# Operate an agency WordPress portfolio

Standardize site inventory, updates, security review, reporting, and handover. A report names the right client, selected changes and unresolved issues.

Canonical: https://xcloud.host/use-cases/playbooks/operate-an-agency-wordpress-portfolio/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Standardize site inventory, updates, security review, reporting, and handover.
For: agency, business-owner

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: An agency maintains several client sites with different update windows and approvers. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: Bulk updates across unrelated sites can create broad outages. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## Illustrative situation

Illustrative scenario, not a customer case study: An agency maintains several client sites with different update windows and approvers. A report names the right client, selected changes and unresolved issues.

## Choose the approach

- Group sites by owner and maintenance agreement, not merely by server. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Register client ownership

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Owner, hostname, approved requirements, sample record and decision date. Register client ownership.

**Action:** Create a client register with legal owner, production site, service window, hosting team, plugin licenses and approval contact for each WordPress property.

**Expected result:** The agency knows which commitments belong to each site.

**Verify:** Ask each client contact to confirm one production hostname and maintenance window.

**If it fails:** If ownership overlaps or is undocumented, separate the affected work until the contract is clarified.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 2. Separate access by xCloud team

**Where:** xCloud team membership and roles dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Target team/site, server or plugin version, license and documented prerequisites. Separate access by xCloud team.

**Action:** In the xCloud dashboard review team membership and role boundaries against the register. Have a team owner give staff named access only to approved teams and sites, then test a staff account's actual visibility.

**Expected result:** Client resources are separated according to agreement.

**Verify:** Have a staff member enumerate visible sites and compare against the approved list.

**If it fails:** If unrelated client resources are visible, have the team owner correct dashboard permissions before a portfolio-wide review.

Capability: Manage xCloud team membership and roles
Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 3. Inventory each site’s changes

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Approved change scope, backup state, selected version and maintenance window. Inventory each site’s changes.

**Action:** Inventory core, themes, plugins and vulnerability findings per site; group selected updates by dependency and business risk rather than clicking all sites at once.

**Expected result:** Each client gets a site-specific change list.

**Verify:** Read the current versions and vendor notes for one proposed update per client.

**If it fails:** If a version or fix path is unknown, leave it pending and record the research owner.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 4. Update one approved site at a time

**Where:** xCloud Updates Manager and WordPress administrator

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Test accounts, sample content or transaction, expected result and provider access. Update one approved site at a time.

**Action:** For each approved site, confirm its backup and eligible staging, then test the relevant transaction or form before the production window. Record exactly which site and components changed.

**Expected result:** A production change has site-specific evidence.

**Verify:** Compare staging and live version, check a client-defined business flow, and inspect update history.

**If it fails:** If a site fails, stop changes to that site without blocking unrelated approved clients.

Capability: Review and apply selected WordPress updates
Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/)

### 5. Review client reports and exit notes

**Where:** xCloud maintenance reports dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Observed results, unresolved failures, backup point and owner contacts. Review client reports and exit notes.

**Action:** Review the period's maintenance report alongside real backup, vulnerability and test records before sharing it. Prepare offboarding access and recovery notes for each client.

**Expected result:** Client reporting reflects observed work and remaining issues.

**Verify:** Check report recipient and site identity; have the client identify their escalation contact.

**If it fails:** If the report omits a failure or mixes client sites, correct it before delivery.

Capability: Prepare and inspect a WordPress maintenance report
Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: A report names the right client, selected changes and unresolved issues. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- Before restoring, compare the chosen recovery point with newer business records. Bulk updates across unrelated sites can create broad outages. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure WordPress content, users and selected plugins** (app; manual): Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them. Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- **Manage xCloud team membership and roles** (dashboard; manual): Team invitations and role changes require an authorized xCloud team owner in the dashboard. A read-only MCP resource view cannot modify access. Checkpoint: Review the exact team, account and role before saving. Sign in as the invited user to verify intended visibility. Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Review and apply selected WordPress updates** (mcp; write): Discover the current schema. Identify explicit plugin/theme slugs and update type; do not omit selection and unintentionally update all items. Checkpoint: Approve selected changes only after a completed backup and staging checks. Verify asynchronous completion and business flows. Operation identifiers to discover: sites.wordpress.update. Scopes: read:sites, write:sites. Sources: [WordPress plugin and theme operations](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/wordpress/reference/plugins-themes.md); [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/)
- **Prepare and inspect a WordPress maintenance report** (dashboard; manual): Client report setup, recipients and interpretation require the xCloud dashboard and agency review. Checkpoint: Check period, site identity, included evidence and recipients before sharing a report. Sources: [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Help with operate an agency wordpress portfolio for the exact xCloud team and site I name. First inspect only resources the connection permits and confirm returned identity, stack and relevant versions. Prepare the following authored workflow: Register client ownership; Separate access by xCloud team; Inventory each site’s changes; Update one approved site at a time; Review client reports and exit notes. Ask the named dashboard, domain, WordPress and application owners to perform operations outside connected capabilities. WordPress staging push/pull, native backup schedules, restore and cache settings remain manual dashboard tasks; the packaged REST wrapper is GET-only. Use the guide’s checks to report observed application evidence, unresolved questions and recovery implications; do not claim completion from a hosting resource read. Acceptance: A production change has site-specific evidence.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Inventory core, themes, plugins and vulnerability findings per site; group selected updates by dependency and business risk rather than clicking all sites at once.
- The business owner compares the controlled sample with this observable result: A production change has site-specific evidence.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): A report names the right client, selected changes and unresolved issues. Steps: phase-4
- **recovery** (covered): Bulk updates across unrelated sites can create broad outages. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [WordPress website maintenance reports for clients](https://xcloud.host/docs/wordpress-website-maintenance-reports-in-xcloud/) — reviewed 2026-09-30
- [WordPress plugin and theme operations](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/wordpress/reference/plugins-themes.md) — reviewed 2026-09-30; v4.4.2

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/playbooks/launch-a-wordpress-learning-site/)

- [Review WordPress plugin updates site by site](https://xcloud.host/use-cases/solutions/review-wordpress-plugin-updates-site-by-site/)
- [Review server capacity for multiple WordPress sites](https://xcloud.host/use-cases/solutions/review-server-capacity-for-multiple-wordpress-sites/)
- [Generate an agency WordPress maintenance report](https://xcloud.host/use-cases/solutions/generate-an-agency-wordpress-maintenance-report/)
