Install the plugin
One plugin per site. It is what gives the agent a locked-down set of abilities instead of full admin.
Requirements
- WordPress 6.0 or newer
- PHP 8.0 or newer
- Permalinks enabled, because the plugin serves a REST namespace and REST needs them
Install it
- In WordPress, go to Plugins → Add New → Upload Plugin.
- Upload the zip and activate it.
- That is all. There is nothing to configure on the WordPress side. The app does the rest.
What it adds
One REST namespace of its own, and nothing else. No admin menu you have to visit, no settings page to fill in, no dashboard widget, no front-end output. The site looks and behaves exactly as it did.
Why a plugin at all
WordPress's own REST API authenticates as a user, and a user is all-or-nothing: an editor can edit everything an editor can edit. There is no built-in way to say "may change Elementor content, may not publish, may not touch files".
The plugin is that layer. Each ability is a separate switch, all of them are off when it is installed, and the check happens on the site, so it holds even if something else were to get hold of the credential.
Updates
The plugin updates itself from multiagentry.com through the normal WordPress
updates screen, for as long as your licence is active. It will not accept a package from
anywhere else: the download URL is checked against that host before WordPress is allowed to
install it, so a hijacked update feed cannot hand your site a different plugin.
If a licence lapses, the plugin keeps working. It simply stops being offered updates.