# Prepare a repeatable WordPress client onboarding

Gather domain, site, access, backup, and ownership details before setup begins. The agency can log in with named access and run agreed acceptance checks.

Canonical: https://xcloud.host/use-cases/solutions/prepare-a-repeatable-wordpress-client-onboarding/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Gather domain, site, access, backup, and ownership details before setup begins.
For: business-owner, operator

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: An agency is onboarding a new WordPress client with a site to maintain. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: Unknown DNS or backup ownership delays incident response. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## Illustrative situation

Illustrative scenario, not a customer case study: An agency is onboarding a new WordPress client with a site to maintain. The agency can log in with named access and run agreed acceptance checks.

## Choose the approach

- Use a repeatable intake sheet but tailor access and tests to the client. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Record domain, hosting, plugin licenses and contacts

**Where:** Business owner acceptance sheet and selected application records

**Permissions:** Named WordPress/app administrator or business owner; use authorized test accounts.

**Inputs:** Record domain, hosting, plugin licenses and contacts; exact site identity, named approver and controlled sample data.

**Action:** Record client's domain/DNS owner, existing host, site administrator, plugin licenses, paid integrations and support contact.

**Expected result:** The intake sheet has operational ownership.

**Verify:** The intake sheet has operational ownership. Record the observed site, account or transaction and time in the release sheet.

**If it fails:** If a critical credential has no owner, keep onboarding incomplete.

Capability: Business owner review and acceptance
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

### 2. Request named team access

**Where:** xCloud team membership dashboard

**Permissions:** Client-controlled xCloud team owner performs invitation; agency verifies granted scope.

**Inputs:** Verify team and site permissions and credential transfer; exact site identity, named approver and controlled sample data.

**Action:** Inspect the intended xCloud team and site permission scope, then ask the client’s authorized team owner to invite the agency’s named accounts through the dashboard. Verify effective access after acceptance; do not request shared passwords.

**Expected result:** The client remains owner and each agency operator has only the agreed scope.

**Verify:** The client remains owner and each agency operator has only the agreed scope. Record the exact account or record tested, result, and time with the responsible owner.

**If it fails:** If the client cannot see its own team, fix access through the authorized owner.

Capability: Manage xCloud team membership and roles
Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

### 3. Inventory core, plugins, themes and vulnerabilities

**Where:** WordPress public/admin views and relevant provider evidence

**Permissions:** Named WordPress/app administrator or business owner; use authorized test accounts.

**Inputs:** Inventory core, plugins, themes and vulnerabilities; exact site identity, named approver and controlled sample data.

**Action:** Inventory core, theme, plugins, vulnerability findings and last backup point on the selected site.

**Expected result:** Maintainers know the starting condition.

**Verify:** Maintainers know the starting condition. Record the observed site, account or transaction and time in the release sheet.

**If it fails:** If backup is unverified, arrange a rehearsal before risky updates.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

### 4. Run client-specific business journey tests

**Where:** WordPress public/admin views and relevant provider evidence

**Permissions:** Named WordPress/app administrator or business owner; use authorized test accounts.

**Inputs:** Run client-specific business journey tests; exact site identity, named approver and controlled sample data.

**Action:** Run the client's actual lead, checkout, booking or editorial journey with a marked test; record failures as baseline issues.

**Expected result:** The service agreement starts with observed behavior.

**Verify:** The service agreement starts with observed behavior. Record the observed site, account or transaction and time in the release sheet.

**If it fails:** If a flow already fails, do not claim it was caused by future maintenance.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

### 5. Agree backup, updates, reporting and exit responsibilities

**Where:** Business owner acceptance sheet and selected application records

**Permissions:** Named WordPress/app administrator or business owner; use authorized test accounts.

**Inputs:** Agree backup, updates, reporting and exit responsibilities; exact site identity, named approver and controlled sample data.

**Action:** Agree update window, report cadence, restore approval and exit checklist; create those reminders in the agency's real task system.

**Expected result:** Both sides know recurring responsibilities.

**Verify:** Both sides know recurring responsibilities. Record the observed site, account or transaction and time in the release sheet.

**If it fails:** If no named client approver exists, defer production change authority.

Capability: Business owner review and acceptance
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud hosting for agencies](https://xcloud.host/agency/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: The agency can log in with named access and run agreed acceptance checks. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- For an access mistake, have the authorized xCloud or WordPress owner correct named roles and retest effective access. Preserve a client-controlled administrator before revoking agency credentials; database restore does not fix xCloud team membership. Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Business owner review and acceptance** (app; manual): Human planning, acceptance and record reconciliation cannot be inferred from xCloud resource reads. The business owner chooses the application's source of truth. Checkpoint: Record approved criteria, observed application evidence, unresolved questions and named follow-up. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Manage xCloud team membership and roles** (dashboard; manual): Team invitations and role changes require an authorized xCloud team owner in the dashboard. A read-only MCP resource view cannot modify access. Checkpoint: Review the exact team, account and role before saving. Sign in as the invited user to verify intended visibility. Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Review a WordPress business journey** (app; manual): Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence. Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### Copyable agent brief

```text
Help with prepare a repeatable wordpress client onboarding for the exact xCloud team and site I name. Read available hosting identity and state first, then ask the named WordPress, app, provider or dashboard owner for operations and records outside this connection. Prepare these authored tasks: Record domain, hosting, plugin licenses and contacts; Request named team access; Inventory core, plugins, themes and vulnerabilities; Run client-specific business journey tests; Agree backup, updates, reporting and exit responsibilities. The acceptance check is: The service agreement starts with observed behavior. Do not infer application transactions or completed dashboard jobs from hosting resource reads. WordPress staging push/pull, backup schedule, restore and cache-setting changes require the authorized dashboard owner; the packaged REST wrapper is GET-only.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Inventory core, theme, plugins, vulnerability findings and last backup point on the selected site.
- The business owner compares the controlled sample with this observable result: The service agreement starts with observed behavior.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): The agency can log in with named access and run agreed acceptance checks. Steps: phase-4
- **recovery** (covered): Unknown DNS or backup ownership delays incident response. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/) — reviewed 2026-09-30
- [xCloud hosting for agencies](https://xcloud.host/agency/) — reviewed 2026-09-30

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/solutions/transfer-wordpress-access-when-a-retainer-ends/)

- [Hand over WordPress maintenance and client reporting](https://xcloud.host/use-cases/playbooks/agency-wordpress-maintenance-handover/)
