access profile made up of capabilities. Job title and WordPress role are not always the same. S Self-hosted\u0026lt;br\u0026gt; Installed on a WordPress site controlled by the customer or their hosting provider. Hosting, updates, backups, security hardening, and server access remain their responsibility unless a separate provider agreement says otherwise. Sensitive action\u0026lt;br\u0026gt; An action that changes data, sends a message, changes access, handles credentials, affects billing, or crosses a trust boundary. Shortcode\u0026lt;br\u0026gt; A bracketed WordPress code such as [example] placed in supported content to render dynamic output. SMS\u0026lt;br\u0026gt; A text message sent through a configured provider. Sending requires correct credentials, consent, templates, and provider availability. Source of truth\u0026lt;br\u0026gt; The current authoritative place for a fact. For documentation coverage, the audit inventory is the baseline; surprising or sensitive claims must also be checked in current source and tested where practical. Staff Dashboard\u0026lt;br\u0026gt; The current GymCore work area that summarizes staff-facing information and actions. Status\u0026lt;br\u0026gt; A named state for a member, lead, payment, proposal, or other record. Use the exact status label and define what changes it. Streak\u0026lt;br\u0026gt; A gamification measure based on qualifying attendance or activity under current rules. Subscription\u0026lt;br\u0026gt; A WooCommerce recurring-billing record. It is related to, but not identical with, a GymCore membership. T Targeted content\u0026lt;br\u0026gt; Website content shown according to supported member or visitor conditions. Configuration is a technical/admin task because incorrect rules can hide or expose content. Taxonomy\u0026lt;br\u0026gt; A WordPress classification used to group content, such as programs or locations. Customer docs should use the visible label unless a developer needs the taxonomy name. Trial\u0026lt;br\u0026gt; A prospective member’s trial-class or introductory-sales process. Requested, scheduled, attended, and converted states must not be treated as interchangeable. Twilio\u0026lt;br\u0026gt; A third-party communication service used for SMS where configured. GymCore does not supply Twilio credentials or carrier consent automatically. W Waiver\u0026lt;br\u0026gt; A versioned agreement and signature record collected from a member or guardian. Waiver configuration and retention should be reviewed with the gym’s legal and privacy advisers. Webhook\u0026lt;br\u0026gt; An outbound or inbound HTTP request used to notify another system of an event. Webhooks can carry sensitive data and must use authentication, validation, HTTPS, and limited access. White label\u0026lt;br\u0026gt; Plan-dependent customization of supported names or presentation. It does not change the canonical product names used in this documentation. WooCommerce\u0026lt;br\u0026gt; The WordPress commerce plugin GymCore uses for products, orders, subscriptions, payments, and related billing behavior. WP-CLI\u0026lt;br\u0026gt; The WordPress command-line interface. Commands are for administrators or developers with server access and should be tested on a backup or staging site when they mutate data.","headings":["A","B","C","D","E","F","G","H","I","K","L","M","O","P","R","S","T","W"],"source_sha256":"","section":"Reference","source":"docs/user-guide/glossary.md"},{"route":"/docs/reference-admin-menus/","slug":"reference-admin-menus","title":"Find the correct GymCore admin screen","summary":"Find the correct GymCore admin screen.","text":"GymCore divides daily work across four top-level WordPress menus. If a menu is missing, first check the person’s role instead of assuming the feature is uninstalled. A “capability” is the internal WordPress permission checked before a page or action opens. The names below are useful when an administrator is handing access to a staff member; staff do not need to know them for daily work. Choose the top-level menu Menu Use it for Main screens registered by the audited source GymCore Admin Owner operations, communications, reports, integrations, AI, settings, and setup Staff Dashboard, Finance Copilot, Sales Kiosk, Communications, Analytics \u0026amp; Reports, Integrations, AI, GymCore Settings, Setup GymCore Students Member records and progression Students, Attendance, Waivers, Badges, Promotions, Belt Tests, Import GymCore Leads Prospects and referrals Lead Pipeline, Lead Sources, Referrals GymCore Classes Curriculum, schedule, tournaments, and videos Programs, Schedule, Tournaments, Technique Videos The menu order is explicitly sorted in GymCore source. Optional providers can add a screen, and a screen is hidden when the signed-in account fails its permission check. Know the important access checks Screen or action Effective permission in source Typical handoff GymCore Settings Destination-specific canonical policy; most core tabs use gymcore_manage_settings, with manage_options as the administrator fallback; Billing retains declared manage_woocommerce compatibility Administrator or a deliberately provisioned destination manager AI hub, AI Knowledge, Analytics \u0026amp; Reports, Referrals, Tournaments manage_woocommerce Administrator or WooCommerce Shop Manager normally Integrations menu and Setup `manage_options` Administrator normally QuickBooks tab Integrations menu requires `manage_options`; its form handlers also require `manage_woocommerce` Use an administrator who has both Staff Access gymcore_manage_staff or administrator fallback manage_options Approved access owner or administrator Data \u0026amp; Privacy gym_manage_data_privacy or administrator fallback manage_options Approved privacy owner or administrator License, GymCore AI Settings manage_options Administrator normally Students `gym_view_attendance` Staff role explicitly granted attendance viewing Attendance check-in `gym_check_in_member` Front-desk role explicitly granted check-in Promotions `gym_view_ranks` Coach or manager explicitly granted rank viewing Belt Tests `gym_promote_student` Promotion-authorized coach or manager Lead Pipeline `gym_manage_leads` Sales or lead-management role Programs and Schedule `gym_manage_curriculum` Curriculum or scheduling manager Sales Kiosk `gym_process_sale` Staff authorized to create sales Technique Videos WordPress post-edit permission Editor or administrator able to edit this post type Staff Access edits only four newer `gymcore_` permissions. It does not grant every `gym_`, WordPress, or WooCommerce permission in this table. Exact steps Safe stop: This lookup requires no commit button. Stop after the lowest-risk read check; do not change a role or grant a permission merely to make a menu appear. Sign in as the actual staff role being tested, not as an administrator. Expected: Only the top-level menus allowed for that role appear. Select the top-level menu in the first table, then select the visible submenu for the task. Expected: The page heading matches the selected submenu; a blank page or “not allowed” message indicates a separate permission or provider problem. For delegated access, perform only the lowest-risk read action needed to confirm the page works. Expected: The account can view the intended records without gaining unrelated settings, financial, promotion, or deletion controls. As an administrator, compare the test role with GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access and the Roles and permissions matrix. Expected: The saved role permissions and the source page’s own permission check explain the visible menu. If they do not, restore the prior role checkboxes and investigate the separate WordPress/WooCommerce gate. When a menu is missing If GymCore Admin is present but a submenu is absent, check that submenu’s permission and whether its provider or companion plugin is active. If GymCore Students, GymCore Leads, or GymCore Classes is absent, verify the account can pass at least one relevant page permission. If QuickBooks is absent for a Shop Manager, the parent Integrations menu still requires administrator-level `manage_options`. A PHP class file by itself is not evidence that a page is registered; see Review code-only candidate surfaces. Verified against: current GymCore and GymCore AI menu registrations and menu ordering in the checked-out source.","headings":["Choose the top-level menu","Know the important access checks","Exact steps","When a menu is missing"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/admin-menus.md"},{"route":"/docs/reference-blocks-shortcodes/","slug":"reference-blocks-shortcodes","title":"Publish targeted GymCore content","summary":"Publish targeted GymCore content.","text":"Site owners can use one editor block and nine shortcodes to place member-specific content on WordPress pages. A shortcode is text in square brackets that WordPress replaces when the page loads; it is not a privacy boundary by itself. Targeted Content block Insert Targeted Content from the block inserter. The registered block name is `gym/targeted-content`. Editor control Block attribute Default Meaning Program `program` Blank Restricts content to the matching program Minimum belt `minBelt` Blank Sets the lowest eligible belt Location `location` Blank Restricts content to a location Members only `membersOnly` Off Requires the member check Foundations only `foundationsOnly` Off Requires Foundations eligibility Logged-in only `loggedIn` Off Hides primary content from signed-out visitors Minimum classes `minClasses` 0 Requires at least this many classes Minimum streak `minStreak` 0 Requires at least this streak Fallback `fallback` Blank Content shown when the visitor does not qualify Block filtering depends on the current user’s GymCore profile and the installed runtime that renders the block. Previewing as an administrator is not a substitute for testing the intended member state. Shortcode catalogue Shortcode Accepted attributes and defaults Output and dependencies `[gym_targeted]` `program=“”`, `min_belt=“”`, `max_belt=“”`, `min_classes=“”`, `min_streak=“”`, `foundations_only=“”`, `members_only=“”`, `logged_in=“”`, `role=“”`, `location=“”`, `fallback=“”` Shows enclosed content when the current visitor matches; `[gym_targeted_content]` is an alias `[gym_member_greeting]` None Signed-in members see their display name, rank, classes, and streak; guests see a generic welcome `[gym_progress_card]` None Shows current-member progress; guests receive a join call to action `[gym_pause_membership]` None Renders the membership-pause flow; the active membership and pause services must be available `[gym_member_badges]` `user_id=“0”`; 0 means current user Renders a member’s badges. Supplying another user’s ID can expose their achievements, so do not use it on a public page `[gym_wall_of_champions]` None Renders the registered achievement wall `[gym_referral_leaderboard]` `limit=“10”`; clamped to 1–50 Shows display names and referral counts; treat it as public member recognition `[gym_referral_code]` None Shows the signed-in member’s referral code `[gym_technique_videos]` `program=“”`, `belt=“”`, `per_page=“12”` clamped to 1–48, `title=“Technique Videos”` Requires login and an active membership; output also depends on published Technique Video records and available video delivery Exact steps Safe stop: Use Preview and test accounts before Update or Publish; publishing is the first step that can expose targeted or fallback content to visitors. Open Pages, select the page, and choose Edit. For visual targeting, select Add block (+), search for Targeted Content, and insert it. For a shortcode, insert a Shortcode block and enter the exact shortcode. Expected: The editor shows the Targeted Content controls or the literal shortcode inside a Shortcode block. Enter the primary content and an explicit fallback when a visitor could fail the targeting rules. Expected: The editor retains both branches before publication. Select Update or Publish. Expected: WordPress confirms the page was updated or published. Open the page signed out, then with test accounts representing every intended program, belt, location, and membership state. Expected: Each account sees only its intended branch. Confirm the member profile, membership, badge, referral, or video record in GymCore when output differs; do not infer a record from a cached page. Symptoms and source checks Literal shortcode text means the registering plugin or module did not load, or the content was not placed in a Shortcode-aware area. Empty targeted content usually means the current user’s source profile does not match and no fallback was supplied. Empty video output can mean no matching published Technique Video record, no active membership, or unavailable VideoPress/runtime delivery. Cached pages can show one member’s branch to another visitor. Exclude personalized pages from shared full-page caches. Verified against: current block registration, shortcode registration, attribute defaults, and render callbacks in the checked-out GymCore source.","headings":["Targeted Content block","Shortcode catalogue","Exact steps","Symptoms and source checks"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/blocks-shortcodes.md"},{"route":"/docs/reference-data-model-storage/","slug":"reference-data-model-storage","title":"Locate the system that owns a GymCore record","summary":"Locate the system that owns a GymCore record.","text":"Before correcting a customer record, identify which system owns it. WordPress holds identities and content, WooCommerce owns commerce records, and GymCore stores operational records in custom tables. A database table name is a support handoff, not an instruction to edit production data directly. The site’s WordPress table prefix replaces `wp_`; for example, `wp_gym_attendance` may be `client1_gym_attendance`. Source-of-truth map Customer information Owning source Important note Login, email, display name, roles WordPress users and user meta GymCore profile values can also live in user meta Products, orders, refunds, subscriptions, payment tokens WooCommerce and its active storage system Do not “repair” an order by changing a GymCore log Classes, tournaments, technique videos, announcements, testimonials, legacy trial leads WordPress custom post types Publication status and post meta are separate from operational custom tables Attendance, ranks, leads, waivers, retention, referrals, scheduled class occurrences GymCore custom tables Use the matching admin workflow when one exists AI conversations and proposed actions GymCore AI custom tables Retention purges conversations/messages in the audited source, not pending actions or every audit record QuickBooks transactions QuickBooks Online GymCore’s sync log records attempts; it is not the accounting ledger SMS delivery Configured SMS provider GymCore logs local submission/status; the provider owns final delivery state Core custom-table catalogue Each name below is appended to the WordPress database prefix. Area Tables Progress and attendance `gym_ranks`, `gym_rank_history`, `gym_attendance`, `gym_achievements`, `gym_belt_tests`, `gym_belt_test_results`, `gym_belt_system` Communications and activity `gym_ai_sms_log`, `gym_funnel_log`, `gym_meta_log`, `gym_retention_log` Tournaments and classes `gym_tournament_registrations`, `gym_tournament_results`, `gym_class_occurrences`, `gym_class_waitlist` Leads and trials `gym_leads`, `gym_lead_stage_operations`, `gym_inbound_provider_events`, `gym_inbound_provider_effects`, `gym_lead_contacts`, `gym_lead_participants`, `gym_lead_touches`, `gym_lead_consent_events`, `gym_lead_notes`, `gym_lead_communications`, `gym_trial_appointments` Waivers and retention `gym_waivers`, `gym_waiver_links`, `gym_churn_scores`, `gym_member_pauses` Referrals and accounting `gym_referrals`, `gym_qbo_sync_log` Tenant, AI knowledge, and audit support `gym_tenant_access_log`, `gym_ai_knowledge` The current registry creates all tables above. Older migrations or extensions may leave additional tables; their presence does not prove current code reads them. GymCore AI custom tables Table Stored information `gym_core_ai_conversations` Conversation headers, user association, persona, and timestamps `gym_core_ai_messages` Messages belonging to conversations `gym_core_ai_pending_actions` Proposed actions and approval state WordPress content types Content type key Customer-facing purpose `gym_class` Class/program content `gym_tournament` Public tournament content `gym_technique_video` Private admin video records rendered for eligible members `gym_announcement` Announcements `hp_testimonial` Testimonials; admin UI exists but no menu entry is registered `hp_trial_lead` Legacy trial-lead content used by older/reporting paths Exact steps Safe stop: Record identifiers and inspect the owning screen without editing tables; stop before any correction when no supported application workflow or scoped restore exists. Start from the visible customer identifier: WordPress user ID/email, WooCommerce order/subscription ID, lead ID, class occurrence, or AI conversation ID. Expected: You have one stable identifier and the time of the reported event. Open the normal WordPress, WooCommerce, GymCore, QuickBooks, or provider screen that owns the record. Expected: The source record explains the current status without relying only on a downstream log. Use logs or custom-table rows to trace related activity, keeping the original identifier and timestamps together. Expected: Related rows point back to the same source record; a missing link is evidence to investigate, not a reason to create one manually. Correct the record through its owning application workflow and re-open the source record. Expected: The source system shows the intended value and downstream logs reflect a new action. If no supported workflow exists, take a scoped backup and escalate for a reviewed data repair rather than editing an unknown table. Privacy and recovery boundaries A WordPress privacy erasure deletes selected GymCore user meta and rank history and anonymizes attendance to user ID `0`; it does not automatically erase WooCommerce, CRM, provider, AI-action, or backup copies. Deleting an AI conversation does not imply every proposed action or external result was removed. Restoring one custom table can leave cross-system references inconsistent. Restore related records as a coordinated incident, then verify the owning source and every affected integration. Verified against: the current GymCore table registry, WordPress post-type registrations, WooCommerce integrations, and GymCore AI activator in the checked-out source.","headings":["Source-of-truth map","Core custom-table catalogue","GymCore AI custom tables","WordPress content types","Exact steps","Privacy and recovery boundaries"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/data-model-storage.md"},{"route":"/docs/reference-internal-candidate-surfaces/","slug":"reference-internal-candidate-surfaces","title":"Review code-only candidate surfaces","summary":"Review code-only candidate surfaces.","text":"This page is for owners handing a suspected “hidden feature” to engineering. A class file can exist without being connected to a menu, URL, scheduled event, or service provider. In that state customers cannot rely on it as product behavior. A “runtime consumer” is simply live code that calls or registers another piece of code. The candidates below had no such connection in the audited source search. Current candidates Candidate What the file suggests Registration evidence in the audited source Customer guidance `IntegrationController` Integration request handling Only the class’s own file references it Do not document an integration endpoint or button from this class alone `CrmContactSync` CRM contact synchronization Only the class’s own file references it Use the documented Form-to-CRM path; do not promise this synchronizer runs `ReferralController` Referral request handling Only the class’s own file references it Use the registered referral admin and shortcode workflows `BeltPresetLoader` and `KarateBeltPreset` Preset belt-system loading No provider, menu action, or other caller was found Do not promise a preset import; use Belt Systems’ visible JSON import `AttendanceDashboard` is not a candidate: it is wired by `AdminServiceProvider` in the current source. Likewise, the current AI SMS log table is managed by active table/store code; an older migration file is not evidence that the active log is unavailable. Exact steps Safe stop: Source inspection and read-only environment verification require no commit button. Stop if no registered entry point reaches the candidate; do not expose or document one by guesswork. Search the current source for construction, dependency-container registration, hook registration, route registration, menu registration, and direct calls to the candidate. Expected: A usable surface has a caller or registration outside its own class file. Trace that registration to a visible menu, HTTP route, scheduled hook, shortcode, block, or background action. Expected: The entry point names an effective permission and a callback that reaches the candidate. Verify the entry point in an environment where the same plugin versions and optional dependencies are active. Expected: The visible entry point exists and reaches the documented result. Do not invent a browser or command-line test when the source exposes no entry point. Record the registration file and source-system result in the support handoff. Expected: Engineering can reproduce the connection without treating class existence as proof. Do not expose candidates by guesswork Do not add a menu, route, hook, or direct database call merely to make one of these classes reachable during support. That is a product change requiring design, authorization, security review, and tests. Verified against: current cross-reference searches and provider registrations in the checked-out GymCore and GymCore AI source.","headings":["Current candidates","Exact steps","Do not expose candidates by guesswork"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/internal-candidate-surfaces.md"},{"route":"/docs/reference-legacy-migrations/","slug":"reference-legacy-migrations","title":"Legacy names, URLs, and migrations","summary":"Legacy names, URLs, and migrations.","text":"Use this page only when moving an older site or retiring old bookmarks. Current customer instructions start at the GymCore customer guide. Naming translation Legacy/internal term Current customer term Rule HMA, Haanpaa Martial Arts, tenant staff names Your gym / your staff HMA material is site-specific and must not be generalized. Gandalf, Pippin, legacy character names GymCore AI or the current configured persona label Do not make internal/persona names the product name. Gym Core / gym-core in old prose GymCore in customer prose; gym-core only for technical identifiers Match current public brand and exact visible menu labels. WooCommerce \u0026gt; Settings \u0026gt; Gym Core GymCore Admin \u0026gt; GymCore Settings Old route redirects; do not teach it. Standalone Roles, Privacy, Belt System, License pages Matching GymCore Settings section Redirect-only migration surfaces. Standalone AI Settings/Audit/White Label URLs GymCore Admin \u0026gt; AI tabs Use the canonical hub. HMA-only surfaces The checked-out legacy hma-ai-chat plugin contains classes and operator surfaces with no canonical GymCore AI counterpart, including its own knowledge store/retriever, operating-overview ability, WooCommerce bridge, and catalogue dump. Do not promise those surfaces to GymCore customers. Migrate only after mapping each required function to a current supported feature. Data migration sequence Inventory source systems, record owners, data fields, consent evidence, identifiers, and retention obligations. Back up WordPress, WooCommerce, GymCore custom tables/options, media, and source exports. Create a field map for users, family relationships, locations, programs, memberships/subscriptions, attendance, ranks, waivers, leads, consent, and finance references. Import to staging with a reversible batch ID. Do not send email/SMS, charge payments, publish posts, or trigger automation. Reconcile counts, totals, duplicate identities, dates/timezones, rank history, attendance history, subscription status, and guardian links. Run role-based acceptance tests with fictional records. Freeze writes or define a delta window, take the final export, import only the delta, and reconcile again. Obtain owner sign-off before directing staff or members to the new system. Keep legacy access read-only for the approved retention period, then revoke credentials and dispose of exports securely. Dangerous migration assumptions A WordPress user import does not create correct WooCommerce subscriptions or payment tokens. An attendance total is not a substitute for dated attendance events when ranks, streaks, and retention depend on history. A current belt field is not a substitute for promotion history. CRM stage names do not prove equivalent workflow semantics. Changing waiver Active version can force every member to re-sign. Enabling global SMS can load retention automations whose toggles default on. Core plan declarations and several visible controls are not fully enforced; validate behavior, not labels. Related guides Import members Data model and storage WP-CLI Backups and removal","headings":["Naming translation","HMA-only surfaces","Data migration sequence","Dangerous migration assumptions","Related guides"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/legacy-migrations.md"},{"route":"/docs/reference-licensing-plan-gates/","slug":"reference-licensing-plan-gates","title":"Verify a GymCore license and plan claim","summary":"Verify a GymCore license and plan claim.","text":"For owners, the practical rule is simple: the License screen reports what this site last learned from getgymcore.com, but a plan label does not prove every local feature is blocked or unlocked. Verify the feature itself before promising access. Declared core plan map Feature declaration Starter Growth Pro Enforcement found in audited local source Members Unlimited Unlimited Unlimited Declared limit only Multiple locations No Up to 3 Unlimited Declaration present; no confirmed local runtime caller AI coaching No Sales and Admin Coaching and Finance too Declaration present; no confirmed local runtime caller White label No No Yes Core declaration has no confirmed caller; GymCore AI separately checks its own Pro tier API access No No Yes Declaration present; registered REST and MCP routes are not consistently gated by it Core tiers are `starter`, `growth`, `pro`, and `invalid`. The license manager caches a server check for one hour and considers persisted status fresh for 24 hours. Network or merchant-service availability can therefore affect when the local badge changes. Separate AI entitlement GymCore AI stores an internal `free` or `pro` tier and checks it for the White Label screen. It is not a customer-entered license key. Do not change the database option to grant access; use the approved license flow and verify the installed plugins’ behavior. Renewal webhooks in plain language getgymcore.com can notify the site after purchase or renewal so the local status refreshes automatically. The two registered endpoints are: `POST /gym/v1/license/activate-webhook` `POST /gym/v1/license/renew-webhook` The notification includes a cryptographic signature made with the shared webhook secret. Engineers call this an HMAC signature. If the secret on the site and merchant account differ, the site must reject the notification. Do not share or log the secret. Exact steps Safe stop: Read and compare local and merchant status first; stop before Activate License or Save Webhook Settings unless the key, site assignment, and recovery path are approved. Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; License as an administrator. Expected: The screen shows a status badge, plan, expiration, license action, and webhook settings. It does not have a general save button. If approved, use Activate License or Save Webhook Settings, then reload the screen. Expected: GymCore shows the server-returned status or a specific error. A network failure is not evidence that the key is invalid. Compare the key’s plan and site assignment in the getgymcore.com merchant portal. Expected: Portal and local status agree after refresh; transfer or membership changes are verified in the portal, not from a local button click. Open and exercise the exact feature with a non-production record. Expected: The feature’s own menu, permission check, and result establish whether it is usable. If local code has no license consumer, document that enforcement gap instead of claiming the plan blocks it. For a genuine purchase or renewal notification, compare the merchant event time with the site’s updated license status. Expected: A valid signed webhook refreshes the local license. There is no safe synthetic customer test documented by the source; use real merchant tooling or an engineering-controlled environment. Reversibility and symptoms Deactivate License is a separate action and should not be used to troubleshoot an unrelated feature. Changing the webhook secret breaks future merchant notifications until both systems agree; it does not reverse a purchase or renewal. A stale local badge with a correct portal record points to cache, network, or webhook delivery—not necessarily billing failure. A visible Pro feature on a lower plan can indicate missing local enforcement; escalate it as a product/security issue. Verified against: current core LicenseManager, LicenseSettings, license webhook controller, and GymCore AI license checks.","headings":["Declared core plan map","Separate AI entitlement","Renewal webhooks in plain language","Exact steps","Reversibility and symptoms"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/licensing-plan-gates.md"},{"route":"/docs/reference-mcp-abilities/","slug":"reference-mcp-abilities","title":"Hand an AI-tool connection to engineering","summary":"Hand an AI-tool connection to engineering.","text":"For a site owner, this catalogue answers two questions: what an approved AI client can ask GymCore to do, and which requests can read personal data or change a customer record. If you are not connecting an external AI tool, no customer setup is required here. Engineers call this connection MCP (Model Context Protocol). GymCore registers WordPress “abilities”—named operations with input rules, output rules, and a permission check—and an installed MCP adapter can expose approved abilities to an authenticated client. “Public” adapter metadata means discoverable to that authenticated client, not anonymous internet access. Inventory count: 39 source inventory rows: 37 concrete core ability names, one dynamic GymCore AI tool family, and one runtime-validation marker. The dynamic family expands from the installed AI tool registry. Registration is not a public support guarantee; verify the installed version, permission callback, schema, and side effects before integration. Security contract Use HTTPS and authenticated WordPress credentials or the explicitly supported integration signature. Give service accounts only the named WordPress permission required by the route or ability. Engineers call that permission a capability. Never place application passwords, tokens, or webhook secrets in browser code, URLs, screenshots, or this documentation. The visible General \u0026gt; REST API switch does not gate registered routes in the audited source. Treat GET/read responses as personal data when they contain members, attendance, ranks, leads, messages, or finance. Treat POST/write calls as potentially irreversible; implement idempotency and verify the source record after each request. Registered catalogue Stable ID Item / route Source Audience Prerequisites Registered path Risk and side effect INV-MCP-0001 Dynamic gandalf/\u0026lt;tool-name\u0026gt; family wp-content/plugins/gym-core-ai/src/MCP/AbilitiesRegistrar.php:166 operator/developer/integration client WordPress Abilities API; installed AI ToolRegistry; MCP adapter for external discovery One ability per installed tool name, normalized to kebab case Read tools are discoverable by default; write tools remain hidden from MCP discovery unless an operator explicitly exposes them, and still pass persona, permission, and approval gates INV-MCP-0002 AI MCP runtime validation marker wp-content/plugins/gym-core-ai/src/Runtime/AiMcpRuntimeValidator.php:113 operator/developer Installed WordPress Abilities API and adapter No standalone ability name; validates runtime availability Diagnostic only; do not call it as an ability or count it as a concrete customer operation INV-MCP-0003 gym-members/list wp-content/plugins/gym-core/src/MCP/GymAbilities.php:64 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-members/list medium: authenticated/operator surface; permission and side effects vary INV-MCP-0004 gym-members/get wp-content/plugins/gym-core/src/MCP/GymAbilities.php:97 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-members/get medium: authenticated/operator surface; permission and side effects vary INV-MCP-0005 gym-members/meta wp-content/plugins/gym-core/src/MCP/GymAbilities.php:120 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-members/meta medium: authenticated/operator surface; permission and side effects vary INV-MCP-0006 gym-members/update-meta wp-content/plugins/gym-core/src/MCP/GymAbilities.php:143 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-members/update-meta medium: authenticated/operator surface; permission and side effects vary INV-MCP-0007 gym-members/parent-portal wp-content/plugins/gym-core/src/MCP/GymAbilities.php:171 member/parent or public visitor WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-members/parent-portal medium: authenticated/operator surface; permission and side effects vary INV-MCP-0008 gym-attendance/check-in wp-content/plugins/gym-core/src/MCP/GymAbilities.php:207 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-attendance/check-in medium: authenticated/operator surface; permission and side effects vary INV-MCP-0009 gym-attendance/history wp-content/plugins/gym-core/src/MCP/GymAbilities.php:238 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-attendance/history medium: authenticated/operator surface; permission and side effects vary INV-MCP-0010 gym-attendance/today wp-content/plugins/gym-core/src/MCP/GymAbilities.php:263 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-attendance/today medium: authenticated/operator surface; permission and side effects vary INV-MCP-0011 gym-attendance/milestones wp-content/plugins/gym-core/src/MCP/GymAbilities.php:284 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-attendance/milestones medium: authenticated/operator surface; permission and side effects vary INV-MCP-0012 gym-schedule/list-classes wp-content/plugins/gym-core/src/MCP/GymAbilities.php:320 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-schedule/list-classes medium: authenticated/operator surface; permission and side effects vary INV-MCP-0013 gym-schedule/weekly wp-content/plugins/gym-core/src/MCP/GymAbilities.php:342 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-schedule/weekly medium: authenticated/operator surface; permission and side effects vary INV-MCP-0014 gym-schedule/roster wp-content/plugins/gym-core/src/MCP/GymAbilities.php:367 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-schedule/roster medium: authenticated/operator surface; permission and side effects vary INV-MCP-0015 gym-schedule/waitlist wp-content/plugins/gym-core/src/MCP/GymAbilities.php:390 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-schedule/waitlist medium: authenticated/operator surface; permission and side effects vary INV-MCP-0016 gym-ranks/get-rank wp-content/plugins/gym-core/src/MCP/GymAbilities.php:426 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-ranks/get-rank medium: authenticated/operator surface; permission and side effects vary INV-MCP-0017 gym-ranks/rank-history wp-content/plugins/gym-core/src/MCP/GymAbilities.php:453 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-ranks/rank-history medium: authenticated/operator surface; permission and side effects vary INV-MCP-0018 gym-ranks/promote wp-content/plugins/gym-core/src/MCP/GymAbilities.php:476 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-ranks/promote high: mutates data, sends communication, or crosses trust boundary INV-MCP-0019 gym-ranks/belt-systems wp-content/plugins/gym-core/src/MCP/GymAbilities.php:509 coach/head coach/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-ranks/belt-systems medium: authenticated/operator surface; permission and side effects vary INV-MCP-0020 gym-sales/products wp-content/plugins/gym-core/src/MCP/GymAbilities.php:538 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sales/products medium: authenticated/operator surface; permission and side effects vary INV-MCP-0021 gym-sales/create-order wp-content/plugins/gym-core/src/MCP/GymAbilities.php:559 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sales/create-order high: mutates data, sends communication, or crosses trust boundary INV-MCP-0022 gym-sales/walk-in wp-content/plugins/gym-core/src/MCP/GymAbilities.php:590 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sales/walk-in medium: authenticated/operator surface; permission and side effects vary INV-MCP-0023 gym-sales/billing wp-content/plugins/gym-core/src/MCP/GymAbilities.php:622 finance/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sales/billing medium-high: sensitive access/configuration INV-MCP-0024 gym-gamification/badges wp-content/plugins/gym-core/src/MCP/GymAbilities.php:658 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-gamification/badges medium: authenticated/operator surface; permission and side effects vary INV-MCP-0025 gym-gamification/member-badges wp-content/plugins/gym-core/src/MCP/GymAbilities.php:679 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-gamification/member-badges medium: authenticated/operator surface; permission and side effects vary INV-MCP-0026 gym-gamification/streak wp-content/plugins/gym-core/src/MCP/GymAbilities.php:702 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-gamification/streak medium: authenticated/operator surface; permission and side effects vary INV-MCP-0027 gym-gamification/foundations wp-content/plugins/gym-core/src/MCP/GymAbilities.php:725 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-gamification/foundations medium: authenticated/operator surface; permission and side effects vary INV-MCP-0028 gym-reports/list wp-content/plugins/gym-core/src/MCP/GymAbilities.php:761 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-reports/list medium: authenticated/operator surface; permission and side effects vary INV-MCP-0029 gym-reports/run wp-content/plugins/gym-core/src/MCP/GymAbilities.php:777 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-reports/run medium: authenticated/operator surface; permission and side effects vary INV-MCP-0030 gym-reports/heatmap wp-content/plugins/gym-core/src/MCP/GymAbilities.php:800 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-reports/heatmap medium: authenticated/operator surface; permission and side effects vary INV-MCP-0031 gym-reports/analytics wp-content/plugins/gym-core/src/MCP/GymAbilities.php:829 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-reports/analytics medium: authenticated/operator surface; permission and side effects vary INV-MCP-0032 gym-sms/send wp-content/plugins/gym-core/src/MCP/GymAbilities.php:863 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sms/send high: mutates data, sends communication, or crosses trust boundary INV-MCP-0033 gym-sms/templates wp-content/plugins/gym-core/src/MCP/GymAbilities.php:891 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sms/templates high: mutates data, sends communication, or crosses trust boundary INV-MCP-0034 gym-sms/conversations wp-content/plugins/gym-core/src/MCP/GymAbilities.php:907 operator/developer/integration client WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-sms/conversations high: mutates data, sends communication, or crosses trust boundary INV-MCP-0035 gym-leads/list wp-content/plugins/gym-core/src/MCP/GymAbilities.php:943 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-leads/list medium: authenticated/operator surface; permission and side effects vary INV-MCP-0036 gym-leads/get