# Operate an AI chat workload

Review model/provider configuration, access, stored data, updates, and recovery assumptions. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/operations/operate-an-ai-chat-workload/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Review model/provider configuration, access, stored data, updates, and recovery assumptions.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the Open Webui application. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- For a Docker app, identify persistent volumes, bind mounts, external databases and app-level export requirements. A Docker backup briefly stops the app, and an in-place restore replaces current state. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Illustrative situation

A team runs Open WebUI for internal AI chat. It needs to verify model connectivity, user access, data handling and resource limits rather than treating the installed UI as a ready model.

## Choose the approach

- Open WebUI is an interface; a separate model endpoint and compute capacity are required for actual responses. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Admin users can access broad settings and data; test limited user behavior with non-sensitive prompts. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Dashboard and application procedure

### 1. Map model dependencies

**Where:** Open WebUI admin and model provider

**Permissions:** Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Model endpoint, credentials, expected latency

**Action:** Record which provider or local model serves requests, who owns it and where prompts/logs are retained.

**Expected result:** A clear dependency and data map.

**Verify:** Check endpoint is reachable from app network.

**If it fails:** If no model endpoint exists, label the UI installed but unusable for chat.

Capability: Configure and test Open Webui in its application UI
Sources: [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/)

### 2. Review users and settings

**Where:** Open WebUI admin settings

**Permissions:** Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Admin/limited roles, signup, retention controls

**Action:** Inspect registration policy, groups and model visibility. Use a limited account for first tests; keep credentials outside prompts.

**Expected result:** A controlled access baseline.

**Verify:** Sign in as limited user and inspect available models/tools.

**If it fails:** If user sees unintended tools or data, correct permissions before rollout.

Capability: Configure and test Open Webui in its application UI
Sources: [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/)

### 3. Measure one safe request

**Where:** Open WebUI chat and model endpoint metrics

**Permissions:** Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Non-sensitive prompt, expected response

**Action:** Send a harmless question using the intended model. Record actual latency, error and resource use without assuming a specific performance level.

**Expected result:** An observed end-to-end response.

**Verify:** Confirm model ID, output and server resource trend.

**If it fails:** If request fails, separate UI, provider authentication and model capacity.

Capability: Configure and test Open Webui in its application UI
Sources: [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/)

### 4. Review retention and exposure

**Where:** Open WebUI data/settings and privacy owner

**Permissions:** Authorized Open Webui application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Chat retention, upload policy, external provider terms

**Action:** Decide what data users may submit, what the UI stores and whether provider receives it. Test deletion and account behavior if required.

**Expected result:** A usable data policy.

**Verify:** Ask a test user to find their conversation and permitted deletion path.

**If it fails:** If behavior differs from policy, restrict access until resolved.

Capability: Configure and test Open Webui in its application UI
Sources: [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/)

### 5. Check backup and updates

**Where:** xCloud Docker Backup and runbook

**Permissions:** Authorized xCloud team/site operator with the discovered write scope for this exact operation and owner approval for its target and interruption.

**Inputs:** DB/volume paths, model endpoint owner, backup

**Action:** Verify a Completed backup of app state, then rehearse a safe restore of test chat/config. Assign update and model-outage responders.

**Expected result:** A recovery plan for UI state and model dependency.

**Verify:** Test login and model request after rehearsal.

**If it fails:** If model endpoint is external, document its separate recovery owner.

Capability: Create and inspect Docker backups
Sources: [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Recovery decisions

- Before data recovery, identify incident time, completed backup, target and records created after the snapshot. Preserve current evidence and live data before replacement. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Use the documented dashboard or application recovery procedure with the authorized owner. Repeat the task-specific limited-user check; reconcile newer records before reopening writes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/); [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/); [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read Open WebUI site, server resources and backup age. Return model/provider dependency questions. Do not claim MCP configures models, users or chats; app admin validates a non-sensitive prompt and data policy.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized Open Webui administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **ai-ops decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Open WebUI administrator and model connections](https://docs.openwebui.com/getting-started/quick-start/settings/) — reviewed 2026-09-30
- [Open WebUI role and group access controls](https://docs.openwebui.com/features/authentication-access/rbac/permissions/) — reviewed 2026-09-30
- [Open WebUI conversation data controls](https://docs.openwebui.com/features/chat-conversations/data-controls/) — reviewed 2026-09-30
- [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/) — reviewed 2026-09-30
- [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md) — reviewed 2026-09-30; v4.4.2
- [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Back up and recover a Docker application](https://xcloud.host/use-cases/operations/docker-backup-and-recovery/)
