Skip to main content

An agency manages many sites with an AI assistant

The situation

An agency looks after a dozen Joomla sites, some of them on YOOtheme Pro. The repetitive jobs are familiar: checking which extensions have updates, finding unpublished articles, changing a line of text across several builder pages, seeing which modules are enabled. Someone on the team already uses an AI assistant for other work and wants it to look at the sites and change them too, without handing over a super user password and without losing track of what it does.

How it is solved

Each site runs its own evoMCP, which exposes it as an MCP server at https://the-site/mcp. There is no shared dashboard across sites; each one is configured separately.

On each site you create as many connections as you need. A connection has a Joomla user whose identity and permissions everything runs under, a permission matrix per component (none, read, write or full), an expiry date, allowed IPs, a monthly quota and an approval mode. The effective permission is always the lower of the matrix and what that user can do in the administrator. A new connection starts with read-only access to content.

A sensible split for an agency:

  • A read-only connection for the assistant that runs checks and queries.
  • A second one with write access to content for whoever edits copy, with approval on every write.
  • A third, with system permissions, only for whoever updates extensions, where system actions always wait for approval.

Clients that run on a desktop or the command line use the connection's token. Clients that connect from the browser (claude.ai, ChatGPT) use OAuth 2.1: the client discovers the server, goes through the Joomla login, and on the consent screen you pick the connection and the components to share.

Anything that changes the site supports dry_run, and by default each write stays pending until an administrator approves it with the exact arguments in view. What the assistant creates is saved as a draft. Every call, rejected ones included, goes into the audit log, and usage (calls, errors, latency) is measured per connection.

What is involved

  • evoMCP: endpoint, connections, permission matrix, approvals, audit and usage metering.
  • Tools for content, for Joomla components (menus, modules, media, users, extensions, templates), for YOOtheme (element catalogue, builder nodes, pages, theme settings) and for the system (updates, cache, logs, scheduled tasks).
  • Where to start: first steps and settings.

Limits

  • The YOOtheme tools that edit the builder require the connection user's group to have the text filter set to "No Filtering".
  • System tools are for super users only, and Joomla core cannot be updated from evoMCP.
  • The advanced layer (SQL and files) ships disabled and needs three locks: the plugin enabled, the switch in the options, and full permission on the advanced component. If you do not need it, leave it off.
  • An approval runs under the identity of the connection's user, not of the person who approves it.
  • Some hosts with an application firewall may block requests that look like SQL injection, or bursts of calls.
  • Prices and licences: pricing.

Related products