wp-content/plugins/gym-core/src/MCP/GymAbilities.php:970 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-leads/get medium: authenticated/operator surface; permission and side effects vary INV-MCP-0037 gym-leads/create wp-content/plugins/gym-core/src/MCP/GymAbilities.php:993 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-leads/create medium: authenticated/operator surface; permission and side effects vary INV-MCP-0038 gym-leads/move-stage wp-content/plugins/gym-core/src/MCP/GymAbilities.php:1026 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-leads/move-stage medium: authenticated/operator surface; permission and side effects vary INV-MCP-0039 gym-leads/funnel wp-content/plugins/gym-core/src/MCP/GymAbilities.php:1054 sales/front desk/admin WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined registered mcp-ability gym-leads/funnel medium: authenticated/operator surface; permission and side effects vary Integration checklist Pin the installed GymCore/GymCore AI version you tested. Confirm exact method, namespace, request schema, permission callback, and response schema in source. Test authentication failure, capability failure, invalid input, empty result, duplicate/retry, and timeout behavior on staging. Redact logs and set retention for request/response payloads. For mutations, use a unique idempotency key where supported or an application-side deduplication record. Verify the WordPress/GymCore/WooCommerce source record and downstream provider after every write. Document credential owner, rotation date, allowed IPs, incident response, and removal procedure. Related guides Webhooks and REST API Credentials and webhooks GymCore AI tools and abilities Diagnostics and support","headings":["Security contract","Registered catalogue","Integration checklist","Related guides"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/mcp-abilities.md"},{"route":"/docs/reference-rest-api/","slug":"reference-rest-api","title":"Hand a website integration to engineering","summary":"Hand a website integration to engineering.","text":"For a site owner, this catalogue identifies which website-to-website requests can read customer data or change GymCore records. Normal staff work should use the visible customer guides and admin screens. Engineers call these requests a REST API: authenticated software sends an HTTP method and URL to WordPress and receives structured data. A route is only a registered URL pattern; it is not proof that an account is authorized, an optional provider is active, or the downstream action succeeds. Inventory count: 148 registered rest-route rows. Registration is not a public support guarantee; verify the installed version, permission callback, schema, and side effects before integration. Security contract Use HTTPS and authenticated WordPress credentials or the explicitly supported integration signature. Give service accounts only the named WordPress permission required by the route. Engineers call that permission a capability. Never place application passwords, tokens, or webhook secrets in browser code, URLs, screenshots, or this documentation. The visible General \u0026gt; REST API switch does not gate registered routes in the audited source. Treat GET/read responses as personal data when they contain members, attendance, ranks, leads, messages, or finance. Treat POST/write calls as potentially irreversible; implement idempotency and verify the source record after each request. Registered catalogue Stable ID Item / route Source Audience Prerequisites Registered path Risk and side effect INV-REST-0001 gym-core-ai/v1/pending-actions wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:62 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/pending-actions medium: authenticated/operator surface; permission and side effects vary INV-REST-0002 gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/approve wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:73 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/approve medium: authenticated/operator surface; permission and side effects vary INV-REST-0003 gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/approve-with-changes wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:98 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/approve-with-changes medium: authenticated/operator surface; permission and side effects vary INV-REST-0004 gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/reject wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:129 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/reject medium: authenticated/operator surface; permission and side effects vary INV-REST-0005 gym-core-ai/v1/actions/bulk wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:160 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/bulk medium: authenticated/operator surface; permission and side effects vary INV-REST-0006 gym-core-ai/v1/actions/log wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:199 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/log medium: authenticated/operator surface; permission and side effects vary INV-REST-0007 gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/status wp-content/plugins/gym-core-ai/src/API/ActionEndpoint.php:239 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/actions/(?P\u0026lt;id\u0026gt;[\\d]+)/status medium: authenticated/operator surface; permission and side effects vary INV-REST-0008 gym-core-ai/v1/heartbeat wp-content/plugins/gym-core-ai/src/API/HeartbeatEndpoint.php:36 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/heartbeat medium: authenticated/operator surface; permission and side effects vary INV-REST-0009 gym-core-ai/v1/message wp-content/plugins/gym-core-ai/src/API/MessageEndpoint.php:38 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/gym-core-ai/v1/message medium: authenticated/operator surface; permission and side effects vary INV-REST-0010 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/AnalyticsController.php:60 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0011 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/AnalyticsController.php:71 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0012 $this-\u0026gt;namespace/check-in wp-content/plugins/gym-core/src/API/AttendanceController.php:70 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/check-in medium: authenticated/operator surface; permission and side effects vary INV-REST-0013 $this-\u0026gt;namespace/attendance/(?P\u0026lt;user_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/AttendanceController.php:108 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/attendance/(?P\u0026lt;user_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0014 $this-\u0026gt;namespace/attendance/record/(?P\u0026lt;record_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/AttendanceController.php:139 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/attendance/record/(?P\u0026lt;record_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0015 $this-\u0026gt;namespace/attendance/today wp-content/plugins/gym-core/src/API/AttendanceController.php:190 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/attendance/today medium: authenticated/operator surface; permission and side effects vary INV-REST-0016 $this-\u0026gt;namespace/billing/pause wp-content/plugins/gym-core/src/API/BillingController.php:63 finance/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/billing/pause medium-high: sensitive access/configuration INV-REST-0017 $this-\u0026gt;namespace/billing/resume wp-content/plugins/gym-core/src/API/BillingController.php:99 finance/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/billing/resume medium-high: sensitive access/configuration INV-REST-0018 $this-\u0026gt;namespace/briefings/class/(?P\u0026lt;class_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/BriefingController.php:59 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/briefings/class/(?P\u0026lt;class_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0019 $this-\u0026gt;namespace/briefings/today wp-content/plugins/gym-core/src/API/BriefingController.php:77 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/briefings/today medium: authenticated/operator surface; permission and side effects vary INV-REST-0020 $this-\u0026gt;namespace/announcements wp-content/plugins/gym-core/src/API/BriefingController.php:95 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/announcements medium: authenticated/operator surface; permission and side effects vary INV-REST-0021 $this-\u0026gt;namespace/classes/(?P\u0026lt;class_id\u0026gt;[\\d]+)/roster wp-content/plugins/gym-core/src/API/ClassRosterController.php:95 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/classes/(?P\u0026lt;class_id\u0026gt;[\\d]+)/roster medium: authenticated/operator surface; permission and side effects vary INV-REST-0022 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ClassScheduleController.php:75 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0023 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ClassScheduleController.php:105 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0024 $this-\u0026gt;namespace/schedule wp-content/plugins/gym-core/src/API/ClassScheduleController.php:123 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/schedule medium: authenticated/operator surface; permission and side effects vary INV-REST-0025 $this-\u0026gt;namespace/occurrences wp-content/plugins/gym-core/src/API/ClassScheduleController.php:152 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/occurrences medium: authenticated/operator surface; permission and side effects vary INV-REST-0026 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ClassScheduleController.php:174 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0027 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/CrmController.php:82 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0028 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/CrmController.php:116 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0029 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/CrmController.php:134 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0030 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/CrmController.php:177 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0031 $this-\u0026gt;namespace/foundations/(?P\u0026lt;user_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/FoundationsController.php:55 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/foundations/(?P\u0026lt;user_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0032 $this-\u0026gt;namespace/foundations/enroll wp-content/plugins/gym-core/src/API/FoundationsController.php:73 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/foundations/enroll medium: authenticated/operator surface; permission and side effects vary INV-REST-0033 $this-\u0026gt;namespace/foundations/coach-roll wp-content/plugins/gym-core/src/API/FoundationsController.php:91 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/foundations/coach-roll medium: authenticated/operator surface; permission and side effects vary INV-REST-0034 $this-\u0026gt;namespace/foundations/clear wp-content/plugins/gym-core/src/API/FoundationsController.php:115 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/foundations/clear medium: authenticated/operator surface; permission and side effects vary INV-REST-0035 $this-\u0026gt;namespace/foundations/active wp-content/plugins/gym-core/src/API/FoundationsController.php:133 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/foundations/active medium: authenticated/operator surface; permission and side effects vary INV-REST-0036 $this-\u0026gt;namespace/badges wp-content/plugins/gym-core/src/API/GamificationController.php:70 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/badges medium: authenticated/operator surface; permission and side effects vary INV-REST-0037 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges wp-content/plugins/gym-core/src/API/GamificationController.php:87 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges medium: authenticated/operator surface; permission and side effects vary INV-REST-0038 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/streak wp-content/plugins/gym-core/src/API/GamificationController.php:108 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/streak medium: authenticated/operator surface; permission and side effects vary INV-REST-0039 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges wp-content/plugins/gym-core/src/API/GamificationController.php:153 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges medium: authenticated/operator surface; permission and side effects vary INV-REST-0040 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges/(?P\u0026lt;slug\u0026gt;[a-z0-9_]+) wp-content/plugins/gym-core/src/API/GamificationController.php:177 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/badges/(?P\u0026lt;slug\u0026gt;[a-z0-9_]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0041 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/HealthController.php:69 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0042 $this-\u0026gt;namespace/attendance-heatmap/(?P\u0026lt;user_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/HeatmapController.php:74 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/attendance-heatmap/(?P\u0026lt;user_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0043 $this-\u0026gt;namespace/attendance-heatmap/(?P\u0026lt;user_id\u0026gt;[\\d]+)/mini wp-content/plugins/gym-core/src/API/HeatmapController.php:102 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/attendance-heatmap/(?P\u0026lt;user_id\u0026gt;[\\d]+)/mini medium: authenticated/operator surface; permission and side effects vary INV-REST-0044 gym/v1/admin/ wp-content/plugins/gym-core/src/API/IntegrationController.php:64 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0045 gym/v1/admin/ wp-content/plugins/gym-core/src/API/IntegrationController.php:74 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0046 gym/v1/admin/ wp-content/plugins/gym-core/src/API/IntegrationController.php:85 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0047 gym/v1/admin/ wp-content/plugins/gym-core/src/API/IntegrationController.php:96 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0048 gym/v1/admin/ wp-content/plugins/gym-core/src/API/IntegrationController.php:107 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0049 $this-\u0026gt;namespace/integrations wp-content/plugins/gym-core/src/API/IntegrationsController.php:56 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/integrations medium: authenticated/operator surface; permission and side effects vary INV-REST-0050 $this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/connect wp-content/plugins/gym-core/src/API/IntegrationsController.php:66 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/connect medium: authenticated/operator surface; permission and side effects vary INV-REST-0051 $this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/disconnect wp-content/plugins/gym-core/src/API/IntegrationsController.php:87 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/disconnect medium: authenticated/operator surface; permission and side effects vary INV-REST-0052 $this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/health wp-content/plugins/gym-core/src/API/IntegrationsController.php:104 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/integrations/(?P\u0026lt;slug\u0026gt;[a-z0-9_-]+)/health medium: authenticated/operator surface; permission and side effects vary INV-REST-0053 self::REST_NAMESPACE/ wp-content/plugins/gym-core/src/API/KioskSearchController.php:38 operator/developer/integration client plugin active REST /wp-json/self::REST_NAMESPACE/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0054 gym/v1/admin/ wp-content/plugins/gym-core/src/API/KnowledgeController.php:65 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0055 gym/v1/admin/ wp-content/plugins/gym-core/src/API/KnowledgeController.php:99 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0056 gym/v1/admin/ wp-content/plugins/gym-core/src/API/KnowledgeController.php:145 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0057 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadCommsController.php:46 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0058 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadCommsController.php:57 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0059 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadCommsController.php:79 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0060 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadCommsController.php:90 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0061 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:78 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0062 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:135 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0063 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:153 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0064 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:164 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0065 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:183 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0066 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:216 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0067 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LeadsController.php:241 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0068 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LicenseWebhookController.php:62 operator/developer/integration client active license REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0069 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LicenseWebhookController.php:72 operator/developer/integration client active license REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0070 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LocationController.php:75 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0071 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LocationController.php:89 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0072 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/LocationController.php:104 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0073 $this-\u0026gt;namespace/user/location wp-content/plugins/gym-core/src/API/LocationController.php:121 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/user/location medium: authenticated/operator surface; permission and side effects vary INV-REST-0074 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/MediaController.php:60 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0075 $this-\u0026gt;namespace/member/coaching/feed wp-content/plugins/gym-core/src/API/MemberCoachingController.php:133 member/parent or public visitor plugin active REST /wp-json/$this-\u0026gt;namespace/member/coaching/feed medium: authenticated/operator surface; permission and side effects vary INV-REST-0076 $this-\u0026gt;namespace/member/coaching/chat wp-content/plugins/gym-core/src/API/MemberCoachingController.php:143 member/parent or public visitor plugin active REST /wp-json/$this-\u0026gt;namespace/member/coaching/chat medium: authenticated/operator surface; permission and side effects vary INV-REST-0077 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/MemberController.php:128 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0078 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/meta wp-content/plugins/gym-core/src/API/MemberMetaController.php:52 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/meta medium: authenticated/operator surface; permission and side effects vary INV-REST-0079 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/foundations/reset wp-content/plugins/gym-core/src/API/MemberMetaController.php:70 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/foundations/reset medium: authenticated/operator surface; permission and side effects vary INV-REST-0080 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/notes wp-content/plugins/gym-core/src/API/NotesController.php:54 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/notes medium: authenticated/operator surface; permission and side effects vary INV-REST-0081 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/notes/(?P\u0026lt;note_id\u0026gt;[a-zA-Z0-9_-]+) wp-content/plugins/gym-core/src/API/NotesController.php:93 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/notes/(?P\u0026lt;note_id\u0026gt;[a-zA-Z0-9_-]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0082 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/OrderController.php:50 operator/developer/integration client WooCommerce REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0083 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/OrderController.php:72 operator/developer/integration client WooCommerce REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0084 $this-\u0026gt;namespace/subscriptions/member/(?P\u0026lt;user_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/OrderController.php:91 member/parent or public visitor WooCommerce; WooCommerce Subscriptions REST /wp-json/$this-\u0026gt;namespace/subscriptions/member/(?P\u0026lt;user_id\u0026gt;[\\d]+) high: mutates data, sends communication, or crosses trust boundary INV-REST-0085 $this-\u0026gt;namespace/subscriptions/summary wp-content/plugins/gym-core/src/API/OrderController.php:110 operator/developer/integration client WooCommerce; WooCommerce Subscriptions REST /wp-json/$this-\u0026gt;namespace/subscriptions/summary high: mutates data, sends communication, or crosses trust boundary INV-REST-0086 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/OrderController.php:122 operator/developer/integration client WooCommerce REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0087 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/OrderController.php:144 operator/developer/integration client WooCommerce REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0088 gym/v1/crm/ wp-content/plugins/gym-core/src/API/ParentPortalController.php:100 member/parent or public visitor plugin active REST /wp-json/gym/v1/crm/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0089 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/programs wp-content/plugins/gym-core/src/API/ProgramController.php:47 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/programs medium: authenticated/operator surface; permission and side effects vary INV-REST-0090 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/programs/(?P\u0026lt;sub_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/ProgramController.php:105 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/programs/(?P\u0026lt;sub_id\u0026gt;[\\d]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0091 $this-\u0026gt;namespace/promotions/eligible wp-content/plugins/gym-core/src/API/PromotionController.php:52 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/promotions/eligible medium: authenticated/operator surface; permission and side effects vary INV-REST-0092 $this-\u0026gt;namespace/promotions/recommend wp-content/plugins/gym-core/src/API/PromotionController.php:73 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/promotions/recommend medium: authenticated/operator surface; permission and side effects vary INV-REST-0093 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/PublicWaiverController.php:75 member/parent or public visitor Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0094 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank wp-content/plugins/gym-core/src/API/RankController.php:70 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank medium: authenticated/operator surface; permission and side effects vary INV-REST-0095 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank-history wp-content/plugins/gym-core/src/API/RankController.php:93 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank-history medium: authenticated/operator surface; permission and side effects vary INV-REST-0096 $this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank/(?P\u0026lt;discipline\u0026gt;[a-z0-9-]+) wp-content/plugins/gym-core/src/API/RankController.php:119 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/members/(?P\u0026lt;id\u0026gt;[\\d]+)/rank/(?P\u0026lt;discipline\u0026gt;[a-z0-9-]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0097 $this-\u0026gt;namespace/ranks/promote wp-content/plugins/gym-core/src/API/RankController.php:143 coach/head coach/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ranks/promote high: mutates data, sends communication, or crosses trust boundary INV-REST-0098 gym/v1/admin/ wp-content/plugins/gym-core/src/API/RbacController.php:61 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0099 gym/v1/admin/ wp-content/plugins/gym-core/src/API/RbacController.php:86 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0100 $this-\u0026gt;namespace/referrals/my wp-content/plugins/gym-core/src/API/ReferralController.php:61 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/referrals/my medium: authenticated/operator surface; permission and side effects vary INV-REST-0101 $this-\u0026gt;namespace/referrals/leaderboard wp-content/plugins/gym-core/src/API/ReferralController.php:71 sales/front desk/admin plugin active REST /wp-json/$this-\u0026gt;namespace/referrals/leaderboard medium: authenticated/operator surface; permission and side effects vary INV-REST-0102 $this-\u0026gt;namespace/referrals wp-content/plugins/gym-core/src/API/ReferralController.php:90 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/referrals medium: authenticated/operator surface; permission and side effects vary INV-REST-0103 gym/v1/admin/reports/sources wp-content/plugins/gym-core/src/API/ReportController.php:67 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/reports/sources medium: authenticated/operator surface; permission and side effects vary INV-REST-0104 gym/v1/admin/reports wp-content/plugins/gym-core/src/API/ReportController.php:77 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/reports medium: authenticated/operator surface; permission and side effects vary INV-REST-0105 gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+) wp-content/plugins/gym-core/src/API/ReportController.php:95 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0106 gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+)/run wp-content/plugins/gym-core/src/API/ReportController.php:118 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+)/run medium: authenticated/operator surface; permission and side effects vary INV-REST-0107 gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+)/export wp-content/plugins/gym-core/src/API/ReportController.php:128 operator/developer/integration client plugin active REST /wp-json/gym/v1/admin/reports/(?P\u0026lt;id\u0026gt;[a-z0-9_]+)/export medium: authenticated/operator surface; permission and side effects vary INV-REST-0108 $this-\u0026gt;namespace/sms/send wp-content/plugins/gym-core/src/API/SMSController.php:66 operator/developer/integration client Twilio credentials + SMS enabled REST /wp-json/$this-\u0026gt;namespace/sms/send high: mutates data, sends communication, or crosses trust boundary INV-REST-0109 $this-\u0026gt;namespace/sms/conversations/(?P\u0026lt;contact_id\u0026gt;[\\d]+) wp-content/plugins/gym-core/src/API/SMSController.php:111 operator/developer/integration client Twilio credentials + SMS enabled REST /wp-json/$this-\u0026gt;namespace/sms/conversations/(?P\u0026lt;contact_id\u0026gt;[\\d]+) high: mutates data, sends communication, or crosses trust boundary INV-REST-0110 $this-\u0026gt;namespace/sms/templates wp-content/plugins/gym-core/src/API/SMSController.php:133 operator/developer/integration client Twilio credentials + SMS enabled REST /wp-json/$this-\u0026gt;namespace/sms/templates high: mutates data, sends communication, or crosses trust boundary INV-REST-0111 $this-\u0026gt;namespace/products wp-content/plugins/gym-core/src/API/SalesController.php:87 sales/front desk/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/products medium: authenticated/operator surface; permission and side effects vary INV-REST-0112 $this-\u0026gt;namespace/calculate wp-content/plugins/gym-core/src/API/SalesController.php:108 sales/front desk/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/calculate medium: authenticated/operator surface; permission and side effects vary INV-REST-0113 $this-\u0026gt;namespace/customer wp-content/plugins/gym-core/src/API/SalesController.php:137 sales/front desk/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/customer medium: authenticated/operator surface; permission and side effects vary INV-REST-0114 $this-\u0026gt;namespace/order wp-content/plugins/gym-core/src/API/SalesController.php:158 sales/front desk/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/order high: mutates data, sends communication, or crosses trust boundary INV-REST-0115 $this-\u0026gt;namespace/lead wp-content/plugins/gym-core/src/API/SalesController.php:172 sales/front desk/admin WooCommerce REST /wp-json/$this-\u0026gt;namespace/lead medium: authenticated/operator surface; permission and side effects vary INV-REST-0116 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ScheduleCalendarController.php:48 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0117 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ScheduleCalendarController.php:88 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0118 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/ScheduleCalendarController.php:156 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0119 $this-\u0026gt;namespace/tournaments wp-content/plugins/gym-core/src/API/TournamentController.php:63 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/tournaments medium: authenticated/operator surface; permission and side effects vary INV-REST-0120 $this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+) wp-content/plugins/gym-core/src/API/TournamentController.php:80 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0121 $this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+)/register wp-content/plugins/gym-core/src/API/TournamentController.php:97 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+)/register medium: authenticated/operator surface; permission and side effects vary INV-REST-0122 $this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+)/results wp-content/plugins/gym-core/src/API/TournamentController.php:114 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/tournaments/(?P\u0026lt;id\u0026gt;\\d+)/results medium: authenticated/operator surface; permission and side effects vary INV-REST-0123 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:85 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0124 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:104 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0125 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:122 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0126 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:139 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0127 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:149 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0128 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:159 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0129 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/TrialAppointmentsController.php:170 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0130 $this-\u0026gt;namespace/twilio/test-message wp-content/plugins/gym-core/src/API/TwilioController.php:56 operator/developer/integration client Twilio credentials + SMS enabled REST /wp-json/$this-\u0026gt;namespace/twilio/test-message medium: authenticated/operator surface; permission and side effects vary INV-REST-0131 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/WaitlistController.php:52 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0132 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/WaiverController.php:56 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0133 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/WaiverController.php:97 operator/developer/integration client Gym Core AI/WP AI Client; API credentials as configured REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0134 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/API/WalkInController.php:71 operator/developer/integration client plugin active REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0135 gym/v1/kiosk/welcome/(?P\u0026lt;user_id\u0026gt;\\d+) wp-content/plugins/gym-core/src/Attendance/KioskWelcomeController.php:121 coach/head coach/admin plugin active REST /wp-json/gym/v1/kiosk/welcome/(?P\u0026lt;user_id\u0026gt;\\d+) medium: authenticated/operator surface; permission and side effects vary INV-REST-0136 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Finance/API/FinanceController.php:84 finance/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium-high: sensitive access/configuration INV-REST-0137 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Finance/API/FinanceController.php:95 finance/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium-high: sensitive access/configuration INV-REST-0138 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Finance/API/FinanceController.php:106 finance/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium-high: sensitive access/configuration INV-REST-0139 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Finance/API/FinanceController.php:130 finance/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium-high: sensitive access/configuration INV-REST-0140 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Finance/API/FinanceController.php:147 finance/admin plugin active REST /wp-json/$this-\u0026gt;namespace/ medium-high: sensitive access/configuration INV-REST-0141 gym/v1/funnel-event wp-content/plugins/gym-core/src/Funnel/FunnelLogger.php:146 site admin/staff plugin active REST /wp-json/gym/v1/funnel-event medium: authenticated/operator surface; permission and side effects vary INV-REST-0142 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Members/ImportController.php:46 site admin/staff plugin active REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0143 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/Members/ImportController.php:56 site admin/staff plugin active REST /wp-json/$this-\u0026gt;namespace/ high: mutates data, sends communication, or crosses trust boundary INV-REST-0144 $this-\u0026gt;namespace/ wp-content/plugins/gym-core/src/PWA/PushSubscriptionEndpoint.php:55 site admin/staff WooCommerce Subscriptions REST /wp-json/$this-\u0026gt;namespace/ medium: authenticated/operator surface; permission and side effects vary INV-REST-0145 gym/v1/sms/webhook wp-content/plugins/gym-core/src/SMS/InboundHandler.php:102 operator/developer/integration client Twilio credentials + SMS enabled REST /wp-json/gym/v1/sms/webhook high: mutates data, sends communication, or crosses trust boundary INV-REST-0146 $this-\u0026gt;namespace/social/draft wp-content/plugins/gym-core/src/Social/SocialPostManager.php:76 site admin/staff plugin active REST /wp-json/$this-\u0026gt;namespace/social/draft medium: authenticated/operator surface; permission and side effects vary INV-REST-0147 $this-\u0026gt;namespace/social/pending wp-content/plugins/gym-core/src/Social/SocialPostManager.php:109 site admin/staff plugin active REST /wp-json/$this-\u0026gt;namespace/social/pending medium: authenticated/operator surface; permission and side effects vary INV-REST-0148 $this-\u0026gt;namespace/social/(?P\u0026lt;post_id\u0026gt;[\\d]+)/approve wp-content/plugins/gym-core/src/Social/SocialPostManager.php:119 site admin/staff plugin active REST /wp-json/$this-\u0026gt;namespace/social/(?P\u0026lt;post_id\u0026gt;[\\d]+)/approve medium: authenticated/operator surface; permission and side effects vary Integration checklist Pin the installed GymCore/GymCore AI version you tested. Confirm exact method, namespace, request schema, permission callback, and response schema in source. Test authentication failure, capability failure, invalid input, empty result, duplicate/retry, and timeout behavior on staging. Redact logs and set retention for request/response payloads. For mutations, use a unique idempotency key where supported or an application-side deduplication record. Verify the WordPress/GymCore/WooCommerce source record and downstream provider after every write. Document credential owner, rotation date, allowed IPs, incident response, and removal procedure. Related guides Webhooks and REST API Credentials and webhooks GymCore AI tools and abilities Diagnostics and support","headings":["Security contract","Registered catalogue","Integration checklist","Related guides"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/rest-api.md"},{"route":"/docs/reference-roles-permissions-matrix/","slug":"reference-roles-permissions-matrix","title":"Roles and permissions matrix","summary":"Roles and permissions matrix.","text":"Use this page to answer “what can this staff member actually see or change?” Start with their job, test the exact task with their account, and grant the smallest access that works. GymCore access is layered. A WordPress role is a bundle of permissions. Engineers call each individual permission a capability. The four Staff Access checkboxes, older GymCore permissions, WooCommerce permissions, and GymCore AI persona/tool gates can all differ. Built-in role defaults WordPress role Main legacy GymCore defaults Staff Access defaults Administrator All GymCore capabilities through administrator sync Manage Members, Manage Billing, View Reports, Manage Staff Shop Manager WooCommerce management; legacy access varies by synced capability All four Staff Access permissions Head Coach (gym_head_coach) Promote/view ranks, check in/view attendance, achievements, SMS, curriculum, announcements, briefings, sales, AI; can edit users Manage Members, View Reports, Manage Staff Coach (gym_coach) Promote/view ranks, check in/view attendance, achievements, briefings, AI View Reports Finance (gym_finance) Finance AI, manage_woocommerce, order capabilities Manage Billing, View Reports Sales (gym_sales) Sales processing, leads, SMS, AI Manage Members Defaults can be changed, and plugin-version capability sync may update role capabilities. Test effective access on the installed site. Staff Access controls Path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access. Visible permission Capability Manage Members gymcore_manage_members Manage Billing gymcore_manage_billing View Reports gymcore_view_reports Manage Staff gymcore_manage_staff The page can apply Gym Owner, Head Instructor, Staff Instructor, or Front Desk presets. Administrators always receive all four newer capabilities. Subscriber and Contributor are excluded from the configurable role table. Capabilities used outside Staff Access Task/surface Capability examples Promotions/ranks gym_promote_student, gym_view_ranks Attendance/kiosk gym_check_in_member, gym_view_attendance SMS gym_send_sms Curriculum/announcements gym_manage_curriculum, gym_manage_announcements Sales/leads gym_process_sale, gym_manage_leads Finance gymcore_view_billing; legacy gym_view_finance and inherited manage_woocommerce remain compatibility sources Core Settings gymcore_manage_settings; administrators with manage_options also qualify GymCore AI hub gym_view_ai_hub; manage_woocommerce remains an overview compatibility source, and individual destinations have additional policies AI administration manage_options GymCore AI persona defaults Persona Gate Sales Agent gym_process_sale Coaching Agent gym_view_briefing My Coach read Finance gym_view_finance Admin Agent manage_options An administrator can override persona gates to read, gym_view_briefing, gym_process_sale, gym_view_finance, gym_use_gandalf, edit_posts, or manage_options. Each tool also declares its own capability. Persona visibility never proves every tool will run. Least-privilege test Create or use a non-production staff test account with the target role. Apply only the intended Staff Access preset/permissions. Sign in as that user in a separate private browser session. Test menu visibility, record lists, direct URLs, REST actions, AI persona visibility, and one safe read tool. Confirm blocked