Build a Clay-style sales agent
~25 min TypeScript PythonWhat you’re building: Research and enrich leads at scale.
Primitives you’ll use: Sandbox, Agent and harness, Postgres, Deployment (App Engine)
Agent prompt
Start with your coding agent
Choose what you are building. The brief names the product it is modelled on, maps it onto MIOSA, and lists the exact commands. Copy it into OSA, Claude Code, Codex, or Cursor.
Template coming soon1 What are you building?
Leave it empty and your agent will propose 3 names, pick one, and use it for resources, the domain and branding.
3 Configure
Reference product
Clay, by Clay (https://www.clay.com): a platform that researches and enriches leads for go-to-market teams.
How it works: Rows of leads are enriched from many data sources and by AI research, then pushed to outreach tools.
Key capabilities:
Lead enrichment from many sources
AI research per row
Waterfalls across providers
Push to sales tools
Build an app LIKE Clay. It is not affiliated with Clay: do not copy its name, branding or assets. Open https://www.clay.com first, confirm the capabilities above, and note anything this brief missed.
How it maps onto MIOSA
The agent that does the domain work -> agent runs (`miosa prompt`, client.runs) streaming events in a sandbox, with the tools it may call defined by you
Domain records and history -> managed Postgres (`DATABASE_URL`) for records, citations and an audit trail
Each customer is isolated -> a workspace per customer (`miosa workspace create`)
Human review and escalation -> agent approvals (`miosa agent approvals`) and a review queue in your product
Goal
Build an app like Clay on MIOSA, as a multi-tenant product sold to my customers. Each customer is isolated in its own workspace; I meter usage and bill them.
Product name: propose 3 product names, pick one, and use it for resource names, the domain and branding. Until you pick, <product-name> stands for it in the commands below.
Scale: a prototype.
Set up
npm i -g @miosa/cli
miosa login && miosa whoami
miosa api-key create <product-name>-key --preset agent
export MIOSA_API_KEY="msk_u_..."
miosa org
miosa connections add models # your own model provider key
Resources
Sandbox: the agent's isolated Linux workspace
miosa create <product-name>-box --template agent-python --wait
Agents and harnesses: what a run can use
miosa agent harnesses
Managed Postgres
miosa api POST /databases -d '{"name":"<product-name>-db","engine":"postgresql"}'
Deployment: a stable, versioned URL
miosa deploy create --from-sandbox <product-name>-box --name <product-name> --wait
Data and storage
Postgres is the system of record with an append-only audit table; nothing the agent decides exists only in a prompt.
Keep sources with every stored field so a human can check them.
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create <product-name>-customer-1
Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Agent loop
Harness: OSA is MIOSA's own harness and works with any model provider you connect, including your own model.
Model: Anthropic (Claude). Calls use my own provider key (`miosa connections add models`); MIOSA platform keys are never used.
Sessions: one chat per project or conversation, so the agent keeps its context. The first `miosa prompt` on a sandbox uses `--new-chat` (a chat id is printed); every later turn passes `--chat <chat-id>`. `--reuse chat` keeps one new machine per chat so files persist.
Streaming: follow a run with `miosa run follow <run-id>` or client.runs.streamEvents(run.id), and steer or stop it with `miosa run steer` and `miosa run interrupt`.
The agent runs inside the sandbox with only the tools you defined. It proposes; your code enforces limits (refund caps, allowed recipients) so the model cannot talk its way past them.
Steps
1. Create the domain database.
miosa api POST /databases -d '{"name":"<product-name>-db","engine":"postgresql"}'
miosa db connection <product-name>-db
Check: Domain tables exist: accounts, people, enrichment fields with their sources, drafts.
2. Create the agent sandbox.
miosa create <product-name>-box --template agent-python --wait
Check: The sandbox is running with DATABASE_URL set.
3. Define the enrichment tools (company data, people data, web research); every returned field must carry its source URL.
miosa prompt --sandbox <product-name>-box --harness osa --model <anthropic-model-id> --chat <chat-id> "Enrich account <id>: find the people and facts, attach a source URL to every field, draft the first email"
Check: The agent completes the case using only those tools.
4. Put a human in the loop where it matters: the agent proposes, a person approves anything irreversible or high-stakes, and low-confidence cases escalate with context.
miosa agent approvals
Check: A refund over the limit, a send, or a filing waits for approval.
5. Write an audit record for every agent action: who, what, inputs, outputs, and the run id.
miosa audit
Check: Any decision can be reconstructed from the audit trail.
6. Publish the agent API and the review UI.
miosa deploy create --from-sandbox <product-name>-box --name <product-name> --dir /workspace --port 3000 --run-command "npm start" --wait
Check: The public_url serves the review queue.
Limits and costs
Customer data is personal data: store only what the task needs, honour deletion requests, and keep an audit trail.
Keep tenant data separate: a workspace per customer, and every query filtered by tenant.
Set `--max-time` on runs and cap tool calls per case.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
The agent resolves a representative case end to end using only the defined tools.
A high-stakes action waited for human approval.
The audit trail reconstructs the decision.
