Playbook WordPress

Operate an agency WordPress portfolio

Standardize site inventory, updates, security review, reporting, and handover. A report names the right client, selected changes and unresolved issues.

Read this guide as Markdown

Requirements and responsibilities

Illustrative situation

Illustrative scenario, not a customer case study: An agency maintains several client sites with different update windows and approvers. A report names the right client, selected changes and unresolved issues.

Choose the approach

Dashboard and application procedure

Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.

Step 1 of 5

Register client ownership

Where
WordPress administrator or the selected plugin/application
Permissions
Named WordPress or selected app administrator; business owner approves results.
Inputs
Owner, hostname, approved requirements, sample record and decision date. Register client ownership.
Action
Create a client register with legal owner, production site, service window, hosting team, plugin licenses and approval contact for each WordPress property.
Expected result
The agency knows which commitments belong to each site.
Verify
Ask each client contact to confirm one production hostname and maintenance window.
If it fails
If ownership overlaps or is undocumented, separate the affected work until the contract is clarified.

Sources: WordPress roles and capabilities · WordPress plugin administration

Step 2 of 5

Separate access by xCloud team

Where
xCloud team membership and roles dashboard
Permissions
Named xCloud team/site administrator; confirm the exact production or staging target.
Inputs
Target team/site, server or plugin version, license and documented prerequisites. Separate access by xCloud team.
Action
In the xCloud dashboard review team membership and role boundaries against the register. Have a team owner give staff named access only to approved teams and sites, then test a staff account's actual visibility.
Expected result
Client resources are separated according to agreement.
Verify
Have a staff member enumerate visible sites and compare against the approved list.
If it fails
If unrelated client resources are visible, have the team owner correct dashboard permissions before a portfolio-wide review.

Sources: xCloud team roles and permissions · xCloud agent capability boundaries

Step 3 of 5

Inventory each site’s changes

Where
WordPress administrator or the selected plugin/application
Permissions
Named WordPress or selected app administrator; business owner approves results.
Inputs
Approved change scope, backup state, selected version and maintenance window. Inventory each site’s changes.
Action
Inventory core, themes, plugins and vulnerability findings per site; group selected updates by dependency and business risk rather than clicking all sites at once.
Expected result
Each client gets a site-specific change list.
Verify
Read the current versions and vendor notes for one proposed update per client.
If it fails
If a version or fix path is unknown, leave it pending and record the research owner.

Sources: WordPress roles and capabilities · WordPress plugin administration

Step 4 of 5

Update one approved site at a time

Where
xCloud Updates Manager and WordPress administrator
Permissions
Named xCloud team/site administrator; confirm the exact production or staging target.
Inputs
Test accounts, sample content or transaction, expected result and provider access. Update one approved site at a time.
Action
For each approved site, confirm its backup and eligible staging, then test the relevant transaction or form before the production window. Record exactly which site and components changed.
Expected result
A production change has site-specific evidence.
Verify
Compare staging and live version, check a client-defined business flow, and inspect update history.
If it fails
If a site fails, stop changes to that site without blocking unrelated approved clients.

Sources: Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins

Step 5 of 5

Review client reports and exit notes

Where
xCloud maintenance reports dashboard
Permissions
Named xCloud team/site administrator; confirm the exact production or staging target.
Inputs
Observed results, unresolved failures, backup point and owner contacts. Review client reports and exit notes.
Action
Review the period's maintenance report alongside real backup, vulnerability and test records before sharing it. Prepare offboarding access and recovery notes for each client.
Expected result
Client reporting reflects observed work and remaining issues.
Verify
Check report recipient and site identity; have the client identify their escalation contact.
If it fails
If the report omits a failure or mixes client sites, correct it before delivery.

Sources: WordPress website maintenance reports for clients

Maintenance

Recovery decisions

  • Before restoring, compare the chosen recovery point with newer business records. Bulk updates across unrelated sites can create broad outages. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first.

    Site backups in xCloud · xCloud agent capability boundaries

  • Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident.

    Site backups in xCloud · WordPress hardening handbook

AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

Supported scope

  • Confirm requirements and inspect resources mcp · read

    Discover the connected profile and operation schema first; only teams granted to the connection are visible.

    Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.

    Operation identifiers and scopes to discover

    teams.index, servers.show, sites.show

    Scopes: read:servers, read:sites

    xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

  • Configure WordPress content, users and selected plugins app · manual

    Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them.

    Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey.

    WordPress roles and capabilities · WordPress plugin administration

  • Manage xCloud team membership and roles dashboard · manual

    Team invitations and role changes require an authorized xCloud team owner in the dashboard. A read-only MCP resource view cannot modify access.

    Checkpoint: Review the exact team, account and role before saving. Sign in as the invited user to verify intended visibility.

    xCloud team roles and permissions · xCloud agent capability boundaries

  • Review and apply selected WordPress updates mcp · write

    Discover the current schema. Identify explicit plugin/theme slugs and update type; do not omit selection and unintentionally update all items.

    Checkpoint: Approve selected changes only after a completed backup and staging checks. Verify asynchronous completion and business flows.

    Operation identifiers and scopes to discover

    sites.wordpress.update

    Scopes: read:sites, write:sites

    WordPress plugin and theme operations · Manage WordPress updates with Updates Manager

  • Prepare and inspect a WordPress maintenance report dashboard · manual

    Client report setup, recipients and interpretation require the xCloud dashboard and agency review.

    Checkpoint: Check period, site identity, included evidence and recipients before sharing a report.

    WordPress website maintenance reports for clients · xCloud agent capability boundaries

Copyable agent brief

Manual checkpoints

  • The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Inventory core, themes, plugins and vulnerability findings per site; group selected updates by dependency and business risk rather than clicking all sites at once.
  • The business owner compares the controlled sample with this observable result: A production change has site-specific evidence.
  • Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.
Feature coverage

Sources

Continue

Explore the next WordPress workflow