WordPress roles and capabilities are a useful starting point, but some access decisions need more context or need to be repeated across sites. Advanced Access Manager (AAM) uses JSON access policies to describe those decisions in a document that a team can read, review, and reuse.
What is an access policy?
An AAM access policy is a JSON document with statements that define access to WordPress resources and actions. A policy can also include parameters and dependencies when a rule needs them. AAM can attach a policy to an access level such as a role, an individual user, or visitors, and it can be revoked when it no longer applies.
Think of the policy as a written answer to a question such as: Which actions should this editor be allowed to perform? The rule stays explicit instead of being scattered across one-off settings or custom code.
Why use policies across sites?
Policies are useful when the same access standard needs to be applied repeatedly. An agency might define a baseline for client editors; a larger team might maintain a policy for a specialized integration. Keeping the rule in JSON makes it easier to inspect, share, and revise. AAM also records policy revisions, so teams can trace changes over time.
The best starting point is one narrow, testable decision. Write down the identity affected, the action, the resource, and any exception. Then build the policy, attach it to the intended access level, and verify the result with a representative account.
Learn the policy format
The JSON Access Policy guide explains the available policy structure and how to work with it. Start with the policy overview for statements, parameters, and dependencies before writing a rule for a live site.