Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Illustrative situation
A WordPress site sends booking and password-reset mail through an external provider. The operator needs to know which handoff failed when messages disappear.
Choose the approach
Separate event creation, WordPress/plugin routing, provider acceptance and recipient inbox.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
A mail test from the provider does not prove the booking or password-reset event fires.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Map critical messages
- Where
- WordPress app owners and mail provider
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Event type, sender, recipient, provider account
- Action
- List each business message and the plugin or core event that creates it. Record expected sender and whether entries are stored.
- Expected result
- A message dependency map.
- Verify
- Ask owners to identify one recent known-good message ID.
- If it fails
- If no provider owner exists, assign one before changing mail settings.
Sources: Manage WordPress plugins
Step 2 of 5
Inspect domain authentication
- Where
- DNS provider and provider admin
- Permissions
- Mail provider and DNS administrators for provider records or test sends; xCloud hosting access alone is insufficient.
- Inputs
- Sending domain, SPF, DKIM, DMARC state
- Action
- Provider/DNS owner checks authenticated domain and current records; preserve unrelated web records.
- Expected result
- A documented sender identity status.
- Verify
- Inspect provider verification and public DNS responses.
- If it fails
- If authentication fails, correct DNS with approval before judging application mail.
Step 3 of 5
Trigger real app events
- Where
- Public form/booking and test inbox
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Safe test booking and reset account
- Action
- Run a non-sensitive booking or password-reset event and record time, on-screen result and entry/message ID if the app exposes one.
- Expected result
- A traceable app event.
- Verify
- Confirm whether app stored a record when applicable.
- If it fails
- If event never fires, fix application logic before SMTP.
Sources: Manage WordPress plugins
Step 4 of 5
Trace provider and recipient
- Where
- Provider logs and recipient inbox
- Permissions
- Mail provider and DNS administrators for provider records or test sends; xCloud hosting access alone is insufficient.
- Inputs
- Message ID, status, bounce reason
- Action
- Match each test to accepted, deferred, rejected or bounced provider state, then inspect recipient inbox and spam folder.
- Expected result
- A known delivery stage.
- Verify
- Compare provider timestamp to app event.
- If it fails
- If provider accepts but inbox rejects, investigate authentication and recipient filtering.
Step 5 of 5
Set detection and replay
- Where
- Runbook and site backup
- Permissions
- Mail provider and DNS administrators for provider records or test sends; xCloud hosting access alone is insufficient.
- Inputs
- Alert owner, stored entries, resend policy
- Action
- Define how failed mail is noticed and when to resend. Preserve or export business entries if supported; otherwise document the data-loss risk.
- Expected result
- An operational failure response.
- Verify
- Test one safe resend without duplicate action.
- If it fails
- If no failure signal exists, schedule provider log review.
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Recovery decisions
If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins · xCloud WordPress site email configuration
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- email-dependencies decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Map critical messages Inspect domain authentication Trigger real app events Trace provider and recipient
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Trace provider and recipient Set detection and replay