Once you've connected an assistant, it can read your account and, if you turn on action permissions, propose changes to DNS, mailboxes, WordPress, PHP, cron jobs, FTP, and cache. Every action works the same way: the assistant shows you exactly what it wants to do, and nothing happens until you approve it. It never touches your password, your payment methods, or your account identity.
This article lists what's actually wired up today, grouped by area, plus how to see what an assistant has done and how to cut it off.
How an action actually runs
The pattern is the same for every tool the connector exposes: you ask in plain language, the assistant calls the matching tool, and instead of applying the change immediately it returns a proposal, a summary of exactly what will change. You review it and say yes. Only then does the change happen. If you say no, or don't respond, nothing is touched. This two-step flow is what makes it safe to grant action permissions in the first place, and it applies whether you're using Claude, ChatGPT, Gemini, Cursor, or Perplexity, since they all talk to the same connector.
DNS and domain lookups
An assistant with DNS permission can add, edit, or remove DNS records for a hosted domain, and can look up WHOIS data for any domain. Keep in mind the split that governs the portal itself: DNS records (A, CNAME, MX, TXT, and so on) live under your hosting's DNS Zone Editor, while the domain's own DNS tab only changes nameservers. An assistant proposing a record change is working in the same place a human would.
Billing visibility
Reading is where this is most useful without any risk. An assistant can pull your invoices and tell you what's unpaid, overdue, or paid, and check renewal dates on a service or domain. It cannot charge a card, add or remove a payment method, or touch anything under Cards on file. Billing actions of that kind only happen when you're signed into the portal yourself.
WordPress management
This is the largest category of action tools. An assistant can update WordPress core, plugins, and themes, toggle a plugin on or off, reset the WordPress admin password, run search-and-replace across the database, create or delete a staging copy, pull site health and debug log output, and toggle maintenance mode. Each of these maps to something WP Toolkit already does in the portal. The assistant gives you a conversational front end with the same confirmation step you'd expect from clicking the button yourself.
Mailboxes, cron, FTP, and cache
An assistant can create a mailbox or reset a mailbox password, add or remove a cron job, create or remove an FTP account or reset its password, and purge cache (including Cloudflare cache, if you've got the CDN goodie enabled). These are the same operations you'd otherwise reach through Email Accounts, Cron Jobs, or FTP Accounts in the portal, or through cPanel directly, as covered in getting around cPanel: the tools that matter.
PHP version
An assistant can switch a domain's PHP version. This only sets the version (7.4 through 8.3), the same scope as the portal's PHP Version tile. It cannot change PHP limits like upload_max_filesize or memory_limit, those still require MultiPHP INI Editor inside cPanel, and no assistant has a tool for that editor.
Support tickets
An assistant can open a support ticket on your behalf, describing the issue for you. It cannot reply inside an existing ticket thread or close one.
What no assistant can ever do
Some things are permanently out of reach, regardless of what permissions you grant. No assistant can make a payment, touch a saved card, change your password or two-factor settings, edit your account contact details, cancel a service, or transfer a domain away. There's also no tool for account-wide PHP limits, for anything in Select PHP Version's extension toggles, or for the Cloudflare CDN's SSL/TLS mode and security settings. Those stay manual for now. If an assistant claims it did one of these, don't trust it. Nothing in the connector can actually perform it.
Reviewing and revoking access
Your portal's Goodies → AI Agents page is the control center: it lists every connected assistant, exactly which tools and permissions each one has, and when it was last used. Disconnecting an assistant there cuts off its access immediately, no ticket needed. If you're setting up a new assistant, the setup guides for connecting an AI assistant, Gemini, and Cursor walk through the connector URL and setup steps for each assistant.
When to open a ticket instead
If an assistant proposes a change you don't understand, decline it and ask us instead: Support, live chat, or email, all answered by real people. Anything account-wide (PHP limits across the whole account, extension toggles, Cloudflare TLS settings) or anything involving payments, passwords, or cancellations needs a human either way, so a ticket or a portal visit is the right move from the start.