Skip to Main Content Enable / Disable keyboard navigation (ENTER key) Accessible Menu Accessibility panel Reset accessibility Sitemap Accessibility statement
Help Center
Welcome to our knowledge base, we are here to help.
Bytheweb 3 dots icon

User Access Control & Permissions

ByTheWeb AI and ByTheWeb GEO use WordPress capabilities to control access to administration screens and actions.

Access is therefore determined primarily by the capabilities assigned to the current WordPress user, rather than only by the name of the user’s role.

This is especially important on websites that use custom roles or modify the standard WordPress role capabilities.

How Does ByTheWeb Control User Access?

Different parts of ByTheWeb require different WordPress capabilities.

The main capabilities currently used include:

  • edit_posts
  • edit_post
  • edit_others_posts
  • manage_categories
  • manage_options

A user must have the capability required by the specific screen or action.

Some actions that modify a particular post or media item also verify that the current user can edit that specific item.

ByTheWeb AI Access Overview

The current ByTheWeb AI administration screens use the following access levels:

ByTheWeb AI AreaRequired Capability
Main Dashboardedit_posts
AI Auditedit_posts
Media Optimizationedit_posts
Settingsedit_others_posts
API Connection & Creditsmanage_options
Getting Startedmanage_options

Specific editing actions can include additional permission checks for the post or media item being modified.

Starting with ByTheWeb AI 1.9.5, the Getting Started setup requires the manage_options capability because it includes initial API Key connection and configuration.

Who Can Access the Main ByTheWeb AI Dashboard?

The main ByTheWeb AI menu and Dashboard require:

edit_posts

The same capability is used for access to:

  • AI Audit
  • Media Optimization

A user without edit_posts does not receive access to these ByTheWeb AI administration pages.

Can a User Modify Content They Are Not Allowed to Edit?

ByTheWeb does not rely only on access to the general plugin menu.

Where an action applies to a specific existing WordPress item, the plugin can also verify permission for that specific item.

For example, supported actions that modify a specific post or media attachment use WordPress item-level permission checks such as:

edit_post

If the current user cannot edit the requested item, the protected action is rejected.

Who Can Use Media Optimization?

The Media Optimization administration page requires:

edit_posts

Actions that save metadata to a specific media attachment also verify that the current user is allowed to edit that attachment.

This applies to fields such as:

  • Alt Text
  • Title
  • Caption
  • Description

For more information, see:

Media Optimization

Who Can Use FAQ Tools Inside the Post Editor?

ByTheWeb AI FAQ tools use WordPress content-editing permissions.

AI FAQ generation requires the edit_posts capability. When an action is tied to a specific existing post, the plugin also checks whether the current user is allowed to edit that post.

Saving manually added or AI-generated FAQ data also requires permission to edit the specific post.

This means access to the ByTheWeb AI menu does not automatically grant permission to modify every post on the website.

Who Can Configure ByTheWeb AI Settings?

The main:

ByTheWeb AI > Settings

screen requires:

edit_others_posts

The current settings area includes configuration for supported features such as:

  • FAQ settings
  • Image settings

The Privacy & Usage and API Connection & Credits tabs are restricted to users with the manage_options capability.

These settings can therefore be managed by users who have the required higher-level editing capability.

Who Can Change the API Key?

The:

ByTheWeb AI > API Connection & Credits

screen requires:

manage_options

Users who do not have manage_options do not receive access to the API Connection & Credits screen through the normal ByTheWeb AI administration menu.

This area includes the domain’s ByTheWeb API connection and credit/package management.

For more information, see:

Connect API Key

Can Editors Manage the API Key and Credits?

The plugin does not grant API Connection & Credits access based simply on the role name “Editor.”

The required capability is:

manage_options

A user without that capability cannot access the API Connection & Credits area through the normal plugin interface.

The main ByTheWeb AI Settings area uses the separate:

edit_others_posts

capability.

