Start here
Running the site
An AI assistant can read and edit your site for you, safely and only if you want it to. This page explains what it can do, what it can never see, and how access is controlled.
Cairn can open a connection that AI assistants know how to use, called MCP. Point an assistant such as Claude at your site, and you can ask it in plain words to read your pages, draft copy, restructure a page, fix headings or write search descriptions.
It works through the same rules a person is held to. It cannot save content the editor would refuse, because everything it writes goes through the same checks.
So the usual arrangement is an assistant that drafts, and a person who publishes. All three switches are set by whoever set up your site; ask them if you want one changed.
With changes allowed, it can work across most of the site: pages and their content, the site menu, reusable blocks, the media library, themes, settings, redirects and the 404 log, forms and the catalogue.
It is not a substitute for knowing what you want to say. It is very good at doing what you decided, everywhere, without getting bored.
No customer data. Orders and enquiries are reported only as counts and statuses, and an order is referred to by its number. No name, email, phone number or address is ever passed to the assistant.
This is deliberate: connecting an assistant to a live shop must never put your customers' details in front of it, or in front of the company that runs it.
An assistant connects with an access token, a long secret that works like a password for it. Treat it like an administrator's password: it can do whatever the account it runs as can do, which is usually everything. Use a separate one for each site, never share one between your live site and a test copy, and never paste it into an email or a chat. Every change the assistant makes is logged against its token.
Tokens are issued by whoever set up your site. To see them, go to /admin/integrations on your site. The Integrations screen lists each one under Machine tokens: its name, whether it is active, revoked or expired, which account it Runs as and how many things it can do, and when it was last used.
If a token has been shared by mistake, revoke it straight away and ask for a new one. Revoking can't be undone. If the screen says This site still has an MCP token in its environment, that older kind of token can't be revoked here: ask whoever set up your site to remove it.
← Redirects and the 404 log
Getting started
Pages
Building with blocks
Navigation and look
Media
Forms and leads
Catalogue
Shop
Bookings and members
Websites for businesses that need more than a brochure. Built, hosted and kept running by us.
Start
Build
Run
© 2026 Cairn. All rights reserved.
Built with Cairn.