actions return a clear denial rather than exposing data. Remove the test account or credentials after acceptance. Never share an administrator account to work around a missing menu. Record access changes and re-test after plugin updates. Related guides Staff Access settings Roles and capabilities Agent personas MCP abilities","headings":["Built-in role defaults","Staff Access controls","Capabilities used outside Staff Access","GymCore AI persona defaults","Least-privilege test","Related guides"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/roles-permissions-matrix.md"},{"route":"/docs/reference-scheduled-jobs-automation/","slug":"reference-scheduled-jobs-automation","title":"Inspect scheduled GymCore work","summary":"Inspect scheduled GymCore work.","text":"GymCore uses WordPress’s scheduler and, where available, WooCommerce Action Scheduler to perform work after the page request ends. For owners, “scheduled” means queued—not completed. Verify the source record, the scheduled entry, and the final provider or customer result. Recurring work registered by source Hook Cadence/start Purpose and dependency `gym_core_report_delivery` Daily, scheduled for 07:00 local time Delivers due saved reports `gym_core_churn_evaluate_daily` Daily, scheduled for 06:00 local time Recalculates churn scores `gym_core_retention_daily` Daily, scheduled for 18:05 local time Runs retention processing; audited provider exits when SMS is disabled `gym_core_pause_auto_resume` Daily Resumes eligible membership pauses `gym_core_pause_reminder` Daily Processes pause reminders `gym_core_anniversary_sweep` Weekly Evaluates membership anniversaries `gym_core_license_check` Daily Refreshes license status `gym_core_daily_maintenance` Daily Runs registered maintenance `gym_core_ai_purge_conversations` Daily Purges expired AI conversations and messages; pending actions and all audit data are not included `gym_core_ai_sms_scan_lapsed` Daily, first run about one hour after scheduling Scans lapsed-member automation when the AutomateWoo bootstrap is active `gym_core_ai_sms_scan_promotion` Daily, first run about two hours after scheduling Scans promotion automation when the AutomateWoo bootstrap is active `gym_core_briefing_sweep` Daily through Action Scheduler Finds due coach briefings and schedules `gym_core_send_briefing_sms` Times are created by plugin code using the site’s WordPress clock. A low-traffic site can run WP-Cron late; Action Scheduler availability and queue health are runtime dependencies. One-time and asynchronous work Hook Trigger `gym_core_ai_send_sms_async` Queued AI SMS send; Action Scheduler is preferred and WP-Cron is the fallback `gym_core_ai_webhook_secret_cleanup` Removes an old AI webhook secret after rotation `gym_core_setup_import_batch` Processes an onboarding import batch `gym_core_qbo_sync_order` QuickBooks order/refund/payout sync; normal delays include 10 seconds for order/refund and 30 seconds for payout `gym_core_async_evaluate_badges` Evaluates badges after relevant activity `gym_core_evaluate_milestones` Evaluates attendance milestones `gym_core_invalidate_heatmap_cache` Invalidates the schedule heatmap cache after a short delay; code can fall back to immediate invalidation `gym_core_retry_public_trial_finalization` Retries trial finalization after 60 seconds `gym_core_seed_referral_codes` Seeds referral codes `gym_core_lead_follow_up_due`, `gym_core_trial_reminder_due`, `gym_core_no_show_recovery_due`, `gym_core_post_trial_follow_up_due`, `gym_core_internal_follow_up_due`, `gym_core_sms_follow_up_due`, `gym_core_email_follow_up_due` Lead and trial follow-up events; Action Scheduler is preferred with WP-Cron fallback Manual QuickBooks re-sync schedules one action per matching order, up to 500, staggered by two seconds. A failed-sync note can schedule a retry after 60 seconds. Exact steps Safe stop: Inspect the queued action and its logs without running or retrying it; stop before a retry when the downstream result is unknown because messages and external writes can duplicate. Record the source record ID, the expected hook, and the time the action should have been created. Expected: The report can be tied to one order, member, lead, report, or maintenance purpose. If WooCommerce Action Scheduler is active, open WooCommerce \u0026gt; Status \u0026gt; Scheduled Actions and search for the exact hook. Otherwise, have an administrator or engineer inspect WordPress cron events with the site’s approved tooling. Expected: The hook is pending, complete, failed, or absent. Do not report completion from “pending.” Open the action’s log or WordPress error log and compare its arguments with the source record. Expected: The queued arguments identify the same record. A completed scheduler entry can still contain a downstream provider failure. Check the final system: WooCommerce/QuickBooks for accounting, the SMS provider for delivery, GymCore tables for ranks/attendance/retention, or the license merchant service for entitlement. Expected: The final source shows the intended result. If it does not, preserve the failed action and error before retrying; repeated jobs can duplicate messages or external writes. Symptoms Many overdue WP-Cron events point to site traffic or cron configuration, not one GymCore record. Failed Action Scheduler entries with authentication errors point to the external provider or credentials. Retention work absent while SMS is disabled matches the audited gate. AI conversation purging does not remove every pending action or audit record; review those stores under the applicable retention policy. Verified against: current recurring and single-event registrations in GymCore and GymCore AI source.","headings":["Recurring work registered by source","One-time and asynchronous work","Exact steps","Symptoms"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/scheduled-jobs-automation.md"},{"route":"/docs/reference-statuses-fields/","slug":"reference-statuses-fields","title":"Interpret GymCore statuses before acting","summary":"Interpret GymCore statuses before acting.","text":"A status describes one part of a record, not the whole customer journey. Read the customer-facing label first, then use the stored value below when handing a case to support or engineering. Do not change a database value simply to make a screen look resolved. Lead pipeline Status group Stored values Default What it answers Pipeline stage `lead`, `trial_booked`, `trial_attended`, `offer_made`, `converted`, `lost` `lead` Where the prospect is in the commercial journey Contact status `new`, `first_attempt_due`, `first_attempted`, `contacted`, `waiting_on_reply`, `stale` `new` What staff have done to reach the lead Trial status `not_scheduled`, `requested`, `scheduled`, `confirmed_24h`, `confirmed_day_of`, `waiver_pending`, `waiver_complete`, `checked_in`, `no_show`, `reschedule_needed`, `cancelled` `not_scheduled` What happened to the trial appointment Sales disposition `none`, `membership_offer_sent`, `started_free_trial`, `comeback_appointment`, `not_interested`, `bad_fit`, `duplicate`, `invalid` `none` The sales outcome or next commitment SMS consent `unknown`, `opted_in`, `opted_out` `unknown` Whether SMS contact is permitted Email consent `unknown`, `opted_in`, `opted_out` `unknown` Whether email contact is permitted The trial-appointment store uses the actionable trial values from `scheduled` through `cancelled`; a lead can still have `not_scheduled` or `requested` before an appointment row exists. A blank Lead Pipeline is a real empty state, not proof of a rendering error. AI proposed actions Stored value Meaning `pending` Waiting for staff review `approved` Approved for dispatch or processing `approved_with_changes` Staff edited and approved it `completed` The action processor recorded completion `rejected` Staff declined it An action JSON record is the machine-readable set of proposed action details. Owners should use the visible approval queue; engineers may inspect that record when diagnosing. “Completed” is a local action state and must still be compared with the destination system, such as the SMS provider, WooCommerce, or a published post. Other operational statuses Record Stored values/default Source boundary Tournament Blank until selected; `upcoming`, `open`, `closed`, `completed` WordPress tournament post meta Class occurrence `active` by default; `cancelled`, `suspended` GymCore class-occurrence row; WordPress post publication is separate Membership pause `active`, `resumed` GymCore pause record; WooCommerce subscription may separately be `on-hold` or `active` QuickBooks sync `success`, `error`, `skipped` GymCore sync log only; QuickBooks owns the accounting result QuickBooks entity `order`, `refund`, `payout`, `failed_retry` Identifies the attempted operation, not its success License badge Active, Expired, Invalid, Not Activated Cached local license state; compare with getgymcore.com Communication provider statuses can change after GymCore first records a message. The configured provider’s latest delivery event is the final delivery source. Exact steps Safe stop: Read and compare the owning records without changing a status; stop when no supported transition exists instead of editing a stored value directly. Record the customer-facing label, stored value if visible, record ID, and timestamp. Expected: You can identify both the status group and the exact record it describes. Open the owning record: lead, trial appointment, AI approval, tournament post, class occurrence, pause, WooCommerce subscription, or QuickBooks transaction. Expected: The source record shows whether the status is current, stale, or describing only one part of the workflow. Compare related records by ID and time rather than forcing their labels to match. Expected: A trial, lead stage, sales disposition, and consent state can legitimately differ because they answer different questions. Use the supported customer action that produces the desired transition, then reload the owning record. Expected: The source record records the new state and related logs show the transition. If no supported transition exists, preserve the record and escalate; direct status edits can skip consent, billing, or notification side effects. Symptom examples A lead at `converted` with SMS `opted_out` is not contradictory; membership and communication permission are separate. A local AI action at `completed` with a provider error still requires delivery investigation. A pause row at `resumed` while a WooCommerce subscription remains `on-hold` indicates a cross-system mismatch. A tournament with blank status will not automatically become `upcoming`; select and save the intended status. Verified against: current lead constants, trial appointment store, AI pending-action store, tournament/class/pause models, QuickBooks sync log, and license UI.","headings":["Lead pipeline","AI proposed actions","Other operational statuses","Exact steps","Symptom examples"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/statuses-fields.md"},{"route":"/docs/reference-wp-cli/","slug":"reference-wp-cli","title":"Run GymCore command-line operations safely","summary":"Run GymCore command-line operations safely.","text":"This page is an administrator-to-engineer handoff. WP-CLI commands run directly against the site and can export personal data, erase records, restore tables, or create demo content. Use the correct environment, a scoped backup, and the site’s approved shell access. Backup and restore commands Command Required input Result and risk `wp gymcore backup \u0026lt;tenant_id\u0026gt;` Tenant ID Creates a tenant backup file `wp gymcore backup-list \u0026lt;tenant_id\u0026gt;` Tenant ID Lists available tenant backups `wp gymcore restore \u0026lt;tenant_id\u0026gt; \u0026lt;file\u0026gt;` Matching tenant ID and backup file Upserts custom-table rows; verify cross-system references after restore The restore command checks the tenant in the backup. It does not replace a full WordPress/WooCommerce/database recovery plan. Demo data Command Behavior `wp gymcore demo-seed` Idempotently creates the registered demo records `wp gymcore demo-seed –reset` Deletes the command’s seeded records and seeds them again `–reset` is destructive to seeded data. It is not a general production cleanup command. Privacy commands Command Behavior `wp gymcore gdpr-export –email=\u0026lt;email\u0026gt; –format=json –output=\u0026lt;file\u0026gt;` Exports the matching person’s data as JSON `wp gymcore gdpr-export –email=\u0026lt;email\u0026gt; –format=csv –output=\u0026lt;file\u0026gt;` Exports the matching person’s data as CSV `wp gymcore gdpr-erase –email=\u0026lt;email\u0026gt;` Requests confirmation, deletes selected GymCore user meta/rank history, and anonymizes attendance to user ID 0 `wp gymcore gdpr-erase –email=\u0026lt;email\u0026gt; –yes` Performs the same erasure without the interactive confirmation Prefer the confirmation prompt. Protect exports, verify identity, review legal holds, and separately assess WooCommerce, CRM, AI logs, third parties, and backups. Import commands Command Options supported by source Dependency or behavior `wp gym import belt-ranks –file=\u0026lt;path\u0026gt;` `–dry-run`, `–batch-size=\u0026lt;n\u0026gt;` default 500, `–skip-existing` Imports belt/rank rows `wp gym import attendance –file=\u0026lt;path\u0026gt;` `–dry-run`, `–batch-size=\u0026lt;n\u0026gt;` default 500 Imports attendance `wp gym import achievements –file=\u0026lt;path\u0026gt;` `–dry-run`, `–skip-existing` Imports achievements `wp gym import users –file=\u0026lt;path\u0026gt;` `–dry-run`, `–skip-existing` Imports users `wp gym import notes –file=\u0026lt;path\u0026gt;` `–dry-run`, `–batch-size=\u0026lt;n\u0026gt;` default 500 Requires Jetpack CRM The current command set has no generic import rollback command. A dry run and pre-import backup are the recovery preparation. Exact steps Safe stop: Run discovery or dry-run commands first and stop before a write, import, privacy, or deletion command until the exact site, backup, arguments, and rollback have been verified. Confirm the shell points to the intended WordPress root and environment, then run `wp core version` and `wp plugin status gym-core`. Expected: WP-CLI identifies the intended site and reports GymCore active. Stop if the URL, database, or plugin state is unexpected. For an import, validate the file outside production and run the same import command with `–dry-run` when that command supports it. Expected: The command reports what it would process without creating source rows. Create and record the appropriate backup before a restore, erasure, reset, or live import. Expected: The backup location, tenant/site, timestamp, and responsible operator are known before the consequential command runs. Run the exact command once without adding undocumented flags. Expected: WP-CLI returns a specific success or error. Preserve the output; do not immediately rerun after a timeout because the first process may have written records. Verify the owning source: imported user, attendance, rank, achievement, or CRM note; restored custom-table counts and sample IDs; exported archive; or anonymized privacy record. Expected: Source records match the command summary and related WordPress/WooCommerce records remain consistent. If they do not, stop further commands and use the recorded backup and output for a reviewed recovery. Verified against: current BackupCommand, DemoCommand, GdprCommand, and ImportCommand registrations in the checked-out GymCore source.","headings":["Backup and restore commands","Demo data","Privacy commands","Import commands","Exact steps"],"source_sha256":"","section":"Reference","source":"docs/user-guide/reference/wp-cli.md"},{"route":"/docs/reports-data-analytics-reports/","slug":"reports-data-analytics-reports","title":"Review analytics and investigate a metric","summary":"Review analytics and investigate a metric.","text":"Load a defined reporting period, trace an unexpected metric to its source records, and export only when an approved recipient needs the data. Access and dependencies Use a Finance Admin, administrator, shop manager, or other account with manage_woocommerce. GymCore supplies member, attendance, rank, lead, referral, class, and retention data. WooCommerce supplies billing and revenue data. The Analytics screen is a summary. Correct the member, check-in, lead, order, or other source record—not the displayed metric. Exact steps Safe stop: Refresh and reconcile the selected period without changing source records; stop before Export CSV until the range, columns, recipient, and storage location are approved. Open GymCore Admin \u0026gt; Analytics \u0026amp; Reports, then select the Analytics tab. Review From and To. The defaults are 30 days before the current UTC date and the current UTC date. Enter the approved period and select Refresh. Expected: The page reloads Active Members, New Members, Churn Rate, Avg. Duration (days), Attendance Rate, Trial Conversion, Referral Conversion, Belt Promotions, AI Chat Engagement, Portal Logins, and Revenue for that period. Compare This Period, Prior Period, and Change. Use Most Popular Classes, Check-in Frequency, Membership Tiers, and Retention by Cohort to narrow an outlier. Open the owning record: the GymCore member, attendance entry, rank, lead, referral, or class; the WooCommerce order for billing; or the AI service record for chat engagement. Expected: The source record’s date and status explain whether it belongs in the selected period. If it does not, correct it through that feature’s approved workflow and refresh analytics. Select Export CSV only when an approved staff recipient needs the current summary. Expected: The browser downloads gym-analytics-YYYY-MM-DD–YYYY-MM-DD.csv for the selected period. The export contains the same snapshot shown on the page; it does not alter source records. Verify the final result against its owning source system: reopen at least one source record for each disputed metric and compare it with the refreshed screen or CSV. Expected: GymCore values agree with GymCore source records, and revenue agrees with the applicable WooCommerce orders. Record any remaining definition mismatch instead of changing data to force a total. Defaults, effects, and data handling The API uses the same 30-days-ago through today defaults when dates are omitted and accepts YYYY-MM-DD dates. Refresh is read-only. Export CSV moves reporting data outside WordPress access controls; store it in an approved location, share it with the smallest audience, and delete it under the gym’s retention policy. If a metric looks wrong Screen stays on Loading: preserve the selected dates and visible error, then ask the administrator to check the analytics REST request and manage_woocommerce access. Revenue differs from finance: compare order dates, statuses, refunds, and the exact reporting period in WooCommerce. Attendance or member count differs: open the underlying GymCore records and check timezone boundaries and duplicate profiles. Export differs from the screen: refresh once with the same dates, then export again; do not merge files from different periods. Related guides Privacy Requests Roles Capabilities Common Checks","headings":["Access and dependencies","Exact steps","Defaults, effects, and data handling","If a metric looks wrong","Related guides"],"source_sha256":"","section":"Reports \u0026 Data","source":"docs/user-guide/reports-data/analytics-reports.md"},{"route":"/docs/reports-data-attendance-membership/","slug":"reports-data-attendance-membership","title":"Review attendance and membership risk","summary":"Review attendance and membership risk.","text":"Use attendance history and trends to investigate behavior, then verify billing separately before contacting a member. Access and dependencies Today, History, and Trends require gym_check_in_member. At-Risk Members also requires manage_woocommerce; use an administrator or another account that has both capabilities. Attendance comes from GymCore check-ins. Billing status comes from the installed WooCommerce and recurring-billing stack. One does not overwrite the other. Exact steps Safe stop: Review the score and owning records without contacting the member; stop before Trigger Retention until identity, consent, workflow, and recipient are verified. Open GymCore Students \u0026gt; Attendance. Select History. Set From, To, Program, and Location, then select Filter. Expected: The history lists check-ins that match the chosen GymCore filters. It does not infer payment status. Select Trends and compare This Week, Last Week, and 4-week avg/week. Open the member or class behind an unexpected count before acting on the trend. If you have manage_woocommerce, select At-Risk Members. The score is out of 100: attendance contributes up to 50 points, missed sessions 25, tenure 15, and portal engagement 10. The inclusion threshold comes from the site’s saved churn configuration, not a universal default. Expected: The tab lists only members at or above that configured threshold and shows the component scores used for each result. Open the member’s GymCore profile and latest check-ins. Then open the owning WooCommerce order or recurring-billing record to check payment and membership status. Expected: Staff can explain whether the risk is an attendance pattern, a billing state, a new-member tenure signal, or low portal engagement; the score alone is not a cancellation. To start approved retention follow-up, select Trigger Retention for one member. Expected: The row changes through Sending… to ✓ Sent when GymCore fires the gym_churn_risk_detected event. An installed AutomateWoo workflow may react to that event; the button does not prove a message was delivered. Verify the final result in the owning workflow or delivery system, then compare the recipient with the GymCore member record. Expected: One approved workflow run or staff task exists for the intended member, and no outreach was sent to an opted-out or wrong recipient. Effects, reversal, and member data Filtering and opening reports are read-only. Trigger Retention can start external automation and cannot recall a message that has already been sent. Disable or pause the owning workflow to stop future sends. Attendance dates, email, risk score, billing state, and engagement data are sensitive; share the minimum facts needed for follow-up and avoid labeling a member as certain to cancel. If the report and source disagree Attendance tab is missing: ask an administrator to verify gym_check_in_member; report access alone is not enough. At-Risk Members is missing: the user also needs manage_woocommerce. A recent check-in is absent: inspect the GymCore attendance record, location, and date filter before changing the member. Trigger Retention shows Error — Retry: check the automation listener and consent state before retrying once. Related guides Privacy Requests Roles Capabilities Common Checks","headings":["Access and dependencies","Exact steps","Effects, reversal, and member data","If the report and source disagree","Related guides"],"source_sha256":"","section":"Reports \u0026 Data","source":"docs/user-guide/reports-data/attendance-membership.md"},{"route":"/docs/reports-data-data-overview/","slug":"reports-data-data-overview","title":"Identify the system that owns a report value","summary":"Identify the system that owns a report value.","text":"Choose the correct report source, trace a value to its stored record, and send corrections to the feature owner instead of editing an export. Access and dependencies Use a Finance Admin, administrator, shop manager, or other account with manage_woocommerce. Open GymCore Admin \u0026gt; Analytics \u0026amp; Reports \u0026gt; Reports for the current report builder. The Billing source requires WooCommerce HPOS order tables. Other sources use WordPress users/posts or GymCore tables. Exact steps Safe stop: Select a source and review its fields without saving or exporting; stop before Save Report until the owner, columns, filters, and personal-data need are approved. Open GymCore Admin \u0026gt; Analytics \u0026amp; Reports, select Reports, and select + New Report. Open Data Source and choose the record family you are investigating. Expected: Current source offers Members, Attendance, Rank History, Billing, Leads, Referrals, and Classes. A new report defaults to the first source, Members. Use this ownership map before selecting columns: Report source Plain-language owner Stored source used by the report Members WordPress member profile owner WordPress users and user metadata Attendance Front desk or attendance owner GymCore attendance records joined to members and classes Rank History Coaching/rank owner GymCore rank-history records Billing Finance/WooCommerce owner WooCommerce HPOS orders, order metadata, and line items Leads Sales/lead owner GymCore trial/lead posts and lead metadata Referrals Referral-program owner GymCore referral records Classes Schedule owner GymCore class posts and class metadata Select only the Columns needed to identify the disputed value. With no saved column selection, the builder checks every available column. Set Date From, Date To, Location, Belt Rank, or Membership Tier only when the chosen source supports that filter. Leave Location at — All — when location is not part of the question. Enter a temporary Report Name, select Save Report, then select Run Report. Expected: GymCore saves the configuration and previews rows from the selected source. Saving does not copy or correct the source records. Verify the final result against the owning source system: open the source record listed in the table above and compare its ID, date, status, and location with the report row. Expected: The source record explains the report value. Send any correction to that feature’s owner, then rerun the report to confirm the change. Defaults, effects, reversal, and data handling New reports use ascending sort, — Default — sort field, — None — group, Disabled schedule, and an empty delivery email. Building and running a report are read-only; saving stores its configuration in WordPress. Deleting the temporary report reverses that saved configuration only; it does not delete source records or prior exports. Keep the source record and its audit history. Owner handoff: Give the owner the report source, source record ID, filter values, expected value, and observed value. Do not send a full export when one redacted row is enough. If a source is unavailable Billing fails or is empty: ask the WooCommerce owner to verify HPOS tables and order access; do not substitute a spreadsheet as the source of truth. A filter has no effect: confirm the selected source contains that field. A row has stale profile data: correct the WordPress or GymCore source record, then rerun; editing a CSV cannot update GymCore. Related guides Privacy Requests Roles Capabilities Common Checks","headings":["Access and dependencies","Exact steps","Defaults, effects, reversal, and data handling","If a source is unavailable","Related guides"],"source_sha256":"","section":"Reports \u0026 Data","source":"docs/user-guide/reports-data/data-overview.md"},{"route":"/docs/reports-data-leads-sales/","slug":"reports-data-leads-sales","title":"Review lead-source and sales results","summary":"Review lead-source and sales results.","text":"Compare captured leads, member conversions, and net WooCommerce revenue without treating a pipeline-stage change as a paid sale. Access and dependencies Use a Finance Admin, administrator, shop manager, or other account with manage_woocommerce. GymCore lead/trial records supply lead counts and source values. WooCommerce orders carrying the GymCore lead-source metadata supply member conversions and revenue. Revenue is each attributed order total minus refunds, never below zero. The report does not use a moved lead card as proof of payment. Exact steps Safe stop: Reconcile the report against lead and WooCommerce records without editing either; stop before a source correction or CSV export until the owner and approved range are clear. Open GymCore Leads \u0026gt; Lead Sources. Choose the source-backed window you need: Last 30 days, Last 90 days, or Last 365 days. The page shows all three tables; use the matching section rather than estimating a custom range. Review Source, Leads, Conversion to member, and Revenue (LTV-to-date). Include Not captured when diagnosing missing campaign attribution. Open a source lead or trial for an unexpected lead count. Then open the attributed WooCommerce order for an unexpected member conversion or revenue value. Expected: The lead record supplies the source and creation date; the WooCommerce order supplies customer, payment, refund, and revenue evidence. The same source label connects them. Correct an invalid source only through the approved lead or order workflow. Do not edit the report total or a downloaded file to force attribution. Expected: Reloading Lead Sources recalculates the affected range from the corrected source records and preserves the original order/payment history. To share one range, select Export CSV — Last 30 days, Export CSV — Last 90 days, or Export CSV — Last 365 days. Expected: GymCore downloads gym-lead-sources-last-N-days-YYYY-MM-DD.csv with one row per source plus totals. The file includes source slug/label, leads, members, conversion percentage, revenue, and range days. Verify at least one lead and one paid/refunded order from the export in GymCore and WooCommerce. Expected: Exported source, conversion, and net revenue agree with their owning records. Document missing attribution separately rather than assigning a guess. Defaults, effects, and lead data An invalid range request falls back to 30 days. The screen is read-only; exporting creates a file outside WordPress access controls. Lead source, email/phone-linked records, customer IDs, conversions, and revenue can identify people or business performance. Limit the file to the approved sales or finance audience and delete it under the gym’s retention policy. If a total looks wrong Many rows show Not captured: inspect the lead form, trial intake, kiosk, and order metadata paths that should set the source. Conversion exists without revenue: check whether the attributed order is unpaid, fully refunded, or outside the selected range. Revenue is lower than the order total: compare WooCommerce refunds; the report subtracts them. A campaign name is split across rows: standardize future source choices at intake, then have the data owner decide whether historical records should be corrected. Related guides Privacy Requests Roles Capabilities Common Checks","headings":["Access and dependencies","Exact steps","Defaults, effects, and lead data","If a total looks wrong","Related guides"],"source_sha256":"","section":"Reports \u0026 Data","source":"docs/user-guide/reports-data/leads-sales.md"},{"route":"/docs/reports-data-schedule-export-reports/","slug":"reports-data-schedule-export-reports","title":"Export or schedule a saved report","summary":"Export or schedule a saved report.","text":"Build the smallest approved report, verify its preview, then download it once or deliver a CSV on a defined schedule. Access and dependencies Use a Finance Admin, administrator, shop manager, or other account with manage_woocommerce. Scheduled delivery needs a valid recipient address, working WordPress cron, and working wp_mail delivery. Agree on columns, filters, recipient, cadence, storage, and deletion before sending personal or financial data. Exact steps Safe stop: Save and verify the report with Schedule set to Disabled and Delivery Email empty; stop before enabling delivery until recipient, timezone, columns, retention, and rollback are approved. Open GymCore Admin \u0026gt; Analytics \u0026amp; Reports, select Reports, then select + New Report. Enter Report Name and choose Data Source. New reports default to Members; choose from Members, Attendance, Rank History, Billing, Leads, Referrals, or Classes. Select the required Columns and set only the necessary Filters: Date From, Date To, Location, Belt Rank, and Membership Tier. With no saved column selection, every source column is checked. Under Sort \u0026amp; Group, choose Sort By, Ascending or Descending, and Group By. Defaults are — Default —, Ascending, and — None —. Leave Schedule at Disabled and Delivery Email empty while testing. Select Save Report. Expected: GymCore displays Report saved. and changes the heading to Edit Report: name. Saving stores the configuration; it does not send or download data. Select Run Report and inspect the preview against at least one owning source record. Expected: The preview shows rows from the chosen data source. Export CSV and Export JSON receive working links only after the saved report runs. For a one-time file, select Export CSV or Export JSON. Expected: The browser downloads the current saved configuration’s results. The file leaves WordPress access controls and must be stored in the approved location. For recurring delivery, set Schedule to Daily, Weekly (Monday), or Monthly (1st), enter Delivery Email, and select Save Report again. Expected: The saved-reports list shows the selected schedule. GymCore’s delivery job evaluates due reports once daily from its scheduled 07:00 cron event; actual delivery also depends on WordPress cron running. On the next due run, verify the final result in the recipient’s inbox: open the attached CSV and compare one row with its GymCore or WooCommerce source record. Expected: The subject identifies the site and report, one CSV is attached, and its values agree with the owning source system. GymCore deletes its temporary attachment after the send attempt. Effects, reversal, and exported data Scheduled email repeatedly moves data outside WordPress. To stop future delivery, set Schedule to Disabled, clear Delivery Email, and save. Delete removes the saved report after confirmation, but neither action recalls prior email or downloaded files. Ask recipients to delete copies under the retention policy. Use a role inbox only when its membership and forwarding rules are controlled. If delivery fails Run Report says to save first: select Save Report, then run it again. No email arrives: verify the schedule is due, the address is valid, WordPress cron ran, and the mail service accepted the message. Attachment is empty or wrong: rerun the report with the same saved filters and compare the preview with the owning records. Former staff still receive it: disable the schedule immediately, remove the address, and ask the mail owner to remove forwarded copies. Related guides Privacy Requests Roles Capabilities Common Checks","headings":["Access and dependencies","Exact steps","Effects, reversal, and exported data","If delivery fails","Related guides"],"source_sha256":"","section":"Reports \u0026 Data","source":"docs/user-guide/reports-data/schedule-export-reports.md"},{"route":"/docs/run-your-gym-daily-opening-checks/","slug":"run-your-gym-daily-opening-checks","title":"Open the gym for the day","summary":"Open the gym for the day.","text":"Purpose Confirm today’s location, schedule, kiosk, staff access, and payment or communication alerts before members arrive. Who can use it For: Opening manager or front-desk opener\u0026lt;br\u0026gt; Access needed: read for Staff Dashboard, gym_check_in_member for Attendance, gym_manage_leads for Lead Pipeline, and gym_process_sale for /sales/\u0026lt;br\u0026gt; Applies to: GymCore Before you start Front-desk or manager account with attendance access; use gym_check_in_member for check-in work. Know today’s date/timezone and active location. Have the dated class schedule and the secured kiosk device available. Safe stopping point: keep member check-in closed if today’s class occurrence, location, roster privacy, or waiver policy is not ready. Open for the day Open GymCore Admin \u0026gt; Staff Dashboard and read Check-ins Today or Visits Today without editing anything. Expected: The dashboard loads the role-appropriate read-only count; no save button exists. Open GymCore Classes \u0026gt; Schedule, select today’s date/location, and confirm each class’s time, program, instructor, capacity, and active/cancelled state. Expected: Today’s dated occurrences match the front-desk schedule. Stop and correct the source class/occurrence before opening check-in if they do not. Open GymCore Students \u0026gt; Attendance and select its check-in tab, or use the admin-bar Check-In Kiosk link if your account has gym_check_in_member. Expected: The intended current location and class occurrence are available; the public kiosk is at /check-in/. On the secured device, confirm the screen cannot expose unrelated WordPress admin pages or another location’s roster. Expected: The device is ready for the documented manual/QR check-in flow and no test member remains selected. Reopen today’s Schedule and Attendance source lists as the final pre-opening check. Do not create a test check-in on a real member. Expected: The schedule and empty/current attendance state are ready for live arrivals; only deliberate check-ins will change data. What happens next These checks do not create attendance. A member record changes only when an authorized user submits a deliberate check-in against a dated class. Defaults and limits The admin-bar kiosk link appears only for gym_check_in_member or manage_options. Dashboard counts are read-only and do not prove that a dated occurrence or kiosk location is correct. Check-in methods now gates accepted REST methods and the current kiosk’s name-search flow, but each installed client still needs an end-to-end check. Privacy and safety notes The kiosk and attendance screens expose member names and class participation. Lock the kiosk to the intended page, position it away from public view, and redact names, member IDs, and waiver state from diagnostics. Troubleshooting Today’s class is absent or duplicated Keep check-in closed for that class. Record the schedule date/timezone, location, class/occurrence IDs, recurrence details, and duplicate titles. Correct the source schedule before recording attendance. The kiosk link is missing or opens the wrong location Record the account role/capabilities, /check-in/ result, selected location, and exact error. Verify gym_check_in_member and location configuration; do not use an administrator’s unlocked browser as the public kiosk. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Use Attendance Today for check-in readiness, WooCommerce for order/payment status, the lead pipeline for scheduled follow-up, and the configured kiosk route for the selected location. The Staff Dashboard is a read-only summary and has no commit button. Source-verified: kiosk link/capability and /check-in/ route in src/Providers/TopLevelMenuServiceProvider.php:78-110; dashboard cards in src/Admin/StaffDashboard.php:351-480.","headings":["Purpose","Who can use it","Before you start","Open for the day","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","Today’s class is absent or duplicated","The kiosk link is missing or opens the wrong location","Related guides","Verify in the source systems"],"source_sha256":"","section":"Run Your Gym","source":"docs/user-guide/run-your-gym/daily-opening-checks.md"},{"route":"/docs/run-your-gym-end-of-day-checks/","slug":"run-your-gym-end-of-day-checks","title":"Close the gym day cleanly","summary":"Close the gym day cleanly.","text":"Purpose Reconcile attendance, front-desk exceptions, communications, and WooCommerce payment issues before closing. Who can use it For: Closing manager, finance reconciler, or designated front-desk closer\u0026lt;br\u0026gt; Access needed: read for Staff Dashboard, gym_check_in_member for Attendance, gym_manage_leads for Lead Pipeline, and the applicable WooCommerce order/report capability for reconciliation\u0026lt;br\u0026gt; Applies to: GymCore Before you start Manager/front-desk account with attendance access; WooCommerce access is required to review failed payments or orders. Know the closing date, timezone, and location. Gather unresolved member, lead, order, and message IDs from the shift. Safe stopping point: review and document uncertain states. Do not “clean up” by deleting records or repeating payments/messages at close. Reconcile the day Open GymCore Students \u0026gt; Attendance, filter to today’s date and location, and compare each class roster with staff notes. Expected: Missing, duplicate, or wrong-occurrence records are identified by member and occurrence ID before correction. Correct confirmed attendance through the attendance guide, then reopen the same date/location filter. Expected: Each intended member appears once against the correct dated occurrence. Open GymCore Leads \u0026gt; Lead Pipeline and review overdue/today follow-ups; save a factual outcome and next date only when the contact happened. Expected: No completed contact is left without an outcome, and no unmade contact is marked complete. With WooCommerce access, review today’s orders and failed payments plus any unresolved kiosk sale. Check order notes/provider status before retrying anything. Expected: Every sale has a single order outcome; uncertain transactions are flagged, not duplicated. Return to GymCore Admin \u0026gt; Staff Dashboard, refresh once, and compare Check-ins Today/Visits Today and payment cards with the source lists. Expected: Dashboard counts agree with confirmed source records or the handoff names the exact discrepancy. The dashboard has no save button. What happens next Confirmed attendance corrections can change streaks, milestones, rank eligibility, and reports. Payment status remains in WooCommerce and the gateway; the dashboard only summarizes it. Defaults and limits Dashboard cards query today’s attendance and this month’s selected WooCommerce statuses; they are summaries, not a close ledger. “New Payments (Month)” labels use different order statuses in finance and sales contexts, so verify orders directly. Privacy and safety notes The close review combines attendance, lead, message, and payment identifiers. Keep the handoff in the approved staff system, limit it to unresolved IDs and facts, and never copy card data, message bodies, waiver images, or credentials. Troubleshooting Attendance still does not reconcile Capture date/timezone, location, class occurrence ID, member ID, duplicate/missing rows, and the exact correction attempted. Leave the discrepancy in handoff rather than deleting an uncertain row. A dashboard payment count differs from WooCommerce Use WooCommerce as the source. Record dashboard role/label/value, order IDs/statuses, date filters/timezone, and active Subscriptions state. Do not alter order status merely to match a card. