ByTheWeb AI and ByTheWeb GEO use WordPress capabilities to control access to administration screens and actions.
Access is therefore determined primarily by the capabilities assigned to the current WordPress user, rather than only by the name of the user’s role.
This is especially important on websites that use custom roles or modify the standard WordPress role capabilities.
How Does ByTheWeb Control User Access?
Different parts of ByTheWeb require different WordPress capabilities.
The main capabilities currently used include:
edit_postsedit_postedit_others_postsmanage_categoriesmanage_options
A user must have the capability required by the specific screen or action.
Some actions that modify a particular post or media item also verify that the current user can edit that specific item.
ByTheWeb AI Access Overview
The current ByTheWeb AI administration screens use the following access levels:
| ByTheWeb AI Area | Required Capability |
|---|---|
| Main Dashboard | edit_posts |
| AI Audit | edit_posts |
| Media Optimization | edit_posts |
| Settings | edit_others_posts |
| API Connection & Credits | manage_options |
| Getting Started | manage_options |
Specific editing actions can include additional permission checks for the post or media item being modified.
Starting with ByTheWeb AI 1.9.5, the Getting Started setup requires the manage_options capability because it includes initial API Key connection and configuration.
Who Can Access the Main ByTheWeb AI Dashboard?
The main ByTheWeb AI menu and Dashboard require:
edit_posts
The same capability is used for access to:
- AI Audit
- Media Optimization
A user without edit_posts does not receive access to these ByTheWeb AI administration pages.
Can a User Modify Content They Are Not Allowed to Edit?
ByTheWeb does not rely only on access to the general plugin menu.
Where an action applies to a specific existing WordPress item, the plugin can also verify permission for that specific item.
For example, supported actions that modify a specific post or media attachment use WordPress item-level permission checks such as:
edit_post
If the current user cannot edit the requested item, the protected action is rejected.
Who Can Use Media Optimization?
The Media Optimization administration page requires:
edit_posts
Actions that save metadata to a specific media attachment also verify that the current user is allowed to edit that attachment.
This applies to fields such as:
- Alt Text
- Title
- Caption
- Description
For more information, see:
Who Can Use FAQ Tools Inside the Post Editor?
ByTheWeb AI FAQ tools use WordPress content-editing permissions.
AI FAQ generation requires the edit_posts capability. When an action is tied to a specific existing post, the plugin also checks whether the current user is allowed to edit that post.
Saving manually added or AI-generated FAQ data also requires permission to edit the specific post.
This means access to the ByTheWeb AI menu does not automatically grant permission to modify every post on the website.
Who Can Configure ByTheWeb AI Settings?
The main:
ByTheWeb AI > Settings
screen requires:
edit_others_posts
The current settings area includes configuration for supported features such as:
- FAQ settings
- Image settings
The Privacy & Usage and API Connection & Credits tabs are restricted to users with the manage_options capability.
These settings can therefore be managed by users who have the required higher-level editing capability.
Who Can Change the API Key?
The:
ByTheWeb AI > API Connection & Credits
screen requires:
manage_options
Users who do not have manage_options do not receive access to the API Connection & Credits screen through the normal ByTheWeb AI administration menu.
This area includes the domain’s ByTheWeb API connection and credit/package management.
For more information, see:
Can Editors Manage the API Key and Credits?
The plugin does not grant API Connection & Credits access based simply on the role name “Editor.”
The required capability is:
manage_options
A user without that capability cannot access the API Connection & Credits area through the normal plugin interface.
The main ByTheWeb AI Settings area uses the separate:
edit_others_posts
capability.
Administrator-only settings, including API Connection & Credits and Privacy & Usage, require:
manage_options
Can Subscribers, Customers or Guests Use ByTheWeb AI Administration Tools?
ByTheWeb AI administration screens and protected actions require logged-in WordPress capabilities such as edit_posts, edit_others_posts, or manage_options.
Users without the required capabilities cannot access those protected administration areas or execute the corresponding protected actions.
This includes normal Subscriber, customer, and unauthenticated guest access when those users do not have the required WordPress editing capabilities.
What If I Use Custom WordPress Roles?
ByTheWeb checks WordPress capabilities rather than depending exclusively on standard role names.
If another plugin or custom site configuration changes the capabilities assigned to a role, ByTheWeb access follows the capabilities that the user actually has.
For example, access to the ByTheWeb AI Dashboard, AI Audit, and Media Optimization depends on:
edit_posts
while access to API Connection & Credits depends on:
manage_options
The role label itself is not the final permission check.
ByTheWeb GEO Access Overview
ByTheWeb GEO separates site-wide administration from individual content editing.
The current main access levels are:
| ByTheWeb GEO Area | Required Capability |
|---|---|
| SEO & GEO Dashboard | edit_others_posts |
| GEO Settings | edit_others_posts |
| SEO Settings | edit_others_posts |
| Post-level GEO fields and saving | Permission to edit the specific post |
| Post-level Fix with AI | Permission to edit the specific post |
| Category / Tag / Taxonomy GEO fields | manage_categories |
| Getting Started / Setup & Preferences | edit_others_posts |
Starting with ByTheWeb GEO 1.3.2, the Getting Started setup and the Setup & Preferences option use the same edit_others_posts capability as the main GEO Dashboard and site-wide settings.
Who Can Access the SEO & GEO Dashboard?
The main ByTheWeb GEO Dashboard requires:
edit_others_posts
The same capability is required for:
- GEO Settings
- SEO Settings
This keeps site-wide reporting and configuration separate from normal post-level editing.
