Governed ability

Update WooCommerce customer

aafm/wc-update-customerGuarded writeHigh risk, locked by default

Update WooCommerce customer is a governed ability in Agent Abilities for MCP, a free WordPress plugin that runs an MCP server on your site.

Updates a WooCommerce customer by id, changing only the fields you send. An empty request body is a no-op success. Returns the full customer shape. Requires the manage-WooCommerce capability.

How it is governed

The same model as every ability in the plugin, stated for this one.

  • Off until you enable it

    Like every ability, Update WooCommerce customer ships switched off. You turn it on one at a time, and an update never widens access on its own.

  • Guarded write

    Writes stay conservative, and the plugin re-checks the capability before the call runs.

  • Capability gated

    A connection only sees Update WooCommerce customer if the user you connected can run it, and the plugin checks that capability again before it executes.

  • Every call audited

    The call is written to the log in your own database, denials included, with the argument keys and the identifiers it touched, never free-text content.

  • Locked behind a second switch

    Update WooCommerce customer is one of the 9 WooCommerce abilities that move money or grant authority. Switching it on here is not enough on its own: it stays locked until you also turn on the high-risk control in Settings, and that switch is written to the audit log like any other change. Since 1.5.0.

Update WooCommerce customer is one of the 52 governed WooCommerce abilities. See the full WooCommerce MCP integration.

See it in action

An illustrative run. Your real calls and data stay on your own site.

agent-abilities · auditGoverned
YouUpdate WooCommerce customer on this site.
RunRunning aafm/wc-update-customer
GateAllowedcapability re-checked before running
Auditaafm/wc-update-customer · principal: editor · args: id
ResultApplies the change, then writes the call to the audit log.

Try it with a prompt

Example requests you could paste to your agent.

  1. Update customer 60's shipping address to their new city.
  2. Change the billing phone number on customer 60.
  3. Fix the last name on WooCommerce customer 214.

These are illustrative example prompts. The agent runs them as the user you connected, checked against that user's capabilities and written to your audit log.

Frequently asked

Short answers for Update WooCommerce customer.

Does this touch personal data?

Yes. Customer records include billing and shipping details, so Update WooCommerce customer stays off until an administrator enables it and returns the full customer shape under the Integrations security disclaimer.

Are fields I leave out preserved?

Yes. Update WooCommerce customer changes only the fields you send, and an empty request body is a no-op success. The caller must hold the manage WooCommerce capability and every change is audited.

Back to all abilities

Governed by default, from the first call.

Update WooCommerce customer is off until you enable it, scoped to the user you connect, and logged like everything else. Turn on only what you need.

Every ability off until you enable it, capability-gated on every call.