What's different here
An assistant can work on the site. Publishing stays with you.
The site has a door a program can use to read and write content: pages, posts, lists, images. What it writes lands as a draft. What reaches visitors is a person's decision.
Why it matters
An assistant can write a hundred pages in a morning. It can also get a hundred pages wrong — in exactly the same confident voice. What separates a useful tool from a liability isn't how good the model is; it's what it can touch without asking.
That's why the door is built from separate permissions and drafts, not from one password that opens everything.
What it looks like in practice
One site built this way has 26 pages. Its log shows 100 writes by the assistant and 5 by a person — and those 5 are the decisions, not the work.
Every line in the log carries the name of the key that wrote it, not ours. Authorship comes from how the request authenticated, never from what the request claims.
Exactly what it can touch
A key gets the permission it asked for, not all of them. There are seven, granted separately:
- read content;
- write drafts — pages, posts, lists;
- upload images;
- delete;
- publish;
- publish ONLY new pages, never one that already exists;
- change the menu and the site's identity — again, as a draft.
A build key holds the first few, lives briefly and is withdrawn once the site is done. A maintenance key holds fewer. The site's administrator can issue a drafts-only key themselves, from the panel.
What you see first
Every write leaves a preview link, signed and time-limited. It needs no account: you can send it to anyone, including yourself, to look at the result before it exists for anybody else.
The assistant can also check its own work: it has a tool that looks for dead links, missing images and pages nothing links to. Those are the mistakes a program cannot otherwise see — to it, every page written is a page finished.
How it connects
Through the MCP connector, with 22 operations, or straight through the API. The server sends the instructions on connect; there is nothing to paste and nothing to remember.
What it does NOT do
- It doesn't publish on its own, unless you deliberately granted that permission.
- It can't change the design: there are no fields for colours, margins or fonts — not for it, and not for you.
- It doesn't touch another site. A key is bound to exactly one, and the site comes from the key, never from the request.
- It doesn't invent things on your behalf: if a piece of information is missing, it leaves the space empty or asks.