# Hand over WordPress maintenance and client reporting

Hand over WordPress maintenance with checked report evidence, a client-owned access rehearsal and named revocation and recovery owners.

Canonical: https://xcloud.host/use-cases/playbooks/agency-wordpress-maintenance-handover/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Prepare a WordPress agency maintenance handover and report
For: agency, client-owner

## Requirements and responsibilities

- Identify every client team and production site, the agency and client contacts, permitted access, response window and the owner of domain, DNS, payments and application accounts. An xCloud team grant is not a grant to every client team. Sources: [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Agree what the report covers and its period: update history, security findings, backup status, availability and the business checks the agency actually ran. Report a scheduled backup separately from a completed recovery point. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)
- Record credentials in the client’s secure handover process, not in the report or an agent prompt. Establish who may approve an outage, restore or production update. Sources: [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Before agency access is removed, establish client-owned named xCloud, WordPress, DNS, backup-storage and paid-provider administration. The client must prove effective access in each required system; a shared credential or emailed password is not a handover. Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

## Illustrative situation

Illustrative scenario: an agency transfers a WordPress site to a client’s monthly care plan. The site takes inquiries and has a payment integration; the client needs proof of work and a clear contact when a checkout or form fails.

## Choose the approach

- Use one report per client site and a fixed reporting period. Separate observed metrics and performed work from proposed tasks so the client can see unresolved risk. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/)
- Keep application acceptance checks alongside host evidence. A green server status does not establish that a lead form or checkout delivered its result. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Dashboard and application procedure

### 1. Confirm client and site inventory

**Where:** xCloud team and site views or connected MCP resource reads

**Permissions:** Authorized owner or administrator for the named team, site and application.

**Inputs:** Client name, team, production domain, site UUID, server, application owner and support contacts.

**Action:** Confirm the exact production site and assigned team. Record who owns DNS, WordPress admin, backups, updates, payment or form integration, and incident response.

**Expected result:** A single site identity and responsibility matrix for the reporting period.

**Verify:** Have the client confirm the domain and escalation contact; compare site URL and returned dashboard\_url.

**If it fails:** If team access is missing, ask the authorized owner to grant it; do not infer a missing site from an empty list.

Capability: Confirm requirements and inspect resources
Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud hosting for agencies](https://xcloud.host/agency/)

### 2. Verify recovery and maintenance evidence

**Where:** Site → Site Backup; Updates Manager; Site → WordPress → Vulnerability Scan

**Permissions:** Authorized owner or administrator for the named team, site and application.

**Inputs:** Last completed backup, destination/retention, update history, open findings and previous maintenance date.

**Action:** Inspect backup completion and retention. Capture selected updates and vulnerability findings with dates, severity and owner. Mark each item as completed, open or blocked.

**Expected result:** Traceable maintenance evidence tied to the named site and period.

**Verify:** Check each report claim against the underlying status or history; record the backup identifier and restoration rehearsal date.

**If it fails:** If backup is missing, failed or inaccessible, escalate before a planned production change and record the gap.

Capability: Configure native WordPress backup and restore
Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)

### 3. Run the client acceptance list

**Where:** Production WordPress and business application interfaces

**Permissions:** Authorized owner or administrator for the named team, site and application.

**Inputs:** Safe test account, form destination, payment sandbox or approved live verification method.

**Action:** Verify the public landing page, contact form delivery, login and the client’s revenue path. For a store, confirm cart, checkout and order email in a safe environment. Record actual observations.

**Expected result:** Pass/fail results for the journeys the client relies on.

**Verify:** Compare receipt or destination evidence, not only a successful page load. Retain test identifiers without exposing customer data.

**If it fails:** If a journey fails, open an incident with symptom, time, owner and next action; do not mark it healthy from host status alone.

