# AI-assisted content under control and with an audit trail

> How to produce content with an AI assistant on Joomla without anything going live on its own, and with a record of every action, using drafts, approval and audit.

# AI-assisted content under control and with an audit trail

## The situation

An editorial team wants an AI assistant to prepare article drafts, tidy categories and suggest changes to pages. The person responsible for the site sets conditions: nothing is published until a person has seen it, there must be a way to tell what the assistant did and when, and it gets no more permissions than it needs.

## How it is solved

With [evoMCP](https://evoaddons.com/en/products/evomcp) the control sits in the server, not in trust in the assistant.

1. **Minimum permissions.** The assistant's connection has write permission on content only. Users, orders and leads stay switched off until you grant them.
2. **Draft and provenance.** What an agent creates is saved as a draft, with its provenance recorded: connection, date and reviewer. Publishing is a sensitive action, not a side effect.
3. **Simulate first.** Almost every write tool supports `dry_run`, and validation up front shows what a call would do without running it.
4. **Human approval.** In the recommended mode every write is returned as `pending_approval`. An administrator reviews the exact arguments under *Approvals* and decides. The assistant reads the outcome with `evomcp_approval_status`. Two other modes exist (only destructive or sensitive actions, and no approval), but actions on users and extensions always need approval.
5. **Audit.** Every call is recorded with connection, user, tool, a summary or hash of the parameters, the result and latency, chained with hashes so that an edit or deletion of entries is detectable. Retention is configurable (90 days by default) and a daily task purges what has expired.

Content that comes from third parties (an article's text, for example) is returned to the assistant marked as untrusted, and tools that return personal data flag it.

## What is involved

- [evoMCP](https://evoaddons.com/en/products/evomcp): connections, approvals, `dry_run`, drafts with provenance and the audit log.
- Content tools and, where needed, generic Joomla entities (categories, tags, menus, modules).
- Documentation: [settings](https://evoaddons.com/en/documentation/evomcp-settings), [tool reference](https://evoaddons.com/en/documentation/evomcp-reference) and [data it handles](https://evoaddons.com/en/documentation/evomcp-data).

## Limits

- The hash chain detects that someone has tampered with the log; it does not prevent it.
- The audit log contains personal data (user, parameter summaries). Keep retention as short as you can.
- An approval runs under the identity of the connection's user.
- evoMCP does not judge whether the text is right. The person reviewing the draft does.
- What obligations your organisation has when using AI for content depends on your case. This is not legal advice; consult your adviser.

## Related products

- [evoMCP](https://evoaddons.com/en/products/evomcp)

---

https://evoaddons.com/en/use-cases/governed-ai
