Multisite operations · Field guide 06
WordPress Multisite Settings History and Safe Undo
The short answer.
ConfigOps keeps each site’s settings evidence isolated and separates it from Network Admin changes: per-site ledgers record supported option writes, while a distinct network ledger records supported Network Options changes.
Read the practical guideMultisite has two configuration scopes.
A network-active plugin must preserve the difference between a setting on one site and a value shared at network level. Combining them into one undifferentiated feed makes recovery harder and riskier.
Site scope
One site ledger
Supported option changes stay attached to the site where the authorized request occurred.
Network scope
One Network Admin ledger
Supported Network Options additions and updates are recorded separately from individual sites.
Recovery scope
One mutation at a time
Network recovery is intentionally narrower and requires complete evidence plus a current-state match.
Isolation is the safety feature.
Network activation should not turn every site’s history into a global stream. ConfigOps preserves the site identifier with each observation and exposes network-level evidence in its own context.
- 01
Confirm the scope
Identify whether the change happened in a site dashboard or Network Admin before searching for evidence.
- 02
Open the right ledger
Review per-site observations in that site and supported Network Options in the separate network history.
- 03
Respect narrower undo
Network option additions and updates can be undone individually when complete evidence still matches.
Evidence stays in WordPress. A conflict, redacted value, incomplete observation, or unsupported storage path prevents automatic Undo.
Read the support contractRecovery procedure
Match the request. Check the current value. Choose the restore scope.
Site settings and network settings are not interchangeable
Each site in a WordPress network has its own option scope. Network Options hold values intended for the network context. The same plugin can expose controls in both places, so an incident report should always state the site ID or Network Admin screen where the save occurred.
ConfigOps maintains isolated evidence for each site and a separate network ledger. That structure helps an operator establish blast radius before considering recovery: one site, one network option, or a broader problem outside supported settings.
- Network and site identifier, including the relevant admin URL.
- Whether the action occurred in a site dashboard or Network Admin.
- Acting user, component, request time, and expected scope.
- A verification performed in every site or network context that could be affected.
What safe network Undo supports
ConfigOps 0.7.0 can undo complete supported network option additions and updates one mutation at a time. It uses the same central rule as site-level recovery: the current network value must still match the captured result.
Named Network Change Sessions can group network-owned evidence across requests, but they do not enable whole-session undo. Network deletes, cross-site aggregation, and bulk actions remain unavailable. These are explicit product limits, because broad network operations need stronger evidence and conflict semantics than a convenient button can provide.
When a network change may affect many sites, inspect and verify its scope before restoring anything. Convenience is not evidence.
Build a Multisite recovery runbook
Assign ownership for network-level settings and keep tested backups that understand your database and file topology. Before a planned network change, define the sites used for verification and the signal that would trigger rollback.
During an incident, stop repeated edits, preserve the current state, locate the relevant site or network observation, and test the smallest recovery on staging when possible. If the cause crosses code, content, or custom storage, escalate to the corresponding recovery system instead of stretching a settings undo beyond its scope.
Sources and next steps
Undo boundaries
Can ConfigOps undo this save?
Check whether the request was observed, its evidence is complete, and current values still match.
Does ConfigOps combine every site into one history?
No. Site evidence remains isolated, and Network Admin changes have a separate ledger.
Can ConfigOps undo Network Options changes?
Version 0.7.0 supports complete network option additions and updates one mutation at a time when the current value still matches.
Can it undo a whole network change at once?
No. Whole-change network undo, network deletes, cross-site aggregation, and bulk actions remain unavailable.