Each customer is isolated in its own workspace and usage is metered against them.
Everything it created can be deleted with nothing left running.
What your choices added
- Build a product. a workspace per customer, per-customer metering and bill-to
- Agent suggests a name. proposes 3 product names and picks one; commands use <product-name>
- Harness: OSA. dispatches with `miosa prompt --harness osa`
- Model: Anthropic. your own provider key
- Prototype. one small machine, no extras, easy to delete
- Postgres. already part of this guide
What you're building
a platform that researches and enriches leads for go-to-market teams Modelled on Clay, by Clay.
Rows of leads are enriched from many data sources and by AI research, then pushed to outreach tools.
Primitives you'll use: Sandbox · Agent and harness · Postgres · Deployment (App Engine)
- Lead enrichment from many sources
- AI research per row
- Waterfalls across providers
- Push to sales tools
Source: www.clay.com. Clay is a trademark of its owner; this guide is not affiliated with or endorsed by them.
What you need on MIOSA
Each row is one thing to create before you start. The number matches the step that uses it.
- Organization and API key Scopes every call; a workspace key is all a worker needs.
miosa api-key create app-key --preset agentDocs - Sandbox The isolated Linux workspace the agent writes code and runs commands in.
miosa create app-box --template nextjs --waitDocs - Postgres Managed relational data, injected as DATABASE_URL in the machine and in production.
miosa api POST /databases -d '{"name":"app-db","engine":"postgresql"}'Docs - A workspace per customer Isolates each customer’s machines, deployments, and data as they onboard.
miosa workspace create customer-1Docs - Branding and white-label Your name and slug on previews, deployments, and the desktop; customers never see MIOSA.
miosa orgDocs - Usage metering and bill-to Usage per customer, and which account pays for new machines.
miosa org billDocs - Agent and harness Turns a prompt into work: pick the harness and model a run uses.
miosa agent harnessesDocs - Deployment (App Engine) Publishes the app to an immutable, versioned URL with rollback.
miosa deploy create --from-sandbox app-box --name app --waitDocs
Architecture
How it maps onto MIOSA
The agent that does the domain work -> agent runs (`miosa prompt`, client.runs) streaming events in a sandbox, with the tools it may call defined by you
Domain records and history -> managed Postgres (`DATABASE_URL`) for records, citations and an audit trail
Each customer is isolated -> a workspace per customer (`miosa workspace create`)
Human review and escalation -> agent approvals (`miosa agent approvals`) and a review queue in your product
Data and storage
Postgres is the system of record with an append-only audit table; nothing the agent decides exists only in a prompt.
Keep sources with every stored field so a human can check them.
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create clay-customer-1Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Agent loop
Harness: OSA is MIOSA's own harness and works with any model provider you connect, including your own model.
Model: Anthropic (Claude). Calls use my own provider key (`miosa connections add models`); MIOSA platform keys are never used.
Sessions: one chat per project or conversation, so the agent keeps its context. The first `miosa prompt` on a sandbox uses `--new-chat` (a chat id is printed); every later turn passes `--chat <chat-id>`. `--reuse chat` keeps one new machine per chat so files persist.
Streaming: follow a run with `miosa run follow <run-id>` or client.runs.streamEvents(run.id), and steer or stop it with `miosa run steer` and `miosa run interrupt`.
The agent runs inside the sandbox with only the tools you defined. It proposes; your code enforces limits (refund caps, allowed recipients) so the model cannot talk its way past them.
Steps
Create the domain database.
miosa api POST /databases -d '{"name":"clay-db","engine":"postgresql"}'miosa db connection clay-dbCheck: Domain tables exist: accounts, people, enrichment fields with their sources, drafts.
Create the agent sandbox.
miosa create clay-box --template agent-python --waitCheck: The sandbox is running with DATABASE_URL set.
Define the enrichment tools (company data, people data, web research); every returned field must carry its source URL.
miosa prompt --sandbox clay-box --harness osa --model <anthropic-model-id> --chat <chat-id> "Enrich account <id>: find the people and facts, attach a source URL to every field, draft the first email"Check: The agent completes the case using only those tools.
Put a human in the loop where it matters: the agent proposes, a person approves anything irreversible or high-stakes, and low-confidence cases escalate with context.
miosa agent approvalsCheck: A refund over the limit, a send, or a filing waits for approval.
Write an audit record for every agent action: who, what, inputs, outputs, and the run id.
miosa auditCheck: Any decision can be reconstructed from the audit trail.
Publish the agent API and the review UI.
miosa deploy create --from-sandbox clay-box --name clay --dir /workspace --port 3000 --run-command "npm start" --waitCheck: The public_url serves the review queue.
Limits and costs
Customer data is personal data: store only what the task needs, honour deletion requests, and keep an audit trail.
Keep tenant data separate: a workspace per customer, and every query filtered by tenant.
Set `--max-time` on runs and cap tool calls per case.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
The agent resolves a representative case end to end using only the defined tools.
A high-stakes action waited for human approval.
The audit trail reconstructs the decision.
Each customer is isolated in its own workspace and usage is metered against them.
Everything it created can be deleted with nothing left running.