Requirements and responsibilities
Have the photographers owner approve public copy, required staff roles and the exact sample journey. A photographer shares galleries and sells selected sessions.
xCloud agent capability boundaries · WordPress roles and capabilities
Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site.
xCloud agent capability boundaries · WordPress plugin administration
Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: A predictable gallery URL is not access control.
Illustrative situation
Illustrative scenario: a photographer publishes approved samples on WordPress and sends a client its finished images through a separate controlled sharing service.
Choose the approach
Choose whether galleries are public, client-private or commerce-enabled. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · WordPress roles and capabilities
Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end.
xCloud agent capability boundaries · WordPress plugin administration
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Define licensing, gallery visibility and delivery dates
- Where
- WordPress or selected application administrator and public test browser
- Permissions
- Named WordPress or selected application administrator; business owner accepts result.
- Inputs
- Define licensing, gallery visibility and delivery dates; named administrator and a harmless representative sample.
- Action
- Define gallery visibility, image license, download permission and delivery deadline for each client collection.
- Expected result
- Private and public work have separate rules.
- Verify
- Private and public work have separate rules. Have the responsible business staff member record the sample identity and observed result.
- If it fails
- If privacy depends only on an unguessable URL, choose real access control.
Sources: WordPress roles and capabilities · WordPress plugin administration
Step 2 of 5
Publish portfolio in WordPress with optimized images
- Where
- WordPress or selected application administrator and public test browser
- Permissions
- Named WordPress or selected application administrator; business owner accepts result.
- Inputs
- Publish portfolio in wordpress with optimized images; named administrator and a harmless representative sample.
- Action
- Publish a small public portfolio in WordPress with optimized previews and clear booking or print-order action.
- Expected result
- Visitors see representative work without private galleries.
- Verify
- Visitors see representative work without private galleries. Have the responsible business staff member record the sample identity and observed result.
- If it fails
- If originals leak through media URLs, revise upload or access settings.
Sources: WordPress roles and capabilities · WordPress plugin administration
Step 3 of 5
Separate public portfolio and client delivery
- Where
- WordPress or selected application administrator and public test browser
- Permissions
- Named WordPress or selected application administrator; business owner accepts result.
- Inputs
- Configure gallery or commerce plugin permissions; named administrator and a harmless representative sample.
- Action
- Publish only public, rights-cleared portfolio images in WordPress. For client-private delivery, choose and configure a documented sharing service such as Nextcloud with its own account owner; WordPress private posts alone do not protect a direct media URL.
- Expected result
- A signed-out visitor sees only public portfolio images; private client assets remain in the separately controlled delivery system.
- Verify
- A signed-out visitor sees only public portfolio images; private client assets remain in the separately controlled delivery system. Record the exact account or record tested, result, and time with the responsible owner.
- If it fails
- If the plugin cannot restrict originals, use another delivery method.
Sources: WordPress roles and capabilities · WordPress plugin administration · WordPress Media Library administration · Nextcloud file sharing administration
Step 4 of 5
Test public and private asset access
- Where
- WordPress or selected application administrator and public test browser
- Permissions
- Named WordPress or selected application administrator; business owner accepts result.
- Inputs
- Test private link access and image download rules; named administrator and a harmless representative sample.
- Action
- Test the public portfolio in an anonymous browser, then test a client share with an authorized client and a different account in the selected sharing service. Check direct link behavior as well as page visibility.
- Expected result
- Only the intended client account or share recipient reaches the private assets under the provider’s configured policy.
- Verify
- Only the intended client account or share recipient reaches the private assets under the provider’s configured policy. Record the exact account or record tested, result, and time with the responsible owner.
- If it fails
- If one client can access another gallery, disable delivery immediately.
Sources: WordPress roles and capabilities · WordPress plugin administration · WordPress Media Library administration · Nextcloud file sharing administration
Step 5 of 5
Back up originals and review access after delivery
- Where
- WordPress or selected application administrator and owner handoff
- Permissions
- Named WordPress/application administrator and business owner; inspect backup separately if recovery is in scope.
- Inputs
- Back up originals and review access after delivery; named administrator and a harmless representative sample.
- Action
- Back up original images separately, remove expired client access and record license terms after delivery.
- Expected result
- The photographer can recover media without reopening private work.
- Verify
- The photographer can recover media without reopening private work. Have the responsible business staff member record the sample identity and observed result.
- If it fails
- If restore revives expired links, audit access before publishing recovered site.
Sources: Site backups in xCloud · xCloud agent capability boundaries · WordPress roles and capabilities
Maintenance
Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: A client views only their gallery and completes the intended inquiry or order. A chat prompt is not a scheduled task.
Manage WordPress updates with Updates Manager · Vulnerability Checker in xCloud
Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone.
Recovery decisions
Before restoring, compare the chosen recovery point with newer business records. A predictable gallery URL is not access control. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first.
Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident.
AI handoff
Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
- Review a WordPress business journey app · manual
Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence.
Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision.
- Configure WordPress content, users and selected plugins app · manual
Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them.
Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey.
WordPress roles and capabilities · WordPress plugin administration
Copyable agent brief
Manual checkpoints
- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Publish only public, rights-cleared portfolio images in WordPress. For client-private delivery, choose and configure a documented sharing service such as Nextcloud with its own account owner; WordPress private posts alone do not protect a direct media URL.
- The business owner compares the controlled sample with this observable result: Only the intended client account or share recipient reaches the private assets under the provider’s configured policy.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.
Feature coverage
- business-acceptance (covered): A client views only their gallery and completes the intended inquiry or order. Test public and private asset access
- recovery (covered): A predictable gallery URL is not access control. Back up originals and review access after delivery
Sources
- xCloud agent capability boundaries
- WordPress roles and capabilities
- WordPress plugin administration
- Site backups in xCloud
- WordPress hardening handbook
- xCloud MCP documentation and connection profiles
- Manage WordPress updates with Updates Manager
- Vulnerability Checker in xCloud
- WordPress Media Library administration
- Nextcloud file sharing administration