Capability: Configure and test application behavior
Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [WooCommerce testing orders](https://woocommerce.com/document/managing-orders/testing-orders/)

### 4. Review and prepare the client report

**Where:** Site → Client Reports; agency review

**Permissions:** Authorized owner or administrator for the named team, site and application.

**Inputs:** Reporting period, confirmed site, source evidence, work log, owners and recipients.

**Action:** Use the dashboard report workflow, then reconcile its entries with backup, update and business-test notes. Add clear unresolved items and next dates through the client’s reporting process.

**Expected result:** A client-ready report that distinguishes completed work, observations and planned action.

**Verify:** Have a second owner check site identity, dates, recipient list, sensitive data and every claimed result.

**If it fails:** If the generated report omits a known failure or counts a pending job as complete, correct the handover before distribution.

Capability: Prepare and inspect a WordPress maintenance report
Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/)

### 5. Rehearse client-owned access and recovery location

**Where:** xCloud team dashboard, WordPress admin, DNS/storage provider and client meeting

**Permissions:** Client-owned administrators sign in; each provider owner controls its own permissions.

**Inputs:** Client-owned named accounts, exact team/site, WordPress role, DNS/storage account, latest completed backup and safe test task.

**Action:** Have the client sign in through its own xCloud and WordPress accounts, locate the intended site and latest completed backup, then complete a harmless content correction or draft review. Ask the DNS and storage owners to demonstrate where their respective controls live without sharing secrets.

**Expected result:** The client can administer routine content and identify recovery and domain controls without agency credentials.

**Verify:** Observe the client account reach the correct team/site, complete the test action and identify backup point and separate provider owners.

**If it fails:** If an invitation is pending or the client cannot find its own backup or DNS owner, defer agency revocation and assign a transfer date.

Capability: Business owner review and acceptance
Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

### 6. Accept responsibilities and next review

**Where:** Agency/client handover meeting and secure document store

**Permissions:** Authorized owner or administrator for the named team, site and application.

**Inputs:** Approved report, access matrix, escalation contacts, restore owner and next review date.

**Action:** Give the client the checked report and a runbook for who to call, how to authorize changes and where backup decisions are recorded. Obtain acknowledgement of open items, client-owned access rehearsal and the agency revocation sequence.

**Expected result:** The agency and client agree on the next maintenance window and incident path.

**Verify:** Ask the receiving owner to locate the latest recovery point and explain the escalation route without reading a credential from the report.

**If it fails:** If ownership or recovery access is disputed, leave the issue open and schedule a specific resolution owner and date.

Capability: Prepare and inspect a WordPress maintenance report
Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [xCloud hosting for agencies](https://xcloud.host/agency/)

### 7. Revoke agency access after acceptance

**Where:** xCloud team dashboard, WordPress and provider account consoles

**Permissions:** Client xCloud owner, WordPress administrator and each DNS/storage/provider owner revoke only their own accounts.

**Inputs:** Signed client acceptance, agency user list, access dependencies and exception dates.

**Action:** After the client accepts the access rehearsal and report, have the xCloud team owner remove agency membership; the WordPress administrator and each DNS, storage or paid-provider owner separately remove agency accounts. Verify no shared credential remains and record any licensed item still awaiting transfer.

**Expected result:** The client retains control while agency access ends on every agreed surface.

**Verify:** Test a client-owned login after revocation and ask each owner to confirm the agency account is gone from that system.

**If it fails:** If a resource still depends on an agency-owned account, leave only that item open with a named transfer owner and date; do not remove the last administrator.

Capability: Business owner review and acceptance
Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud hosting for agencies](https://xcloud.host/agency/)

## Maintenance

- At the agreed cadence, review update and vulnerability queues, backup completion, failed business checks and whether the client report reached its intended recipient. Reconcile findings with the next maintenance plan. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Recheck team access whenever a client or agency contact changes; revoke departed people through the authorized team process and keep application credentials in a secure store. Sources: [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- For an incident, identify the latest completed backup and its data-loss window; preserve newer leads, orders or bookings before approving any dashboard restore. Assign the client decision owner and test the business path after recovery. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- If the report’s period or evidence is wrong, correct and redistribute it through the agreed client process, with the previous version clearly superseded. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/)

