Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Illustrative situation
A client site has several plugins with no clear owner. The agency needs to assign purpose, renewal, security and update responsibility before removing anything.
Choose the approach
A plugin may be inactive yet retain sensitive data or license obligations.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Ownership includes who tests affected business flow, not only who clicks Update.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Build component list
- Where
- WordPress Plugins and must-use inventory
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Slugs, versions, active state, vendor
- Action
- Record ordinary and must-use plugins, versions and installed sources. Note components absent from xCloud update list.
- Expected result
- A complete ownership worksheet.
- Verify
- Cross-check WordPress and xCloud lists.
- If it fails
- If an unknown plugin appears, investigate its source before editing it.
Sources: Manage WordPress plugins
Step 2 of 5
Map purpose to journey
- Where
- Client site and staff
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Forms, checkout, booking, analytics, security
- Action
- For each active component, name the task it supports and the person who can verify it. Flag duplicates and abandoned features.
- Expected result
- A dependency map with criticality.
- Verify
- Ask the owner to demonstrate one critical journey.
- If it fails
- If nobody can explain a plugin, leave it installed pending safe staging analysis.
Sources: Manage WordPress plugins
Step 3 of 5
Assign commercial ownership
- Where
- Vendor portal and client contract
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- License holder, renewal date, support entitlement
- Action
- Record who owns license, renewal, vendor notices and support access. Document a separate owner-led credential handoff through the approved secret manager; do not transfer credentials in this inventory task.
- Expected result
- A renewal and support owner.
- Verify
- Ask the owner to confirm the recipient and handoff channel.
- If it fails
- If license belongs to a former agency, plan transfer or replacement.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Step 4 of 5
Assign change accountability
- Where
- Agency maintenance plan
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Update approver, tester, window, rollback owner
- Action
- Give each critical plugin a person who reviews advisories, stages updates and decides release or deferral.
- Expected result
- A repeatable change path.
- Verify
- Check one pending update has tester and recovery point.
- If it fails
- If no tester is available, escalate before automatic update policy changes.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Manage WordPress updates with Updates Manager
Step 5 of 5
Review removals safely
- Where
- Staging copy and client approval
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Candidate plugin, data export, test cases
- Action
- For a redundant component, export needed data, disable it on staging and run its affected tasks. Schedule production removal separately.
- Expected result
- A supported keep/replace/remove decision.
- Verify
- Compare task results before and after staged disablement.
- If it fails
- If a business flow fails, restore the plugin and record dependency.
Sources: Manage WordPress plugins · Create a staging environment in xCloud
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recovery decisions
If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- plugin-ownership decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Build component list Map purpose to journey Assign commercial ownership Assign change accountability
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Assign change accountability Review removals safely
Sources
- xCloud agent capability boundaries
- xCloud MCP documentation and connection profiles
- Manage WordPress core, themes and plugins
- Site backups in xCloud
- WordPress security hardening
- WordPress roles and capabilities
- Create WordPress pages
- Manage WordPress plugins
- Manage WordPress updates with Updates Manager
- Create a staging environment in xCloud