# Review a WordPress site’s admin users

Confirm account owners and intended access with the site owner before changing permissions. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/workflows/review-a-wordpress-site-s-admin-users/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Confirm account owners and intended access with the site owner before changing permissions.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## Illustrative situation

A former contractor may still have WordPress administrator access to a client site. The owner must audit user roles and remove stale access without locking out the client.

## Choose the approach

- Compare WordPress users with xCloud team membership; they are independent access systems. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- Retain a tested emergency administrator before removing or downgrading any account. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## Dashboard and application procedure

### 1. List current users

**Where:** WordPress Users → All Users

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Site ID, user email, role, last known owner

**Action:** Export or record users and roles, including service accounts and pending invitations. Mark who still has a business reason for access.

**Expected result:** A dated access roster.

**Verify:** Compare each admin with the client staff and vendor list.

**If it fails:** If an unfamiliar admin appears, preserve evidence and escalate before altering it.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 2. Inspect capabilities

**Where:** WordPress role settings and plugin-specific roles

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Administrator, editor, custom roles

**Action:** Check what each role can actually do, including plugin-created capabilities. Identify accounts that can install plugins, edit users or view sensitive submissions.

**Expected result:** A least-privilege target role for each person.

**Verify:** Test a limited account's actual view in a safe session.

**If it fails:** If a custom role has broad permissions, correct the role design before reassignment.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 3. Secure an owner account

**Where:** WordPress Users and secret manager

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Client owner identity, MFA method, recovery contact

**Action:** Confirm the current client administrator can sign in and recover access. Create or verify a second approved recovery path if policy requires.

**Expected result:** At least one working authorized owner after cleanup.

**Verify:** Have the owner complete a fresh-session login.

**If it fails:** If no owner can log in, resolve recovery before deleting accounts.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 4. Remove stale WordPress access

**Where:** WordPress Users

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Departed account and approved replacement

**Action:** Downgrade or remove the contractor's WordPress user after reassigning owned content as needed. Rotate any shared WordPress secrets.

**Expected result:** No stale WordPress login.

**Verify:** Recheck the Users list and test the removed account cannot sign in.

**If it fails:** If a service integration breaks, restore only its documented service credential, not contractor access.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 5. Record recurring review

**Where:** Client access register and xCloud Team Management

**Permissions:** xCloud team owner authorized to review or change membership; preserve another working owner.

**Inputs:** Review cadence, joiner/leaver owner

**Action:** Document decisions, residual service accounts and next review. Have the team owner separately remove any stale xCloud team membership after confirming another owner can still administer the site.

**Expected result:** An auditable access record in both systems.

**Verify:** Have another administrator confirm WordPress users and xCloud team roster.

**If it fails:** If the roster drifts, investigate changes and repeat the review promptly.

Capability: Review and revoke xCloud team access
Sources: [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## Recovery decisions

- If the wrong user loses access, use the verified remaining owner and the documented WordPress or xCloud team recovery route to restore only that person’s approved role. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)
- Recheck both independent rosters and sign-in paths; investigate any unapproved grant. Do not restore a site database to undo an access-register mistake. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read xCloud team membership and named site identity only. Return WordPress user-review questions; do not claim hosting MCP sees all WP roles or revoke users. An authorized WP admin and team owner perform and verify separate access changes.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **users decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/) — reviewed 2026-09-30
- [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [xCloud team roles and permissions](https://xcloud.host/docs/team-roles-permissions-in-xcloud/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Release WordPress staging changes without losing live data](https://xcloud.host/use-cases/playbooks/wordpress-staging-release-with-live-data/)