Administrator-only settings, including API Connection & Credits and Privacy & Usage, require:

manage_options

Can Subscribers, Customers or Guests Use ByTheWeb AI Administration Tools?

ByTheWeb AI administration screens and protected actions require logged-in WordPress capabilities such as edit_posts, edit_others_posts, or manage_options.

Users without the required capabilities cannot access those protected administration areas or execute the corresponding protected actions.

This includes normal Subscriber, customer, and unauthenticated guest access when those users do not have the required WordPress editing capabilities.

What If I Use Custom WordPress Roles?

ByTheWeb checks WordPress capabilities rather than depending exclusively on standard role names.

If another plugin or custom site configuration changes the capabilities assigned to a role, ByTheWeb access follows the capabilities that the user actually has.

For example, access to the ByTheWeb AI Dashboard, AI Audit, and Media Optimization depends on:

edit_posts

while access to API Connection & Credits depends on:

manage_options

The role label itself is not the final permission check.

ByTheWeb GEO Access Overview

ByTheWeb GEO separates site-wide administration from individual content editing.

The current main access levels are:

ByTheWeb GEO AreaRequired Capability
SEO & GEO Dashboardedit_others_posts
GEO Settingsedit_others_posts
SEO Settingsedit_others_posts
Post-level GEO fields and savingPermission to edit the specific post
Post-level Fix with AIPermission to edit the specific post
Category / Tag / Taxonomy GEO fieldsmanage_categories
Getting Started / Setup & Preferencesedit_others_posts

Starting with ByTheWeb GEO 1.3.2, the Getting Started setup and the Setup & Preferences option use the same edit_others_posts capability as the main GEO Dashboard and site-wide settings.

Who Can Access the SEO & GEO Dashboard?

The main ByTheWeb GEO Dashboard requires:

edit_others_posts

The same capability is required for:

  • GEO Settings
  • SEO Settings

This keeps site-wide reporting and configuration separate from normal post-level editing.

For more information, see:

SEO & GEO Dashboard

Who Can Change Site-Wide GEO Settings?

The main GEO configuration screens require:

edit_others_posts

This includes the current site-wide ByTheWeb GEO settings available through the plugin administration menu.

A user who can edit only their own content does not automatically receive access to these site-wide settings.

Who Can Change ByTheWeb GEO SEO Settings?

The ByTheWeb GEO SEO Settings screen also requires:

edit_others_posts.

Remember that ByTheWeb GEO’s overlapping traditional SEO controls are used only when ByTheWeb GEO is the active SEO provider.

When Yoast SEO or Rank Math SEO is active, ByTheWeb GEO adapts its interface and output accordingly.

For compatibility details, see:

Requirements & Compatibility

Who Can Edit GEO Data on an Individual Post?

Post-level ByTheWeb GEO data uses the WordPress permission for the specific post.

When post-level data is saved, ByTheWeb GEO verifies:

edit_post

for the requested post ID.

A user therefore cannot use the ByTheWeb GEO post-level save action to modify a post that WordPress does not allow that user to edit.

Who Can Use Post-Level Fix with AI?

Supported post-level AI actions also verify permission for the specific WordPress post.

The user must be allowed to edit that post before the requested action is processed.

Fix with AI additionally depends on the connected ByTheWeb AI functionality when an AI-assisted action is requested.

For more information, see:

Fix with AI using ByTheWeb AI

Who Can Optimize Categories, Tags and Other Supported Taxonomies?

ByTheWeb GEO taxonomy editing requires:

manage_categories

This permission check is used when saving ByTheWeb GEO data for supported taxonomy terms.

The taxonomy workflow can include supported fields such as:

  • Short Answer
  • AI Summary
  • FAQ
  • GEO metadata
  • Applicable SEO metadata when ByTheWeb GEO is the active SEO provider

A user without manage_categories cannot save these ByTheWeb taxonomy fields through the protected taxonomy workflow.

Can Subscribers, Customers or Guests Access the ByTheWeb GEO Dashboard?

The main GEO Dashboard requires:

edit_others_posts

Post-level actions require permission to edit the corresponding post.

Taxonomy editing requires:

manage_categories

Users who do not have the required WordPress capabilities cannot use those protected administration areas and actions.

Is There Still a Yoast SEO Migration Permission?

No.

The old ByTheWeb GEO Yoast migration workflow is no longer part of the current plugin.

The previous:

Migrate to ByTheWeb

tab, migration actions, and related AJAX endpoints were removed.

ByTheWeb GEO now uses its provider-aware integration with Yoast SEO and Rank Math SEO instead of requiring that SEO data be migrated into ByTheWeb.

How Are Protected ByTheWeb Actions Secured?

ByTheWeb uses WordPress request verification and capability checks on its protected administration actions.

For the current actions covered by the plugins, this includes mechanisms such as:

  • WordPress nonce verification
  • current_user_can() capability checks
  • Item-specific edit_post checks where applicable

These checks are performed on the server side before protected changes are accepted.

What Is Nonce Verification Used For?

WordPress nonces are used to verify protected administrative requests before the corresponding action is processed.

For example, current ByTheWeb actions use nonce checks when saving or processing operations such as:

  • AI FAQ generation
  • Media metadata changes
  • ByTheWeb GEO post data
  • ByTheWeb GEO taxonomy data
  • Dashboard recalculation and optimization actions

A request that fails the required verification is not processed by the protected handler.

Why Are Capability Checks Also Required?

A valid request token alone does not determine whether a user is authorized to perform an action.

ByTheWeb also checks the relevant WordPress capability.

Depending on the operation, that can include:

  • edit_posts
  • edit_post
  • edit_others_posts
  • manage_categories
  • manage_options

This separates request verification from WordPress user authorization.

Are API Key Management and AI-Assisted Features the Same Permission?

No.

ByTheWeb AI intentionally uses different access levels.

The Dashboard, AI Audit, and Media Optimization use:

edit_posts

The main Settings area uses:

edit_others_posts

API Connection & Credits and the Getting Started setup require:

manage_options

Actions tied to a specific post or media item can also require permission to edit that specific item.

A user can therefore have access to supported ByTheWeb AI tools without automatically receiving access to the domain’s API Key, subscription, or credit-management controls.

Can Multiple Authorized WordPress Users Use the Connected AI Features?

If a WordPress user has the capability required for a supported ByTheWeb AI action, that user can access the corresponding protected feature on that website.

The ByTheWeb AI connection and credit balance are associated with the connected website domain rather than with a separate API Key for each WordPress user.

For credit information, see:

Free vs. Credits

Does Deactivating a User Remove Content They Already Created?

Changing or removing a WordPress user’s access does not automatically delete normal WordPress content that has already been created and saved.

FAQ data, image metadata, and other WordPress content already saved on the website are not deleted simply because a user’s permissions are changed.

The ability of another user to edit that content continues to depend on normal WordPress permissions.

Quick Permission Summary

edit_posts

Used for current ByTheWeb AI content-oriented administration areas such as:

  • Dashboard
  • AI Audit
  • Media Optimization

Specific item changes can require additional permission for the item itself.

edit_post

Used to verify permission for a specific post or media item before supported item-level changes are saved.

edit_others_posts

Used for higher-level administration such as:

  • ByTheWeb AI Settings
  • ByTheWeb GEO Dashboard
  • GEO Settings
  • SEO Settings

manage_categories

Used for supported ByTheWeb GEO taxonomy editing.

manage_options

Used for:

  • API Connection & Credits
  • API Key management
  • Package and credit-management access in the WordPress plugin

Where Should I Go Next?

For SEO & GEO Dashboard permissions:

SEO & GEO Dashboard

For AI-assisted GEO improvements:

Fix with AI using ByTheWeb AI

For API Key management:

Connect API Key

For general compatibility:

Requirements & Compatibility