# Review what AI assistants did on your site

Agent activity lists every ability call on your WordPress site, refused ones too: who made it, how it came in and how it ended.

The screen is under **BetterShield › Activity › Agent activity**. In WordPress, an ability is a named action a plugin offers to AI assistants and other tools, such as reading the score; each use of one is a call. This screen shows the calls that were made, where **Agents › Surface** shows what callers are able to do.

> **Note:** Recording needs WordPress 7.1 or newer. On an earlier version the screen says agent activity is not recorded on this version, and nothing is listed.

## What is recorded

Every time an ability is called on the site, whichever plugin registered it and however the call came in, including calls that were refused. Each record keeps the ability name, the time, the account it ran as, how the call came in, and the outcome. The input is kept only as a digest, never its contents, because an input can carry a secret.

Refusals also reach the [site activity log](/docs/activity-log/): **Ability refused** once per ability per request, and **Abilities refused repeatedly** when ten requests within an hour carry a refusal. Another plugin can stop the recording, and BetterShield cannot prevent that, but it writes **Agent activity recording stopped** to the log, at most once an hour.

## Turn recording on or off

**Record what agents do on this site** is on by default. The same switch appears in two places: the **Recording agent activity** card under **Settings › General**, and the same card under **Agents › Permissions**. Turning it off asks for your password first when **Ask for my password before an action that removes a protection** is on. Rows already recorded stay, and a note above the list says recording is off.

## The figures at the top

| Figure | What it shows |
|---|---|
| **Recording** | **On**, **Off** or **Unavailable**. |
| **Calls** | Calls kept, or calls matching your filters. |
| **Refused** | Calls that asked for more than the account was allowed. |
| **Completed** | Calls that ran and answered. |

## Filters

- **Outcome**, as chips with counts: **All**, **Refused**, **Completed**, **Input rejected**, **Input unreadable**, **Output rejected**, **Answered early**, **Failed** and **Did not finish**.
- **Namespace:** the first part of an ability name, with counts. WordPress does not record which plugin registered an ability, so a namespace is a naming convention, not proof of who is behind it.
- **Came through:** **Any door**, **MCP** (a connected assistant), **REST**, **WP-CLI** or **PHP**.
- **Clear filters** resets all three.

## Reading a row

Each row shows the time, the ability name, the account it ran as, how it came in (over MCP, over REST, via WP-CLI or in PHP), how long it took when that is measurable, and the outcome with any error code. A refused call is highlighted.

- **Everything this account did** narrows the list to that account. **Show every account** goes back.
- **Agent surface**, at the top, opens **Agents › Surface**, which shows what agents are able to do.
- **Show older entries** loads more.

## How long rows are kept

As long as the activity log: 30 days, or 90 days (Ultra). The note at the foot says which applies. The screen has no export; use `wp bettershield agents --format=csv` ([WP-CLI commands](/docs/wp-cli-commands/)).

## Related

- [Connect an AI assistant](/docs/connect-an-ai-assistant/)
- [Activity log](/docs/activity-log/)
- [WP-CLI commands](/docs/wp-cli-commands/)
