Operations WordPress

Review agency access across client teams

Inventory team boundaries and remove stale access only with the accountable owner. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Read this guide as Markdown

Requirements and responsibilities

Illustrative situation

An agency lost a contractor and needs to review access across several client teams. WordPress administrator accounts and xCloud team roles must both be considered.

Choose the approach

Dashboard and application procedure

Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.

Step 1 of 5

Build access matrix

Where
xCloud Team Management and client roster
Permissions
Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
Inputs
Teams, members, roles, assigned servers
Action
List every agency user and invite in client teams. Map each to contract and active employment status.
Expected result
A team-by-team roster.
Verify
Compare email identities with HR/offboarding list.
If it fails
If account ownership is uncertain, investigate before revocation.

Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Step 2 of 5

Compare WordPress access

Where
Each client WordPress Users screen
Permissions
Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Administrator accounts, service accounts, owner
Action
For each site, separately list WordPress admins and custom roles. Match them to the team roster and identify service accounts.
Expected result
A combined but system-specific access picture.
Verify
Confirm named client owner can sign in.
If it fails
If no recovery admin remains, establish approved access before removal.

Sources: WordPress roles and capabilities

Step 3 of 5

Review permission breadth

Where
xCloud role permissions and WordPress roles
Permissions
Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
Inputs
Server scope, admin capability, sensitive sites
Action
Check whether each person needs all assigned teams/servers and whether WordPress role exceeds job duties.
Expected result
A least-privilege change proposal.
Verify
Have client owner confirm intended access for each user.
If it fails
If a broad role is required temporarily, set a removal date.

Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Step 4 of 5

Revoke approved stale access

Where
xCloud Team Management; WordPress Users
Permissions
xCloud team owner authorized to review or change membership; preserve another working owner.
Inputs
Departed identity, approval, replacement
Action
Team owner removes stale xCloud membership in dashboard; WordPress admin separately removes/downgrades site account and rotates shared credentials.
Expected result
Access removed in both systems.
Verify
Verify lists again and test the departed login fails.
If it fails
If an integration uses the credential, replace with a dedicated service account rather than restoring personal access.

Sources: xCloud team roles and permissions

Step 5 of 5

Document and schedule review

Where
Agency access register
Permissions
Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
Inputs
Final matrix, exceptions, next date
Action
Record who approved each change and any remaining shared/service account. Schedule a next portfolio access review.
Expected result
Auditable offboarding with owner.
Verify
Ask another admin to verify a sample client team and site.
If it fails
If a client team was missed, leave the review open until reconciled.

Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Maintenance

Recovery decisions

AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

Supported scope

  • Confirm requirements and inspect resources mcp · read

    Discover the connected profile and operation schema first; only teams granted to the connection are visible.

    Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.

    Operation identifiers and scopes to discover

    teams.index, servers.show, sites.show

    Scopes: read:servers, read:sites

    xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Copyable agent brief

Manual checkpoints

  • Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
  • An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
  • Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
  • Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage

Sources

Continue

Explore all use cases