Skip to content

Rebuild knowledge-base around Context GROQ and Knowledge Bases - #53

Merged
jarodreyes merged 4 commits into
mainfrom
rebuild/knowledge-base-context
Sep 23, 2026
Merged

jarodreyes merged 4 commits into
mainfrom
rebuild/knowledge-base-context

Conversation

@jarodreyes

@jarodreyes jarodreyes commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Rebuild the knowledge-base starter around Sanity Context: GROQ for structured Beacon catalog/FAQ/policy facts, Knowledge Bases for grounded help articles and uploaded files.
  • Replace the App SDK dashboard, Insights classifier, and playbook/Content Health surfaces with a help center plus support (/chat) and ops (/internal) agents.
  • Seed the 30 vs 45 day refund conflict and add homepage storytelling for how a Knowledge Base is built, reviewed, and served through one source type per MCP.

Test plan

  • cd knowledge-base && pnpm install && pnpm run format:check && pnpm run lint && pnpm run typecheck && pnpm run validate
  • pnpm bootstrap on a fresh project (schema deploy, private dataset, embeddings, Viewer token, seed import)
  • Create the two Knowledge Bases and four MCP endpoints from the README; paste URLs + org Context Viewer token into app/.env.local
  • Support GROQ: "Which plan includes SMS under $200/mo?"
  • Support KB: "Is a paused campaign's audience still billed?" and "What is the refund window?" (30 days after resolving the Issue)
  • Ops GROQ: "Which critical policies are overdue for review?"
  • Ops KB: "What are the first 15 minutes of a SEV-1?"
  • Homepage tells the GROQ vs Knowledge Base story and still lists published help articles

Made with Cursor

Replace the App SDK dashboard with a help center plus support and ops chat, seed Beacon content including the 30 vs 45 day refund conflict, and document the product-side MCP setup.

Co-authored-by: Cursor <cursoragent@cursor.com>
@jarodreyes
jarodreyes deployed to commerce-plp-management September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-plp-management September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to ai-shopping-assistant September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 18, 2026 20:33 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 18, 2026 20:33 — with GitHub Actions Active

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present after the first check poll, so that signal was skipped; remaining configured signals and approval policies do not require human review. Reviewers were not assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Approver

import {handleChat} from '@/lib/chat-handler'

export async function POST(req: Request) {
return handleChat(req, 'ops')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Agentic Security Review
Severity: HIGH

POST /api/chat/internal calls handleChat(req, 'ops') with no session, secret, or middleware check. That handler then attaches SANITY_ORGANIZATION_TOKEN to the ops GROQ and Knowledge Base MCP URLs and auto-runs those tools. /internal and the public nav expose the same staff surface.

Impact: Anyone who can reach a deployed help center can retrieve internal runbooks and policy data that this starter treats as staff-only, and can spend the deployer’s Anthropic quota as an unauthenticated MCP proxy.

Fix in Cursor Fix in Web

Reviewed by Cursor Security Reviewer for commit 7f37c25. Configure here.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No this works as intentional. For the starter I want people to be able to easily demo and experience the internal chat as well. WE shouldn't publish this starter live as a demo since these are ungated chat routes.

The ops surface is fictional Beacon content, not a staff trust boundary; call out auth only if real internal sources are wired later.

Co-authored-by: Cursor <cursoragent@cursor.com>
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-plp-management September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-plp-management September 18, 2026 20:45 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to ai-shopping-assistant September 18, 2026 20:45 — with GitHub Actions Active
@vercel

vercel Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
agentic-localization Ready Ready Preview Sep 22, 2026 5:00pm UTC
ai-shopping-assistant Ready Ready Preview Sep 22, 2026 5:00pm UTC
commerce-pdp-starter Ready Ready Preview Sep 22, 2026 5:00pm UTC
commerce-plp-starter Ready Ready Preview Sep 22, 2026 5:00pm UTC
content-analytics-starter Ready Ready Preview Sep 22, 2026 5:00pm UTC

Request Review

…onventions

Correctness
- Fail loudly when /initial-context is refused or empty: throw
  InitialContextError, return 502 {error} from the chat routes, render it
  in the chat UI. An empty KB outline was previously a silent "no results".
- Restore the 22 markdown seed sources beside their PDFs so
  `seed:files` and the "edit the source" story work again.
- Commit packages/@starter/sanity-types/sanity.types.ts (un-ignore) so
  fresh clones and Vercel builds resolve the types.
- KB dataset source query dereferences products/topics to titles.
- beacon-catalog groqFilter only passes published FAQs.
- Seed review dates are relative to generation time; bootstrap regenerates
  before import so the Needs Review demo does not rot.
- Model -> claude-sonnet-5. Prompts: FAQ answerText projection,
  internalCategory->title instead of a nonexistent `category` field.
- Close MCP clients on every streamText exit path (onError/onAbort,
  consumeStream, allSettled connects).

Setup path
- Each chat route runs with whichever of its GROQ / KB MCP URLs is set.
- New context/ directory with copy-paste purpose, source query, groqFilter
  and full Instructions text for both Knowledge Bases and all four MCPs.
- Cache initial context 5 min per endpoint; Accept: text/plain per docs.
- Drop the unused SANITY_ORGANIZATION_ID prompt and env var.
- README: Labs page (not Manage -> Apps) for enabling Knowledge Bases,
  URL override params, seed editing, Deploying section, two stale files,
  manual-Instruction fallback, accurate bootstrap and token descriptions.

