THE COMPLETE MANUAL

Keep a clear
reference close.

All guides and documentation in one place. Print this page or save it as a PDF.

Guides / Free & Pro

Install Free and add Pro

Install the correct ZIPs, in the right order, on a supported staging host.

Where to start

WordPress → Plugins → Add New Plugin → Upload Plugin

Before you start

The current Studio v7 package requires WordPress 7.0 or later, PHP 8.3 or later, and MySQL or MariaDB. WordPress Playground uses SQLite and is not supported by this build.

Keep a current backup and use a staging site. The combined Free-and-Pro delivery bundle contains two separate installable ZIPs; the outer bundle is not itself a WordPress plugin.

Install the pair

  1. Extract the outer delivery bundle on your computer, if you received one.
  2. In WordPress, upload the Free ZIP, install it and activate Logged.ai.
  3. If you are using Pro, upload the matching Pro ZIP next and activate it. Keep Free active alongside Pro.
  4. Open Logged.ai → Setup. Review the initial choices, then check Settings → System status.

Check the result

Free works as its own edition. Pro adds workflows to Free and needs a compatible pair. If activation reports a database or compatibility requirement, resolve that requirement before retrying; do not bypass it.

Guides / Free & Pro

Set up your first workspace

Choose your focus and display detail, then review any collection changes before applying them.

Where to start

Logged.ai → Setup

Follow the four steps

  1. Under Your goal, choose the work you want to make easier: understanding activity, reviewing access, troubleshooting changes or reviewing store activity.
  2. Under Your experience, choose Essentials, Operator or Expert and a light or dark appearance. The sample illustrates how the interface changes.
  3. Review Your toolkit. Workflow suggestions do not purchase Pro or enable a remote service.
  4. At Review & launch, choose whether to keep current collection settings or apply the suggested preset. Read the proposed retention and category changes.
  5. Confirm any collection change. If retention becomes shorter, review its separate deletion confirmation. Finish setup with the displayed action.

What setup changes

Choosing a goal personalizes recommendations. Collection changes are a separate choice on the final step. Display detail and appearance do not grant permissions, enable alerts or turn on response policies.

After setup, use Overview for an initial snapshot and Settings → System status to inspect monitoring health.

Guides / Free & Pro

Find who changed what

Narrow the activity list and inspect the difference between the acting user and the affected object.

Where to start

Logged.ai → Activity → Events

Start with a question

  1. Enter a type of change in Find a type of change, such as role, plugin or content. Select an area if you know it, then choose Find changes.
  2. Open Refine by person, time or source for acting user ID, affected user ID, object ID, date, outcome or execution-channel filters.
  3. Open the relevant record. Read the Actor, Affected object and Outcome separately, then inspect Captured field differences.
  4. When present, follow Activity from this request to review records sharing that request identifier.

Read the evidence carefully

The actor performed the observed operation; the subject is the account or object affected. They can be different. Current profile labels help you navigate but are not a historical profile snapshot.

An attempted or failed operation is not the same as a stored change. Missing before-and-after values do not prove that nothing changed. Unsupported operations and direct database edits can be absent.

Search matches recorded action types rather than private post content. Date filters use UTC with an inclusive start and exclusive end. Filters change the view and exports, not collection.

Guides / Free & Pro

Review a request finding

Understand what WordPress observed before attributing a source or considering a response.

Where to start

Logged.ai → Requests → Findings; Source and verification

Inspect the observation

  1. Open Findings and select a retained observation or minute group.
  2. Review the recorded pattern, method, minimized path, source quality and response effect. A concerning pattern is a reason to investigate.
  3. Open Source and verification to see the configured address source and run the harmless Observer self-test when needed.
  4. If your site uses a proxy, ask the server administrator to establish the exact trusted boundary before changing Address source.

Trust forwarding deliberately

Actual connection peer is the default. The alternative is Explicit trusted proxies and X-Forwarded-For, using reviewed proxy addresses or CIDRs. The immediate connection peer must match the trust set before forwarding data is considered. Other forwarding headers are ignored.

Save request-source configuration only after confirming control of that boundary. Changing it invalidates dependent exact-source targets. A derived or masked address is network context, not a person's identity.

Know the blind spots

The observer sees requests reaching the WordPress plugin layer. Static files, cache hits and upstream responses may not reach it. A successful self-test covers its one routed request, not the whole site. Admitted observations are not a count of all traffic or unique attackers.

Guides / Free & Pro

Preview a temporary response safely

Review a narrowly scoped policy, keep recovery available and revoke it when no longer needed.

Where to start

Logged.ai → Requests → Findings; Response → Manual policies

Preview before activation

  1. From an eligible request observation, choose Preview temporary policy and a finite duration. If the preview is unavailable, review the stated evidence or permission requirement.
  2. Read the exact site, path or reviewed source conditions, GET/HEAD methods, expiry and matcher examples. Inspect optional exact-path exceptions when offered.
  3. Keep OS-level recovery access available. Observation-only is the initial choice and never denies a request.
  4. Only after reviewing the effect, choose active mode and acknowledge the scope and recovery procedure. Activation also enables local response for valid existing policies.
  5. Use Response → Manual policies to inspect the current mode and retained policies. Choose Revoke for a policy you no longer need.

Recovery

A server operator can run wp logged-ai response disable --url=YOUR_SITE, or set define('LOGGED_AI_DISABLE_RESPONSE', true); before WordPress loads. There is no public recovery URL or bypass cookie.

Policy expiry is checked on eligible requests without waiting for cron. Exact-source targeting can affect shared-network users and ordinary login, checkout or API reads. Exceptions apply only to the selected policy; they do not grant WordPress access or override other policies.

Coverage

This is a temporary WordPress-layer control. It does not replace an upstream firewall, and earlier code may already have run. Ambiguous or encoded input can remain observation-only.

Guides / Free & Pro

Choose your fixed email alerts

Select important changes and recipients who already have access to the evidence.

Where to start

Logged.ai → Alerts → Fixed alerts

Configure the essentials

  1. Under Choose what matters, select the available fixed rules. Examples include administrator creation or promotion, a plugin installation and a bounded failed-authentication burst.
  2. Choose up to five eligible WordPress accounts under Choose who receives it.
  3. Set a cooldown from 60 to 86,400 seconds to suppress repeated matches.
  4. If using the selected security-component rule, choose the installed components you want to monitor for deactivation.
  5. Choose Save alert settings, then inspect Recent delivery work when new matching activity occurs.

Interpret delivery state

Alerts contain a short description and an authenticated link. WordPress mail acceptance is not proof that a mailbox received a message.

Rule changes cancel older queued work. A crashed sending attempt can remain delivery unknown rather than being silently repeated. Cooldowns and synthetic tests are recorded separately.

Calling a selected component a security component is your classification. A plugin's name alone does not prove that it protects the site.

Guides / Free & Pro

Export a useful slice of evidence

Choose a small streamed export or a larger background file without making it public.

Where to start

Logged.ai → Activity → Events; Reports → Exports

Export the current selection

  1. Filter Activity to the records you need.
  2. Open Export this selection and choose Download JSON or Download CSV. This streamed route includes up to 500 matching site records and does not save a file on the web server.
  3. For a larger set, use Create filtered background export from Activity, or open Reports → Exports and choose a format and UTC date range.
  4. Check the job's recorded state before downloading. A queued job is not a completed export.

Background file requirements

Stored private exports require a Linux or Unix host with owner-only filesystem permissions. Windows private file exports are not supported in this development build. If the storage requirement panel appears, have the hosting administrator resolve it; do not make the directory public or weaken permissions.

Background files expire after 24 hours and have a maximum of 1,000,000 rows and 256 MiB. Their worker fixes the matching membership when it starts; this is not a transactionally complete database snapshot. Scheduling may be delayed.

Handle the download

Export dates and content retain UTC. Keep downloaded evidence in an appropriately restricted location. Removing data from WordPress cannot recall files that someone already downloaded.

Guides / Pro

Work through an investigation case

Read the linked evidence, assign a reviewer and record a decision without confusing association with proof.

Where to start

Logged.ai → Investigations → Cases

Review and decide

  1. Open the Case list and filter by case status if needed. Open the case you want to review.
  2. Read Follow the sequence and inspect the retained source evidence, priority explanation and request-evidence links.
  3. Use the investigator field to assign an authorized reviewer, or leave it blank to unassign.
  4. Add a short investigation note without credentials or unnecessary personal information. Confirm the displayed site and case before saving.
  5. Choose the appropriate status and Save case status. Reopening a closed case requires the explicit reopen choice.

Read links accurately

A shared local request identifier is stronger context than an address-and-time association. Shared NAT, proxy use and ordinary authorized activity remain alternative explanations for address links.

Priority helps order review. Neither priority nor a related sequence proves malicious intent, fraud or causality. The history retains reviewer notes, assignment and status decisions.

If there are no cases

Review Incident rules from the Cases page before relying on case processing. Investigations → Background processing explains the required saved configuration and explicit background-processing choice. An empty list alone does not establish that the site is safe.

Guides / Pro

Build an alert with a clear outcome

Prepare a destination, preview a rule and distinguish the saved state from an unsaved draft.

Where to start

Logged.ai → Alerts → Advanced alerts

Prepare the destination

  1. Complete Set up storage if offered. This step enables no rule or destination.
  2. Read the one-time server-setup panel. Destination setup requires PHP Sodium and a valid private alert encryption key. An administrator must preserve any existing key; replacing it can make encrypted records unreadable.
  3. Add a labelled WordPress email, signed HTTPS webhook or Slack webhook destination. Choose an eligible WordPress recipient for email, or supply the appropriate secret URL for a webhook.
  4. Review the minimized-facts consent, choose the destination's enabled state, and Save destination. Saving does not send a test.

Preview and save the rule

  1. Use the readable builder for a supported severity rule, including threshold, window, count, grouping, cooldown, severity and destination choices.
  2. Choose Preview expression. It examines a bounded retained sample without saving a rule or sending a notification.
  3. Review the result and the draft, then choose Save rule version. Check the confirmation for enabled or disabled state and whether replay was requested.
  4. If needed, explicitly authorize Queue synthetic test on an enabled destination. Review Recent delivery history afterward.

Avoid surprises

The declarative source remains authoritative, especially for compound rules. New versions normally start with future sources; explicit replay can create notifications from retained sources.

A webhook signing secret is displayed once after saving. Store it privately. Editing a webhook requires its URL again, changes the secret and invalidates queued messages for the prior revision.

Accepted means the transport or mail subsystem reported acceptance. It does not prove receipt. A rule still needs an enabled, available destination; a successful configuration save is not an end-to-end delivery test.

Guides / Pro

Make a useful review repeatable

Save a search, generate a private report and schedule a review you can inspect later.

Where to start

Logged.ai → Reports → Saved searches and reports

Save the view

  1. Complete the local reporting-workspace check if offered. It does not email a report.
  2. Create a New saved search with a useful title, report type and activity filters. Types include site activity, user activity, sensitive changes, authentication, WooCommerce and incident cases/local summary.
  3. Choose private visibility or sharing with site investigators, then save. Sharing a search does not grant evidence access.
  4. Open the saved search and Generate a report for the required period in CSV, JSON or HTML. Check the generated status before downloading.

Schedule a review

  1. Open Schedules and New schedule after creating your own saved search.
  2. Select the search, daily or weekly cadence, local hour, timezone and output format.
  3. Choose whether to enable the schedule and notify your account email, acknowledge the private report copies, then Save schedule.
  4. Review recorded job state. If background scheduling is unavailable, follow the page's guidance and check the site's cron runner.

What is retained

Reports include bounded source membership, not a complete database snapshot. The limit is 10,000 records and 16 MiB; private report copies expire after seven days.

Notifications contain a minimal summary and authenticated link, not an attached report. Removing a saved search also cancels its reports and removes its schedules. These database-backed Pro reports are separate from Free's private-file export storage.

Docs / Free & Pro

Display detail and saving changes

Understand Essentials, Operator and Expert, and how a visible draft becomes saved configuration.

Where to start

Display detail control on Logged.ai workspace pages

Choose how much to see

Essentials emphasizes readable stories and guided controls. Operator opens working controls and filters. Expert exposes more source detail, precise values and diagnostics.

Display detail changes presentation only. It does not change collection, alerts, response policies, stored evidence or permissions. You can open individual details at any level.

Save each form deliberately

A form's own Save or Apply action commits its changes. An unsaved marker describes edits in that form; it is not confirmation that the server stored them. Undo edits restores the form's saved values.

Changing Display detail preserves open work and edits. A preview is also not a save. Read the result panel after submitting, especially for enabled states, replay and destination availability.

If another administrator changed the same configuration, reload current settings and review your intended change again. Do not treat a stale-form error as a completed save.

Docs / Free & Pro

Collection, attribution and coverage

Know which view you are reading and what an absent event, unfamiliar actor or summary count means.

Where to start

Logged.ai → Settings → Collection controls; Activity → Events

Collection and filters are different

Collection controls determine the supported categories recorded on your site. Activity filters select from already-retained records. A preset or exclusion is a collection choice; changing a filter does not change future capture.

Supported collectors cover WordPress account, content, settings and component activity, with WooCommerce-specific activity. General WordPress hooks are not dedicated coverage for every SEO, forms, membership or custom-field plugin.

Preserve uncertainty

Check acting user, affected object, execution channel and observed outcome separately. A background action or unknown actor should not be reassigned to whichever administrator is currently looking at the screen.

A deleted user can leave a retained identifier without a current profile. Before/after values can be minimized or unavailable. The absence of a field or record is not proof that no operation occurred.

Read summaries within their scope

Overview cards and the activity map summarize a retained sample. They are not a complete traffic count or network-topology map. Request minute groups count admitted observations, not unique attackers.

Activity cannot reconstruct unsupported direct database edits or events missed before activation, during a gap or after retention removed them. Local storage also does not make the evidence independently immutable.

Docs / Free & Pro

Privacy, retention and erasure

Choose address privacy, review deletion effects and distinguish deactivation from uninstall.

Where to start

Logged.ai → Settings → Privacy and retention

Address privacy

Request IP mode offers Masked, Full derived address and Disabled. Masked is the default and represents shared network context. Disabled removes address context and makes source targeting unavailable. Full records the derived address until its separate expiry.

No IP pseudonym is retained. More private choices immediately restrict what is displayed or exported; removing older stored copies uses bounded cleanup. Administrative activity events do not retain IP addresses.

Retention

  1. Review the saved periods for administrative events, request observations, request groups, inactive response history, exact client addresses and diagnostics.
  2. If shortening a period, read the specific affected-data explanation and acknowledge irreversible removal. Separate purge permission is required.
  3. Choose Save privacy settings, then inspect Retention status. Use the confirmed Prune expired events action only when you intend to remove one expired batch.

Personal-data requests

WordPress privacy tools match an email to an account on the current site. Export Personal Data supplies a reference for an authorized administrator to review associated audit records; Logged.ai does not add those activity records to the WordPress download.

Erasure requires both WordPress privacy permission and evidence-purge permission. It removes matching evidence and linked request-address context, not the WordPress account. After an account is deleted, email cannot recover its former ID; an authorized operator needs the known ID for the scoped privacy CLI. Other sites need separate authorized requests.

Leaving the plugin

Deactivation preserves data. Uninstall preserves it unless an administrator with installation-purge permission explicitly saves the deletion choice. That choice covers Logged.ai data across the WordPress installation, including its sites and networks. It is not a routine update step.

Already-downloaded exports and reports cannot be recalled by later erasure.

Docs / Free & Pro

Site, network and permission boundaries

Use the workspace that owns the evidence and keep viewing, settings and deletion permissions distinct.

Where to start

Site Admin → Logged.ai; Network Admin → Logged.ai

Choose the right scope

The site workspace follows the current authorized WordPress site. Network Admin has a separate Logged.ai workspace for network-origin evidence, network exports and network privacy settings.

A network-origin export does not combine all site timelines. Other networks and individual sites have their own scope. Logged.ai's WordPress multisite views are not a shared dashboard for unrelated client installations.

Permissions remain separate

Viewing events does not automatically permit changing settings, exporting evidence, examining sensitive address context, managing response or purging data. Navigation shows only registered pages that your current account can access.

Pro investigation and reporting workflows also check evidence authority. A shared search or an authenticated link does not grant missing permissions. If a page becomes unavailable, check the current account, site context, active plugin pair and assigned permissions.

Operational planning

Use a staging copy of your own multisite arrangement before rollout. Confirm compatibility with the WordPress, WooCommerce and multisite versions you use. Commercial site allowances are a separate licensing policy from WordPress capabilities.

Docs / Free & Pro

Troubleshoot without losing context

Separate a collection gap, a queued job and a delivery problem, then prepare a minimized diagnostic record.

Where to start

Logged.ai → Settings → System status

When activity is missing

  1. Confirm the correct WordPress site and current filters in Activity. Reset the filters if necessary.
  2. Check Collection controls for excluded categories and Privacy and retention for the relevant evidence period.
  3. Open System status and read the collection, retention and background-work state. Preserve the exact failure code and when it occurred.
  4. For request visibility, use Requests → Source and verification and the Observer self-test. Remember that cached and upstream traffic may be outside the observer.

When a job or notification stalls

Inspect the specific export, report or alert history. Pending, cancelled, suppressed, failed and accepted are different results. A returned background tick does not prove all work completed, and WordPress scheduling depends on the host's cron setup.

For advanced alerts, check both saved rule state and destination state. For private background exports, resolve the storage requirement shown by the interface. Do not change filesystem permissions to make private files publicly accessible.

Prepare diagnostics

Under Diagnostic export preview, inspect the complete snapshot before confirming Download diagnostic JSON. The preview describes versions, scoped counts, configuration flags and sanitized state codes; it excludes audit records, credentials, recipient addresses, destination URLs and private paths.

The preview expires after five minutes. Reload for a fresh preview if needed. Keep raw activity, webhook URLs, encryption keys and customer information out of ordinary support messages.

Docs / Free & Pro

Update the pair and resume a schema upgrade

Use the matched development pair and follow recorded upgrade state instead of uninstalling to start over.

Where to start

WordPress → Plugins; Logged.ai → Settings → Schema upgrade when offered

Update with a recovery point

  1. Back up the current database, plugin files and any separately configured private keys or storage. Keep the previous package pair available.
  2. On staging, follow the current package instructions: update Free first, then the matching Pro ZIP. Do not uninstall as an update method.
  3. Open Logged.ai and inspect any compatibility or schema-upgrade message before continuing normal work.
  4. When Schema upgrade is offered, inspect its status and choose Run next upgrade phase. Each submission advances one resumable phase; scheduled work may also resume it when cron runs.
  5. After completion, check System status, saved configuration and a small representative workflow on your own site.

If the upgrade pauses

A busy message can mean another upgrade is running; retry later rather than bypassing the lock. Preserve the recorded error if a phase cannot complete. Do not delete tables, reset checkpoints or repeatedly reinstall to hide the failure.

Schema changes are additive and checkpointed in the implementation, but a code rollback is not a database restore. Activity missed while an incompatible phase is pending cannot be reconstructed. Recovery must keep code compatible with the current data.

Current limits

These instructions describe the 0.1.1-dev Studio v7 pair. Public release and paid update delivery are not yet available. Do not assume a paid updater is connected because a Pro connection or updates screen exists.