An AI assistant connected to your project can do almost everything you can do in the admin panel, with the same permissions and the same checks.
Every action the assistant takes goes through the same admin API the admin panel uses, with the session of the admin it is connected as. The same validation and permission checks apply.
If that admin cannot open a screen, the assistant cannot use the tools behind it either.
The tools cover every area of the admin panel:
Pages and design
Pages, components, custom CSS, fonts and head tags.
Navigation
Menus, footers and navigations.
Forms
Forms and catalogs.
Logic
Functions, API calls and event triggers.
Database
Custom tables and custom queries.
Shop
Shop settings, checkout, shipping, products, categories, tags and orders.
Subscriptions
Subscription groups, plans and prices.
Users
Users, user tags, onboarding and admins.
Messaging
Email, mobile messages and notifications.
Site
Theme and translations.
There is no staging copy and no undo. Every change the assistant saves is on your public site at once.
The assistant is instructed to ask before anything destructive or hard to undo: deleting, deactivating, changing a table that holds data, changing query security, running a function for real, or attaching a function to live events.
In the built-in Chat, a plan with steps like these stops and asks for your approval. Reply confirm to go ahead, or say what to change.
Because the site is live, the assistant is set up to test in ways that leave your data alone.
The assistant tests functions with a dry run, which rolls back database changes from custom queries.
A dry run still performs external API calls. The assistant is told to ask first when a call would send, charge or create something.
It is instructed never to create fake or test records on your live site.
Some things stay with you.
It cannot upload files. Upload images in the admin panel first, and the assistant can then use them from your media library.
It never asks for or reveals API keys, passwords or tokens.
Tools are marked as read-only or destructive, so assistants that support it can auto-approve reads and ask you before destructive steps.