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Reconcile attendance in Attendance History, money in WooCommerce and the gateway, and lead actions in the Lead Pipeline. Use the Staff Dashboard only to locate differences; it is read-only and has no save or close-day action. Source-verified: card labels, queried statuses, and date logic in src/Admin/StaffDashboard.php:351-480,500-548; source records remain authoritative.","headings":["Purpose","Who can use it","Before you start","Reconcile the day","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","Attendance still does not reconcile","A dashboard payment count differs from WooCommerce","Related guides","Verify in the source systems"],"source_sha256":"","section":"Run Your Gym","source":"docs/user-guide/run-your-gym/end-of-day-checks.md"},{"route":"/docs/run-your-gym-front-desk-routines/","slug":"run-your-gym-front-desk-routines","title":"Run the front desk without duplicating records","summary":"Run the front desk without duplicating records.","text":"Purpose Handle arrivals, member lookup, waivers, walk-ins, check-in, and sales without giving front-desk staff unnecessary access. Who can use it For: Front-desk and staffed-sales operators\u0026lt;br\u0026gt; Access needed: read for Staff Dashboard; task access is separate—gym_check_in_member, gym_manage_leads, or gym_process_sale as the visit requires\u0026lt;br\u0026gt; Applies to: GymCore Before you start Use your own front-desk account with the capabilities required for the specific member, lead, or check-in task. Have the active location, dated class occurrence, member/lead email or phone, and any required consent or waiver state. Safe stopping point: do not create a person, check-in, order, or message when an existing matching record or an unresolved first attempt is visible. Handle a front-desk visit Open GymCore Admin \u0026gt; Staff Dashboard and note Visits Today or the available role-specific cards. This page is read-only. Expected: You have an opening snapshot, not a transaction list. For an arriving member, open GymCore Students \u0026gt; Students and search before creating; then use GymCore Students \u0026gt; Attendance for the confirmed dated class. Expected: One existing member is selected and one attendance record is created only after confirmation. For a prospect, search GymCore Leads \u0026gt; Lead Pipeline before using New Lead/Create Lead; keep consent separate from notes. Expected: One lead record owns follow-up history instead of a duplicate profile. For a sale or billing question, open the WooCommerce order/subscription source record or GymCore Admin \u0026gt; Sales Kiosk as appropriate. Never create a second member to repair an order. Expected: Payment evidence stays with the order/provider and member access is verified separately. Before handoff, reopen each changed member, attendance, lead, or WooCommerce record and write down unresolved IDs for the next shift. Expected: Every action has one source-record result; unresolved provider/payment/message attempts are not repeated. What happens next Each completed action belongs to one member, lead, attendance, or WooCommerce source record. A dashboard card, provider message, or verbal report is not a replacement for that record. Defaults and limits Front-desk work crosses screens with different capabilities. Staff Access edits only part of the current capability set, so verify the effective task permission with a test front-desk account before launch. Dashboard cards are read-only summaries. Privacy and safety notes Search results can reveal contact, attendance, waiver, and purchase history. Confirm identity before opening a profile, keep the screen out of public view, and collect consent in its dedicated field rather than a free-text note. Troubleshooting Search returns two people who may be the same person Stop. Capture both user/lead IDs, names, redacted email/phone match, and linked order IDs. Ask an administrator to reconcile; do not delete or merge by guesswork. A check-in, message, or payment has an uncertain result Do not submit again. Capture the source-record ID, provider/order/message ID, timestamp/timezone, visible notice, and current status. Reconcile the first attempt before retrying. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Verify attendance in Attendance History, membership and payment in WooCommerce and the gateway, and prospect work in the Lead Pipeline. The Staff Dashboard does not save any of these changes. Source-verified: dashboard is read-gated in src/Admin/StaffDashboard.php:108-123; task screens enforce their own capabilities. Third-party results require installed-version validation.","headings":["Purpose","Who can use it","Before you start","Handle a front-desk visit","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","Search returns two people who may be the same person","A check-in, message, or payment has an uncertain result","Related guides","Verify in the source systems"],"source_sha256":"","section":"Run Your Gym","source":"docs/user-guide/run-your-gym/front-desk-routines.md"},{"route":"/docs/run-your-gym-multiple-locations/","slug":"run-your-gym-multiple-locations","title":"Work in the correct gym location","summary":"Work in the correct gym location.","text":"Purpose Filter schedules, members, products, reports, and staff work by location without treating locations as separate WordPress sites. Who can use it For: Site administrator or multi-location operations manager\u0026lt;br\u0026gt; Access needed: gymcore_manage_settings, or the administrator fallback manage_options, for GymCore Settings \u0026gt; Locations; the WooCommerce gym_location taxonomy and class edits also require their applicable post-edit capabilities\u0026lt;br\u0026gt; Applies to: GymCore Before you start Use the canonical Settings policy or administrator fallback to create/edit location owner records; staff still need the capability for each downstream task. Know the exact location name/stable key and whether you are changing a location record, current selector, class occurrence, product assignment, or member home location. Safe stopping point: stop before saving if two locations share a confusing identity or the affected classes/members/products are not inventoried. Configure and verify a location Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Locations and review plan usage, readiness, active records, and archived records. Expected: the embedded owner shows stable keys, location details, assignment actions, and any blocker without exposing an unrelated legacy Settings form. Select Add location or edit an existing record. Confirm the unique name/key, timezone, public contact/location details, primary state, capacity, and hours. Expected: the owner form—not the two unreachable legacy field definitions—owns the saved location record. Save only after confirming the revision and affected assignments. Use review/archive/reassign rather than direct deletion. Expected: the location appears once with the intended revision. Stale revisions, plan limits, and unresolved assignments block unsafe writes. Open the relevant class, product, and member source records and set/verify the location shown on each form. Expected: Each operational record points to the intended saved location term. Verify with GymCore Classes \u0026gt; Schedule, GymCore Students \u0026gt; Students, and a test member-facing page/location selector. Expected: Filters and displays show the correct location. Verify archive, shortcode, cart, checkout, sales-kiosk, and custom-query behavior separately; the legacy product-filter definition is not an editable current control. What happens next The saved location can be referenced by classes, products, members, and reports. Renaming, archiving, or reassigning it can change those relationships; it does not create a separate site or store. Defaults and limits Locations is an embedded owner with create/edit, CSV review/apply, assignment review, archive/restore, and migration/rollback paths. The old require-location and product-filter definitions are not rendered. Multi-location is plan-gated, and every downstream consumer still needs installed acceptance. Privacy and safety notes Location records can publish an address, phone number, hours, and coordinates. Use public business contact data only, and review downstream class, member, and product assignments before renaming or deleting a term. Troubleshooting A location is missing or incomplete in the owner list Record the ID, stable key, revision, archive state, and saved metadata. Confirm the owner record and migration state directly instead of recreating the location. Staff see the wrong location’s records Capture the account role, active selector/cookie location, member/class/product IDs, assigned location IDs, and filter state. Do not rename, archive, or recreate a location while diagnosing assignments. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Confirm each record in the embedded Locations owner and the location stored on the affected class, lead, product, member, or order. Archive/shortcode visibility is useful query evidence, but it is not cart/checkout, sales-kiosk, or purchase-authorization proof. Source-reviewed: embedded location ownership, assignment/archive workflows, and the 2.1.0 location consumers. Installed downstream verification remains required.","headings":["Purpose","Who can use it","Before you start","Configure and verify a location","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","A location is missing or incomplete in the owner list","Staff see the wrong location’s records","Related guides","Verify in the source systems"],"source_sha256":"","section":"Run Your Gym","source":"docs/user-guide/run-your-gym/multiple-locations.md"},{"route":"/docs/run-your-gym-staff-dashboard-tour/","slug":"run-your-gym-staff-dashboard-tour","title":"Read the staff dashboard","summary":"Read the staff dashboard.","text":"Purpose Use the Staff Dashboard as a starting point, then open the source record before taking action. Who can use it For: Staff who need an operational summary before opening a task screen\u0026lt;br\u0026gt; Access needed: read for the dashboard; each linked task screen checks its own capability\u0026lt;br\u0026gt; Applies to: GymCore Before you start Sign in with your own WordPress account; the page requires only read, but each linked work area can require more. Know your assigned WordPress/GymCore role. The dashboard chooses an admin, coach, finance, or sales view from that role and capability state. Safe stopping point: reviewing cards is read-only. Do not act on a count until you open its source list and confirm the records behind it. Read a dashboard summary Open GymCore Admin \u0026gt; Staff Dashboard and confirm the page heading Gym Dashboard. Expected: The role section is Overview, Coaching, Finance, or Sales. No save button exists on this read-only dashboard. For an admin, read Check-ins Today, location cards, Active Members, Pending Actions, and Failed Payments. Expected: Cards show counts assembled from attendance, WooCommerce Subscriptions/orders, and the optional AI pending-action store. For a coach, read location-today cards, Promotion Eligible, My Classes Today, program counts, and Your Badges. Finance sees Active Memberships, Failed Payments, and New Payments (Month); sales sees New Payments (Month) and Visits Today. Expected: Only the role-specific card set is shown. Open the owning list before acting: attendance for check-ins, WooCommerce for payments/subscriptions, promotions for eligibility, or AI approvals for pending actions. Expected: The source list explains the count; the card itself is not treated as a transaction or member record. Refresh the dashboard, then reopen the same source list as the final verification. Do not expect the dashboard to save or correct a record. Expected: Any count change is supported by a changed source record, not by the refresh alone. What happens next Nothing is committed from this page. The dashboard is read-only; open Attendance, Promotions, WooCommerce, or AI approvals to inspect or change the underlying record. Defaults and limits The page requires read. Administrators are detected with manage_options; coaches by gym_head_coach/gym_coach roles; finance by manage_woocommerce or shop manager; everyone else receives sales context. Active-membership cards return 0 when WooCommerce Subscriptions is unavailable. AI chat/pending counts depend on the companion plugin. Privacy and safety notes Cards can reveal attendance, membership, payment-failure, and AI-action counts. Share only the minimum card label and redacted source-record IDs needed to investigate a mismatch. Troubleshooting The wrong role section appears Record the section heading, your WordPress role list, and whether your account has manage_options or manage_woocommerce. The current fallback is the sales view; changing Staff Access alone may not change every effective capability. A count disagrees with its source list Record the card label/value, source-list filters, timestamp/timezone, relevant record IDs, and active WooCommerce Subscriptions/GymCore AI state. Do not create or delete records to force the totals to match. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Open the source linked by the card—Attendance, WooCommerce, Leads, or another task screen—and confirm the underlying records. The Staff Dashboard is read-only, has no commit button, and should not be used as the final record of a correction. Source-verified: menu/capability and role selection in src/Admin/StaffDashboard.php:108-123,208-265; card labels and sources at :327-480.","headings":["Purpose","Who can use it","Before you start","Read a dashboard summary","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","The wrong role section appears","A count disagrees with its source list","Related guides","Verify in the source systems"],"source_sha256":"","section":"Run Your Gym","source":"docs/user-guide/run-your-gym/staff-dashboard-tour.md"},{"route":"/docs/set-up-gym-profile-and-locations/","slug":"set-up-gym-profile-and-locations","title":"Set your gym profile and locations","summary":"Set your gym profile and locations.","text":"Purpose Set the GymCore brand values and create location terms used by memberships, schedules, and orders. Access and dependencies For: Gym owner or site administrator\u0026lt;br\u0026gt; Capability: gymcore_manage_settings, or the administrator fallback manage_options, for GymCore Admin \u0026gt; GymCore Settings and its Locations destination\u0026lt;br\u0026gt; Dependencies: WooCommerce active; approved organization name, public business contact data, and location slugs GymCore has several identity stores. Organization name is not the WordPress Site Title, the setup wizard’s gym name, or the GymCore AI gym name. Decide which value each surface should show before editing. Set the profile Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; General. Enter Organization name, Short name, and Brand voice, then select Save changes. Expected: WordPress shows the settings-saved notice and the same values remain after a reload. Open a member-facing page and any approved message preview that uses the brand values. Expected: The installed build shows the intended organization name and tone. Rendering outside the settings screen is runtime-dependent, so record any surface that still uses WordPress or GymCore AI identity instead. Create and verify a location Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Locations and select Add location. Expected: the embedded location owner opens its create form; it does not redirect to a separate legacy taxonomy Settings form. Enter a unique Name and stable key plus only the public timezone, address, phone/email, hours, coordinates, capacity, and primary-location metadata exposed by the form. Save the location. Expected: the location appears once in the active list with its saved revision and owner fields. Open the affected class, membership product, and member record and verify their saved location. Expected: Each source record references the intended term; the Settings summary alone is not assignment proof. Current product limit: the old Require location selection and Filter products by location definitions remain in source but are not rendered by the embedded Locations owner. Do not present either as an editable control or a verified purchase boundary. Defaults, side effects, and recovery Setting Source default Limit or effect Organization name Your Gym Member-facing use varies by runtime surface. Short name GymCore Intended for compact/PWA labels. Brand voice Warm, encouraging, direct, and community-focused. Guidance for assisted/default copy, not a delivery control. Legacy require-location definition yes in source Not rendered by the current Locations owner. Legacy product-filter definition yes in source Not rendered; stored state and installed consumers require separate review. Profile values are reversible by saving the previous values. Use the location owner’s review/archive workflow rather than deleting a term; renaming, archiving, or reassigning can affect classes, products, members, orders, and reports, so inventory those records first. Privacy and troubleshooting Use public business data in location fields. Do not store staff home addresses, private phone numbers, API keys, or member data there. If Locations omits metadata, record the stable key/revision and inspect the location owner record without recreating it. If a selector or schedule shows the wrong location, record the location ID/key and the assignment on the affected source record. Do not archive or recreate the location while diagnosing. If Save changes succeeds but member-facing identity is unchanged, identify whether that surface reads WordPress Site Title, GymCore Organization name, GymCore AI Gym Name, or white-label settings. Verify in the source systems Reopen GymCore Settings \u0026gt; General, the embedded Locations owner, and each affected class/product/member record. Treat those saved records as assignment evidence; location persistence does not prove cart, checkout, sales-kiosk, or purchase authorization. Related guides Check the site before installing GymCore Verify the site before launch Work in the correct gym location Source-verified: src/Admin/Settings.php general definitions and src/Admin/LocationsSettingsPage.php plus src/Location/LocationRepository.php owner paths. Member-facing results still require installed-version verification.","headings":["Purpose","Access and dependencies","Set the profile","Create and verify a location","Defaults, side effects, and recovery","Privacy and troubleshooting","Verify in the source systems","Related guides"],"source_sha256":"","section":"Set Up GymCore","source":"docs/user-guide/set-up/gym-profile-and-locations.md"},{"route":"/docs/set-up-install-and-activate/","slug":"set-up-install-and-activate","title":"Install and activate GymCore","summary":"Install and activate GymCore.","text":"Purpose Install the licensed GymCore ZIP, understand activation side effects, and verify the plugin from WordPress source screens. Access and dependencies For: Site administrator\u0026lt;br\u0026gt; Capabilities: install_plugins and activate_plugins; manage_options for Setup\u0026lt;br\u0026gt; Dependencies: WooCommerce active, licensed ZIP available, and a host-confirmed restore point Activation is not a read-only check. The current activator creates tables, roles/capabilities, defaults, a daily cron event, location terms, and sometimes a hidden comp-membership WooCommerce product; it also flushes rewrite rules and queues a Setup redirect. Install the plugin Confirm the host’s latest backup has a documented restore procedure. Open Plugins \u0026gt; Installed Plugins and verify WooCommerce is active. Expected: The restore point is identified and WooCommerce opens without a dependency error. Open Plugins \u0026gt; Add Plugin \u0026gt; Upload Plugin, choose the licensed ZIP, and select Install Now. Expected: WordPress reports that the package installed and shows Activate Plugin. Stop on any filesystem or package error. Select Activate Plugin once. Expected: GymCore remains active in Plugins \u0026gt; Installed Plugins and the next admin request may redirect to GymCore Admin \u0026gt; Setup. Open GymCore Admin \u0026gt; Setup but do not assume the Commercial wizard can complete configuration. Follow Use the setup wizard without losing site access before entering data. Expected: Setup opens for an administrator without changing a setting merely by viewing it. Confirm GymCore Admin, GymCore Students, GymCore Leads, and GymCore Classes appear, then open the relevant source pages. Expected: Each permitted menu loads; visibility alone does not prove plan enforcement or a complete configuration. Defaults, side effects, and recovery The reviewed activation code: records the activation time and GymCore version; creates GymCore tables and grants capabilities; schedules gym_core_daily_maintenance daily; seeds two location terms from current source and may create a hidden Comp Membership product with SKU comp-membership; uses add_option() for defaults, so reactivation does not overwrite existing option values. Deactivation is not documented as data removal. Do not delete tables, options, terms, users, or the comp product as an uninstall shortcut. If activation damages the site, stop and use the host restore procedure or an administrator-approved recovery; record the plugin error before retrying. Privacy and security Treat the ZIP as licensed software and keep it out of public file shares. Activation can create privileged roles and capabilities; verify staff access before inviting users. Do not paste license keys or server paths into support screenshots. Troubleshooting If activation reports a WooCommerce version error, capture the installed WooCommerce version and the exact message. The current source compares WC_VERSION with 10.3, while its error text names “GymCore Billing”; do not guess which package to replace. If menus are absent, confirm the plugin is active and WooCommerce loaded, then record the current user’s capabilities and the exact admin URL. If WordPress redirects repeatedly to Setup, do not keep activating. Capture the redirect URL and the gym_core_setup_redirect/wizard state through an approved administrator or support path. Verify in the source systems Reopen Plugins \u0026gt; Installed Plugins, WooCommerce \u0026gt; Status \u0026gt; Scheduled Actions, the WordPress role list, Products, and GymCore Admin \u0026gt; Setup. These screens show whether activation persisted and what it created; no installed activation test was run for this documentation rewrite. Related guides Check the site before installing GymCore Use the setup wizard without losing site access Verify the site before launch Source-verified: src/Activator.php and current onboarding controllers. Environment results remain installation-dependent.","headings":["Purpose","Access and dependencies","Install the plugin","Defaults, side effects, and recovery","Privacy and security","Troubleshooting","Verify in the source systems","Related guides"],"source_sha256":"","section":"Set Up GymCore","source":"docs/user-guide/set-up/install-and-activate.md"},{"route":"/docs/set-up-launch-checklist/","slug":"set-up-launch-checklist","title":"Verify the site before launch","summary":"Verify the site before launch.","text":"Purpose Prove that the installed site is ready for staff and members without treating a wizard checkmark or dashboard card as evidence. Access and dependencies For: Gym owner and site administrator\u0026lt;br\u0026gt; Capabilities: manage_options for setup/access; destination-specific GymCore policies for Settings; manage_woocommerce for WooCommerce; task capabilities for staff checks\u0026lt;br\u0026gt; Dependencies: Approved test accounts for each intended role, provider-owned test procedures, and a confirmed restore path This is a read-only checklist; it has no commit button. Perform a mutating check only when its linked guide, rollback, and provider procedure are approved for the installed environment. Verify launch readiness Reopen Plugins \u0026gt; Installed Plugins and WooCommerce \u0026gt; Status \u0026gt; Scheduled Actions. Confirm GymCore and WooCommerce are active and recent scheduled actions complete. Expected: The plugin state and scheduled-action source screens show no unresolved launch blocker. Reopen GymCore Admin \u0026gt; GymCore Settings \u0026gt; General and Locations. Compare names and location slugs with classes, products, and member-facing pages. Expected: Each surface uses the intended identity/location or the mismatch is documented. The old product-filter definition is not rendered by the Locations owner; verify actual archive, shortcode, cart, checkout, sales-kiosk, and purchase behavior independently. Sign in with owner, coach, finance, sales/front-desk, member, and guardian test accounts that already exist for staging or approved validation. Open only the menus each role needs. Expected: Needed screens load and restricted screens stay unavailable. Staff Access covers only four RBAC capabilities, so this role check is required. Open GymCore Classes \u0026gt; Schedule, GymCore Students \u0026gt; Attendance, and member/parent portal pages. Verify a dated class, location, roster privacy, waiver policy, and portal ownership. Expected: The current source records agree. Do not rely on the saved waitlist, check-in-method, or badge-notification toggles; their reviewed consumers are missing. In WooCommerce, review one approved membership product, checkout configuration, gateway status, and—if installed—Subscriptions behavior. Use the provider’s approved non-production verification method. Expected: WooCommerce and the gateway show the same result. No fictional or undocumented payment test is implied. Review Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers, Member Outreach, and the Waiver owner before enabling outreach or changing the active waiver version. Expected: Consent, sender, templates, and provider ownership are documented. The legacy SMS/Retention forms are not rendered; outreach remains blocked until a supported emergency-disable/configuration path and every defaulted retention path are reviewed. Return to each source screen and record the installed GymCore/WooCommerce versions, test account role, visible result, and rollback owner. Expected: Launch approval is based on source records and named evidence, not a checklist badge. Do not use Quick Start as launch proof The WordPress Dashboard GymCore Quick Start widget appears only after the legacy setup-complete option is set. Current source includes obsolete URLs and stale completion lookups: it checks customer/subscriber roles for members, old staff role slugs for staff, a legacy kiosk option, and direct pages that have moved. A checked or unchecked item can therefore be wrong. Privacy and recovery Use synthetic or explicitly approved test records. Never reuse a real member for payment, waiver, message, or role tests. Keep provider IDs and record IDs in the approved test log; redact names, phone numbers, tokens, waiver images, and payment details. If a launch check changes data unexpectedly, stop, preserve the source-record history/order notes/provider event, and follow the linked task’s rollback. Do not “clean up” by deleting evidence or repeating a payment/message. Final source-system verification The launch reviewer must reopen WordPress plugin/role screens, GymCore settings and task records, WooCommerce orders/subscriptions, and provider logs. No installed runtime suite was executed as part of this documentation remediation. Related guides Install and activate GymCore Give staff the minimum access Know which system owns the change Verify in the source systems Verify each launch item in the screen that owns it: WordPress users and URL settings, WooCommerce products/orders/gateway, GymCore classes and attendance, the lead pipeline, and communication providers. Do not use the stale Quick Start completion marks as launch evidence. Source-verified: src/Onboarding/QuickStartWidget.php for stale lookups/links and current task/settings source for the named product limits.","headings":["Purpose","Access and dependencies","Verify launch readiness","Do not use Quick Start as launch proof","Privacy and recovery","Final source-system verification","Related guides","Verify in the source systems"],"source_sha256":"","section":"Set Up GymCore","source":"docs/user-guide/set-up/launch-checklist.md"},{"route":"/docs/set-up-setup-wizard/","slug":"set-up-setup-wizard","title":"Use the setup wizard without losing site access","summary":"Use the setup wizard without losing site access.","text":"Use GymCore Admin \u0026gt; Setup after activation to configure the site in a controlled order. GymCore 2.2.0 source renders the commercial wizard forms and keeps the Website field in wizard state instead of writing WordPress siteurl or home. RV-01 passed on the exact deployed plugin tree on 2026-08-21. Access and preparation Use a WordPress administrator account with manage_options. Create and verify a restorable database/files backup before changing production configuration. Record the installed Gym Core version and the current WordPress Address (URL) and Site Address (URL) under Settings \u0026gt; General. Have the intended gym name, public website, contact email, phone, martial-arts type, locations, timezone, capacity, rank policy, membership setup, staff roles, and communication policy approved. Treat the wizard as configuration, not proof that WooCommerce, gateways, messaging, AI, or third-party integrations work. Validate Gym Information first Open GymCore Admin \u0026gt; Setup and select Start Setup or the visible continue action. Expected: The next current step renders its form. The Gym Information step contains Gym name, Website, Contact email, and Phone. On Gym Information, submit a blank Gym name once before entering real values. Expected: The page remains on the step and visibly reports Gym name is required. Enter the approved gym name. Enter the public marketing URL in Website only if wanted; add the approved contact email and phone. Continue, then use Back to return once. Expected: The entered values remain in wizard state. Current 2.2.0 source updates WordPress blogname, may update admin_email when a valid contact email is supplied, and does not write siteurl or home. In a separate tab, reload Settings \u0026gt; General and confirm WordPress Address (URL) and Site Address (URL) remain byte-for-byte unchanged. Safe stop: If either URL changed, stop the wizard, keep the site out of publication, restore the baseline if needed, and report the installed version and exact step as a regression. Complete the remaining steps deliberately Martial Arts Type: choose only the approved discipline/program options. Locations: verify each location name, timezone, capacity, and contact details before continuing. Rank System: choose the intended source-backed system; do not assume every visible custom threshold drives eligibility. Memberships and Staff: create or map only approved fictional/non-production records during staging validation. Verify real WooCommerce products and role capabilities separately before launch. Communications and AI: leave outbound channels disabled until credentials, consent, recipients, provider logs, and rollback have been tested. Finish the wizard only after reviewing the summary. Expected: GymCore records wizard completion and exposes the normal admin destinations. Completion does not certify the high-risk flows in the runtime validation matrix. Defaults, effects, and recovery The first commercial step is not skippable. Later skip behavior is defined per step and does not mean the skipped dependency is configured elsewhere. Wizard progress is stored in gym_core_wizard_state; completion is recorded separately. To correct ordinary profile data, use the canonical GymCore settings or owning WordPress/WooCommerce record rather than rerunning the wizard blindly. If a step fails to render, an error is not visible, or navigation loses data, capture the installed version, visible step, sanitized browser/server error, and baseline state, then stop before repeating a mutating request. Verify before launch Reopen the owning source screens for organization details, locations, class/rank configuration, WooCommerce products, staff capabilities, communication channels, and AI/integration status. Confirm siteurl and home are unchanged. Run the launch checklist and the applicable runtime validation matrix rows. Runtime status: RV-01 passed on GymCore 2.2.0 source commit 080f1ada9d454b1ba823d1b6b41bbd6efdcd64ad on 2026-08-21. The reviewed evidence covers Gym Information rendering, required-field error, four-field persistence, unchanged siteurl/home, and complete fixture cleanup. The internal runtime matrix retains the evidence record; this public guide does not expose internal evidence paths.","headings":["Access and preparation","Validate Gym Information first","Complete the remaining steps deliberately","Defaults, effects, and recovery","Verify before launch"],"source_sha256":"","section":"Set Up GymCore","source":"docs/user-guide/set-up/setup-wizard.md"},{"route":"/docs/set-up-staff-and-roles/","slug":"set-up-staff-and-roles","title":"Give staff the minimum access","summary":"Give staff the minimum access.","text":"Purpose Create individual staff accounts, apply the four Staff Access permissions, and verify every required screen with the actual role. Access and dependencies For: Site administrator\u0026lt;br\u0026gt; Capability: manage_options for Staff Access; WordPress create_users/promote_users for accounts and roles\u0026lt;br\u0026gt; Menu: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access Have a written task list for the staff member and a separate test account for the target role. Do not change the only working administrator account. Assign and verify access Open Users \u0026gt; Add New, create one account for the staff member, and assign the closest current role: gym_head_coach, gym_coach, gym_finance, or gym_sales. Select Add New User. Expected: The user appears once under Users with the intended role and receives only the approved account notification. Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access. Review the row for that role and the four columns: Manage Members, Manage Billing, View Reports, and Manage Staff. Expected: The matrix shows the current saved map. Administrator checkboxes are disabled because administrators always receive all four. Change only the permissions required by the written task list. A preset button prompts for a role slug and changes checkboxes only; it does not save them. Expected: The intended boxes change, with no access committed yet. Select Save Role Permissions. Expected: WordPress reports that role permissions were saved and the matrix persists after reload. Sign in as the target test user and open every required and prohibited task screen. Expected: Required work succeeds and prohibited work is denied. Record the exact capability used by any screen that does not follow the four-column matrix. Factory defaults Role Four Staff Access capabilities Administrator / Shop Manager All four gym_head_coach Manage Members, View Reports, Manage Staff gym_coach View Reports gym_finance Manage Billing, View Reports gym_sales Manage Members Current product limit Staff Access edits only four gymcore_* RBAC capabilities. Current GymCore menus and actions also check legacy gym_*, WordPress, and WooCommerce capabilities such as gym_check_in_member, gym_manage_leads, gym_process_sale, gym_promote_student, edit_posts, manage_woocommerce, and manage_options. Saving this matrix is not proof that a role can—or cannot—perform every task. Changes are reversible by restoring the previous matrix and selecting Save Role Permissions. Removing a WordPress role or deleting a user is a different, more destructive action; do not use it to troubleshoot access. Privacy and troubleshooting Use individual accounts and multifactor authentication where your identity provider supports it. Never ask staff to share passwords or borrow an administrator session. If a menu is absent, identify the exact screen capability in current source or with an approved capability audit; do not keep granting all four boxes. If a preset appears to do nothing, enter the exact role slug at its prompt, inspect the boxes, then save explicitly. If access remains after a box is cleared, check the user’s other roles and WordPress/WooCommerce capabilities. Administrators always have full access. Verify in the source system Reopen Users and Staff Access, then repeat the task with the target test account. The effective role test—not the checkbox matrix—is final evidence. Related guides Verify the site before launch Read the staff dashboard Know which system owns the change Source-verified: src/Admin/RolesPage.php, src/RBAC/RoleManager.php, and src/Capabilities.php for access, labels, four capabilities, presets, and defaults.","headings":["Purpose","Access and dependencies","Assign and verify access","Factory defaults","Current product limit","Privacy and troubleshooting","Verify in the source system","Related guides"],"source_sha256":"","section":"Set Up GymCore","source":"docs/user-guide/set-up/staff-and-roles.md"},{"route":"/docs/settings-reference-accounting-quickbooks/","slug":"settings-reference-accounting-quickbooks","title":"Accounting and QuickBooks settings reference","summary":"Accounting and QuickBooks settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; Integrations \u0026gt; QuickBooks\u0026lt;br\u0026gt; Who can change it: the visible Integrations menu requires manage_options, and the QuickBooks form/action handlers require manage_woocommerce. The effective UI user needs both, normally a WordPress administrator.\u0026lt;br\u0026gt; Visible actions: Connect to QuickBooks Online or Disconnect QBO controls authorization; Save Accounting Settings stores mappings and sync choices; Queue Re-Sync schedules a separate historical sync.