Governed ability
Update WooCommerce order
aafm/wc-update-orderGuarded writeHigh risk, locked by default
Update WooCommerce order is a governed ability in Agent Abilities for MCP, a free WordPress plugin that runs an MCP server on your site.
Updates a WooCommerce order by id, changing only the fields you send. Requires the manage-WooCommerce capability.
How it is governed
The same model as every ability in the plugin, stated for this one.
- Off until you enable it
Like every ability, Update WooCommerce order ships switched off. You turn it on one at a time, and an update never widens access on its own.
- Guarded write
Writes stay conservative, and the plugin re-checks the capability before the call runs.
- Capability gated
A connection only sees Update WooCommerce order if the user you connected can run it, and the plugin checks that capability again before it executes.
- Every call audited
The call is written to the log in your own database, denials included, with the argument keys and the identifiers it touched, never free-text content.
- Locked behind a second switch
Update WooCommerce order is one of the 9 WooCommerce abilities that move money or grant authority. Switching it on here is not enough on its own: it stays locked until you also turn on the high-risk control in Settings, and that switch is written to the audit log like any other change. Since 1.5.0.
Update WooCommerce order is one of the 52 governed WooCommerce abilities. See the full WooCommerce MCP integration.
See it in action
An illustrative run. Your real calls and data stay on your own site.
Try it with a prompt
Example requests you could paste to your agent.
Update the shipping address on order 730.
Change the billing email on order 542.
Set the customer note on order 1088.
These are illustrative example prompts. The agent runs them as the user you connected, checked against that user's capabilities and written to your audit log.
Frequently asked
Short answers for Update WooCommerce order.
Which fields does it change?
Update WooCommerce order changes only the fields you send on the order you name by id. Other fields are left as they were.
How is it governed?
Order records can include personal details, so Update WooCommerce order is off by default, requires the manage WooCommerce capability, and logs each call by ability name and argument keys.
Governed by default, from the first call.
Update WooCommerce order is off until you enable it, scoped to the user you connect, and logged like everything else. Turn on only what you need.
Every ability off until you enable it, capability-gated on every call.