Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Illustrative situation
An agency inherited a WordPress portfolio with inconsistent domains and owners. It needs a current inventory so backups and incidents reach the right people.
Choose the approach
Use stable xCloud site IDs alongside domains, since domains can change.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Keep credentials out of the inventory; link to approved secret storage instead.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Enumerate authorized sites
- Where
- xCloud teams and Sites
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Teams, site IDs, production/staging flags
- Action
- List every WordPress site accessible to the agency, including staging and inactive entries. Do not include another client's team by assumption.
- Expected result
- A preliminary portfolio table.
- Verify
- Compare site counts to client contracts.
- If it fails
- If a site appears without contract ownership, flag it for review.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Create a staging environment in xCloud
Step 2 of 5
Resolve service identity
- Where
- DNS, xCloud domain and WordPress settings
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Canonical host, aliases, server, WP version
- Action
- Record domains, server IDs and WordPress versions for each site. Identify demo hosts and redirects separately.
- Expected result
- A reliable site-to-domain map.
- Verify
- Open a sample public URL and compare dashboard mapping.
- If it fails
- If domain points elsewhere, investigate before recording it as live.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Step 3 of 5
Attach operational owners
- Where
- Client contacts and agency roster
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Maintainer, DNS, mail, payment and backup owners
- Action
- Assign a named person or team for each dependency and emergency contact. Note which providers live outside xCloud.
- Expected result
- A complete escalation path.
- Verify
- Ask owners to confirm access and responsibility.
- If it fails
- If a dependency has no owner, mark it as a risk rather than filling a placeholder.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Step 4 of 5
Check recovery coverage
- Where
- xCloud Site Backup
- Permissions
- Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.
- Inputs
- Latest Completed row, scope, destination
- Action
- Add latest backup time, files/database scope and restore-test date for each production site.
- Expected result
- A portfolio view of recovery gaps.
- Verify
- Spot-check a high-value site against backup history.
- If it fails
- If a site lacks a completed backup, open a corrective task immediately.
Sources: Site backups in xCloud · xCloud agent capability boundaries
Step 5 of 5
Protect and refresh inventory
- Where
- Agency knowledge base
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Access list, update cadence, source timestamp
- Action
- Restrict the inventory, link secrets indirectly and refresh it after site creation, migration, domain change or client offboarding.
- Expected result
- A maintained operational source of truth.
- Verify
- Verify one recent change appears in the table.
- If it fails
- If two inventories disagree, reconcile IDs and owners before incident use.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recovery decisions
If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- site-inventory decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Enumerate authorized sites Resolve service identity Attach operational owners Check recovery coverage
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Check recovery coverage Protect and refresh inventory