\u0026lt;br\u0026gt; Owning system: GymCore stores the connection and mappings; QuickBooks Online remains the accounting source. This is a separate form, not GymCore Settings \u0026gt; Billing. Confirm the target QuickBooks company and account IDs before connecting, mapping, or re-syncing; queued and completed external records are not undone by changing a setting. Connection controls Client ID Stored key: gym_core_qbo_client_id Type/default: text; blank. Allowed value: Intuit OAuth application client ID. Purpose/dependency: identifies the approved Intuit app; required with Client Secret before Connect. Side effect: changes which OAuth app requests access. Change/leave: replace only during an approved app migration; leave unchanged while the connection is healthy. Security/privacy: account identifier; restrict screenshots and support logs. Client Secret Stored key: gym_core_qbo_client_secret Type/default: password; blank. Allowed value: matching Intuit app secret. Purpose/dependency: authenticates the OAuth application. Side effect: replacing it can break refresh/token exchange until Intuit matches. Change/leave: rotate after exposure or owner/vendor change; leave it alone for ordinary reconnect troubleshooting. Security/privacy: high-value credential. The current form persists sanitized text in a WordPress option; protect database/backups and never share it. Connect to QuickBooks / Disconnect Type/default: nonce-protected OAuth actions; disconnected until authorized. Allowed value: valid Intuit authorization, realm ID, callback code, and matching one-time state. Purpose/dependency: exchanges authorization for tokens or removes the current connection. Side effect: Connect grants access to the selected QuickBooks company. Disconnect stops future sync but does not undo previously created QuickBooks records. Change/leave: connect only to the verified production company; disconnect only with a reconciliation and rollback plan. Security/privacy: finance trust boundary; verify company name/realm and authorized staff before approving. Sync options Sync Payments Stored key: gym_core_qbo_sync_orders Type/default: checkbox; on. Allowed value: on/off. Purpose/dependency: syncs completed or processing WooCommerce orders as QuickBooks Sales Receipts. Side effect: can create accounting records automatically. Change/leave: turn on only after account mapping and duplicate tests; turn off during migration or incident containment. Security/privacy: financial and customer data crosses systems. Sync Payouts Stored key: gym_core_qbo_sync_payouts Type/default: checkbox; on. Allowed value: on/off. Purpose/dependency: syncs WooPayments payouts as QuickBooks Bank Deposits. Side effect: can create deposit records used in reconciliation. Change/leave: enable after bank/clearing mapping is verified; leave off when payouts are entered another way. Security/privacy: financial records; duplicate deposits materially distort books. Account mapping Every account value is a free-text QuickBooks numeric account ID. The form does not prove the account exists, has the correct type, or belongs to the connected realm. Field Stored key Default Purpose When to change / security impact Default Income Account ID gym_core_qbo_default_income_account_id Blank Fallback income account for sales receipts. Set from the verified Chart of Accounts; a wrong ID misclassifies revenue. Bank Account ID (Deposits) gym_core_qbo_bank_account_id Blank Bank target for deposits. Match the actual settlement account; finance-admin only. Clearing Account ID gym_core_qbo_clearing_account_id Blank Optional WooPayments/undeposited-funds account. Use only when the accounting workflow requires clearing. Deposit-To Account ID gym_core_qbo_deposit_account_id Blank Deposit destination mapping. Verify it does not duplicate the bank/clearing role. Shipping Income Account ID gym_core_qbo_shipping_account_id Blank Classifies shipping income. Leave blank only when the integration has an approved fallback. AR Account ID (Failed Retry Notes) gym_core_qbo_ar_account_id Blank Associates failed-retry receivable notes. Verify account type and finance policy. Product category account map gym_core_qbo_category_account_map[category-slug] Blank per current WooCommerce category Overrides income account by category. Reconcile every active category; new categories may need mapping. Manual re-sync From date / To date Type/default: required date inputs; no stored default. Allowed value: valid start and end dates. Purpose/dependency: finds up to 500 completed/processing orders in the range and schedules one sync action per order, staggered by two seconds. Side effect: queues real accounting writes. Existing deduplication behavior must be verified before a repeat. When to use: only for a documented gap after reconciling WooCommerce, sync logs, and QuickBooks. When to leave alone: do not use as a generic “refresh” button or after a timeout until the queue/log is checked. Security/privacy: bulk financial operation; take a backup/export and record operator, range, count, and reason. Sync log The page shows the most recent 50 events. Use it to identify source record, operation, time, and error, then verify the matching WooCommerce order/payout and QuickBooks record. A local success does not prove a bank settled funds. Verify a settings or sync action After Save Accounting Settings, reload the page and confirm the company, account mappings, and sync choices remain. In WooCommerce, record the source order, refund, payout, amount, and timestamp before testing its normal sync path. Match that source record to the GymCore sync-log entry and then to the transaction in the connected QuickBooks company. QuickBooks is the final accounting source; a queued action or local success message is not sufficient. If using Queue Re-Sync, confirm the date range and expected order count before submitting, then monitor each queued record. Fix or reverse incorrect accounting entries in QuickBooks under your accounting policy; changing GymCore settings does not remove records already sent. Related guides Accounting Billing and renewals troubleshooting Integrations overview Protect credentials and webhooks","headings":["Connection controls","Client ID","Client Secret","Connect to QuickBooks / Disconnect","Sync options","Sync Payments","Sync Payouts","Account mapping","Manual re-sync","From date / To date","Sync log","Verify a settings or sync action","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/accounting-quickbooks.md"},{"route":"/docs/settings-reference-attendance/","slug":"settings-reference-attendance","title":"Attendance settings reference","summary":"Attendance settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Attendance\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. Attendance settings affect check-in rules and milestone evaluation. Gym Core 2.1.0 uses the selected check-in methods in the kiosk bootstrap and REST check-in guard. The Sales Kiosk consumes the kiosk timeout. Field reference Check-in methods Stored key/control: gym_core_checkin_methods Purpose: Limits accepted REST check-in methods and controls whether name search appears in the current kiosk. Type: Multi-select Default: QR code scan, Name search, Manual (Staff) Allowed values/range: Any combination of qr, search, manual Dependencies: Kiosk UI. Side effects: A disabled method receives a checkin_method_disabled REST error; disabling search hides the current kiosk’s member-search flow. Staff recovery and imported attendance are unaffected. When to change it: Remove a method only after verifying every kiosk/client used by the gym supports the remaining method. When to leave it alone: Keep all three defaults until the installed kiosk and any QR/manual client have been tested. Security/privacy: Name search may expose roster identity on a public kiosk. Kiosk auto-logout Stored key/control: gym_core_kiosk_timeout Purpose: Resets the separate sales kiosk after inactivity. Although this field appears under Attendance, the audited attendance kiosk does not consume it. Type: Number Default: 10 seconds Allowed values/range: Integer 5–60 seconds Dependencies: Sales kiosk endpoint and JavaScript. Side effects: Shorter values reduce shoulder-surfing but may interrupt users. When to change it: Raise only after observing accessibility/usability problems in the sales kiosk. When to leave it alone: Leave at 10 for shared front-desk devices. Security/privacy: A longer timeout leaves member details visible longer. Prevent duplicate check-ins Stored key/control: gym_core_prevent_duplicate_checkin Purpose: Blocks the same member from checking into the same class twice in one day. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Attendance validator and class identity. Side effects: On rejects duplicate records; off permits repeated records and can distort reports. When to change it: Turn off only for a documented workflow requiring repeated same-day records. When to leave it alone: Leave on for normal attendance integrity. Security/privacy: Attendance is personal data and may drive eligibility. Attendance milestones Stored key/control: gym_core_attendance_milestones Purpose: Defines counts that fire milestone events used by AutomateWoo. Type: Text Default: Blank, which uses 10, 25, 50, 100, 150, 200, 250, 300, 500, 1000 Allowed values/range: Comma-separated positive class counts Dependencies: Attendance recorded; AutomateWoo only for downstream workflows. Side effects: Changes future event thresholds; prior awards are not automatically rebuilt. When to change it: Change before launching milestone automations. When to leave it alone: Leave blank to use source defaults. Security/privacy: Milestone messages disclose attendance and need approved recipients/consent. Verify a change Select Save changes and confirm Settings saved. Reload Attendance and confirm the values remain. Check in a non-production member through the intended interface, then confirm the attendance row records the expected time and location. If changing milestone thresholds, confirm the resulting milestone evaluation against that member’s attendance source records. If changing Kiosk Session Timeout, verify the Sales Kiosk session expires at the new limit. If changing Check-in methods, verify the kiosk visibility and accepted/rejected REST methods on the installed build. Source review proves consumers exist; it does not replace that end-to-end test. Restore the prior setting if the live result is wrong; existing attendance rows and completed milestone awards are not automatically reversed. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Installed kiosk/client verification is still required.","headings":["Field reference","Check-in methods","Kiosk auto-logout","Prevent duplicate check-ins","Attendance milestones","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/attendance.md"},{"route":"/docs/settings-reference-belt-systems/","slug":"settings-reference-belt-systems","title":"Belt Systems settings reference","summary":"Belt Systems settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Belt Systems\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible actions: Create System creates a new system; Save Changes updates the system being edited; Import, Export JSON, and Delete are separate actions. + Add Rank only changes the unsaved form. Belt systems are configuration records, not proof that rank evaluation uses them. The audited progression code still reads the older rank settings, so verify an actual promotion workflow before relying on a new system. Export JSON before editing or deleting a live system. Field reference System Name Stored key/control: system label Purpose: Human-readable system name. Type: Text Default: Blank Allowed values/range: Required text Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. System Slug Stored key/control: system_slug Purpose: Unique machine identifier. Type: Text Default: Blank Allowed values/range: Required lowercase letters, digits, hyphens; immutable after creation Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Rank Name Stored key/control: rank_name[] Purpose: Names a rank. Type: Text Default: Blank Allowed values/range: Required text Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Color Stored key/control: rank_color[] Purpose: Displays rank color. Type: Color Default: #ffffff Allowed values/range: 3- or 6-digit hex Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Stripes Stored key/control: rank_stripe_count[] Purpose: Sets stripe count. Type: Select Default: 0 Allowed values/range: Integer 0–4 Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Min Weeks Stored key/control: rank_min_weeks[] Purpose: Stores rank criterion. Type: Number Default: 0 Allowed values/range: Integer ≥0 Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Min Classes Stored key/control: rank_min_classes[] Purpose: Stores rank criterion. Type: Number Default: 0 Allowed values/range: Integer ≥0 Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Instructor Required Stored key/control: rank_require_instructor[] Purpose: Stores instructor-approval criterion. Type: Checkbox Default: Off Allowed values/range: On / Off Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Position Stored key/control: rank_position[] Purpose: Orders ranks. Type: Drag order Default: Row order Allowed values/range: Lowest to highest Dependencies: manage_woocommerce; custom belt system store. Side effects: Changes custom stored system data, but audited promotion eligibility reads static RankDefinitions rather than this store. When to change it: Use for controlled system design/export; verify runtime consumers before rollout. When to leave it alone: Do not assume edits change promotion eligibility. Security/privacy: Rank structure affects member records; deleting/importing is high impact. Verify a change Select Export JSON for the live system and store the file securely before editing. Use Create System, Save Changes, or Import as appropriate, then return to the Belt Systems list and reopen the record. Compare the displayed slug, labels, colors, order, ages, stripes, and class requirements with the exported or intended JSON. Evaluate one non-production promotion against the older Ranks settings as well as the belt-system record. The saved system alone does not prove the progression engine uses it. Re-import the known-good export if a reversible edit is wrong; deletion without an export is not recoverable from this screen. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","System Name","System Slug","Rank Name","Color","Stripes","Min Weeks","Min Classes","Instructor Required","Position","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/belt-systems.md"},{"route":"/docs/settings-reference-billing/","slug":"settings-reference-billing","title":"Billing settings reference","summary":"Billing settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Billing\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. This tab stores the membership-product category used by billing lookups. Changing it can change which WooCommerce products GymCore treats as memberships. Field reference Annual freeze limit (days) Stored key/control: gym_core_pause_annual_limit Purpose: Caps total pause days per member per calendar year. Type: Number Default: 60 Allowed values/range: Integer 1–365 Dependencies: Membership pause workflow; WooCommerce billing remains separate. Side effects: Requests beyond the limit are blocked; existing pause history remains. When to change it: Set to the published membership policy before accepting pauses. When to leave it alone: Leave it when policy has not changed. Security/privacy: Financial/member-policy effect; communicate changes and preserve audit evidence. Verify a change Select Save changes and confirm Settings saved. Reload Billing and confirm the selected category remains. In Products, open a known membership product and confirm it belongs to that WooCommerce category. Run the GymCore workflow that identifies membership products and compare its result with the WooCommerce product record. Restore the prior category if products are classified incorrectly; existing orders are not recategorized. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","Annual freeze limit (days)","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/billing.md"},{"route":"/docs/settings-reference-crm/","slug":"settings-reference-crm","title":"CRM settings reference","summary":"CRM settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; CRM\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. CRM settings can send lead data to a third party. Use fictional contact details for initial verification and confirm the destination account before enabling automatic sync. Field reference Enable form-to-CRM Stored key/control: gym_core_crm_enabled Purpose: Creates/updates Jetpack CRM contacts from Jetpack Forms and WooCommerce customers; completed first orders move a contact to Closed Won. Type: Checkbox Default: Off Allowed values/range: On / Off Dependencies: Jetpack CRM active; compatible form/order events. Side effects: On copies contact and lead data into Jetpack CRM and adds source/status metadata. When to change it: Enable only after choosing how the internal GymCore Leads pipeline and Jetpack CRM will be operated. When to leave it alone: Leave off when Jetpack CRM is absent or not the approved duplicate store. Security/privacy: Copies names, emails, phones, location, and activity into another data store. Primary location sales rep Stored key/control: gym_core_crm_rockford_rep Purpose: Assigns primary-location leads to a staff user. Type: Select Default: Auto (first admin) Allowed values/range: Blank or an administrator/shop manager user Dependencies: Form-to-CRM on and eligible WordPress user. Side effects: Changes ownership of newly processed leads. When to change it: Set when a named rep owns this location. When to leave it alone: Leave Auto only if first-admin assignment is intentional. Security/privacy: Displays staff email in selector and grants operational visibility through CRM. Secondary location sales rep Stored key/control: gym_core_crm_beloit_rep Purpose: Assigns secondary-location leads to a staff user. Type: Select Default: Auto (first admin) Allowed values/range: Blank or an administrator/shop manager user Dependencies: Same as primary rep. Side effects: Changes ownership of newly processed leads. When to change it: Set when a named rep owns the secondary location. When to leave it alone: Leave Auto only when acceptable. Security/privacy: Same staff/lead privacy considerations. Default pipeline stage Stored key/control: gym_core_crm_default_pipeline_stage Purpose: Sets the initial Jetpack CRM stage for new leads. Type: Select Default: New Lead Allowed values/range: New Lead, Contacted, Trial Booked, Trial Done, Negotiation, Closed Won, Closed Lost; filter may add values Dependencies: Form-to-CRM on and matching CRM workflow. Side effects: New contacts enter this stage; existing contacts are not bulk-moved. When to change it: Change only when the sales workflow has a different defined entry stage. When to leave it alone: Leave at New Lead for normal capture. Security/privacy: Wrong stages can hide follow-up work. Verify a change Select Save changes and confirm Settings saved. Reload CRM and confirm the endpoint, form selection, and enablement state remain. Submit fictional lead data through the selected form. Match the GymCore lead/contact record and sync log to the record created in the configured CRM. If the third-party system has no matching record, treat the sync as failed even if WordPress saved the settings; disable sync or restore the prior endpoint while investigating. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","Enable form-to-CRM","Primary location sales rep","Secondary location sales rep","Default pipeline stage","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/crm.md"},{"route":"/docs/settings-reference-gamification/","slug":"settings-reference-gamification","title":"Gamification settings reference","summary":"Gamification settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Gamification\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. Points and badge thresholds affect future evaluations. Gym Core 2.1.0 does not expose the former badge-notification toggle on this settings tab. Field reference Streak freeze allowance Stored key/control: gym_core_streak_freezes_per_quarter Purpose: Sets quarterly freezes that protect a member streak. Type: Number Default: 1 Allowed values/range: Integer 0–4; 0 disables Dependencies: Gamification master switch and streak engine. Side effects: Changes how future missed periods affect streaks. When to change it: Change to match the written member policy. When to leave it alone: Leave at 1 if no formal alternative exists. Security/privacy: Affects fairness and member-visible progress. Targeted content Stored key/control: gym_core_targeted_content_enabled Purpose: Enables targeted member shortcodes and block behavior. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Logged-in member context and configured content. Side effects: Off suppresses personalized targeted-content output. When to change it: Turn off before removing or redesigning targeted member pages. When to leave it alone: Leave on if those pages are in use. Security/privacy: Personalized output can reveal rank, program, location, or progress on shared screens. Verify a change Select Save changes and confirm Settings saved. Reload Gamification and confirm the values remain. Trigger the relevant achievement rule with a non-production member and compare the resulting achievement or point record with the member’s source activity. Restore the prior threshold if the award is wrong. Do not promise a badge-earned message from this tab; current source exposes no badge-notification setting here. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Installed achievement and targeted-content verification is still required.","headings":["Field reference","Streak freeze allowance","Targeted content","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/gamification.md"},{"route":"/docs/settings-reference-general/","slug":"settings-reference-general","title":"General settings reference","summary":"General settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; General\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. Brand fields feed member-facing copy and installable-app metadata. Record the old public name before changing it so you can restore it if member-facing labels become inconsistent. Field reference Organization name Stored key/control: gym_core_brand_name Purpose: Names the organization in member-facing copy, SMS signatures, and PWA metadata. Type: Text Default: Your Gym Allowed values/range: Plain text Dependencies: None. This does not inherit the WordPress Site Title or GymCore AI Gym Name. Side effects: Changes core member-facing brand text; existing historical messages do not change. When to change it: Set before launch and after a legal or public brand change. When to leave it alone: Leave it alone if only the WordPress Site Title or AI-only name needs to change. Security/privacy: Public-facing value; do not enter legal details you do not want members to see. Short name Stored key/control: gym_core_brand_short_name Purpose: Provides a compact PWA and limited-space UI label. Type: Text Default: GymCore Allowed values/range: Plain text; keep compact Dependencies: PWA surfaces must be active. Side effects: Changes future compact labels and metadata. When to change it: Set to a recognizable short form of the organization name. When to leave it alone: Leave it when the default is acceptable or the PWA is not used. Security/privacy: Public-facing; avoid confidential internal abbreviations. Brand voice Stored key/control: gym_core_brand_voice Purpose: Guides core AI-assisted retention/promotion messages and default outbound copy. Type: Textarea Default: Warm, encouraging, direct, and community-focused. Allowed values/range: Plain text guidance Dependencies: Only consumers in GymCore core use it; GymCore AI response settings are separate. Side effects: Changes future generated core messages, not prior content or GymCore AI chat style. When to change it: Change when generated outreach consistently misses your approved tone. When to leave it alone: Leave it until templates and compliance wording have been reviewed. Security/privacy: Do not paste secrets, member data, or regulated claims into prompt guidance. Gamification Stored key/control: gym_core_gamification_enabled Purpose: Turns the badge and streak engine on or off. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Gamification modules and member-facing surfaces must be active. Side effects: On allows badges, streaks, and achievements to update and display. When to change it: Turn off when launching without gamification or investigating achievement behavior. When to leave it alone: Leave on if members already rely on progress displays. Security/privacy: Low privacy impact, but achievements can reveal attendance patterns. SMS notifications Stored key/control: gym_core_sms_enabled Purpose: Master gate for core Twilio SMS and, currently, the entire Retention provider. Type: Checkbox Default: Off Allowed values/range: On / Off Dependencies: Valid Twilio fields under SMS; consent and opt-out processes. Side effects: On permits core SMS and loads retention workflows, including non-SMS retention paths. When to change it: Enable only after credentials, consent, templates, recipients, and retention defaults are reviewed. When to leave it alone: Leave off during setup or when no approved texting program exists. Security/privacy: Outbound messages may expose PII and create telecom cost/compliance obligations. REST API Stored key/control: gym_core_api_enabled Purpose: Visible API toggle. Type: Checkbox Default: Off Allowed values/range: On / Off Dependencies: None. Side effects: No runtime consumer was found: changing it does not disable or enable registered REST or MCP routes. When to change it: Do not use this control as a security switch; manage authentication and capabilities instead. When to leave it alone: Leave at its current value until a product fix defines behavior. Security/privacy: Misleading security control; route-level permissions remain the actual boundary. Verify a change Select Save changes and confirm Settings saved. Reload General and confirm the edited value remains. For brand or short-name changes, open /manifest.json and the affected member-facing page; for contact or timezone changes, run the specific workflow that displays or schedules the value. Confirm the WordPress option named in Stored key/control contains the intended value. Restore the recorded prior value with Save changes if any public label or scheduled time is wrong. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","Organization name","Short name","Brand voice","Gamification","SMS notifications","REST API","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/general.md"},{"route":"/docs/settings-reference-gymcore-ai/","slug":"settings-reference-gymcore-ai","title":"GymCore AI settings reference","summary":"GymCore AI settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; AI \u0026gt; Settings. Nested tabs are Agents, Webhook \u0026amp; Security, Response Style, and General. White Label is a separate Pro-only AI hub tab.\u0026lt;br\u0026gt; Who can change it: an account with manage_options, normally a WordPress administrator.\u0026lt;br\u0026gt; Visible actions: Save Changes stores fields on the open settings subtab. Webhook-secret rotation and legacy-key clearing are separate confirmation actions. The White Label tab uses Save White Label Settings. System Status reports GymCore and WP AI Client readiness without inspecting provider credential values. AI settings can expose gym context to a configured model provider or change which proposed actions reach staff review, so use fictional prompts for verification and keep credentials out of screenshots. Agents All per-persona values are saved together in the gym_core_ai_agent_overrides option. The option is an array keyed by persona slug; do not edit it directly. Field Type Default Allowed values Purpose, dependencies, side effects, and safety Enabled Checkbox per persona On On/Off Hides or enables a persona. Does not bypass tool capabilities. Disable unused personas to reduce exposure. Display Name Text per persona Built-in name Plain text Cosmetic staff label. Separate from Gym Name and White Label Brand Name. Description Text per persona Built-in description Plain text Staff-facing scope summary; it does not enforce scope. Capability Select per persona Persona-specific read, gym_view_briefing, gym_process_sale, gym_view_finance, gym_use_gandalf, edit_posts, manage_options Determines persona visibility. Lowering it exposes the persona to more users; test with a non-admin account. System Prompt Override Textarea per persona Blank Plain text; {{gym_name}} supported Replaces the entire built-in prompt. It can remove safety/grounding rules; leave blank unless the full replacement is reviewed. Webhook \u0026amp; Security Field Type Default Allowed values Purpose, dependencies, side effects, and safety Webhook Secret Masked read-only + rotate action Generated on activation Generated secret Authenticates automation webhooks. Rotation keeps previous secret valid 5 minutes; update sender immediately and never disclose it. IP Allowlist Multiline text Empty One valid IP per line Restricts accepted source IPs when enforcement is on. Confirm proxy/egress addresses first. Enforce IP allowlist Checkbox Existing installs: off fallback; fresh activation may initialize on On/Off On + empty list denies all; off + empty list falls open to signature-only access. Prefer on after staging test. Response Style Field Type Default Allowed values Purpose, dependencies, side effects, and safety Custom greeting Text Blank Plain text Optional opening line appended through response customization. Do not imply a public chatbot. Custom fallback message Text Blank Plain text Used when the assistant cannot answer. Include a safe staff escalation, not private contact details. Custom sign-off line Text Blank Plain text Appended sign-off. Keep names/branding current. Tone Select Default/blank Default, Friendly, Professional, Concise Adds global style guidance to all personas. Separate from core Brand voice. Response length Select Default/blank Default, Short, Medium, Detailed Adds global length guidance; it does not cap model tokens or data access. General The visible fields persist as gym_core_ai_gym_name, gym_core_ai_retention_days, gym_core_ai_notify_on_pending, gym_core_ai_slack_webhook_url, gym_core_ai_sms_admin_numbers, and gym_core_ai_notify_include_summary. Provider/model state is managed separately under Connections \u0026amp; Security \u0026gt; Provider and model. Field Type Default Allowed values Purpose, dependencies, side effects, and safety Gym Name Text Blank → WordPress Site Title Plain text Injected into prompts/context and {{gym_name}}. It does not inherit core Organization name. Conversation retention (days) Number 30 Integer 1–365 Daily purge for conversations/messages only; excludes action/audit history and third parties. Notify on pending action Checkbox On On/Off Controls Slack/SMS external notifications; admin notice remains. Slack incoming webhook URL URL Blank HTTPS hooks.slack.com URL Credential and delivery target. Blank disables Slack. Rotate on exposure/offboarding. SMS admin numbers Multiline Empty One E.164 number per line, at least 8 cleaned characters Requires core Twilio. Sends metadata-only action alerts. Keep list current. Include action summary in Slack Checkbox Off On/Off May expose member names, refund reasons, and other PII. Enable only in an approved private workspace. Provider and model Path: GymCore Admin \u0026gt; AI \u0026gt; Connections \u0026amp; Security \u0026gt; Provider and model. Only providers configured by WordPress are selectable. Refresh the authoritative model catalog, save an exact provider/model draft, run the fixed readiness probe, and activate only a passing draft. Provider credentials remain owned by WordPress Connectors and are never rendered or copied by GymCore AI. Internal AI license tier gym_core_ai_license_tier is an internal free/pro option used for AI locked states, including White Label. It is not a customer-entered license-key field. Do not change it in the database to grant access; use the approved licensing flow and verify the installed product’s entitlement behavior. White Label Path: GymCore Admin \u0026gt; AI \u0026gt; White Label. Pro and manage_options required. Field Type Default Allowed values Effect Brand Name Text GymCore AI Plain text Interface brand label only. Logo URL URL/media Blank Valid URL Interface logo. Primary Color Color #1a1a2e Valid hex Interface accent color. Hide Branding Checkbox Off On/Off Hides powered-by credit. Custom Welcome Message Textarea Blank Plain text Configured welcome message; no public website bot is implied. Verify a change Select Save Changes on the edited AI subtab, reload that subtab, and confirm the value remains. For White Label, use Save White Label Settings instead. Use fictional gym and member details to run the exact agent or response-style workflow affected by the change. Compare the conversation, proposed action, approval state, and resulting GymCore source record. System Status alone does not prove a provider request succeeded. Check the configured model provider’s request/error record when available. Restore the prior setting with the same visible save action if the response or action scope is wrong. A rotated secret invalidates the old secret, and an external action already completed cannot be undone by changing AI settings. Related guides Install and configure GymCore AI Agent personas Security, privacy, and retention White Label","headings":["Agents","Webhook \u0026amp; Security","Response Style","General","Provider and model","Internal AI license tier","White Label","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/gymcore-ai.md"},{"route":"/docs/settings-reference-license/","slug":"settings-reference-license","title":"License settings reference","summary":"License settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; License\u0026lt;br\u0026gt; Who can change it: an account with manage_options, normally a WordPress administrator.\u0026lt;br\u0026gt; Visible actions: Activate License, Deactivate License, and Save Webhook Settings submit separate forms. Manage Membership and Transfer License open the merchant portal; this screen has no general save button. The license key and webhook secret are credentials. Do not paste them into support tickets or screenshots. Activation, renewal, portal, and transfer results depend on getgymcore.com and network access. Field reference License Status Stored key/control: status badge Purpose: Shows local license status. Type: Read-only Default: Not Activated Allowed values/range: Active, Expired, Invalid, Not Activated Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Plan Stored key/control: tier Purpose: Shows the activated tier. Type: Read-only Default: Saved tier Allowed values/range: Starter, Growth, Pro or server response Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Expires Stored key/control: expiry Purpose: Shows expiry when present. Type: Read-only Default: Blank Allowed values/range: Date from activation status Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. License Key Stored key/control: gym_core_license_key Purpose: Activates or deactivates this site. Type: Password/action Default: Blank Allowed values/range: Purchased key Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Webhook endpoint Stored key/control: gym/v1/license/activate-webhook Purpose: URL supplied to merchant dashboard. Type: Read-only URL Default: Site REST URL Allowed values/range: Current site URL Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Webhook Secret Stored key/control: gym_core_webhook_secret Purpose: Authenticates purchase/renewal webhook. Type: Masked password Default: Blank Allowed values/range: Secret from merchant dashboard Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Manage Membership Stored key/control: signed portal link Purpose: Opens external portal. Type: Action link Default: n/a Allowed values/range: Active license Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Transfer License Stored key/control: signed portal link Purpose: Opens transfer workflow. Type: Action link Default: n/a Allowed values/range: Active license Dependencies: manage_options; network access for activation; merchant dashboard for webhook. Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version. When to change it: Change only during approved activation, transfer, rotation, or deactivation. When to leave it alone: Do not deactivate to troubleshoot an unrelated feature. Security/privacy: License keys and webhook secrets are credentials; never share them. Verify a license action Use only the action you intend: Activate License, Deactivate License, or Save Webhook Settings. Reload License and confirm the status badge, plan, and expiration shown by GymCore. Compare the result with the same license in the getgymcore.com merchant portal. A local badge alone does not prove a portal transfer or renewal succeeded. For webhook-secret changes, confirm the masked ending matches the intended secret and verify the next genuine activation or renewal event updates the local status. Restore the previous secret only if it is still valid at the merchant service; deactivation and external transfers have separate effects. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","License Status","Plan","Expires","License Key","Webhook endpoint","Webhook Secret","Manage Membership","Transfer License","Verify a license action","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/license.md"},{"route":"/docs/settings-reference-locations/","slug":"settings-reference-locations","title":"Locations settings reference","summary":"Locations settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Locations\u0026lt;br\u0026gt; Who can change it: an account allowed by gymcore_manage_settings; administrators with manage_options also qualify. manage_woocommerce alone is insufficient.\u0026lt;br\u0026gt; Current actions: Add location, Upload locations, edit, review assignments, archive, restore, and migration/rollback actions exposed by the location owner. Locations is an embedded owner workflow, not a WC-style Settings form. The old gym_core_require_location and gym_core_filter_products_by_location field definitions remain in source but are not rendered on this destination. Location manager The page shows: active-location plan usage and the installed consumer-readiness summary; current and archived locations; stable location key, name, timezone, address/contact data, coordinates, capacity, hours, and primary-location state; links to create, edit, review assignments, archive, or restore a location; CSV upload with mapping, dry-run review, and row-by-row apply that can report a partial result; bounded migration and rollback controls when their prerequisites are available. A location key becomes immutable after creation. Archive review identifies member and class assignments and requires a replacement where applicable. Plan limits and stale revisions block unsafe writes. Unreachable legacy field definitions Legacy option Source default Intended consumer Current UI status gym_core_require_location yes Visitor location selection Not rendered gym_core_filter_products_by_location yes Location-aware product queries Not rendered Do not tell an operator to use Save changes for these options. Their source definitions and any stored values do not prove current checkout, cart, kiosk, or catalog enforcement. Canonical location term metadata is not exposed through generic taxonomy REST. Use the Locations owner or a documented GymCore API so validation, plan limits, revision checks, and mutation evidence are preserved. Verify a supported location change Use fictional records on an authorized non-production site. Confirm plan capacity and take the required backup before mutation. Create or edit through the location owner form and verify the stable key, revision, primary status, timezone, hours, and address/contact fields after reload. For archive, review assignment counts, select the intended replacement, then verify members/classes and archive state together. For CSV import, complete mapping and dry-run review first. Do not apply if any row is invalid, conflicts, or exceeds the plan. Apply processes rows independently: if any row fails, stop, capture the created/updated IDs and row errors, reconcile the stored locations, and correct only the failed rows instead of blindly rerunning the file. Test each relevant consumer separately. A saved location does not certify catalog, cart, checkout, order, API, iCal, AI, kiosk, or report behavior. Expected: a direct owner action persists one concurrency-checked change. An import reports every successful and failed row; earlier successful rows can remain committed after a later failure. Reconcile the stored locations before any retry, and restore or roll back immediately if affected consumers disagree with source state. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Installed consumer acceptance remains required.","headings":["Location manager","Unreachable legacy field definitions","Verify a supported location change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/locations.md"},{"route":"/docs/settings-reference-privacy/","slug":"settings-reference-privacy","title":"Data \u0026 Privacy settings reference","summary":"Data \u0026 Privacy settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Data \u0026amp; Privacy Who can use it: an account allowed to manage Data \u0026amp; Privacy; WordPress administrators also qualify. Visible actions: the available controls depend on the data domain and its current state. They can include Save policy, Preview, Verify backup, Activate queued job, bounded job controls, scoped holds, transaction recovery, and privacy-tombstone replay. These controls can remove local data. A saved policy does not remove data, and a preview changes nothing. Do not activate or run a job until the owner has approved the retention period, the backup is verified, holds are clear, and the preview is current. What this page controls Data \u0026amp; Privacy separates local records into governed domains because conversations, approvals, member history, financial records, and backups have different owners and recordkeeping requirements. Each domain card shows: the authoritative owner; the configured policy; the effective policy; copies that may remain in connected services or with recipients; the controls available for that domain; the latest preview, job state, and PII-free receipt when present. This page does not run a person-specific privacy request, uninstall GymCore, delete backups, or remove records from WooCommerce, payment providers, QuickBooks, a CRM, messaging providers, or recipients. Governed domains ID Local data Owner and current boundary DP-01 AI conversations and messages GymCore AI local storage. The retention period is configurable from 1–365 days. Provider request logs follow the provider’s policy. DP-02 Terminal AI action details GymCore AI local storage; policy is not configured by default. DP-03 AI decision audit history GymCore AI local storage; policy is not configured by default. DP-04 AI memory WordPress user metadata; policy is not configured by default. DP-05 AI-composed SMS logs GymCore local storage; Twilio and recipients may retain copies. DP-06 AI knowledge documents Managed manually in AI Knowledge. DP-07 Lead and provider-event records Managed by the Lead Privacy policy and connected systems. DP-08 Consent, waivers, attendance, ranks, and member history Managed by WordPress Privacy and separate evidence policies; excluded from generic age-based removal. DP-09 WooCommerce, payment, subscription, refund, and accounting records Managed by WooCommerce and connected providers; this page does not delete them. DP-10 Local QuickBooks sync log Preview-only, with a 90-day source fallback and required backup attestation. QuickBooks and WooCommerce remain unchanged. DP-11 Operational, access, funnel, churn, outreach, and metadata logs Separate local stores; each needs an approved policy and exclusions. DP-12 Backups, restores, uninstall, and legacy AI plugin data Managed through operator and plugin-lifecycle procedures, not routine retention. Policy and job controls Save policy DP-01 exposes Keep AI conversations for with a source fallback of 30 days and an allowed range of 1–365 days. Save policy stores the configured period and invalidates an older preview. It does not make the policy effective and does not remove records. Preview Preview reads the current policy and reports: records eligible now; records protected by a hold; current writes; mutation safety; backup verification. Counts can change before a run. If a hold, current write, backup state, worker, or other safety check is unavailable, mutation remains blocked. Verify backup For domains that expose it, enter an opaque backup-manifest reference and select Verify backup. The reference must be 16–128 letters, numbers, underscores, or hyphens. Do not enter a backup URL, password, token, member name, or other sensitive value. Backup attestation records operator evidence. It does not inspect every backup copy or delete data from backups. Activate and run a queued job When the preview is current, safety is available, the worker exists, and backup requirements pass, the page can expose Activate queued job. The exact confirmation is shown beside the field. Activation queues the job but changes no governed records in that request. Run next batch performs one bounded batch. Pause, Resume, Retry, and Cancel job change the saved job state under the allowed lifecycle rules. The effective policy advances only after the exact policy version’s job completes. A saved or queued policy is not automatically effective. Holds and recovery Place scoped hold protects a specific opaque scope and invalidates existing previews. Release hold and require new preview requires the exact confirmation shown on the page. Recover expired transaction lease is an operator recovery action for a closed, expired prior transaction. Do not use it while the prior connection may still be active. Replay pending privacy erasures is for a restored site. It reapplies pending privacy tombstones after the required exact confirmation. These are advanced recovery and legal-safety controls. Stop and ask the approved data owner when authority, evidence, backup status, or hold scope is uncertain. Person-specific privacy requests For a request tied to a verified email address, use WordPress’s privacy tools instead of a retention job: Tools \u0026gt; Export Personal Data Tools \u0026gt; Erase Personal Data The Data \u0026amp; Privacy page also links to WordPress Privacy. Follow the privacy request guide because GymCore, WooCommerce, connected services, backups, and legal records have separate boundaries. Verify a change Reload Data \u0026amp; Privacy and confirm the configured and effective policy are shown separately. After saving a policy or recording backup evidence, run a new Preview. Confirm the preview shows verified counts or Unavailable; never interpret an unavailable count as zero. After activation, confirm the queued job ID and state before selecting Run next batch. After each batch, confirm the committed checkpoint and PII-free receipt. After completion, confirm the effective policy changed only for the completed domain and policy version. Check connected owners separately. A local receipt does not prove deletion from a provider, recipient, backup, WooCommerce, QuickBooks, or CRM. Related guides Settings Reference index Export or erase personal data Back up, deactivate, and remove GymCore GymCore AI security, privacy, and retention Roles and capabilities Verified against: Admin\\DataPrivacyPage and DataPrivacy\\DataPrivacyManager at repository baseline f5eb447cc on 2026-08-12.","headings":["What this page controls","Governed domains","Policy and job controls","Save policy","Preview","Verify backup","Activate and run a queued job","Holds and recovery","Person-specific privacy requests","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/privacy.md"},{"route":"/docs/settings-reference-ranks/","slug":"settings-reference-ranks","title":"Ranks settings reference","summary":"Ranks settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Ranks\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. Rank automation can change student progression records. Test thresholds with a non-production student and record the prior values before enabling automatic promotion. Field reference Require coach recommendation Stored key/control: gym_core_require_coach_recommendation Purpose: Requires recommendation before instructor approval. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Promotion workflow. Side effects: Adds/removes the recommendation gate. When to change it: Change only after agreeing promotion authority. When to leave it alone: Leave on for two-person review. Security/privacy: Affects member rank records and staff authority. Notify on promotion Stored key/control: gym_core_notify_on_promotion Purpose: Sends promotion email and, when configured, SMS. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Email delivery; global SMS + Twilio for text. Side effects: Promotion can create outbound messages immediately. When to change it: Disable before test promotions or when consent/templates are not ready. When to leave it alone: Leave on only after testing both channels. Security/privacy: Promotion status is member data. Auto-create promotion posts Stored key/control: gym_core_auto_promotion_posts Purpose: Publishes a celebration post and may share through Jetpack Publicize. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Publishing permissions; Jetpack Publicize for social sharing. Side effects: A promotion can create public content. When to change it: Turn off unless public posting, consent, names/images, and social accounts are approved. When to leave it alone: Leave on only with an active editorial review process. Security/privacy: High public/privacy impact, especially for minors. Enable foundations gate Stored key/control: gym_core_foundations_enabled Purpose: Requires new Adult BJJ students to clear Foundations before live training. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Adult BJJ/Foundations workflow. Side effects: Changes training eligibility gate. When to change it: Change only under head-instructor safety policy. When to leave it alone: Leave on if the program is in use. Security/privacy: Safety-critical; do not disable to work around bad data. Phase 1 — Classes Before Coach Rolls Stored key/control: gym_core_foundations_phase1_classes Purpose: Sets classes before first coach-roll evaluation. Type: Number Default: 10 Allowed values/range: Integer ≥1 Dependencies: Foundations on. Side effects: Changes new/effective progress thresholds. When to change it: Align to written curriculum. When to leave it alone: Leave when policy is unchanged. Security/privacy: Safety/eligibility data. Phase 2 — Coach Rolls Required Stored key/control: gym_core_foundations_coach_rolls_required Purpose: Sets supervised coach rolls required. Type: Number Default: 2 Allowed values/range: Integer ≥1 Dependencies: Foundations on and recorded coach rolls. Side effects: Changes clearance criteria. When to change it: Change only with head-instructor approval. When to leave it alone: Leave when policy is unchanged. Security/privacy: Safety-critical. Phase 3 — Total Classes to Clear Stored key/control: gym_core_foundations_total_classes Purpose: Sets total classes required to clear Foundations. Type: Number Default: 25 Allowed values/range: Integer ≥1 Dependencies: Foundations on. Side effects: Changes clearance criteria. When to change it: Align to curriculum. When to leave it alone: Leave when policy is unchanged. Security/privacy: Safety-critical. Adult BJJ White — Min Days Stored key/control: gym_core_threshold_adult_bjj_white_days Purpose: Visible promotion threshold input. Type: Number Default: 25 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ White — Min Classes Stored key/control: gym_core_threshold_adult_bjj_white_classes Purpose: Visible promotion threshold input. Type: Number Default: 17 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Blue — Min Days Stored key/control: gym_core_threshold_adult_bjj_blue_days Purpose: Visible promotion threshold input. Type: Number Default: 500 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Blue — Min Classes Stored key/control: gym_core_threshold_adult_bjj_blue_classes Purpose: Visible promotion threshold input. Type: Number Default: 225 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Purple — Min Days Stored key/control: gym_core_threshold_adult_bjj_purple_days Purpose: Visible promotion threshold input. Type: Number Default: 700 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Purple — Min Classes Stored key/control: gym_core_threshold_adult_bjj_purple_classes Purpose: Visible promotion threshold input. Type: Number Default: 400 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Brown — Min Days Stored key/control: gym_core_threshold_adult_bjj_brown_days Purpose: Visible promotion threshold input. Type: Number Default: 700 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Adult BJJ Brown — Min Classes Stored key/control: gym_core_threshold_adult_bjj_brown_classes Purpose: Visible promotion threshold input. Type: Number Default: 400 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kids BJJ Default — Min Days Stored key/control: gym_core_threshold_kids_bjj_default_days Purpose: Visible promotion threshold input. Type: Number Default: 340 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kids BJJ Default — Min Classes Stored key/control: gym_core_threshold_kids_bjj_default_classes Purpose: Visible promotion threshold input. Type: Number Default: 64 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kids BJJ White — Min Days Stored key/control: gym_core_threshold_kids_bjj_white_days Purpose: Visible promotion threshold input. Type: Number Default: 0 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kids BJJ White — Min Classes Stored key/control: gym_core_threshold_kids_bjj_white_classes Purpose: Visible promotion threshold input. Type: Number Default: 0 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kickboxing Level 2 — Min Days Stored key/control: gym_core_threshold_kickboxing_level2_days Purpose: Visible promotion threshold input. Type: Number Default: 500 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Kickboxing Level 2 — Min Classes Stored key/control: gym_core_threshold_kickboxing_level2_classes Purpose: Visible promotion threshold input. Type: Number Default: 200 Allowed values/range: Integer ≥0 Dependencies: Ranks settings. Side effects: Audited eligibility reads a separate aggregate threshold store, so this field is not proven to change eligibility. When to change it: Do not tune production eligibility with this field until a runtime fix/test confirms it. When to leave it alone: Leave at current value and use coach review. Security/privacy: Incorrect assumptions can produce premature or delayed promotion decisions. Verify a change Select Save changes and confirm Settings saved. Reload Ranks and confirm each changed threshold remains. Evaluate one non-production student whose attendance, tenure, points, and promotion state are known. Compare the result with that student’s rank record and the gym_rank_history custom-table entry. If an automatic result is wrong, disable the relevant automation or restore the prior threshold before correcting the student record separately. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","Require coach recommendation","Notify on promotion","Auto-create promotion posts","Enable foundations gate","Phase 1 — Classes Before Coach Rolls","Phase 2 — Coach Rolls Required","Phase 3 — Total Classes to Clear","Adult BJJ White — Min Days","Adult BJJ White — Min Classes","Adult BJJ Blue — Min Days","Adult BJJ Blue — Min Classes","Adult BJJ Purple — Min Days","Adult BJJ Purple — Min Classes","Adult BJJ Brown — Min Days","Adult BJJ Brown — Min Classes","Kids BJJ Default — Min Days","Kids BJJ Default — Min Classes","Kids BJJ White — Min Days","Kids BJJ White — Min Classes","Kickboxing Level 2 — Min Days","Kickboxing Level 2 — Min Classes","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/ranks.md"},{"route":"/docs/settings-reference-readme/","slug":"settings-reference-readme","title":"Settings Reference","summary":"all current sections, injected fields, and known control gaps.","text":"Every current GymCore settings section is listed here. Each page names the exact menu, effective WordPress capability, visible save or separate action, field defaults and ranges, dependencies, side effects, reversibility/privacy concerns, and a way to verify the result in its source system. Start with Understand GymCore settings for the plain-language map of settings groups, owners, defaults, recommendations, effective behavior, setup-wizard boundaries, and verification. A successful save confirms storage only. Test the workflow that consumes the setting. Controls explicitly marked as having no confirmed runtime consumer were visible and persisted in the audited source, but should not be presented as active product behavior. Most core operational tabs under GymCore Admin \u0026gt; GymCore Settings use gymcore_manage_settings; administrators with manage_options also qualify. CRM, communications aliases, billing, Finance, Waiver, Staff Access, Data \u0026amp; Privacy, and AI use their own destination policies. manage_woocommerce alone exposes only inherited Billing, Finance, and AI compatibility destinations—not core Settings, Locations, or Referrals. The pages below name each exact policy and whether the surface uses Save changes or a separate action. Core settings sections General — 6 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; General Locations — embedded location owner plus 2 unreachable legacy field definitions; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Locations Schedule — 3 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Schedule Ranks — 21 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Ranks Attendance — 4 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Attendance Gamification — 2 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Gamification SMS — 6 unreachable legacy field definitions; current alias opens Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers CRM — 4 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; CRM Referrals — 10 typed field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Referrals Waiver — immutable owner under GymCore Students \u0026gt; Waiver Versions plus 3 guarded legacy projections Billing — 1 documented field/control entry; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Billing Retention — 10 unreachable legacy field definitions; current alias opens Communications \u0026amp; Automations \u0026gt; Member Outreach Staff Access — 5 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access Data \u0026amp; Privacy — owner-managed lifecycle controls and WordPress privacy tools; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Data \u0026amp; Privacy Belt Systems — 9 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; Belt Systems License — 8 documented field/control entries; GymCore Admin \u0026gt; GymCore Settings \u0026gt; License Separately surfaced and injected settings GymCore AI settings — agent overrides, webhook security, response style, credentials status, model, notifications, retention, and white label. Accounting and QuickBooks settings — OAuth application credentials, sync toggles, account mapping, manual re-sync, and logs under Integrations. Attendance milestones are injected into Attendance by MilestoneTracker and documented with that section. CRM fields are owned by FormToCrm and rendered in CRM. RetentionSettings still registers a legacy field provider, but the current registry redirects the alias instead of rendering it. Privacy, Belt Systems, Staff Access, and License use custom forms rather than the normal WooCommerce-style field renderer. AI Knowledge is a separate CRUD/import surface with title, body, tags, and topic fields. Known control gaps General \u0026gt; REST API does not gate registered REST or MCP routes. Schedule \u0026gt; Enable waitlist and Attendance \u0026gt; Check-in methods have active Settings controls but still need installed end-to-end checks. The two legacy Locations toggles and six legacy SMS definitions are not rendered by their current embedded/external destinations. The prior Gamification \u0026gt; Notify on badge earned field is no longer present in current source. Ranks threshold fields and Belt Systems criteria are not the source read by the audited eligibility engine. Staff Access edits four newer RBAC capabilities, not every capability used across GymCore. Core license declarations are not consistently enforced by local runtime consumers. Legacy retention definitions default on in source, but the current destination does not render them; the audited daily runner is also gated by the global SMS option. Related guides Understand GymCore settings GymCore AI Licensing and plan gates Roles and permissions matrix Privacy requests","headings":["Core settings sections","Separately surfaced and injected settings","Known control gaps","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/README.md"},{"route":"/docs/settings-reference-referrals/","slug":"settings-reference-referrals","title":"Referrals settings reference","summary":"Referrals settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Referrals\u0026lt;br\u0026gt; Who can change it: an account with gymcore_manage_settings, or a WordPress administrator with manage_options. manage_woocommerce alone is not sufficient.\u0026lt;br\u0026gt; Visible action: Save changes validates the selected mode and stores one complete revision. A successful request shows Settings saved. Referral rewards can create financial or membership value. Keep the program off until the selected delivery path has passed with fictional records on a non-production site. Shared controls Program enabled Control: gym_core_referral_enabled Type/default: Checkbox; off when no typed revision exists and after legacy migration. Effect: An enabled save checks readiness once and stores a new enabled revision. Later referral attributions snapshot that stored revision while it remains enabled; readiness is not re-evaluated at attribution. Turning it off does not change existing decisions. Dependencies: Action Scheduler plus the selected mode’s readiness checks. Failure behavior: Enabling is rejected when readiness is not ready. Clearing this control copies the current revision into a new disabled revision without revalidating a degraded delivery dependency; reload and confirm it is off. Reward mode Control: gym_core_referral_reward_mode Type/default: Select; WooCommerce fixed-cart coupon by default. Allowed values: coupon, sms_credit, custom. Effect: Selects one typed delivery contract. Only the selected mode’s fields are validated and stored in the revision. Configuration note Control: gym_core_referral_configuration_note Type/default: Optional textarea; empty. Purpose: Owner-visible reason for the revision. Security/privacy: Do not store credentials, member data, payment data, or provider payloads. Expected revision Control: gym_core_referral_expected_revision Type: Hidden concurrency value. Effect: Rejects a save when another owner already stored a newer revision. Reload and review instead of overwriting it. Coupon mode Coupon amount Control: gym_core_referral_coupon_amount Type/default: Store-currency decimal text; 10 formatted to the store currency precision when no typed revision exists (10 for zero-decimal stores, 10.00 for two-decimal stores). Allowed range: Greater than zero and no more than 100000, with no more decimal places than the WooCommerce store allows. Dependencies: WooCommerce and Action Scheduler. Each save snapshots the store currency current at that moment; there is no separate changed-currency confirmation between a disabled save and a later enable save. Delivery policy: Fixed-cart, non-stackable, one use, one use per customer, excluded from sale items, and expires after 183 days. Delivery rejects a missing or invalid recipient. Verify a non-empty referrer email restriction and exact coupon policy readback in the created coupon. initial_order_only is stored as metadata, not independently enforced by current Gym Core source. Message-credit mode Message-credit units Control: gym_core_referral_sms_units Type/default: Number; 10 when no matching typed revision exists. Allowed range: Whole numbers from 1 through 10000. Meaning: Integer outbound-message units. They are not money, Twilio account funds, or carrier segments. Dependencies: An external PHP integration must register a version 1 message-credit ledger, credit-aware sender, and ready Twilio transport; current Gym Core provides no ready registration. Action Scheduler is also required. Custom mode Custom reward identifier Control: gym_core_referral_custom_identifier Type: Text. Allowed value in this form: Up to 64 lowercase letters, digits, underscores, or hyphens; must begin with a letter. Do not use periods because the WordPress settings sanitizer removes them before validation. Custom owner description Control: gym_core_referral_custom_description Type: Textarea. Allowed length: 10–280 characters. Purpose: Explains the promised reward to owners. Do not include member data or secrets. Custom handler key Control: gym_core_referral_custom_handler Type: Text. Allowed value in this form: Up to 64 lowercase letters, digits, underscores, or hyphens; must begin with a letter. Do not use periods. Requirement: An external PHP integration must register the handler; current Gym Core provides none. The descriptor must declare readiness, idempotency, reconciliation, and a durable delivery contract. The save-time readiness check does not prove that delivery and reconciliation callbacks are callable; the delivery worker rejects missing callbacks. Custom handler contract version Control: gym_core_referral_custom_version Type/default: Number; 1 when no matching typed revision exists. Requirement: Must match the registered handler descriptor. A stale or mismatched version rejects the save. Verify a change Save with Program enabled off and confirm the new preview and values after reload. Verify the selected mode’s dependencies and source-system test evidence. Enable the program, save, and confirm the revision remains enabled after reload. Run one fictional referral through attribution, qualification, scheduled delivery, source-system read-back, and cleanup. Gym Core terminalizes an undelivered reward as exhausted after five delivery attempts. See Configure and verify referral rewards for the complete acceptance path. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: Gym Core 2.2.0 integrated source.","headings":["Shared controls","Program enabled","Reward mode","Configuration note","Expected revision","Coupon mode","Coupon amount","Message-credit mode","Message-credit units","Custom mode","Custom reward identifier","Custom owner description","Custom handler key","Custom handler contract version","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/referrals.md"},{"route":"/docs/settings-reference-retention/","slug":"settings-reference-retention","title":"Retention settings reference","summary":"Retention settings reference.","text":"Current menu path: GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Member Outreach\u0026lt;br\u0026gt; Who can open it: an account allowed by gymcore_manage_communications; administrators with manage_options also qualify.\u0026lt;br\u0026gt; Current action: review outreach and automation status. The audited build does not render a Retention settings form or a Save changes action. The legacy Retention field provider has been removed. The current destination registry sends the old retention alias to Member Outreach, while a few stored option IDs remain as runtime or migration compatibility inputs. Treat those values as legacy state, not as proof that an operator can configure or safely run a workflow. Unreachable legacy field definitions These option IDs remain only where runtime consumers or upgraded-install migration still read them. They are not active controls in the audited Settings interface. Legacy option Source default Intended consumer Current UI status gym_core_retention_inactive_7_enabled yes 7-day inactive SMS Not rendered gym_core_retention_inactive_7_template blank 7-day SMS copy Not rendered gym_core_retention_streak_break_enabled yes Streak-break SMS Not rendered gym_core_retention_streak_break_template blank Streak-break copy Not rendered gym_core_retention_missed_3_enabled yes Coach outreach queue Not rendered gym_core_retention_inactive_30_enabled historical Retired 30-day email path No active consumer gym_core_retention_mailpoet_list_id historical Retired MailPoet path No active consumer gym_core_retention_inactive_90_enabled yes Win-back SMS Not rendered gym_core_retention_inactive_90_offer blank Win-back copy Not rendered gym_core_churn_threshold 70 At-risk scoring Not rendered Source defaults do not prove the corresponding option is currently stored, enabled, reachable, or safe. Global SMS supplies the Twilio client for SMS sequences; the coach queue has separate workflow gates. Operator procedure Open Communications \u0026amp; Automations \u0026gt; Member Outreach and review current readiness, ownership, audience, consent, and provider status. Do not look for the legacy Retention tab or change these values directly in the database. If an upgraded site depends on a legacy value, have an administrator or developer inspect the stored option and consuming runtime read-only before proposing a change. Change workflow intent only through Communications. Do not activate or trigger contact until a non-production fixture proves audience selection, consent, scheduling, message content, logging, and provider delivery. Expected: the current UI reports workflow intent and effective status without claiming that the ten legacy option IDs are editable settings. Related guides Settings Reference index Automated retention Launch checklist Roles and capabilities Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Runtime outreach acceptance remains separate.","headings":["Unreachable legacy field definitions","Operator procedure","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/retention.md"},{"route":"/docs/settings-reference-schedule/","slug":"settings-reference-schedule","title":"Schedule settings reference","summary":"Schedule settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Schedule\u0026lt;br\u0026gt; Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.\u0026lt;br\u0026gt; Visible action: Save changes stores every field on this tab. A successful request shows Settings saved. These values define class-duration and booking windows used by scheduling workflows. Existing appointments are not rewritten when a default changes. Field reference Default class capacity Stored key/control: gym_core_default_class_capacity Purpose: Sets the fallback headcount ceiling; a class can override it. Type: Number Default: 30 Allowed values/range: Integer ≥ 1 Dependencies: Class scheduling/capacity consumer. Side effects: New/effective class capacity uses this when no class-specific value exists. When to change it: Change to your normal safe room or mat capacity. When to leave it alone: Leave it when most classes have explicit capacities. Security/privacy: Capacity is a safety/operations control; verify fire code and coaching ratios. Enable waitlist Stored key/control: gym_core_waitlist_enabled Purpose: Enables member waitlist UI, REST/MCP waitlist access, waitlist mutations, and cancellation-triggered auto-fill dispatch. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Full class and waitlist workflow. Side effects: Off prevents new join/leave operations and hides or unregisters current access paths without deleting queued rows. On permits those paths and cancellation-triggered promotion processing. When to change it: Turn on only after testing full-class placement, cancellation, roster results, and any notification dependency. When to leave it alone: Keep off when the installed member flow or roster/notification result has not been verified. Security/privacy: A failed waitlist can create attendance and communication disputes. iCal feed Stored key/control: gym_core_ical_enabled Purpose: Controls the class-schedule calendar feed. Type: Checkbox Default: On Allowed values/range: On / Off Dependencies: Published schedule and rewrite endpoint. Side effects: On makes the feed available to calendar subscribers; cached clients may retain old events. When to change it: Turn off if schedule data should not be available through the feed. When to leave it alone: Leave on when members use calendar subscriptions. Security/privacy: Feed URLs may reveal class times; treat as public unless access controls are verified. Verify a change Select Save changes and confirm Settings saved. Reload Schedule and confirm all three values remain within their documented ranges. Create or inspect a non-production class occurrence and booking boundary; confirm its displayed duration and allowable booking window match the new setting. Confirm the corresponding WordPress option named in Stored key/control contains the intended value. For Enable waitlist, also test member UI, route availability, join/leave, cancellation, roster state, and notification delivery on the installed build. Source review proves the setting has consumers; it does not prove the whole outcome. Restore the prior value if the schedule workflow differs. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Installed end-to-end waitlist verification is still required.","headings":["Field reference","Default class capacity","Enable waitlist","iCal feed","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/schedule.md"},{"route":"/docs/settings-reference-sms/","slug":"settings-reference-sms","title":"SMS settings reference","summary":"SMS settings reference.","text":"Current menu path: GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers\u0026lt;br\u0026gt; Who can open it: an account allowed by gymcore_manage_communications; administrators with manage_options also qualify.\u0026lt;br\u0026gt; Current action: review SMS provider readiness. The audited build does not render the legacy SMS settings form, credential save, rate-limit save, or Send test SMS action. The source still contains legacy WC-style field definitions, but the current destination registry sends the old sms alias to Channels \u0026amp; providers. Existing option values may still be consumed at runtime. Do not interpret their presence as a supported editing surface. Unreachable legacy field definitions Legacy option/control Source default Intended use Current UI status gym_core_twilio_account_sid blank Twilio account identifier Not rendered gym_core_twilio_auth_token blank Twilio credential Not rendered gym_core_twilio_messaging_service_sid blank Messaging Service sender Not rendered gym_core_twilio_phone_number blank Single-number sender Not rendered gym_core_twilio_test_button none Billable outbound test Not rendered gym_core_sms_rate_limit 1 Per-contact hourly limit Not rendered The account SID and phone identifiers are sensitive operational data. The auth token is a secret and must never be copied into screenshots, tickets, logs, or documentation. A test send is an external side effect and can create provider charges. Operator procedure Open Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers and review the reported SMS readiness and owner. Do not look for the legacy SMS tab or edit these options directly in the database. If an upgraded site depends on legacy values, have an administrator or developer inspect the stored options and runtime consumer read-only before proposing a credential rotation. Use only a supported, approval-gated credential workflow. Test sends require a consented non-production destination and explicit approval. Confirm the GymCore delivery record and provider record after any authorized test; never infer delivery from a saved option. Expected: the current UI reports provider readiness without exposing secrets or claiming the six legacy definitions are editable controls. Related guides Settings Reference index Connect Twilio and test SMS delivery Launch checklist Roles and capabilities Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. Provider delivery still requires installed runtime acceptance.","headings":["Unreachable legacy field definitions","Operator procedure","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/sms.md"},{"route":"/docs/settings-reference-staff-access/","slug":"settings-reference-staff-access","title":"Staff Access settings reference","summary":"Staff Access settings reference.","text":"Exact menu path: GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access\u0026lt;br\u0026gt; Who can change it: an account with manage_options, normally a WordPress administrator.\u0026lt;br\u0026gt; Visible action: Save Role Permissions stores all role checkboxes. Preset buttons only change the unsaved form until this action is selected. The complete role-to-four-capability map is stored in gym_core_rbac_role_caps. Use the visible table and presets; do not edit the serialized option directly. These controls grant four GymCore capabilities; they do not replace WordPress roles or every separate menu gate. Record each role’s current checkboxes before changing access, and verify with a non-administrator test account. Field reference Role preset Stored key/control: preset selector Purpose: Copies one of Gym Owner, Head Instructor, Staff Instructor, Front Desk into the four visible permissions. Type: Checkbox/select Default: Current role map Allowed values/range: Configured WordPress roles except subscriber/contributor Dependencies: WordPress role and saved RBAC map. Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities. When to change it: Change with a named user test account and least privilege. When to leave it alone: Do not assume this page controls every GymCore feature. Security/privacy: Access-control change; administrators always retain the four caps. Manage Members Stored key/control: gymcore_manage_members Purpose: Controls surfaces that check this newer RBAC capability. Type: Checkbox/select Default: Role preset/default Allowed values/range: Configured WordPress roles except subscriber/contributor Dependencies: WordPress role and saved RBAC map. Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities. When to change it: Change with a named user test account and least privilege. When to leave it alone: Do not assume this page controls every GymCore feature. Security/privacy: Access-control change; administrators always retain the four caps. Manage Billing Stored key/control: gymcore_manage_billing Purpose: Controls surfaces that check this newer RBAC capability. Type: Checkbox/select Default: Role preset/default Allowed values/range: Configured WordPress roles except subscriber/contributor Dependencies: WordPress role and saved RBAC map. Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities. When to change it: Change with a named user test account and least privilege. When to leave it alone: Do not assume this page controls every GymCore feature. Security/privacy: Access-control change; administrators always retain the four caps. View Reports Stored key/control: gymcore_view_reports Purpose: Controls surfaces that check this newer RBAC capability. Type: Checkbox/select Default: Role preset/default Allowed values/range: Configured WordPress roles except subscriber/contributor Dependencies: WordPress role and saved RBAC map. Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities. When to change it: Change with a named user test account and least privilege. When to leave it alone: Do not assume this page controls every GymCore feature. Security/privacy: Access-control change; administrators always retain the four caps. Manage Staff Stored key/control: gymcore_manage_staff Purpose: Controls surfaces that check this newer RBAC capability. Type: Checkbox/select Default: Role preset/default Allowed values/range: Configured WordPress roles except subscriber/contributor Dependencies: WordPress role and saved RBAC map. Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities. When to change it: Change with a named user test account and least privilege. When to leave it alone: Do not assume this page controls every GymCore feature. Security/privacy: Access-control change; administrators always retain the four caps. Verify a change Record the current four checkboxes for the role, make the smallest edit, and select Save Role Permissions. Reload Staff Access and confirm the role’s saved checkboxes. Sign in with a non-administrator test account assigned only to that role and open the exact menu and action being delegated. Confirm the account can perform only the intended actions. If access is too broad or still blocked by a separate WordPress, WooCommerce, or legacy gym_* gate, restore the prior checkboxes and select Save Role Permissions again. Related guides Settings Reference index Launch checklist Roles and capabilities Common troubleshooting checks Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.","headings":["Field reference","Role preset","Manage Members","Manage Billing","View Reports","Manage Staff","Verify a change","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/staff-access.md"},{"route":"/docs/settings-reference-understand-settings/","slug":"settings-reference-understand-settings","title":"Understand GymCore settings","summary":"owners, setup recommendations, safety boundaries, and how to verify a change.","text":"For: Gym owners, site administrators, and managers Access needed: Your account must have permission for the section you want to view or change. Applies to: GymCore and the separate GymCore AI companion plugin GymCore keeps each setting with the part of the product that owns the work. Use the Settings search to find a control, then confirm the owner, prerequisites, and effect before saving. Start here In WordPress, open GymCore Admin \u0026gt; GymCore Settings. The page groups settings by the work they control: Group Use it for Foundation Organization identity and licensing. Gym operations Locations, schedule, capacity, waitlists, and attendance. Member progress Rank systems, promotion rules, badges, and streaks. Growth \u0026amp; relationships Lead routing, referrals, waivers, and member outreach. Communications Channel readiness, providers, workflows, and delivery controls. Finance Membership pause policy and financial owner links. Governance \u0026amp; AI Staff access, data/privacy controls, and GymCore AI. Some results open another GymCore page. That is intentional. Twilio belongs to GymCore Admin \u0026gt; Communications \u0026gt; Channels \u0026amp; providers; active waivers belong to GymCore Students \u0026gt; Waiver Versions; and GymCore AI has its own hub and settings. Before you change a setting Check the Source of truth label. It names the page or system that controls the value, so you know where to make changes and where to confirm the result. Read the field description and prerequisites. Record the current value when the change affects members, messages, access, payments, privacy, or public content. Confirm the visible action. Some sections use Save changes; others use a protected action such as Publish, Activate, Rotate, or Run. Save only the section you reviewed. Test the workflow that uses the setting. A saved setting is not proof that a workflow is ready. A message still needs a configured provider, approved recipients, consent, and active Communications policy. An AI model still needs a passing readiness check and activation. A retention policy still needs its own review and activation. Default does not mean recommended GymCore uses four different states: Default: what GymCore uses when nothing has been saved. Saved value: what your site currently stores. Recommendation: a value suggested for your gym during setup or in documentation. Effective behavior: what GymCore can do now after permissions, services, approvals, and other gates are checked. A setup recommendation should help you start, not silently replace a choice you already made. When rerunning setup, review the summary before accepting changes. What the setup wizard can configure Depending on the setup flow and installed plugins, the wizard can collect or create: your gym name and WordPress site identity; locations and time zones; martial arts programs and starting belt templates; class programs and membership products; staff accounts; payment-provider readiness; Twilio provider details through the Communications owner; GymCore AI readiness. The wizard can save setup information or provider details, depending on the flow. Completing it does not by itself activate customer messaging, public publishing, accounting sync, retention actions, or an AI model. Review and activate each owner-controlled workflow separately. Settings that need extra care Messages and automations Open GymCore Admin \u0026gt; Communications. Provider setup and workflow activation are separate: Set up the provider. Review channels and workflows. Confirm audiences, targets, consent, quiet hours, rates, and approvals. Activate only after the review is current. Changing Twilio credentials can return active Communications to review. This prevents messages from continuing under unreviewed provider settings. Access Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Staff Access. Lowering an access requirement can expose member, finance, or AI information to more people. Test with a non-administrator account. Do not rely only on a job title; the server checks permissions. Payments and accounting WooCommerce owns charges, refunds, renewals, payment methods, and subscription status. GymCore settings can add policy or integration intent, but they do not replace WooCommerce records. QuickBooks environment, credentials, accounts, categories, and settlement mappings have no universal default. Connect and verify them against the real QuickBooks company before enabling sync. Data and privacy Open GymCore Admin \u0026gt; GymCore Settings \u0026gt; Data \u0026amp; Privacy. A configured retention number is not automatically active. Review the effective policy, backup status, preview, holds, and activation record. Export, erase, activate, and recovery actions have separate confirmations because they can affect personal data. GymCore AI GymCore AI is a separate companion plugin. Provider credentials remain in WordPress Connectors. GymCore AI settings control assistant presentation, response style, topic routing, webhook security, retention, and staff notifications. Leave custom prompts and identity overrides blank unless you need them. Blank values keep the built-in behavior and reduce configuration drift. Enabling an assistant does not grant new permissions or bypass action review. Verify your change Use the check that matches the setting: Setting area What to verify Organization Reload the page and check the affected member-facing label or app metadata. Locations Confirm the location exists, its time zone is correct, and assigned products/classes behave as expected. Schedule Create or inspect a test class; verify capacity, waitlist, and calendar behavior. Attendance Use a test member and class; verify the allowed check-in method and duplicate protection. Ranks Use a test member; compare the effective rank system, binding, and eligibility result. CRM Submit a fictional lead and confirm the contact, stage, tags, and assignment in the CRM. Referrals Confirm the typed revision and readiness; do not promise a reward until delivery is ready. Communications Use previews and approved test recipients; check delivery records and suppression behavior. Billing Verify the WooCommerce subscription and the GymCore policy result. Privacy Confirm the effective policy or durable job result, not only the configured value. GymCore AI Use fictional data; confirm provider readiness, response behavior, action review, and audit evidence. If a setting is missing Confirm you opened the current path, not an old WooCommerce settings URL. Search from GymCore Admin \u0026gt; GymCore Settings. Check whether the result opens an owner page such as Communications, Finance, Waiver Versions, or AI. Confirm the required plugin, license, connection, and permission are available. Ask a WordPress administrator to check the setting if your account does not have access. Do not edit the WordPress database as a routine workaround. Owner pages may validate, encrypt, version, audit, or coordinate changes that a direct option edit would bypass. Field-by-field reference Use the reference page for the area you are changing: General Locations Schedule Attendance Ranks Belt Systems Gamification CRM Referrals Waiver Billing Retention and Member Outreach SMS and Twilio Staff Access Data \u0026amp; Privacy License Accounting and QuickBooks GymCore AI Related guides Complete the setup wizard Run the launch checklist Protect credentials and webhooks Roles and capabilities Settings Reference index","headings":["Start here","Before you change a setting","Default does not mean recommended","What the setup wizard can configure","Settings that need extra care","Messages and automations","Access","Payments and accounting","Data and privacy","GymCore AI","Verify your change","If a setting is missing","Field-by-field reference","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/understand-settings.md"},{"route":"/docs/settings-reference-waiver/","slug":"settings-reference-waiver","title":"Waiver settings reference","summary":"Waiver settings reference.","text":"Current owner: GymCore Students \u0026gt; Waiver Versions\u0026lt;br\u0026gt; View capability: gymcore_view_waiver_versions\u0026lt;br\u0026gt; Draft/preview capability: gymcore_manage_waiver_drafts\u0026lt;br\u0026gt; Publish/forward-rollback capability: gymcore_publish_waiver_versions GymCore Settings \u0026gt; Waiver redirects to GymCore Students \u0026gt; Waiver Versions and has no save scope. The legacy gym_core_waiver_version, gym_core_waiver_require_drawn_signature, and gym_core_waiver_text options remain as guarded compatibility projections; ordinary option writes are rejected. Current workflow Open GymCore Students \u0026gt; Waiver Versions and record the active publication ID and pointer revision. Enter a version label, counsel-approved waiver text, acknowledgement version, signature mode, optional ordered form-field JSON, and change summary. Select Save draft. Expected: the mutable draft saves with a revision. The active waiver does not change. Select Generate impact preview. Expected: the preview reports the affected and unknown-identity cohorts, current publication/pointer revisions, and whether publication is ready. Missing impact evidence, unknown identities, a stale draft/pointer, or an exceeded impact cap blocks publication. Review the rendered text, policy, cohort counts, and publication owner. Enter a publication reason and the displayed PUBLISH \u0026lt;version label\u0026gt; confirmation phrase. Select Publish immutable version once. Expected: GymCore appends one immutable publication, compare-and-swaps the active pointer, records audit/outbox evidence, and preserves prior publications. A changed draft or pointer fails closed instead of overwriting newer work. Policy fields Field Current behavior Version label Required human label for the draft/publication. Waiver text Required source HTML; canonical HTML/plain text and hashes are committed to the immutable publication. Acknowledgement version Required policy identifier. Signature mode drawn_signature or acknowledgement_only. Form fields Optional ordered JSON using supported field types. Invalid JSON or fields block the draft. Change summary Required on the draft. Publication reason Required at publication. Forward rollback Rollback never edits or reactivates history directly. Enter a prior publication ID and reason under Forward rollback preview. GymCore copies that immutable publication into a new draft, then requires a fresh preview and publication confirmation. Verify in source systems Reopen Waiver Versions and confirm the active publication ID/pointer revision. Then open GymCore Students \u0026gt; Waivers \u0026gt; Missing Current Waiver and one fictional/non-production signature record. The active publication, rendered policy, and signature evidence must agree. Never use production members to test publication. Do not delete signature records or edit compatibility options to make current-status counts look correct. Related guides Publish and collect a waiver version Settings Reference index Launch checklist Roles and capabilities Source-reviewed: src/Admin/WaiverVersionAdminPage.php, src/API/WaiverVersionController.php, src/Waiver/WaiverVersionService.php, and src/Waiver/WaiverVersionRepository.php on 2026-07-28. No installed publication is claimed.","headings":["Current workflow","Policy fields","Forward rollback","Verify in source systems","Related guides"],"source_sha256":"","section":"Settings Reference","source":"docs/user-guide/settings-reference/waiver.md"},{"route":"/docs/navigation-map/","slug":"navigation-map","title":"Role and task navigation map","summary":"Role and task navigation map.","text":"Use this map when you know your role or the outcome you need, but not the product area. Links point to the one article that owns the procedure; role-based onboarding pages should link here rather than repeat changing steps. Choose by role Gym owner or site administrator First week Check system requirements. Install and activate GymCore. Complete the setup wizard. Configure your gym and locations. Add staff and assign access. Run the launch checklist. Ongoing administration Roles and capabilities Settings Reference Integrations Privacy requests Back up, deactivate, and remove GymCore Gym manager or front-desk staff Start of shift Daily opening checks Front-desk routines Check-in and kiosk mode Common member work Add or edit a member Connect families and guardians Manage memberships Collect waivers Pause or cancel a membership Coach or head coach Before and after class View programs, classes, and the schedule Record or correct attendance Assign curriculum and techniques Member development Review readiness and promote members Manage belt tests Configure badges, streaks, and milestones Sales staff Capture and create leads. Work the lead pipeline. Manage trials and conversion. Use the sales kiosk. Read lead and sales reports. Finance or bookkeeping staff Membership billing and renewals Failed renewals and overdue accounts Refunds and billing corrections Accounting Finance Copilot Finance data is sensitive. If a menu or action is missing, ask a site administrator to review your assigned role instead of sharing an administrator account. Member or parent Use the member and parent portals Manage waivers Troubleshoot member and parent access Customer staff should send members directly to these pages. Do not send them to WordPress administrator references. WordPress administrator, developer, or integration partner These topics are intentionally outside beginner flows: System requirements Webhooks and the REST API Protect credentials and webhooks REST API reference MCP and WordPress abilities WP-CLI commands Data model and storage Internal and candidate surfaces Choose by task I need to… Start here Then check Get a new site ready Install and activate GymCore Launch checklist Add staff safely Add staff and assign access Roles and permissions matrix Add one member Add or edit a member Memberships Move many members into GymCore Import members Data overview Connect a child to a parent Families and guardians Member and parent portals Build next week’s schedule Programs, classes, and schedule Capacity and waitlists Check members into class Check-in and kiosk mode Attendance troubleshooting Fix a wrong check-in Record or correct attendance Audit logs Follow up with new leads Work the lead pipeline Send email and SMS Convert a trial Trials and conversion Membership billing and renewals Handle a failed payment Failed renewals Billing troubleshooting Send a text message Send email and SMS Consent and deliverability Configure automated follow-up Automated retention Retention settings Promote a member Promotion workflow Rank settings Put GymCore content on a page Blocks and shortcodes Blocks and shortcodes reference Export a report Schedule and export reports Privacy requests Connect another system Integrations overview Webhooks and REST API Use GymCore AI GymCore AI overview Chat with GymCore AI Approve an AI-proposed change Action approvals AI audit logs Find every setting and its side effects Settings Reference Launch checklist Look up a product term Glossary FAQ Fix something that stopped working Common checks Collect diagnostics Navigation rules for maintainers Put each article in one top-level category, even when more than one role uses it. Link across categories under Related guides; do not duplicate the procedure. A role path may contain links only. It must not become a second version of task instructions. Keep owner/admin prerequisites visible before a lower-access user begins a task. Keep developer routes, internal option names, database details, and command-line work in Reference, unless a customer task truly requires them. Mark plan-dependent, companion-plugin, and third-party-service requirements before the first step.","headings":["Choose by role","Gym owner or site administrator","Gym manager or front-desk staff","Coach or head coach","Sales staff","Finance or bookkeeping staff","Member or parent","WordPress administrator, developer, or integration partner","Choose by task","Navigation rules for maintainers"],"source_sha256":"","section":"Start Here","source":"docs/user-guide/navigation-map.md"},{"route":"/docs/start-here-choose-your-path/","slug":"start-here-choose-your-path","title":"Choose the right guide for your job","summary":"routes by role and goal.","text":"Purpose Choose the shortest owner, front desk, coach, sales, finance, member, parent, or developer path to the task you need. Who can use it For: Any staff member choosing the correct task guide\u0026lt;br\u0026gt; Access needed: The top-level GymCore menus require read; each linked task can require a narrower capability such as gym_check_in_member, gym_manage_leads, or manage_woocommerce. Applies to: GymCore Before you start You do not need to sign in or change a record to use this page. Know whether you are acting as an owner/admin, front desk, coach, sales, finance, member, or parent. That choice changes which menus and records you should use. Stop after opening the linked guide. Read its access, prerequisites, impact, and rollback notes before making a live change. Choose a guide Choose the role that matches the work: Owner/admin, Front desk, Coach, Sales, Finance, Member, or Parent. Expected: The role section lists common jobs instead of every GymCore feature. Select the job, not a guessed menu name. For example, choose “record attendance” before opening GymCore Students \u0026gt; Attendance. Expected: The linked task guide opens with its exact current menu path and access requirement. Read Before you start and Defaults and limits in that guide before touching the live record. Expected: You can identify the required data, safe stopping point, and member, payment, or communication impact. If your role does not match Access needed, stop and ask an administrator to verify the effective capability. Do not borrow an administrator account. Expected: The work is assigned to an authorized user or your own role is corrected before a record changes. Open the named menu and confirm its page heading matches the guide. This navigation workflow is read-only; there is no save button and no source record changes. Expected: You are on the correct page and can begin the linked task without changing data. What happens next GymCore changes only the records and behavior it owns. WordPress, WooCommerce, installed extensions, and third-party services keep control of their own data and delivery. Defaults and limits This page is a documentation router, not a product setting. Current source exposes GymCore Admin, GymCore Students, GymCore Classes, and GymCore Leads to signed-in users with read; each child screen can require another capability. Privacy and safety notes This routing page does not display customer records. Follow the access and privacy limits in the selected task guide before opening its operational screen. Troubleshooting A role link opens the wrong kind of task Return here and choose by the action you need. Orders, refunds, gateways, and recurring payments belong in WooCommerce even when the person also has a GymCore profile. The linked menu is not visible Record the guide URL, exact menu path, your WordPress role, and the page heading or permission error. An administrator should compare the screen’s effective capability with your account; Staff Access does not manage every capability used by current GymCore screens. Related guides Readme Know which system owns the change Common Checks Verify in the source systems Follow the selected guide to its named WordPress, GymCore, WooCommerce, or provider screen and use that guide’s final verification. This page only routes readers and has no commit button. Source-verified: menu labels and base read capability in src/Providers/TopLevelMenuServiceProvider.php:30-73; child screens may require additional capabilities.","headings":["Purpose","Who can use it","Before you start","Choose a guide","What happens next","Defaults and limits","Privacy and safety notes","Troubleshooting","A role link opens the wrong kind of task","The linked menu is not visible","Related guides","Verify in the source systems"],"source_sha256":"","section":"Start Here","source":"docs/user-guide/start-here/choose-your-path.md"},{"route":"/docs/faq/","slug":"faq","title":"GymCore FAQ","summary":"GymCore FAQ.","text":"Product and setup Is GymCore a hosted service? No. The audited product is a WordPress/WooCommerce plugin installed on your site. Your organization or hosting provider remains responsible for hosting, backups, updates, email delivery, security, and server access. GymCore AI is a separate companion plugin. Where do I start? Use Choose your path, then complete the launch checklist. Owners and administrators should also review the full Settings Reference. Why is a menu missing? Menus are capability-filtered and can also require a plugin/extension. Ask an administrator to compare the account with the roles and permissions matrix. Do not share an administrator login. Members, attendance, and ranks Why did a member check in twice? Confirm the class/date and Settings \u0026gt; Attendance \u0026gt; Prevent duplicate check-ins. That control blocks the same member in the same class/day, not every same-day attendance event. Correct the source attendance record and review the audit trail. Can I choose which kiosk methods appear? Gym Core 2.1.0 uses Check-in methods to show or hide name search in the current kiosk and to reject disabled REST check-in methods. It is not a replacement for kiosk authentication, device, or network security, and every installed QR/manual client still needs an end-to-end test. Do Ranks thresholds and custom Belt Systems control eligibility? Not reliably in the audited version. Eligibility reads a separate static/aggregate definition path. Use coach review and verify the effective rules before acting. See Rank systems and thresholds. Does changing the waiver version matter? Yes. Any change to Active version forces all members to re-sign. Treat it as a policy publication, not a normal text edit. Classes and locations Does Enable waitlist turn waitlists on or off? Gym Core 2.1.0 uses Enable waitlist to gate member UI, REST routes and mutations, MCP registration/execution, and auto-fill dispatch. Verify the installed full-class, cancellation, roster, and notification flow before telling members that placement or promotion is complete. Does Filter products by location prevent wrong-location purchases? The runtime consumer can filter WooCommerce product archives and product shortcodes when a visitor has an active location, but the corresponding legacy field definition is not rendered by the current Locations owner. It does not establish cart, checkout, sales-kiosk, or purchase authorization; inspect actual stored/runtime state and test every downstream path before launch. SMS and retention What must be ready before sending SMS? Provider ownership/readiness, administrator access to the Twilio credential form, sender, rate limit, member phone, consent/opt-out evidence, approved message, authorized role, and a successful supported test. Channels \u0026amp; providers provides the administrator-only credential form and Send test SMS action. See Configure SMS. Why is retention not running? Open Communications \u0026amp; Automations \u0026gt; Member Outreach and inspect launch, channel, workflow, consent, provider, and scheduler state. The retired dedicated Retention form is not rendered. Global SMS supplies the Twilio client for SMS sequences; the coach queue has separate runtime gates, and the old MailPoet path is retired. Can enabling SMS start outreach? Not by itself. Global SMS only supplies the Twilio client. External retention SMS also requires enabled Communications launch, channel, workflow, consent, rate, duplicate, and provider gates. Review migrated intent and every sequence before activation. Billing and referrals Where are payment processors configured? In WooCommerce, not GymCore Settings \u0026gt; Billing. GymCore Billing currently controls the annual membership-freeze limit. Finance Copilot and QuickBooks have separate surfaces. How are referral rewards configured? Choose one typed mode under GymCore Settings \u0026gt; Referrals: WooCommerce fixed-cart coupon, integer outbound-message credits, or a registered receipt-based custom handler. Message-credit and custom modes require external PHP registrations that current Gym Core does not provide. Readiness is checked when an enabled revision is saved, not continuously at attribution. Keep Program enabled off until the complete fictional referral and delivery path passes on a non-production site. GymCore AI Is there a public website chatbot? No current public visitor chatbot is documented or supported by the audited source. GymCore AI is a signed-in staff/admin interface. White Label does not change that boundary. Where do I configure the AI provider and model? Configure credentials in WordPress Settings \u0026gt; Connectors. Then open GymCore Admin \u0026gt; AI \u0026gt; Connections \u0026amp; Security \u0026gt; Provider and model, refresh the authoritative catalog, save an exact model draft, run readiness, and activate it. GymCore AI never reads, copies, or stores provider credentials. Why did changing Conversation retention not remove an action? That setting purges conversations/messages only. Pending actions, approvals, execution results, and Audit Log records have no configurable automatic purge in the audited source. Does an AI answer mean the data changed? No. Read the source record. Write tools queue a pending action, require review, and must reach completed. Then verify the owning GymCore/WooCommerce/provider record. Can MCP clients call GymCore tools? When WordPress Abilities API and an MCP adapter are installed and authenticated, registered abilities can be exposed. Capability checks and write approvals still apply, but the external client may retain data. See MCP abilities. Privacy, security, and support Does Erase Personal Data remove everything everywhere? No. GymCore deletes selected user meta/rank history and anonymizes attendance, but WooCommerce, CRM, AI action history, model providers, Slack, SMS, backups, and integrations need separate review. What should I send support? Exact menu/URL, timestamp and timezone, affected record IDs, expected result, actual result, error text, plugin versions, and safe diagnostics. Remove member data, credentials, webhook URLs, secrets, payment data, and full phone/email values. Related guides Troubleshooting Glossary Role and task index Settings Reference","headings":["Product and setup","Is GymCore a hosted service?","Where do I start?","Why is a menu missing?","Members, attendance, and ranks","Why did a member check in twice?","Can I choose which kiosk methods appear?","Do Ranks thresholds and custom Belt Systems control eligibility?","Does changing the waiver version matter?","Classes and locations","Does Enable waitlist turn waitlists on or off?","Does Filter products by location prevent wrong-location purchases?","SMS and retention","What must be ready before sending SMS?","Why is retention not running?","Can enabling SMS start outreach?","Billing and referrals","Where are payment processors configured?","How are referral rewards configured?","GymCore AI","Is there a public website chatbot?","Where do I configure the AI provider and model?","Why did changing Conversation retention not remove an action?","Does an AI answer mean the data changed?","Can MCP clients call GymCore tools?","Privacy, security, and support","Does Erase Personal Data remove everything everywhere?","What should I send support?","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/faq.md"},{"route":"/docs/troubleshooting-billing-renewals/","slug":"troubleshooting-billing-renewals","title":"Resolve billing and renewal problems","summary":"Resolve billing and renewal problems.","text":"Start with the WooCommerce order or subscription and the payment provider transaction. GymCore Admin \u0026gt; GymCore Settings \u0026gt; Billing controls the annual membership-pause limit; it does not configure gateways, taxes, renewals, refunds, or dunning. A charge or refund may be duplicated Stop retrying. Record the order ID, subscription ID, amount, currency, gateway, exact time, and staff account. Open the WooCommerce order and read its status, order notes, and refund rows. Open the payment-provider transaction separately and match its provider ID and settled/refunded amount. Expected: One provider transaction accounts for the money movement. A GymCore or AI Completed status is not proof that the gateway settled or refunded it. If WooCommerce and the provider disagree, preserve both IDs and timestamps. Do not create a manual correction until the payment owner chooses the source-of-truth reconciliation. A renewal did not run Open the WooCommerce subscription and confirm its status, payment method, next payment date, related orders, and notes. Check WooCommerce \u0026gt; Status \u0026gt; Scheduled Actions for the subscription’s renewal/dunning hook and its last error. Confirm WooCommerce Subscriptions and the configured gateway are active and that WordPress cron is running. Expected: The subscription, scheduled action, renewal order, and provider log describe the same state. Do not change the GymCore annual pause limit to repair a failed renewal. A failed-payment reminder or dunning step is missing Confirm the failed order exists, the subscription extension owns the retry schedule, the recipient is eligible, and the communication provider has no suppression or rejection. If GymCore AI drafted a dunning message, verify whether it is only a draft, a Pending proposal, or a completed send. Expected: The owning system shows either the scheduled retry/message or a specific blocking reason. Draft text and pending approval do not send anything. QuickBooks does not match WooCommerce Open GymCore Admin \u0026gt; Integrations \u0026gt; QuickBooks, check connection health, and compare the sync record with the WooCommerce order and provider transaction. QuickBooks is a downstream accounting copy; do not edit the payment source merely to make the accounting view match. Expected: The WooCommerce order and gateway transaction reconcile first, then the QuickBooks sync reflects the corrected source. Verify the recovery Reopen the WooCommerce order/subscription, provider transaction, scheduled action, and any downstream accounting record. Expected: Status, amount, currency, transaction ID, and next renewal date agree, and no duplicate action exists. Escalate with billing evidence Provide sanitized order/subscription IDs, gateway transaction ID, timestamps with timezone, amounts/currency, order-note text, scheduled-action status/error, and relevant plugin versions. Never include card data, gateway secrets, customer names, or full billing addresses. Related guides Find the owning system before retrying Collect diagnostics and contact support Review AI action history GymCore settings reference","headings":["A charge or refund may be duplicated","A renewal did not run","A failed-payment reminder or dunning step is missing","QuickBooks does not match WooCommerce","Verify the recovery","Escalate with billing evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/billing-renewals.md"},{"route":"/docs/troubleshooting-classes-attendance-kiosk/","slug":"troubleshooting-classes-attendance-kiosk","title":"Resolve class, attendance, and kiosk problems","summary":"Resolve class, attendance, and kiosk problems.","text":"Use the class occurrence and attendance row as the source records. Before retrying, record the class ID, date/timezone, location, program, instructor, member ID, and current check-in rows. A member cannot check in Confirm the exact class occurrence is published for the current date, time, location, and program. Confirm the member belongs to the intended location/program and has the required access state. Check for an existing attendance row for the same member, class, and day before another attempt. Expected: Either the existing row explains the duplicate prevention or one new attendance row is created. Do not repeatedly submit while the first request may still be processing. The kiosk is blank or buttons do nothing Secure the device so member rosters and admin sessions are not exposed. Reload once and inspect the browser console/network for the failing request, HTTP status, and visible error. Confirm GymCore is active, the kiosk asset loaded, the user/session is authenticated as intended, and the REST request has current authentication. Check rewrite rules only when the route returns 404; re-save permalinks on staging before production. Expected: The kiosk loads the intended occurrence and a fictional check-in creates one source row. Gym Core 2.1.0 rejects methods disabled by Check-in methods and uses the setting for the current kiosk’s name-search visibility; verify the installed client rather than inferring success from a saved option. A full class does not show or move a waitlist Confirm the class capacity and current roster, then test full-class behavior with fictional accounts on staging. Gym Core 2.1.0 uses Enable waitlist to gate member UI, routes, data mutations, MCP exposure, and auto-fill dispatch. Expected: Record what the installed version actually does. Source review does not prove that cancellation produces a roster enrollment or delivered message; do not edit live capacity to conceal a failed end-to-end result. Attendance is duplicated or wrong Open the source attendance history before deleting or adding anything. Correct the smallest wrong row through the owning workflow, then inspect reports, streaks, milestones, promotion eligibility, and retention signals that consume attendance. Expected: Exactly one intended attendance row remains, and downstream summaries recalculate to the same class/member/date. The timeout behaves differently from documentation The audited kiosk timeout option is measured in seconds and is consumed by the sales kiosk, not the attendance/check-in kiosk. Do not tune that option to repair an attendance kiosk session. Verify the recovery Reopen the class occurrence, roster, member attendance history, and affected downstream report. Expected: IDs, date/timezone, location, and check-in count agree across the source records; no duplicate retry is present. Escalate with attendance evidence Provide the class occurrence ID, sanitized member ID, location/program, timestamp and timezone, existing attendance row IDs, route/status, console error, and GymCore version. Remove names, roster screenshots, health data, and session/nonces. Related guides Find the owning system before retrying Collect diagnostics and contact support Troubleshoot installation and setup GymCore settings reference","headings":["A member cannot check in","The kiosk is blank or buttons do nothing","A full class does not show or move a waitlist","Attendance is duplicated or wrong","The timeout behaves differently from documentation","Verify the recovery","Escalate with attendance evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/classes-attendance-kiosk.md"},{"route":"/docs/troubleshooting-email-sms/","slug":"troubleshooting-email-sms","title":"Resolve email and SMS delivery problems","summary":"Resolve email and SMS delivery problems.","text":"Start with one intended recipient, one message/event, and the sending provider. A local “sent” response does not prove delivery to a mailbox or phone. An SMS test cannot be sent Open GymCore Admin \u0026gt; Communications \u0026amp; Automations \u0026gt; Channels \u0026amp; providers. Sign in as a site administrator to review the Twilio credential form, provider status, and Send test SMS control. Other communications managers see status only. Save the required Twilio settings first. Do not edit options directly or manipulate the old Settings URL. Confirm the current administrator profile has a staff-owned billing phone, then use Send test SMS once and accept the confirmation. Expected: the page reports readiness and the test result. Confirm the matching Twilio message SID and final provider status before treating the test as delivered. SMS is accepted locally but not delivered Open the Twilio message and read its status/error. Confirm the destination is valid E.164, the account/sender can reach that country, the recipient has consented and not opted out, and the GymCore per-contact rate limit did not block the send. Expected: Twilio shows delivered or a specific rejection/undelivered reason. The carrier/provider status is the delivery source of truth. An expected email is missing Identify the exact WordPress/WooCommerce event and recipient. Confirm the email/template is enabled and the source order, subscription, member, or retention event reached the required status. Check the sending provider log, domain authentication, bounce/suppression, spam/quarantine, and recipient address. Expected: The provider shows the message as delivered, bounced, suppressed, or rejected with a provider ID. A generated template or queued event is not delivery. A legacy retention email or list action is expected Current GymCore source has no MailPoet bridge or active 30-day retention-email consumer. The old option IDs are compatibility history, not a supported workflow. Use the installed email extension’s own workflow and delivery log if the owner intentionally configured one there. Expected: Record the legacy expectation as retired. Do not enable SMS or invent a MailPoet connection to force an unsupported path. An AI approval alert is missing Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General and check Notify on pending action, Slack URL, and SMS admin numbers (one per line). AI SMS alerts are queued through Action Scheduler/cron and limited to one per recipient per minute; Slack is limited to 10 posts per five minutes. Expected: The local action remains Pending whether or not the alert arrives. Verify the action in AI \u0026gt; Audit Log before generating another proposal. Verify the recovery Send one approved fictional/staff test, then compare the local log/action with the provider record and destination. Expected: One message has matching recipient, timestamp, provider ID, and final provider status. No duplicate send exists. Escalate with delivery evidence Provide the sanitized recipient suffix, event/action ID, timestamp/timezone, template or action type, provider message ID, provider status/error, scheduled-action status, and relevant versions. Never include Twilio tokens, Slack URLs, message bodies with member data, or full recipient lists. Related guides Configure approval notifications Manage credentials and webhooks Find the owning system before retrying Collect diagnostics and contact support","headings":["An SMS test cannot be sent","SMS is accepted locally but not delivered","An expected email is missing","A legacy retention email or list action is expected","An AI approval alert is missing","Verify the recovery","Escalate with delivery evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/email-sms.md"},{"route":"/docs/troubleshooting-gymcore-ai/","slug":"troubleshooting-gymcore-ai","title":"Resolve GymCore AI problems","summary":"Resolve GymCore AI problems.","text":"Use this plain-language order first: confirm the AI screens are available, try one harmless read, decide whether the result is a read, draft, or proposed change, then verify the owning source record. Do