Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the Open Webui application. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
For a Docker app, identify persistent volumes, bind mounts, external databases and app-level export requirements. A Docker backup briefly stops the app, and an in-place restore replaces current state. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Illustrative situation
A team runs Open WebUI for internal AI chat. It needs to verify model connectivity, user access, data handling and resource limits rather than treating the installed UI as a ready model.
Choose the approach
Open WebUI is an interface; a separate model endpoint and compute capacity are required for actual responses.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Admin users can access broad settings and data; test limited user behavior with non-sensitive prompts.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Map model dependencies
- Where
- Open WebUI admin and model provider
- Permissions
- Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Model endpoint, credentials, expected latency
- Action
- Record which provider or local model serves requests, who owns it and where prompts/logs are retained.
- Expected result
- A clear dependency and data map.
- Verify
- Check endpoint is reachable from app network.
- If it fails
- If no model endpoint exists, label the UI installed but unusable for chat.
Sources: Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls
Step 2 of 5
Review users and settings
- Where
- Open WebUI admin settings
- Permissions
- Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Admin/limited roles, signup, retention controls
- Action
- Inspect registration policy, groups and model visibility. Use a limited account for first tests; keep credentials outside prompts.
- Expected result
- A controlled access baseline.
- Verify
- Sign in as limited user and inspect available models/tools.
- If it fails
- If user sees unintended tools or data, correct permissions before rollout.
Sources: Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls
Step 3 of 5
Measure one safe request
- Where
- Open WebUI chat and model endpoint metrics
- Permissions
- Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Non-sensitive prompt, expected response
- Action
- Send a harmless question using the intended model. Record actual latency, error and resource use without assuming a specific performance level.
- Expected result
- An observed end-to-end response.
- Verify
- Confirm model ID, output and server resource trend.
- If it fails
- If request fails, separate UI, provider authentication and model capacity.
Sources: Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls
Step 4 of 5
Review retention and exposure
- Where
- Open WebUI data/settings and privacy owner
- Permissions
- Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Chat retention, upload policy, external provider terms
- Action
- Decide what data users may submit, what the UI stores and whether provider receives it. Test deletion and account behavior if required.
- Expected result
- A usable data policy.
- Verify
- Ask a test user to find their conversation and permitted deletion path.
- If it fails
- If behavior differs from policy, restrict access until resolved.
Sources: Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls
Step 5 of 5
Check backup and updates
- Where
- xCloud Docker Backup and runbook
- Permissions
- Authorized xCloud team/site operator with the discovered write scope for this exact operation and owner approval for its target and interruption.
- Inputs
- DB/volume paths, model endpoint owner, backup
- Action
- Verify a Completed backup of app state, then rehearse a safe restore of test chat/config. Assign update and model-outage responders.
- Expected result
- A recovery plan for UI state and model dependency.
- Verify
- Test login and model request after rehearsal.
- If it fails
- If model endpoint is external, document its separate recovery owner.
Sources: Back up and restore Docker apps · Docker backup operations and storage constraints · Open WebUI administrator and model connections
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Recovery decisions
Before data recovery, identify incident time, completed backup, target and records created after the snapshot. Preserve current evidence and live data before replacement.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
Use the documented dashboard or application recovery procedure with the authorized owner. Repeat the task-specific limited-user check; reconcile newer records before reopening writes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Open WebUI administrator and model connections · Open WebUI role and group access controls · Open WebUI conversation data controls · Back up and restore Docker apps · Docker backup operations and storage constraints · xCloud One Click Apps catalog
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized Open Webui administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- ai-ops decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Map model dependencies Review users and settings Measure one safe request Review retention and exposure
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Review retention and exposure Check backup and updates
Sources
- xCloud agent capability boundaries
- xCloud MCP documentation and connection profiles
- Open WebUI administrator and model connections
- Open WebUI role and group access controls
- Open WebUI conversation data controls
- Back up and restore Docker apps
- Docker backup operations and storage constraints
- xCloud One Click Apps catalog