## AI handoff

Connect xCloud MCP in an agent client and select the intended team. Discover the current tools, schemas and scopes. Use reads for inventory; present exact site, server, domain, cost, interruption and data impact before each approved write. Use returned dashboard\_url values for manual work. The packaged REST fallback accepts GET requests only; never use it for writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure native WordPress backup and restore** (dashboard; manual): Native schedule, retention and destination changes and all restores are dashboard-only. Checkpoint: Use Site → Site Backup. Before restoring, confirm backup, target, scope and treatment of newer records. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure and test application behavior** (app; manual): xCloud hosting operations do not configure WooCommerce checkout, n8n workflows, Nextcloud sharing policy or application users. Checkpoint: An application administrator verifies each real business journey and records observed outcomes. Sources: [WooCommerce testing orders](https://woocommerce.com/document/managing-orders/testing-orders/); [n8n Webhook node and test/production URLs](https://docs.n8n.io/integrations/builtin/core-nodes/n8n-nodes-base.webhook/); [Nextcloud file sharing administration](https://docs.nextcloud.com/server/stable/admin_manual/configuration_files/file_sharing_configuration.html); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Prepare and inspect a WordPress maintenance report** (dashboard; manual): Client report setup, recipients and interpretation require the xCloud dashboard and agency review. Checkpoint: Check period, site identity, included evidence and recipients before sharing a report. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Business owner review and acceptance** (app; manual): Human planning, acceptance and record reconciliation cannot be inferred from xCloud resource reads. The business owner chooses the application's source of truth. Checkpoint: Record approved criteria, observed application evidence, unresolved questions and named follow-up. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Manage xCloud team membership and roles** (dashboard; manual): Team invitations and role changes require an authorized xCloud team owner in the dashboard. A read-only MCP resource view cannot modify access. Checkpoint: Review the exact team, account and role before saving. Sign in as the invited user to verify intended visibility. Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
For the named client team and WordPress site, read permitted site, update, vulnerability and completed backup evidence and prepare a period-specific maintenance report. Ask the client to demonstrate client-owned xCloud and WordPress access, locate the latest backup and identify separate DNS and storage owners. Record the harmless content rehearsal and unresolved transfer items. Do not send the report, invite or revoke users, update, rescan or restore through this prompt. Give each authorized account owner a separate post-acceptance revocation checklist; the packaged REST fallback is GET-only.
```

### Manual checkpoints

- Review and share the checked maintenance report through the approved client channel.
- Client-owned administrators demonstrate xCloud, WordPress, DNS and backup access; the client accepts the rehearsal.
- After acceptance, each xCloud, WordPress and external-provider owner revokes agency access in its own console and verifies client control.

## Feature coverage

- **inventory-and-access** (covered): Names the exact client site and responsibilities. Steps: inventory
- **maintenance-evidence** (covered): Checks backup, update and security evidence. Steps: baseline
- **business-acceptance** (covered): Verifies client-facing outcomes. Steps: business-check
- **report-and-handover** (covered): Reviews report and receiving owner. Steps: report, handover
- **client-owned-access** (covered): Client signs in and locates content, backup and provider control with its own accounts. Steps: client-access, revoke-agency

## Sources

- [xCloud hosting for agencies](https://xcloud.host/agency/) — reviewed 2026-09-30
- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [WooCommerce testing orders](https://woocommerce.com/document/managing-orders/testing-orders/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [n8n Webhook node and test/production URLs](https://docs.n8n.io/integrations/builtin/core-nodes/n8n-nodes-base.webhook/) — reviewed 2026-09-30
- [Nextcloud file sharing administration](https://docs.nextcloud.com/server/stable/admin_manual/configuration_files/file_sharing_configuration.html) — reviewed 2026-09-30

## Continue

[Review the WordPress update procedure](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Build a salon website and booking journey with WordPress](https://xcloud.host/use-cases/solutions/salon-appointment-booking/)
- [Transfer WordPress access when a retainer ends](https://xcloud.host/use-cases/solutions/transfer-wordpress-access-when-a-retainer-ends/)
