Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Illustrative situation
A site manager sees 17 pending WordPress updates before a sales campaign. They need to identify risky dependencies and prepare a change plan, with no production update in this task.
Choose the approach
Separate security fixes from feature releases and identify exact plugin/theme slugs rather than using an all-update action.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Defer components with unknown compatibility until staging and owner checks are possible; record the accepted exposure.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Identify the review scope
- Where
- xCloud site and WordPress → Updates
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Site ID, current WP version, campaign dates
- Action
- Open the named site and confirm its domain and environment. Record WordPress core version and the date of the last completed backup.
- Expected result
- A dated review target, not an update request.
- Verify
- Compare the xCloud site ID with the campaign owner's inventory.
- If it fails
- If the site or environment does not match, do not continue with component assessment.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Site backups in xCloud
Step 2 of 5
Inventory pending versions
- Where
- xCloud Updates Manager and WordPress Updates
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Core, theme and plugin names and slugs
- Action
- Read pending versions and installed versions for each component. Group inactive plugins separately and identify any must-use plugins not shown in normal update notices.
- Expected result
- A component-by-component update table.
- Verify
- Cross-check at least the critical checkout/form/booking plugins in WordPress admin.
- If it fails
- If lists disagree, capture both views and inspect the component before planning a write.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Manage WordPress updates with Updates Manager
Step 3 of 5
Read impact evidence
- Where
- Vendor changelogs, xCloud vulnerability findings
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Release notes, advisories, compatibility claims
- Action
- Inspect changelogs for database migrations, minimum PHP/WordPress versions and breaking changes. Match vulnerability findings to installed versions and affected features.
- Expected result
- A priority and risk note for every important update.
- Verify
- Reference the actual advisory or vendor release for each high-priority component.
- If it fails
- If release notes are missing, mark compatibility unverified rather than guessing.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Vulnerability Checker in xCloud · xCloud site PHP settings
Step 4 of 5
Choose staging checks
- Where
- Staging plan and business-flow owners
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Checkout, form, account, email and cache test cases
- Action
- Select the smallest coherent update batch and assign a staging test for each affected flow. Check staging eligibility and ensure a safe production backup exists before scheduling a future change.
- Expected result
- A reviewable future update plan with named testers.
- Verify
- Confirm the test cases can observe both success and failure of critical flows.
- If it fails
- If no staging path or owner exists, document the deferral and compensating monitoring.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Manage WordPress updates with Updates Manager · Site backups in xCloud · Create a staging environment in xCloud
Step 5 of 5
Record decision without applying
- Where
- Change record or client maintenance plan
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Exact slugs, proposed versions, risks and approval owner
- Action
- Publish a decision table: update now after a separate approval, defer with reason, or replace the component. Include the planned window and rollback decision point. Do not call sites.wordpress.update in this review.
- Expected result
- A documented recommendation and no production version change.
- Verify
- Reopen Updates Manager and confirm pending versions remain unchanged.
- If it fails
- If a version changed during review, investigate actor/history and refresh the plan.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Manage WordPress updates with Updates Manager
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recovery decisions
If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress updates with Updates Manager · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- updates decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Identify the review scope Inventory pending versions Read impact evidence Choose staging checks
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Choose staging checks Record decision without applying
Sources
- xCloud agent capability boundaries
- xCloud MCP documentation and connection profiles
- Manage WordPress updates with Updates Manager
- Manage WordPress core, themes and plugins
- Site backups in xCloud
- WordPress security hardening
- WordPress roles and capabilities
- Create WordPress pages
- Manage WordPress plugins
- Vulnerability Checker in xCloud
- xCloud site PHP settings
- Create a staging environment in xCloud