# Deploy Metabase for internal reporting

Confirm source database access and security requirements before publishing dashboards. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/workflows/deploy-metabase-for-internal-reporting/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Confirm source database access and security requirements before publishing dashboards.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the Metabase application. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- For a Docker app, identify persistent volumes, bind mounts, external databases and app-level export requirements. A Docker backup briefly stops the app, and an in-place restore replaces current state. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Illustrative situation

An operations team wants a Metabase dashboard against its order database. It must avoid giving analysts write privileges or broader table access than needed.

## Choose the approach

- Connect with a dedicated least-privilege database account; Metabase groups add another layer of access control. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- A data connection alone does not create reliable metrics: one saved question must be checked against a known source count. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Dashboard and application procedure

### 1. Define report and data scope

**Where:** Analytics owner and source database

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Required tables, freshness, authorized viewer group

**Action:** Write one concrete reporting question and list the minimum schemas and rows needed. Identify the database owner and approved network path.

**Expected result:** A narrow reporting contract.

**Verify:** Compare requested data with internal access policy.

**If it fails:** If sensitive tables are not needed, exclude them from the connection role.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting)

### 2. Deploy Metabase

**Where:** xCloud One-Click Apps dashboard

**Permissions:** Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.

**Inputs:** Template, Docker server, HTTPS hostname

**Action:** Install the current Metabase template on a compatible server and secure first administrator access.

**Expected result:** A reachable Metabase admin UI.

**Verify:** Inspect app version, HTTPS and site ID.

**If it fails:** If the app starts but cannot persist settings, inspect its application database/storage.

Capability: Install a selected one-click app in xCloud dashboard
Sources: [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 3. Create a read-only connection

**Where:** Source DB admin and Metabase Admin → Databases

**Permissions:** Authorized Metabase application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Dedicated DB role, host, database, allowed schemas

**Action:** Grant the connector minimum SELECT rights, then add the database in Metabase with the least-privilege credentials. Keep secrets out of reports.

**Expected result:** A connection that can read only intended data.

**Verify:** Run a query against allowed table and verify an unauthorized table is denied.

**If it fails:** If Metabase cannot connect, check network and DB grants; do not grant superuser access as a shortcut.

Capability: Configure and test Metabase in its application UI
Sources: [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data)

### 4. Set Metabase group rights

**Where:** Metabase Admin → Permissions

**Permissions:** Authorized Metabase application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Analyst and viewer groups, collections

**Action:** Limit data and collection permissions, including All Users defaults. Give viewers only the saved report they need.

**Expected result:** A viewer sees the report without unrestricted query access.

**Verify:** Sign in as a viewer and inspect visible tables/questions.

**If it fails:** If hidden data is reachable, fix DB role and Metabase group permissions together.

Capability: Configure and test Metabase in its application UI
Sources: [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data)

### 5. Validate and protect reports

**Where:** Metabase question/dashboard and xCloud backup

**Permissions:** Authorized xCloud team/site operator with the discovered write scope for this exact operation and owner approval for its target and interruption.

**Inputs:** Known order count, date range, app backup

**Action:** Build one saved question, compare its result to a source-system count and add it to a dashboard. Check completed app backup and owner for schema changes.

**Expected result:** A correct sample dashboard with recovery ownership.

**Verify:** Repeat count after a controlled source update and verify freshness.

**If it fails:** If numbers disagree, investigate filters, time zone and sync before distributing the dashboard.

Capability: Create and inspect Docker backups
Sources: [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Recovery decisions

- Before data recovery, identify incident time, completed backup, target and records created after the snapshot. Preserve current evidence and live data before replacement. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Use the documented dashboard or application recovery procedure with the authorized owner. Repeat the task-specific limited-user check; reconcile newer records before reopening writes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting); [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read chosen Docker server, Metabase site and backup state. Return resource and network questions. Do not supply or create database credentials, Metabase groups or dashboards through hosting MCP; DB and app administrators must test least privilege.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized Metabase administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **reporting decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Metabase database connections](https://www.metabase.com/docs/latest/databases/connecting) — reviewed 2026-09-30
- [Metabase data permissions](https://www.metabase.com/docs/latest/permissions/data) — reviewed 2026-09-30
- [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/) — reviewed 2026-09-30
- [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md) — reviewed 2026-09-30; v4.4.2
- [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Back up and recover a Docker application](https://xcloud.host/use-cases/operations/docker-backup-and-recovery/)