not start by changing webhook security or retrying a write. Staff Dashboard says AI Chat is not available Confirm Gym Core and Gym Core AI are active under Plugins \u0026gt; Installed Plugins. Open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General and read System Status. Record the installed versions and the exact dashboard notice. Expected: GymCore is active and WordPress AI Client reports at least one configured provider. The dashboard recognizes the current Gym Core AI plugin; do not add compatibility constants or restore retired credentials. The AI hub or a tab is missing The overview uses gym_view_ai_hub; legacy manage_woocommerce remains a compatibility source. Approvals \u0026amp; Audit, Connections \u0026amp; Security, and Brand use their own administrative policies with the administrator fallback; Brand is also license-gated. The current hub does not register a Chat tab—chat is intended for GymCore Admin \u0026gt; Staff Dashboard. Expected: The user sees only tabs allowed by both capability and installed module/license. Correct the role rather than sharing an administrator account. A harmless read fails or looks wrong Open GymCore Admin \u0026gt; AI \u0026gt; Connections \u0026amp; Security \u0026gt; Provider and model and confirm an exact provider/model tuple is active after a passing readiness probe. Select an authorized persona and ask for one fictional record or narrow date range. Inspect the tool detail for ok or error, then open the GymCore/WooCommerce source record. Expected: A read-only answer matches the source and has no commit button. A green System Status row proves dependency detection, not response accuracy or tool readiness. A proposed change did not happen Open Pending Actions when the chat panel is available and GymCore Admin \u0026gt; AI \u0026gt; Audit Log: Pending: awaiting review; the source must be unchanged. Approved: immediate execution may have failed; check execution_error and the source before retrying. Approved with Changes: instructions are stored; a separate revision/completion handler is required. Completed: the tool returned successfully; verify the source and provider. Rejected: not executed through the approval path. Expected: The action ID has one status and the owning source record confirms the final state exactly once. Conversation retention does not purge these action/audit rows. A notification is missing Check AI \u0026gt; Settings \u0026gt; General, the pending action ID, Slack/Twilio provider logs, rate limits, and Action Scheduler/cron. Alert delivery does not affect whether the action remains pending. Expected: The Audit Log remains the local action record; the provider is the delivery source of truth. White Label saves but no interface changes Reopen AI \u0026gt; White Label and confirm White label settings saved. and the Live Preview. Current source has no verified consumer of those values outside settings/config and the preview. Expected: Persistence and preview can be verified; a runtime brand change cannot be claimed until a real consumer is identified and tested. A webhook returns 401 or 403 Only after the owner flow above points to the inbound webhook, hand this technical check to the integration operator: Confirm the X-HMA-Signature timestamp is within five minutes and the signature was calculated over the exact raw body. Confirm the sender uses the current secret (or previous secret during the five-minute rotation overlap). Confirm the server-observed source address is in IP Allowlist and the reverse proxy sets REMOTE_ADDR correctly. Keep Enforce IP allowlist on; on + empty list denies all, while off + empty list accepts any signature-valid source address. Expected: One staging request from the allowed sender authenticates and creates the expected local status/record; altered, stale, or disallowed requests fail. Do not report this result unless it was actually run. Escalate with AI evidence Provide installed versions, visible path/tab, persona, sanitized conversation/action ID, action status/detail, source record ID, provider request ID, timestamp/timezone, and exact error. Remove prompts containing personal data, action JSON, API keys, webhook secrets/signatures, Slack URLs, cookies, and nonces. Related guides Configure GymCore AI Chat safely with GymCore AI Review and decide an AI-proposed action Collect diagnostics and contact support","headings":["Staff Dashboard says AI Chat is not available","The AI hub or a tab is missing","A harmless read fails or looks wrong","A proposed change did not happen","A notification is missing","White Label saves but no interface changes","A webhook returns 401 or 403","Escalate with AI evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/gymcore-ai.md"},{"route":"/docs/troubleshooting-installation-setup/","slug":"troubleshooting-installation-setup","title":"Troubleshoot installation and setup","summary":"Troubleshoot installation and setup.","text":"GymCore will not activate Confirm the installed site runs PHP 8.0 or later and the current supported WordPress/WooCommerce combination. Confirm WooCommerce is active; the Gym Core plugin header declares it as required. Capture the exact activation notice or PHP fatal and the installed plugin path/version. Expected: One Gym Core copy is active and no requirement/fatal notice appears. Do not reinstall over production or deactivate WooCommerce as a first diagnostic step. GymCore AI will not initialize Confirm WordPress 7.0+, PHP 8.0+, and GymCore active. Then open GymCore Admin \u0026gt; AI \u0026gt; Settings \u0026gt; General and inspect System Status for GymCore and an available AI path. Expected: GymCore is detected and WordPress AI Client reports a configured provider. This does not prove chat works; validate the Staff Dashboard and exact activated provider/model separately. Sign-in or assets broke after onboarding Treat any onboarding-time change to WordPress siteurl or home as a regression. Gym Core 2.1.0 source keeps Website in wizard state and does not write either installation URL. Stop submitting the form, preserve the installed version and exact step, and ask the host/server owner to restore the approved values through a supported recovery method. Expected: WordPress admin, sign-in, and assets load from the approved site URL. Preserve the prior/current values and recovery timestamp, and rerun RV-01 only after the deployed current head is identified. A setup link opens the wrong page Navigate through current menus instead of repeating the shortcut: use GymCore Admin \u0026gt; GymCore Settings and its visible sections. For AI configuration use GymCore Admin \u0026gt; AI \u0026gt; Settings; chat is intended for GymCore Admin \u0026gt; Staff Dashboard, not an AI \u0026gt; Chat tab. Expected: The current menu opens the source-registered page. Record the broken shortcut separately; do not change capabilities or page slugs to make it work. A front-end route returns 404 Confirm the required plugin/module is active and the expected page/endpoint belongs to the installed version. On staging after a backup, open Settings \u0026gt; Permalinks and save once to refresh rewrite rules. Expected: WordPress reports the permalink structure saved. This refreshes rewrite rules; it does not prove that an unregistered route exists. Test /check-in/, /sales/, member/parent portal endpoints, and calendar feeds individually rather than assuming one result applies to all. Expected: Only routes registered by the installed modules return their intended page. If one still fails, capture that exact path and server rewrite result. Deactivation or deletion changed more than expected Deactivation removes GymCore custom roles and named scheduled events while preserving data. WordPress deletion runs the uninstall handler and drops GymCore custom tables. It is not a complete cleanup of every option, user-meta value, WooCommerce record, upload, backup, or provider copy. Expected: Compare the observed effect with Back up, deactivate, or remove GymCore and restore on staging before any production repair. Verify the recovery Reopen WordPress admin, Plugins \u0026gt; Installed Plugins, GymCore Admin \u0026gt; GymCore Settings, one member/order source record, scheduled actions, and every affected front-end route. Expected: Requirements, menus, source data, jobs, and routes match the approved configuration, with no duplicate plugin copy or undocumented option/table edit. Escalate with setup evidence Provide installed WordPress/PHP/WooCommerce/GymCore versions, plugin path, exact activation or fatal text, affected URL, HTTP status, rewrite/server result, and the most recent approved configuration change. Remove database credentials, admin reset links, cookies, and member data. Related guides Back up, deactivate, or remove GymCore Configure GymCore AI Find the owning system before retrying Collect diagnostics and contact support","headings":["GymCore will not activate","GymCore AI will not initialize","Sign-in or assets broke after onboarding","A setup link opens the wrong page","A front-end route returns 404","Deactivation or deletion changed more than expected","Verify the recovery","Escalate with setup evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/installation-setup.md"},{"route":"/docs/troubleshooting-integrations-api/","slug":"troubleshooting-integrations-api","title":"Resolve integration and API problems","summary":"Resolve integration and API problems.","text":"Owner flow Name the service and the single missing or incorrect result. Open the GymCore source record and the matching provider or client record. Record their IDs, statuses, and timestamps before retrying anything. Run one harmless connection or read check on staging. Expected: The check returns a specific local and, when applicable, provider status without changing a customer record. Compare both sides again; do not replay a message, order, refund, or member change until duplicates are excluded. Expected: The records either agree exactly once or identify the side that rejected, delayed, or lost the request. A connection label alone is not proof of sync, delivery, or settlement. Only after this owner check should a technical operator inspect the route, signature, REST nonce, WordPress capability, or MCP connection described below. An integration card is missing Open GymCore Admin \u0026gt; Integrations with an administrator account. The page shows only providers registered in the current runtime; if it reports No integrations are registered, there is no customer configuration form to recover. Expected: The intended provider has a labelled card, or the absence is recorded as a module/registration issue. Do not write credentials directly into options. A provider is Connected but not working Select Test Connection on the provider card. Expected: The card reports Healthy or Unhealthy. This checks the registered provider connection only; it does not create a customer record or prove a later sync. Compare Healthy or Unhealthy with the provider status/dashboard and the most recent request ID. Confirm the saved account, scopes, endpoint/environment, and credential have not been revoked. Expected: The GymCore health response and provider account agree. Connected means configuration is stored; it does not prove sync, delivery, or settlement. A sync or webhook result is missing Identify one source record and one provider record. Compare timestamps/timezones, IDs, event type, retries, and provider response before replaying. For inbound AI webhooks, keep IP enforcement on while checking the exact signed request on staging. Expected: One request maps to one source/provider result or a specific rejection. Do not replay an order, refund, message, or member mutation until duplicates are excluded. A REST request fails Hand these checks to the technical operator after the owner flow identifies the exact route: Result Check first 401 Authentication or expired/missing signed-in credential 403 WordPress capability, REST nonce, webhook signature, or IP allowlist 404 Route namespace/version, plugin/module registration, or rewrite handling 400/422 Required input names, types, and validation 409 Current record/action state or duplicate/conflict protection 5xx PHP log, dependency, database, or downstream provider failure The visible REST API checkbox under GymCore General settings is not consumed as a runtime kill switch by the registered routes. Do not toggle it as a security fix. Expected: One least-privilege staging request with fictional data returns the documented status and result. For a read-only route, no commit button or approval exists; for a write, inspect pending approval and the source record. An MCP client cannot see or call an ability In plain language, MCP is an external client connection that can advertise selected GymCore AI functions. It does not create anonymous access. Confirm the WordPress Abilities API and MCP adapter required by the installed version are active. Confirm the dedicated service account is authenticated and has the ability’s required WordPress capability. Confirm the ability is registered and not suppressed by gym_core_ai_mcp_public_ability. Compare the advertised input schema with the request and check the pending-action flow for writes. Expected: The client advertises only approved abilities. Reads return only permitted data; writes become pending and do not change the source before review. Verify the recovery Repeat one harmless connection/read on staging, then reopen the GymCore source record and provider/client record. Expected: IDs, timestamp, status, and result agree exactly once. For writes, approval status, completion, and final source-record verification remain separate checks. Escalate with integration evidence Provide the provider/integration label, route or ability name, method, namespace, installed versions, sanitized request/action/source IDs, timestamp/timezone, HTTP/provider status, and exact error. Remove request bodies with personal data, credentials, auth headers, cookies, REST nonces, webhook URLs/secrets/signatures, and database details. Related guides Manage credentials and webhooks Protect AI data and connections AI tools and abilities reference Collect diagnostics and contact support","headings":["Owner flow","An integration card is missing","A provider is Connected but not working","A sync or webhook result is missing","A REST request fails","An MCP client cannot see or call an ability","Verify the recovery","Escalate with integration evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/integrations-api.md"},{"route":"/docs/troubleshooting-members-portals/","slug":"troubleshooting-members-portals","title":"Resolve member, family, and portal problems","summary":"Resolve member, family, and portal problems.","text":"Start by matching identity records. Record the WordPress user ID, billing email, GymCore member ID, guardian/child relationship, membership or subscription ID, location, and program before creating or editing anything. A member cannot open the portal Confirm the person is signing in to the intended WordPress account and site. Match the WordPress user with the GymCore member/customer and the active membership/subscription record. Test with the member’s own least-privilege account; an administrator can hide access defects. Expected: One WordPress account maps to the intended member and active access source. Do not create a duplicate user to bypass a mismatched email or ID. A parent cannot see a child Open the source family/member relationship and verify the saved parent and child user IDs in both directions where the product expects them. Confirm both accounts belong to the correct site and location. Expected: The existing child appears for the authorized guardian. If the relation is wrong, correct that source relationship rather than creating another child account. Rank or attendance looks stale Open the member’s source rank history and attendance records, confirm date/timezone and program/location, and compare them with the portal view. Correct the source row through its owning workflow before clearing caches. Expected: The portal reflects the verified source history. A cache refresh must not create a new rank or attendance row. A waiver blocks access or asks for another signature Compare the signature’s publication/version evidence with GymCore Students \u0026gt; Waiver Versions and its active publication ID. Do not edit guarded legacy waiver options or publish another version to repair one member; publication can require re-signature for the affected cohort. Expected: The member is either covered by the current version or receives the intended re-sign flow. Preserve the signature record and version evidence. A billing state and portal access disagree Compare the WooCommerce order/subscription status and next renewal with the portal’s membership source. Use WooCommerce and the payment provider as the financial source of truth. Expected: Access follows the intended current membership/subscription state without changing a payment record solely to make the portal look correct. A privacy request affects a member or family Use Tools \u0026gt; Export Personal Data or Tools \u0026gt; Erase Personal Data with the verified email, then separately review related family accounts, WooCommerce, CRM, GymCore AI, providers, and backups. GymCore erasure anonymizes attendance and deletes rank/profile data it handles; it does not erase every related system. Expected: Each identity and related account has an explicit export, erasure/anonymization, retention, or follow-up disposition. Verify the recovery Sign in with the affected least-privilege account and reopen the member profile, family relationship, rank/attendance history, waiver, and subscription source relevant to the symptom. Expected: The portal shows the intended person and records, forbidden family/member data remains inaccessible, and no duplicate user or relationship exists. Escalate with member evidence Provide sanitized WordPress/member/guardian/child/order/subscription IDs, role, location/program, affected portal path, timestamp/timezone, source status/version, and exact error. Remove names, emails, phone numbers, waiver content/signatures, medical/coach notes, payment data, cookies, and screenshots of other family members. Related guides Process a privacy request Review roles and permissions Resolve billing and renewal problems Collect diagnostics and contact support","headings":["A member cannot open the portal","A parent cannot see a child","Rank or attendance looks stale","A waiver blocks access or asks for another signature","A billing state and portal access disagree","A privacy request affects a member or family","Verify the recovery","Escalate with member evidence","Related guides"],"source_sha256":"","section":"Troubleshooting","source":"docs/user-guide/troubleshooting/members-portals.md"},{"route":"/docs/website-content-blocks-shortcodes/","slug":"website-content-blocks-shortcodes","title":"Add targeted content to a page","summary":"Add targeted content to a page.","text":"Use the Targeted Content block when editors need visible controls. Use a Shortcode block for GymCore’s other member widgets. Both depend on the current visitor’s source records; they are not a substitute for WordPress access control. Exact steps Safe stop: Use WordPress Preview and test every audience branch before Update or Publish; publication can expose protected or fallback content immediately. Open Pages, select the page, and choose Edit. Select Add block (+), search for Targeted Content, and insert it. Expected: The editor adds a GymCore Targeted Content block with controls for program, belt, location, member/login state, minimum classes, minimum streak, and fallback content. Add the protected message, set only the rules needed for this audience, and enter fallback content for visitors who do not match. Expected: Both the matching and fallback branches remain visible in the editor. Select Update or Publish. Expected: WordPress confirms the page was updated or published. Open the page signed out and with test members representing every intended program, belt, location, attendance, and membership state. Expected: Each visitor sees the correct branch. Confirm unexpected results against that test member’s GymCore profile rather than the administrator preview. Add a shortcode In the page editor, select Add block (+) and insert a Shortcode block. Enter the exact shortcode, such as `[gym_member_greeting]`, `[gym_progress_card]`, `[gym_referral_code]`, or `[gym_technique_videos]`. Expected: The editor displays the literal shortcode inside its Shortcode block; the rendered page replaces it with GymCore output. Select Update or Publish, then test the page with the intended visitor state. Expected: The widget renders from the current member, referral, badge, or video source records. Literal shortcode text on the live page means the registering module did not load or that page area does not process shortcodes. See the complete block and shortcode catalogue for every registered shortcode, attribute, default, and privacy note. Privacy and caching Do not set `user_id` on `[gym_member_badges]` to another real member on a public page. The referral leaderboard exposes display names and referral counts; obtain approval before presenting members publicly. Exclude personalized pages from shared full-page caching. A cached member branch can be shown to the wrong visitor. Video and membership results depend on the installed runtime and current source records; a successful page update does not prove the member can view the content. Final source verification Reopen the page in WordPress and confirm its saved block or shortcode, then compare each rendered member value with the corresponding GymCore user, membership, attendance, referral, badge, or video record. Verified against: current GymCore block and shortcode registrations and render callbacks.","headings":["Exact steps","Add a shortcode","Privacy and caching","Final source verification"],"source_sha256":"","section":"Website \u0026 Content","source":"docs/user-guide/website-content/blocks-shortcodes.md"},{"route":"/docs/website-content-member-web-app/","slug":"website-content-member-web-app","title":"Install the member web app","summary":"Install the member web app.","text":"GymCore provides browser metadata and a service worker so supported devices can install the member area like an app. There is no App Store download and no GymCore setting that guarantees an install prompt; the browser, device, HTTPS state, theme assets, and member-area availability decide whether installation is offered. What the site publishes Resource Current source-backed behavior `/manifest.json` Publishes the organization name, short name, theme/background colors, icons, and app launch settings Start URL `/my-account/gym-dashboard/` Scope Site root, `/` Display/orientation Standalone, portrait `/sw.js` Service-worker response registered by GymCore `/offline` Offline fallback route Install helper Loaded on WooCommerce My account pages only; the browser may still suppress its prompt The app name comes from GymCore Admin \u0026gt; GymCore Settings \u0026gt; General. Icon URLs point to packaged theme assets in the audited source; this screen does not expose an icon picker or start-page setting. Exact steps Safe stop: Test installation with a fictional member on a non-production device; stop before distributing install instructions until sign-in, launch URL, member data, and uninstall behavior are verified. Confirm the site uses HTTPS and sign in as a non-production member. Expected: The member can open My account and `/my-account/gym-dashboard/` without an access or redirect error. Open a My account page in a supported browser. Use the browser’s visible Install app action or its share/menu action named Add to Home Screen. Expected: The browser shows an install confirmation when its own installability rules are met. Button wording and placement vary by browser and device; GymCore cannot force it to appear. Confirm the install. Expected: An icon appears on the device and launches a standalone window whose first URL is `/my-account/gym-dashboard/`. Open the installed app while signed in, then test one member workflow. Expected: The workflow reads the same member source record as the normal website. Offline support is a fallback, not a promise that every account action works without a connection. Diagnose a missing prompt or wrong launch Open `/manifest.json` in the same environment. Expected: The response contains the intended name, short name, start URL, scope, and 192/512 icon entries. Open `/sw.js` and `/offline`. Expected: Both return site responses rather than a 404 or security error. Compare the manifest’s name with GymCore Settings \u0026gt; General and verify the packaged icon URLs load. Expected: Source settings and published metadata agree. Restore the prior General value if a branding edit is wrong; an already installed icon/name may remain cached until the browser refreshes or reinstalls the app. If all resources are correct but no install action appears, use that browser’s installability diagnostics or test a supported browser/device. Expected: The browser reports the unmet condition. Do not document a GymCore failure solely because one browser suppresses its prompt. Verified against: current PWA controller routes, manifest values, service-worker registration, and My Account install helper.","headings":["What the site publishes","Exact steps","Diagnose a missing prompt or wrong launch"],"source_sha256":"","section":"Website \u0026 Content","source":"docs/user-guide/website-content/member-web-app.md"},{"route":"/docs/website-content-testimonials-content/","slug":"website-content-testimonials-content","title":"Publish a testimonial","summary":"Publish a testimonial.","text":"Testimonials are private WordPress admin records that an installed website block can render publicly. The current post type has an editor but no registered admin-menu entry, so open its direct WordPress URL: `/wp-admin/edit.php?post_type=hp_testimonial` An account must have the normal WordPress permission to edit posts. Fields that the current editor saves Visible editor field Use Title Customer name or approved attribution; the website renderer can fall back to this Content Approved testimonial text Featured image Approved customer image Publish status Only published testimonials are selected by the audited renderer The post type registers `hp_who`, `hp_context`, and `hp_rating` metadata, but the audited source does not add visible controls for them. The separate GymCore Blocks renderer reads different author/rating keys. Do not promise that “who,” context, or rating values entered by another tool will appear without verifying the installed renderer. Exact steps Safe stop: Save the testimonial as a draft and use Preview first; stop before Publish until the quote, attribution, image rights, and consent are approved. Open the direct URL above and select Add New Testimonial. Expected: WordPress opens the testimonial editor with title, content, featured image, and publication controls. Enter the approved attribution in Title, the exact approved quotation in the content editor, and an approved Featured image if needed. Expected: The editor contains only content the customer authorized for publication; do not add health, billing, or membership details that were not approved. Select Publish. For an existing record, select Update. Expected: WordPress confirms the testimonial was published or updated. Open the website page that contains the installed testimonial renderer. Expected: A published testimonial can be selected by that renderer. Order may be random and the default maximum can be six, so one refresh is not proof that a missing item is unpublished. Reopen the testimonial record and compare its title, content, featured image, and status with the rendered result. Expected: WordPress is the source for the testimonial record. If author/rating output differs, inspect the installed block’s metadata mapping rather than repeatedly editing unexposed fields. Remove or correct content Use Draft or Move to Trash in WordPress to stop a record from being selected; cached pages may need their normal cache purge. Correct the source testimonial and select Update. Editing a page snapshot does not correct the record. Deletion can remove an auditable consent record; retain publication approval according to your privacy policy. Verified against: current `hp_testimonial` post-type registration and the checked-out GymCore Blocks testimonial renderer.","headings":["Fields that the current editor saves","Exact steps","Remove or correct content"],"source_sha256":"","section":"Website \u0026 Content","source":"docs/user-guide/website-content/testimonials-content.md"},{"route":"/docs/website-content-tournaments/","slug":"website-content-tournaments","title":"Publish a tournament","summary":"Publish a tournament.","text":"Use GymCore Classes \u0026gt; Tournaments. Creating or editing tournaments requires `manage_woocommerce`, normally available to administrators and WooCommerce Shop Managers. Tournament fields Field Default/allowed value Effect Title Blank text Public tournament name Content Blank Public description Featured image None Public tournament image Tournament Date Blank date Event date Location Blank text Displayed event location SmoothComp URL Blank valid URL Stores the third-party event URL Status Blank; Upcoming, Open, Closed, Completed Customer-facing lifecycle value; GymCore does not choose one by default Registration Deadline Blank date Displayed/used registration cutoff The tournament post type is public and has a `/tournaments` archive. A stored SmoothComp URL does not prove results were imported. The audited importer fetches third-party page data and directs staff to review and enter results manually; third-party availability and markup remain outside GymCore’s control. Exact steps Safe stop: Save a draft and preview the event first; stop before Publish until dates, location, registration deadline, status, image, and external URL are approved. Open GymCore Classes \u0026gt; Tournaments and select Add New. Expected: WordPress opens Add New Tournament with the standard content editor and Tournament Details. Enter the title, description, date, location, registration deadline, and an explicit Status. Add a featured image and SmoothComp URL only when approved. Expected: Required event facts are present and Status is not left at — Select —. Select Publish. For an existing tournament, select Update. Expected: WordPress confirms the tournament was published or updated. Select View Tournament and open the tournament archive. Expected: The public title, content, image, and saved details match the WordPress record. Theme/runtime templates determine the final layout. If using SmoothComp, open the stored URL and follow the visible importer/review workflow without assuming automatic parsing. Expected: The external event is reachable and any result entered in GymCore is checked against the source event. A fetch message is not proof that registrations or results were written. Correct or withdraw a tournament Change the source post to Draft or Trash to remove publication; changing Status alone does not change WordPress publication. Correct dates, location, or status in the tournament record and select Update. If SmoothComp and GymCore disagree, keep the external event as the result source and document the manual correction. Reverting a WordPress edit does not change third-party data. Verified against: current tournament post-type registration, details meta box, save handler, archive settings, and SmoothComp importer behavior.","headings":["Tournament fields","Exact steps","Correct or withdraw a tournament"],"source_sha256":"","section":"Website \u0026 Content","source":"docs/user-guide/website-content/tournaments.md"},{"route":"/docs/website-content-video-library/","slug":"website-content-video-library","title":"Publish a technique video","summary":"Publish a technique video.","text":"Use GymCore Classes \u0026gt; Technique Videos. The screen uses WordPress post-edit permissions. Technique Video records are not public URLs; eligible members see published records through GymCore’s video shortcode/runtime. Video fields Field Default/allowed value Effect Title Blank Member-facing video title Excerpt Blank Member-facing summary where the renderer uses it Featured image None Thumbnail VideoPress GUID Blank text; source describes the 8-character VideoPress identifier Identifies a Jetpack VideoPress video; may be blank when an attachment embed is used by the installed runtime Duration (seconds) 0; integer 0 or greater Display duration metadata Technique Tags Blank comma-separated text Search/filter keywords Program Site taxonomy terms Limits matching by program Belt Site taxonomy terms Limits matching by belt Publish status Draft until published Only published records are returned by the member shortcode The source seeds common program and belt terms, but site administrators can change taxonomy terms. Video playback depends on Jetpack VideoPress or the installed attachment/runtime path; saving a GUID does not prove playback. Exact steps Safe stop: Save a draft and test the VideoPress asset with fictional member access before Publish; publication can expose the catalogue entry to matching members. Open GymCore Classes \u0026gt; Technique Videos and select Add New Video. Expected: WordPress opens Add New Technique Video with title, excerpt, featured image, Program, Belt, and Video Details controls. Enter the title and summary, select the intended Program and Belt terms, and add the approved thumbnail. Expected: The saved audience labels match the members who should find the video. Enter the VideoPress GUID, Duration (seconds), and comma-separated Technique Tags that match the source video. Expected: Duration is zero or greater and the GUID identifies the intended VideoPress asset. Do not use a private test member’s data in tags or titles. Select Publish. For an existing record, select Update. Expected: WordPress confirms the record is published or updated. Open a page containing `[gym_technique_videos]` as a non-production member with an active membership and matching Program/Belt. Expected: The video appears and playback reaches the intended asset. Signed-out, inactive, or non-matching members should not receive the same result. Reopen the Technique Video and compare its status, terms, GUID, duration, and tags with the member output and the VideoPress asset. Expected: WordPress owns the catalogue record and VideoPress owns playback. Diagnose the side that disagrees instead of replacing a GUID repeatedly. Correct or withdraw a video Set the WordPress record to Draft or Trash to remove it from published shortcode results; allow for normal cache expiry. Restore the prior GUID or taxonomy terms and select Update when a reversible metadata edit is wrong. Removing the WordPress record does not delete the third-party VideoPress asset. Delete external media only under the approved media-retention process. Verified against: current Technique Video post type, taxonomies, metadata defaults/save handler, and member video shortcode.","headings":["Video fields","Exact steps","Correct or withdraw a video"],"source_sha256":"","section":"Website \u0026 Content","source":"docs/user-guide/website-content/video-library.md"},{"route":"/docs/spark-to-gymcore-migration-handoff/","slug":"spark-to-gymcore-migration-handoff","title":"Prepare a Spark data handoff for a GymCore migration","summary":"Prepare a secure, assisted handoff of Spark records for an approved GymCore migration.","text":"This guide is only for an approved, assisted GymCore migration that your migration contact has arranged with you. It is not a self-service feature and does not authorize an export, import, deployment, or production change. Before you begin Confirm with your migration contact that the handoff is expected and that you are authorized to complete it. Get the one-time secure handoff instructions before gathering any records. Use only those instructions to send files. Do not send files through email, chat, text message, support tickets, shared drives, or screenshots. Keep original files unchanged. Do not open, edit, rebuild, or replace them. Keep your original files according to the approved retention policy and the handoff instructions. Gather the requested records Safe stop: Gathering or downloading a record does not change Spark and does not begin an import. You can stop before handing anything off. Use the current Spark account tools to gather the records your migration contact requested. For each file, record the report name, any filters or date range, and the account or location it covers. Include former or inactive records whenever the available export allows it. If coverage is unclear or a requested record is unavailable, pause and ask your migration contact or Spark for clarification instead of guessing or substituting a partial file. Follow the one-time secure handoff instructions to send only the requested original files. Confirm with your migration contact that the received file count matches what you sent. Keep the source system unchanged Do not delete, alter, or discontinue your Spark account while the assisted migration is being reviewed. Keep the source records available until your migration contact confirms a separate approved next step. If anything looks incomplete or unexpected, stop and preserve the original files and source records for review. What happens next Your migration contact reviews the handoff, confirms coverage and exceptions, and tells you whether another case-specific step is needed. This guide does not authorize import, deployment, production changes, or cancellation of the source system. Any later action requires separate, case-specific authorization after the required review, no-write assessment, backup and rollback checks, and exception resolution. Protect personal records The files may contain personal records. Use only the approved handoff instructions and share only the requested original files. Never include passwords, access codes, payment-card information, bank details, or service secrets. If someone asks you to use a different delivery method, pause and confirm it with your migration contact. If you need help If an export option is unavailable, coverage is unclear, or the handoff instructions do not match the approved migration, stop and contact your migration contact. Do not work around the issue by changing files, sending a partial substitute, or starting a product action on your own.","headings":["Before you begin","Gather the requested records","Keep the source system unchanged","What happens next","Protect personal records","If you need help"],"source_sha256":"","section":"Migrations","source":"docs/user-guide/migrations/spark-to-gymcore-migration-handoff.md"}]
Exact menu path: GymCore Admin > GymCore Settings > Billing<br>
Who can change it: any account with the manage_woocommerce capability. WordPress administrators and WooCommerce Shop Managers normally have it.<br>
Visible action: Save changes stores every field on this tab. A successful request shows Settings saved.
This tab stores the membership-product category used by billing lookups. Changing it can change which WooCommerce products GymCore treats as memberships.
Field reference
Annual freeze limit (days)
- Stored key/control:
gym_core_pause_annual_limit - Purpose: Caps total pause days per member per calendar year.
- Type: Number
- Default: 60
- Allowed values/range: Integer 1–365
- Dependencies: Membership pause workflow; WooCommerce billing remains separate.
- Side effects: Requests beyond the limit are blocked; existing pause history remains.
- When to change it: Set to the published membership policy before accepting pauses.
- When to leave it alone: Leave it when policy has not changed.
- Security/privacy: Financial/member-policy effect; communicate changes and preserve audit evidence.
Verify a change
- Select Save changes and confirm Settings saved.
- Reload Billing and confirm the selected category remains.
- In Products, open a known membership product and confirm it belongs to that WooCommerce category.
- Run the GymCore workflow that identifies membership products and compare its result with the WooCommerce product record. Restore the prior category if products are classified incorrectly; existing orders are not recategorized.
Related guides
Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.