SOP · 14-minute read

A maintenance rhythm
your whole team can follow.

The full daily, weekly, monthly and quarterly maintenance methodology — plus an incident workflow — so care-plan delivery doesn't depend on what one person remembers to check.

Last reviewed 17 August 2026 by the Stack2 team — we run our own agency hosting operation the same way.

Why "someone checks it" isn't a system

Undocumented maintenance is one resignation away from a client incident.

When maintenance lives in one person's head, quality depends entirely on that person's memory, mood and workload that week. A written SOP is what turns care-plan delivery into something the whole team — including a new hire in week one — can run consistently.

Purpose, roles and scope

Before the task list: define what this SOP actually covers.

Purpose. Keep every site on a care plan patched, backed up, monitored and reported on — consistently, regardless of who's running maintenance that week.

Roles. A maintenance operator runs the daily and weekly cycle. An escalation lead owns anything that turns into a genuine incident. A site owner is accountable for each client relationship and signs off scope and exceptions.

Service tiers this SOP applies to. Monitoring-only sites get the daily checks only. Protect-level and hands-on sites get the full daily-through-quarterly rhythm below.

Daily

  • Check for failed or skipped backups overnight — investigate same day, don't let a second failure stack on top of the first.
  • Check uptime alerts for any site that went down — confirm it's back up and note the cause if known.
  • Review new critical vulnerability notices against the plugin/theme inventory — patch immediately if a managed site is affected.
  • Triage any client-reported issue into the escalation workflow below if it's not a two-minute fix.

Weekly

  • Review pending core, plugin and theme updates across the portfolio.
  • Run scheduled updates for Protect-tier and hands-on sites, with a backup taken immediately before each run.
  • Spot-check each updated site's front end and admin dashboard after updates apply.
  • Log and handle rollback exceptions (see incident workflow) — don't leave a broken update mid-week.

Monthly

  • Send the client report — updates applied, uptime, backups completed, and any incidents with resolution notes.
  • Review open tickets across the portfolio and close out anything stale.
  • Run a five-minute profitability check per care plan: labour time against price, using the pricing calculator if margin looks off.
  • Flag any client communication needed — scope creep, a site that's outgrown its tier, or a renewal conversation coming up.

Quarterly

  • Full access review — confirm who has admin access to each site and remove anyone who shouldn't.
  • A genuine restore test on a sample of sites — not just confirming a backup file exists, actually restoring it.
  • PHP and plugin compatibility sweep ahead of major version deprecations.
  • Care-plan scope and price review against the profitability check from the monthly cycle.

Incident workflow

Not every problem is an incident. A failed plugin update that's fixed by a rollback in five minutes is routine. An incident is anything client-facing, security-related, or unresolved after 30 minutes of troubleshooting — at that point, it moves to the escalation lead with:

  1. Severity — is the site down, degraded, or cosmetically broken?
  2. Ownership — the escalation lead owns it from this point; the maintenance operator stays available but isn't solely responsible.
  3. Client communication — the site owner decides if and when the client is told, based on severity and visibility.
  4. Post-incident notes — what happened, what fixed it, and whether the SOP needs a new exception entry so it doesn't repeat.
Free toolkit

Get the editable SOP pack

This methodology as an editable DOCX — role placeholders, checkboxes, escalation fields and a client-specific exception register — plus the pricing calculator and audit sheet.

  • Agency Maintenance SOP (DOCX) — daily/weekly/monthly/quarterly tasks with owners and escalation fields
  • Care Plan Profit Calculator (XLSX) — inputs, formulas and a worked example
  • Portfolio Audit Sheet (XLSX) — RAG scoring, priority view and an example row

Free, no obligation. Delivered immediately — no call required.

Instant access. Practical agency templates. Unsubscribe anytime.

The rhythm, automated

See how AutoCare, monitoring and reports map to this rhythm.

AutoCare applies the weekly update run on your schedule with an automatic backup before every change — and generates the monthly client report without anyone building it by hand. Uptime and vulnerability monitoring cover the daily checks around the clock.

14 days free. No credit card required.

FAQ

Common questions

How long should a weekly WordPress update run take?
For a well-maintained site with no major version jumps, a safe update run — backup, apply updates, spot-check — typically takes 5-10 minutes per site when done manually, or is largely unattended when scheduled updates and automated backups are already in place.
What should trigger an immediate rollback?
A visible front-end error, a broken checkout or form on a business-critical page, or the admin dashboard becoming inaccessible after an update. If the issue isn't obviously caused by the update just applied, investigate before rolling back — a rollback undoes the fix along with the problem.
Who should own the quarterly access review?
The escalation lead or a senior team member, not the person who runs weekly updates. A quarterly access review is a control, and controls are weaker when the person doing daily work also self-audits their own access.
Do I need a separate SOP for every client?
No — one SOP with a documented exception register per client is more maintainable than dozens of near-identical documents. Most sites follow the standard rhythm; the exception register captures the handful that genuinely need different handling (a legacy plugin, a client-managed staging step, an unusual release window).