For more information, see:
Who Can Change Site-Wide GEO Settings?
The main GEO configuration screens require:
edit_others_posts
This includes the current site-wide ByTheWeb GEO settings available through the plugin administration menu.
A user who can edit only their own content does not automatically receive access to these site-wide settings.
Who Can Change ByTheWeb GEO SEO Settings?
The ByTheWeb GEO SEO Settings screen also requires:
edit_others_posts.
Remember that ByTheWeb GEO’s overlapping traditional SEO controls are used only when ByTheWeb GEO is the active SEO provider.
When Yoast SEO or Rank Math SEO is active, ByTheWeb GEO adapts its interface and output accordingly.
For compatibility details, see:
Who Can Edit GEO Data on an Individual Post?
Post-level ByTheWeb GEO data uses the WordPress permission for the specific post.
When post-level data is saved, ByTheWeb GEO verifies:
edit_post
for the requested post ID.
A user therefore cannot use the ByTheWeb GEO post-level save action to modify a post that WordPress does not allow that user to edit.
Who Can Use Post-Level Fix with AI?
Supported post-level AI actions also verify permission for the specific WordPress post.
The user must be allowed to edit that post before the requested action is processed.
Fix with AI additionally depends on the connected ByTheWeb AI functionality when an AI-assisted action is requested.
For more information, see:
Who Can Optimize Categories, Tags and Other Supported Taxonomies?
ByTheWeb GEO taxonomy editing requires:
manage_categories
This permission check is used when saving ByTheWeb GEO data for supported taxonomy terms.
The taxonomy workflow can include supported fields such as:
- Short Answer
- AI Summary
- FAQ
- GEO metadata
- Applicable SEO metadata when ByTheWeb GEO is the active SEO provider
A user without manage_categories cannot save these ByTheWeb taxonomy fields through the protected taxonomy workflow.
Can Subscribers, Customers or Guests Access the ByTheWeb GEO Dashboard?
The main GEO Dashboard requires:
edit_others_posts
Post-level actions require permission to edit the corresponding post.
Taxonomy editing requires:
manage_categories
Users who do not have the required WordPress capabilities cannot use those protected administration areas and actions.
Is There Still a Yoast SEO Migration Permission?
No.
The old ByTheWeb GEO Yoast migration workflow is no longer part of the current plugin.
The previous:
Migrate to ByTheWeb
tab, migration actions, and related AJAX endpoints were removed.
ByTheWeb GEO now uses its provider-aware integration with Yoast SEO and Rank Math SEO instead of requiring that SEO data be migrated into ByTheWeb.
How Are Protected ByTheWeb Actions Secured?
ByTheWeb uses WordPress request verification and capability checks on its protected administration actions.
For the current actions covered by the plugins, this includes mechanisms such as:
- WordPress nonce verification
current_user_can()capability checks- Item-specific
edit_postchecks where applicable
These checks are performed on the server side before protected changes are accepted.
What Is Nonce Verification Used For?
WordPress nonces are used to verify protected administrative requests before the corresponding action is processed.
For example, current ByTheWeb actions use nonce checks when saving or processing operations such as:
- AI FAQ generation
- Media metadata changes
- ByTheWeb GEO post data
- ByTheWeb GEO taxonomy data
- Dashboard recalculation and optimization actions
A request that fails the required verification is not processed by the protected handler.
Why Are Capability Checks Also Required?
A valid request token alone does not determine whether a user is authorized to perform an action.
ByTheWeb also checks the relevant WordPress capability.
Depending on the operation, that can include:
edit_postsedit_postedit_others_postsmanage_categoriesmanage_options
This separates request verification from WordPress user authorization.
Are API Key Management and AI-Assisted Features the Same Permission?
No.
ByTheWeb AI intentionally uses different access levels.
The Dashboard, AI Audit, and Media Optimization use:
edit_posts
The main Settings area uses:
edit_others_posts
API Connection & Credits and the Getting Started setup require:
manage_options
Actions tied to a specific post or media item can also require permission to edit that specific item.
A user can therefore have access to supported ByTheWeb AI tools without automatically receiving access to the domain’s API Key, subscription, or credit-management controls.
Can Multiple Authorized WordPress Users Use the Connected AI Features?
If a WordPress user has the capability required for a supported ByTheWeb AI action, that user can access the corresponding protected feature on that website.
The ByTheWeb AI connection and credit balance are associated with the connected website domain rather than with a separate API Key for each WordPress user.
For credit information, see:
Does Deactivating a User Remove Content They Already Created?
Changing or removing a WordPress user’s access does not automatically delete normal WordPress content that has already been created and saved.
FAQ data, image metadata, and other WordPress content already saved on the website are not deleted simply because a user’s permissions are changed.
The ability of another user to edit that content continues to depend on normal WordPress permissions.
Quick Permission Summary
edit_posts
Used for current ByTheWeb AI content-oriented administration areas such as:
- Dashboard
- AI Audit
- Media Optimization
Specific item changes can require additional permission for the item itself.
edit_post
Used to verify permission for a specific post or media item before supported item-level changes are saved.
edit_others_posts
Used for higher-level administration such as:
- ByTheWeb AI Settings
- ByTheWeb GEO Dashboard
- GEO Settings
- SEO Settings
manage_categories
Used for supported ByTheWeb GEO taxonomy editing.
manage_options
Used for:
- API Connection & Credits
- API Key management
- Package and credit-management access in the WordPress plugin
Where Should I Go Next?
For SEO & GEO Dashboard permissions:
For AI-assisted GEO improvements:
For API Key management:
For general compatibility: