Back to blog

Blogo Team

WordPress AI Writing Workflow: Connect, Review and Save Drafts

A seven-step WordPress AI writing workflow: pick the right user role, connect with an application password, send drafts only, verify the saved post and publish by hand.

A safe WordPress AI writing workflow has three separate actions: the tool writes, a person approves sending the text to the site, and a person publishes. Keep those apart and the worst outcome is a draft nobody liked. Merge them and the worst outcome is an unreviewed article about your products, live, with your company name on it.

WordPress already has what you need to enforce this: user roles, post statuses and application passwords. The seven steps below use them, and each step ends with a check.

The three WordPress features this relies on

Post status. Every post has one. WordPress's post status documentation lists them: draft (not public), pending (waiting for someone with publishing rights), future (scheduled), private, and publish (visible to everyone). An AI tool should only ever create draft or pending.

User roles. What an account can do depends on its role. Under WordPress's roles and capabilities, a Contributor can write and manage their own posts but cannot publish them; an Author can publish their own posts; an Editor can publish anyone's.

Application passwords. WordPress supports application passwords for outside tools: a separate password generated on a user's Edit User screen and used over HTTPS, so the tool never holds the password that person logs in with.

Choose the role for the integration account

Give the tool its own WordPress user rather than borrowing a person's login. The role you assign is the real safety setting; a "save as draft" checkbox inside the tool is only a preference.

Role for the tool's accountCan create draftsCan upload imagesCan publishUse when
ContributorYesNoNoThe tool sends text only, and you want WordPress itself to block publishing
AuthorYesYesYes, own postsThe tool must upload images; you accept relying on the tool's draft-only behaviour
EditorYesYesYes, any postThe tool must edit posts created by other users
AdministratorYesYesYes, plus site settingsAvoid for a writing tool

Start with Contributor if the tool works with it. If it needs more, grant Author and compensate with step 5 below. Some tools ask for an administrator account in their setup guide for convenience; ask the vendor what the lowest working role is before agreeing.

The workflow in seven steps

1. Create the account and the application password

The site administrator creates a user named for the tool (for example "ai-drafts"), assigns the role chosen above, and generates an application password on that user's profile, labelled with the tool's name and the date.

Pass: the tool has its own user; the password is labelled; nobody's personal login was shared.

2. Connect over HTTPS and store the password once

Enter the site URL, username and application password in the tool's connection screen. Keep the password out of chat prompts, screenshots, tickets and emails. If it was ever pasted somewhere it should not be, delete it and generate a new one.

Pass: the tool reports a successful connection to an https:// address, and the password exists only in the tool and the administrator's password manager.

3. Send a test draft

Before any real article, send a short test post. Open WordPress and find it under Posts, in the Drafts filter.

Pass: the test post exists, its status is Draft, its author is the integration user, and nothing new appears on the public blog page.

4. Review the article before it leaves the tool

Check facts, links and the call to action while the article is still in the writing tool. If a sentence is waiting on an engineer or the owner, the article waits too. Use the AI article fact-check process for the claims and the technical writing workflow when a specialist must sign off.

Approve one article for one site at a time. A setting that sends every finished article automatically removes this step, and with it the reason for having a workflow.

Pass: every factual sentence has an owner who confirmed it, and a named person said "send this one".

5. Send, then verify what arrived

Send the article. Then look at the post in WordPress, because the tool's "success" message only reports that WordPress accepted a request.

Check in WordPressPass looks like
StatusDraft or Pending. Not Scheduled, not Published
Title and slugThe title you approved; a short, readable slug
BodyHeadings are headings, tables are tables, no stray markup
LinksInternal links point to live pages on your own domain
AuthorThe integration user, or reassigned to the right person
DuplicatesExactly one post with this title in Drafts

Open the preview as well. Formatting that looked right in the tool can break in your theme, tables especially.

6. Finish the post in WordPress

Some fields are yours to set, whatever tool you use: category and tags, featured image, the meta description in your SEO plugin, the author shown to readers, and any custom fields your theme uses. Check whether your tool fills any of them, and treat the rest as a fixed list to complete by hand.

Pass: the post has a category, a featured image and a meta description, and the preview looks like your other articles.

7. Publish by hand

A person with publishing rights reads the preview one last time and presses Publish or schedules it. Then open the public URL in a private browser window to confirm that the live page is the version you approved.

Pass: the post is public, the URL is the intended one, and the person who published is recorded.

When a send times out

This is the failure that creates duplicates. The tool shows an error or spins indefinitely; WordPress may or may not have saved the post.

Do not press send again yet. Open Posts and look in Drafts for the title. If it is there and complete, the send worked and only the reply was lost. If it is there but cut short, delete that draft and resend. If it is absent after a minute or two, resend once.

Should the same timeout recur, look on the hosting side. A security plugin or firewall blocking outside requests is a common cause, and the person to ask is the site administrator.

Editing after the draft is in WordPress

Decide where edits happen. If you correct the text in WordPress and later resend from the tool, you may get a second draft or lose your corrections, depending on how the tool handles updates.

The simplest rule is that once a draft is in WordPress, WordPress is the master copy. Its revisions feature keeps a record of each saved draft and lets you compare and restore earlier versions, which covers mistakes made during editing.

Disconnecting

When you stop using a tool or change vendors:

  1. Turn off any scheduled or queued sends in the tool.
  2. Disconnect the site in the tool's settings.
  3. Have the administrator delete the application password, then the integration user if it is no longer needed. Reassign that user's posts to a real person first.
  4. Check Drafts for unfinished posts the tool left behind.

Revoking access leaves existing posts untouched. Drafts stay drafts and published posts stay published until someone changes them.

A draft-only tool, as an example

Blogo creates WordPress drafts only. It sends the title, body and slug with the status set to draft, and it never publishes; the WordPress drafts documentation covers the connection and what is sent. The meta description, categories and featured image are set by the owner in WordPress, which is step 6 above. The WordPress draft writer page covers the product side.

FAQ

Does saving a draft make the article public?

No. A draft is visible only to logged-in users with the right role. It becomes public when someone publishes it.

Should the AI tool use my administrator login?

No. Give it its own user with the lowest role that works, and an application password. If that password leaks, you delete one password instead of resetting your own account.

Can an AI tool publish directly to WordPress?

Many can, and some do by default. Whether it should is your decision. For articles that state product facts, the cost of a person pressing Publish is a minute, and the cost of a wrong specification going live is a customer acting on it.

What if the tool needs the Author role but I don't want it publishing?

Confirm in step 3 that it sends drafts, check the status after every send as in step 5, and ask the vendor in writing whether any setting or update could change that behaviour.

Does the draft keep its formatting?

Usually headings, lists, links and tables arrive intact, and theme styling differs. That is why step 5 includes the preview. Fix formatting in WordPress, not by resending.

Who should be allowed to publish?

Whoever is accountable for what the company says in public. In a small manufacturer that is often the owner or sales manager. Marketing prepares; they press the button.

Want Blogo to draft your next article?

Start with your website. You check every fact before anything goes to WordPress.