Conventions
- Remove duplicate AGENTS.md (CLAUDE.md -> AGENT.md symlink remains).
- Add deploy.yml mirroring commerce-pdp-management, with the read token
  the private-dataset app build needs.
- Build functions in CI before the bundle-size check (starter + root).
- Remove dead `next lint` script (Next 16). Ignore .pnpm-store/ at root.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jarodreyes

Copy link
Copy Markdown
Contributor Author

Fixed some issues that were identified in the other starters around CI/CD processes and missing sanity types.

Comment thread knowledge-base/app/lib/mcp.ts Outdated
return (value ?? {}) as ToolSet
}

export function renameTools(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We'd recommend not renaming tools, as they are referenced by their OOTB name in initial context.

Could the instructions field in the MCP endpoint cover the reasons as to why it should call these GROQ tools instead?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good. We should probably add a sentence clarifying this since my agent got this idea from the patterns doc around Context: https://www.sanity.io/docs/ai/sanity-context-patterns specifically renaming groq_query when there are multiple endpoints.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

addressed in 2accc27

Comment thread knowledge-base/app/lib/mcp.ts Outdated
if (cached && cached.expires > Date.now()) return cached.value

// The endpoint returns text/plain (Markdown), per the docs.
const response = await fetch(`${url.replace(/\/$/, '')}/initial-context`, {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prefer using new URL() and append to pathname instead, so query params don't get mangled. (Query params can be used for important stuff like workspace)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

addressed in 2accc27

Comment thread knowledge-base/app/lib/constants.ts Outdated
- "Is a paused campaign's audience still billed?" -> Knowledge Base.
- "What is the refund window?" -> GROQ for the FAQ fact. If the user wants the policy explained, also read the Knowledge Base.

GROQ hybrid search (semanticSimilarity only inside score()):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd try removing instructions regarding how to use semanticSimilarity and which tools exists. Context MCP should provide all the instructions it needs in initial context and tool descriptions. Users shouldn't need to be concerned about the inner workings of the MCP ideally. Let us know if you experience any regressions!

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good. removed in 2accc27

Comment thread knowledge-base/app/lib/constants.ts Outdated
Routing:
- "Which policies are overdue for review?" -> GROQ on policy.
- "How do I handle a SEV-1?" -> Knowledge Base runbooks.
- Credit thresholds ($500) live on the refund policy (GROQ). The customer-facing refund window is 30 days.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pattern could cause drift from actual content. If the goal is to tell the agent to check refund policy in the dataset for credit threshold values, I'd try adding it in the instructions field on the MCP endpoint instead. That's where we recommend putting retrieval tips. (Good practice even though it's probably not gonna drift in this example)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good. Removed in 2accc27

…nner prompts

Per @torbratsberg on #53:
- Stop renaming MCP tools. Initial context refers to them by their served
  names, so the renamed toolset and the inlined instructions disagreed.
  Only initial_context is dropped (its payload is inlined). GROQ and KB
  modes expose disjoint tool sets, so nothing collides.
- Build the /initial-context URL with new URL() and append to pathname,
  so query params on the MCP URL (e.g. ?workspace=) are preserved.
- Remove GROQ/semanticSimilarity how-to and tool inventories from the
  system prompts. Prompts now carry voice, boundaries, and which surface
  owns which kinds of facts; retrieval guidance lives in each MCP's
  initial context and instructions field (context/mcp/*.md).
- Remove hardcoded content values ($500 threshold, 30-day window) from
  the ops prompt and from the checked-in MCP instructions; point at the
  policy documents and the Knowledge Base's Instruction instead.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jarodreyes
jarodreyes deployed to ai-shopping-assistant September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-plp-management September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-plp-management September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to knowledge-base September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes deployed to commerce-pdp-management September 22, 2026 16:58 — with GitHub Actions Active
@jarodreyes
jarodreyes merged commit dbddbbf into main Sep 23, 2026
16 of 20 checks passed
@jarodreyes
jarodreyes deleted the rebuild/knowledge-base-context branch September 23, 2026 15:29

This branch had an error being deployed

1 failed and 9 active deployments
Preview – ai-shopping-assistant — 2accc273 Deployed Sep 22, 2026 by vercel[bot]
Preview – content-analytics-starter — 2accc273 Deployed Sep 22, 2026 by vercel[bot]
Preview – agentic-localization — 2accc273 Deployed Sep 22, 2026 by vercel[bot]
Preview – commerce-pdp-starter — 2accc273 Deployed Sep 22, 2026 by vercel[bot]
Preview – commerce-plp-starter — 2accc273 Deployed Sep 22, 2026 by vercel[bot]
agentic-localization — 2accc273 Deployed Sep 22, 2026 by jarodreyes via agentic-localization (Node 22) #205
ai-shopping-assistant — 2accc273 Deployed Sep 22, 2026 by jarodreyes via ai-shopping-assistant #205
commerce-pdp-management — 2accc273 Deployed Sep 22, 2026 by jarodreyes via commerce-pdp-management (Node 20) #205
knowledge-base — 2accc273 Deployed Sep 22, 2026 by jarodreyes via knowledge-base (Node 20) #205
commerce-plp-management — 2accc273 Deployed Sep 22, 2026 by jarodreyes via commerce-plp-management (Node 22) #205
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants