Every site we host runs on Minservers, our own managed platform. This is how we watch it — and where AI earns a place in that, and where it deliberately doesn’t.
Layers, not a single monitor
- Every five minutes, a health check hits every site and alerts on anything that isn’t answering properly.
- Every night, an integrity audit compares each WordPress site against a recorded baseline: administrator accounts, must-use plugins, core file checksums, and any PHP sitting where only images should be. Findings go out by email the same night.
- Every morning, a patch-and-repair pass fixes only the unambiguous problems — executable files in upload folders, known-malicious plugins — and demotes, never deletes, an administrator it doesn’t recognise. Everything it touches is reported.
- From a second machine, an off-box watcher checks the platform from outside, so a server that is down — or compromised — can’t silence its own alarm.
The lesson behind the stack: an uptime monitor tells you a site is up, not that it’s yours.
Where the AI sits
When a monitor fails, the alert arrives with an Investigate button. It runs a fixed set of read-only checks, signs the evidence, and hands it to an AI agent that reads it and posts a diagnosis and a proposed fix.
The agent has no server access: no SSH, no Docker, no credentials. It treats what it’s given as data rather than instructions, so a log line crafted to look like a command is just a log line. The Fix button records a request — a person decides, and a person does it.
That’s the pattern we bring to client work: let the model do the reading and the first draft of the thinking, fence what it can touch, and keep the irreversible decisions with someone accountable.