POM AI setup checklist
Use this before the first production content is generated, and again whenever a site is cloned, migrated or handed to a new team. Each item is a state you can verify on screen, not an intention.
Licensing and authorization
- [ ] Settings → POM AI → License shows a masked key and a valid status.
- [ ] The Domain line matches the site's real public host.
- [ ] The plan and expiry dates shown are the ones you are paying for.
- [ ] The credit balance loads on that tab.
- [ ] On multisite, every subsite that will use AI has saved its own key; the main site's key has been saved separately for updates.
- [ ] Nobody outside the team can reach the License tab. It requires
manage_options.
A validated license that shows the wrong domain usually means the site was migrated after activation. Revalidate from the new host.
Business context
- [ ] Your business short description is filled in and reads like a real positioning sentence, not a placeholder.
- [ ] The structured profile covers the applicable brand, offering, audience, positioning, voice, vocabulary, restrictions, proof, visual and translation sections.
- [ ] The profile counter stays at or below 50,000 characters.
- [ ] On a multilingual site, the short description and relevant profile sections have been reviewed in each language.
- [ ] Someone owns keeping these fields current when the business changes.
Generic output almost always traces back to a thin or stale description here rather than to the tool that produced it.
Enabled tools
- [ ] Only the tools you actually use are ticked under AI Tools.
- [ ] Each enabled tool has been run once on a harmless example.
- [ ] The translation tool is only enabled if Polylang or Polylang Pro is active.
- [ ] Every enabled tool's menu entry appears where the interface tour says it should.
Who can generate
- [ ] You know which roles hold
edit_postsandupload_fileson this site, because those are the capabilities that grant access to the writing and media tools. - [ ] No account that should not spend credits has those capabilities.
- [ ] Editors have been told that generation costs money from a shared account balance.
Credits and spend control
- [ ] The current balance is enough for the intended workload.
- [ ] The team knows to use the estimate-and-confirm path rather than generating directly until they know a tool's typical cost.
- [ ] If several sites share one account, a per-domain spending limit has been considered in My Account → POM AI Management on account.pom.es.
- [ ] Someone monitors the usage log in that same screen.
See POM AI credits.
Prompt templates
- [ ] Templates that the team should reuse have been saved under Settings → POM AI → Prompt templates.
- [ ] Each template is assigned to the contexts where it makes sense, and no others.
- [ ] No template contains customer data, credentials or unpublished commercial information.
Templates are visible to everyone who can use the tools, so treat their content as shared internal text.
Editorial review
- [ ] A named person reviews generated text before publication.
- [ ] A named person verifies image rights, alternative text and cropping before generated images go on public pages.
- [ ] Translations are reviewed by someone who reads the target language.
- [ ] The team knows that generated output is a draft, not a finished asset.
Review AI output responsibly sets out what "review" needs to cover.
Privacy
- [ ] The team knows what is transmitted to the account service and what is not. See Understand data sent for AI processing.
- [ ] Prompts do not contain personal data about customers or staff unless there is a lawful reason and it is necessary for the task.
- [ ] Screenshots shared with support are redacted.
MCP, if used
- [ ] POM AI MCP is enabled deliberately, not by accident.
- [ ] Only the write gates you need are on: content, options, POM Theme and WooCommerce catalog are four separate switches.
- [ ] Connected clients have the narrowest scopes that let them work.
- [ ] The allowed CORS origins list contains only origins you control.
- [ ] Log retention matches your internal policy.
Start from POM AI MCP if any box above is unclear.
Operations
- [ ] The site can make outbound HTTPS requests and this is documented for whoever maintains the server.
- [ ] Updates are configured: on multisite, POM AI is network-active or active on the main site.
- [ ] A rollback plan exists for bulk operations, particularly bulk image metadata and bulk translation.
- [ ] Bulk operations have been tried on staging before production.
Sign-off
The checklist passes when every box is ticked from the actual screens, on the actual site, by someone who can also fix what fails. A checklist completed from a staging clone does not describe production.