# Publish a WordPress editorial site

Set up an editorial publishing workflow with release and backup checks. A draft remains private, an editor can publish, and a contributor cannot change site settings.

Canonical: https://xcloud.host/use-cases/playbooks/publish-a-wordpress-editorial-site/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Set up an editorial publishing workflow with release and backup checks.
For: business-owner, operator

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: An editorial team publishes daily and needs draft review without accidental public disclosure. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: A production database push can overwrite fresh posts or comments. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)
- Before any database copy or restore starts, the authorized operator restricts the target and quarantines outbound mail, payment, fulfillment and other provider effects. Restored settings may overwrite plugin suppression; reapply sandbox credentials and verify isolation before testing. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

## Illustrative situation

Illustrative scenario, not a customer case study: An editorial team publishes daily and needs draft review without accidental public disclosure. A draft remains private, an editor can publish, and a contributor cannot change site settings.

## Choose the approach

- Choose author, editor and administrator roles around actual approval authority. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Approve taxonomy and editorial roles

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Owner, hostname, approved requirements, sample record and decision date. Approve taxonomy and editorial roles.

**Action:** Map sections, post types and approvals with the editor-in-chief. Identify who owns bylines, image rights, correction notes and publication timing.

**Expected result:** An editorial workflow and article taxonomy are approved.

**Verify:** Walk one sample story from pitch to correction on paper and identify each approver.

**If it fails:** If rights or approval are missing, leave the story in draft rather than expose it publicly.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 2. Give staff the correct WordPress permissions

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Target team/site, server or plugin version, license and documented prerequisites. Give staff the correct WordPress permissions.

**Action:** On the already-provisioned approved WordPress site, assign named administrator, editor, author and contributor accounts to actual duties. Avoid shared logins and verify the hosting team/site independently in xCloud.

**Expected result:** Each user has the intended scope.

**Verify:** Sign in with test contributor and editor accounts and compare their visible actions.

**If it fails:** If a writer can change site settings, correct roles before importing the archive.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 3. Publish a reviewed sample story

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Approved change scope, backup state, selected version and maintenance window. Publish a reviewed sample story.

**Action:** Build categories and templates, then add one draft story, media credit and internal review comment. Publish only through the agreed editor.

**Expected result:** The post renders under the right section and attribution.

**Verify:** Preview with an authorized editor account; confirm a signed-out visitor cannot read the draft, then publish and inspect byline and credit.

**If it fails:** If an unauthenticated draft leaks or attribution is wrong, correct template or permission rules before the next story.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 4. Test correction and canonical URL

**Where:** WordPress public pages, administrator and relevant external provider

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Test accounts, sample content or transaction, expected result and provider access. Test correction and canonical URL.

**Action:** Create a correction to the sample article without changing its intended URL. Inspect the canonical address, search result and internal links after publication.

**Expected result:** Readers reach the current article and can see the correction context.

**Verify:** Compare original and corrected URL, public copy, author information and archive listing.

**If it fails:** If the URL changes unexpectedly, add a reviewed redirect and update internal links.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 5. Plan backup around publishing

**Where:** xCloud Site Backup dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Observed results, unresolved failures, backup point and owner contacts. Plan backup around publishing.

**Action:** Schedule maintenance outside high-volume publishing windows and confirm backups contain posts, uploads and users. Record the editor to consult before a database restore.

**Expected result:** Publishing can continue through planned maintenance and recovery.

**Verify:** Restore a copy and compare a recent article, media item and contributor account.

**If it fails:** If new posts exist after the backup, export or reconcile them before any in-place recovery.

Capability: Configure native WordPress backup and restore
Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: A draft remains private, an editor can publish, and a contributor cannot change site settings. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- Before restoring, compare the chosen recovery point with newer business records. A production database push can overwrite fresh posts or comments. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure WordPress content, users and selected plugins** (app; manual): Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them. Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- **Review a WordPress business journey** (app; manual): Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence. Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- **Configure native WordPress backup and restore** (dashboard; manual): Native schedule, retention and destination changes and all restores are dashboard-only. Checkpoint: Use Site → Site Backup. Before restoring, confirm backup, target, scope and treatment of newer records. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Help with publish a wordpress editorial site for the exact xCloud team and site I name. First inspect only resources the connection permits and confirm returned identity, stack and relevant versions. Prepare the following authored workflow: Approve taxonomy and editorial roles; Give staff the correct WordPress permissions; Publish a reviewed sample story; Test correction and canonical URL; Plan backup around publishing. Ask the named dashboard, domain, WordPress and application owners to perform operations outside connected capabilities. WordPress staging push/pull, native backup schedules, restore and cache settings remain manual dashboard tasks; the packaged REST wrapper is GET-only. Use the guide’s checks to report observed application evidence, unresolved questions and recovery implications; do not claim completion from a hosting resource read. Acceptance: Readers reach the current article and can see the correction context.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Build categories and templates, then add one draft story, media credit and internal review comment. Publish only through the agreed editor.
- The business owner compares the controlled sample with this observable result: Readers reach the current article and can see the correction context.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): A draft remains private, an editor can publish, and a contributor cannot change site settings. Steps: phase-4
- **recovery** (covered): A production database push can overwrite fresh posts or comments. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/playbooks/operate-an-agency-wordpress-portfolio/)

- [Check editorial roles before site handover](https://xcloud.host/use-cases/solutions/check-editorial-roles-before-site-handover/)
- [WordPress for publishers](https://xcloud.host/use-cases/for/wordpress-for-publishers/)
- [Review WordPress content after migration](https://xcloud.host/use-cases/solutions/review-wordpress-content-after-migration/)
