

The log: what each change arrived on, which application password authenticated it, what it touched and which fields. The same entries are readable over the REST API.
An AI agent, a headless front end, a sync script and a cron job all reach WordPress the same way a person never does: over an API. When something on the site is not what you left it as, the question is not “who changed this” but “did a person change this, or did something else”.
This plugin answers that question and only that question. It records changes that arrived over the REST API, WP-Cron, WP-CLI or XML-RPC. A change made by a person clicking in wp-admin is not recorded – not filtered out afterwards, not stored and hidden, simply never written.
General activity logs record everything, which means the automated change you are looking for is one line in a thousand made by your own team. This one starts from the other end. If you already run an activity log, this sits beside it and answers a different question.
rest, cron, cli or xmlrpc.On its own admin screen, filtered by channel, object type and date range. Or over the REST API at digitizer-ai-agent-log/v1/activity, which requires manage_options. There is deliberately no route that deletes: a log that can be erased through the API is a log an attacker erases on the way out.
Each site keeps its own log, in its own table, and a run that switches between sites files each change under the site it happened on.