Build a knowledge-base agent
~25 min TypeScript PythonWhat you’re building: Answer from the company docs with citations.
Primitives you’ll use: Sandbox, Qdrant vectors, Agent and harness, Deployment (App Engine)
Agent prompt
Start with your coding agent
Choose what you are building. The brief names the product it is modelled on, maps it onto MIOSA, and lists the exact commands. Copy it into OSA, Claude Code, Codex, or Cursor.
Template coming soon1 What are you building?
Leave it empty and your agent will propose 3 names, pick one, and use it for resources, the domain and branding.
3 Configure
Reference pattern
Knowledge-base agent, by Your company (/docs/build/perplexity): an internal agent that answers questions over the company docs and cites the page.
How it works: The company corpus is ingested into a vector store; the agent retrieves relevant chunks and answers, citing the source page.
Key capabilities:
Answers over internal docs
Cites the source page
Members of the organization only
Keeps the index fresh
This is a pattern, not a copy of one product. Open /docs/build/perplexity, then design the smallest version that does the capabilities above.
How it maps onto MIOSA
Ingest and chunk the docs -> a MIOSA sandbox running the ingest job
Vector search -> managed Qdrant (`QDRANT_URL`)
Answers with citations -> agent runs (`miosa prompt`, client.runs) streaming events
Internal chat UI -> a MIOSA deployment (`miosa deploy create`), immutable and versioned
Goal
Build Answer from the company docs with citations. on MIOSA, as a multi-tenant product sold to my customers. Each customer is isolated in its own workspace; I meter usage and bill them.
Product name: propose 3 product names, pick one, and use it for resource names, the domain and branding. Until you pick, <product-name> stands for it in the commands below.
Scale: a prototype.
Set up
npm i -g @miosa/cli
miosa login && miosa whoami
miosa api-key create <product-name>-key --preset agent
export MIOSA_API_KEY="msk_u_..."
miosa org
miosa connections add models # your own model provider key
Resources
Sandbox: the agent's isolated Linux workspace
miosa create <product-name>-box --template agent-node --wait
Agents and harnesses: what a run can use
miosa agent harnesses
Managed Qdrant (vectors)
miosa api POST /databases -d '{"name":"<product-name>-index","engine":"qdrant"}'
Deployment: a stable, versioned URL
miosa deploy create --from-sandbox <product-name>-box --name <product-name> --wait
Data and storage
Keep application data in managed Postgres with a row-level owner (member id or team), and keep an append-only audit table for agent actions.
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create <product-name>-customer-1
Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Agent loop
Harness: OSA is MIOSA's own harness and works with any model provider you connect, including your own model.
Model: Anthropic (Claude). Calls use my own provider key (`miosa connections add models`); MIOSA platform keys are never used.
Sessions: one chat per project or conversation, so the agent keeps its context. The first `miosa prompt` on a sandbox uses `--new-chat` (a chat id is printed); every later turn passes `--chat <chat-id>`. `--reuse chat` keeps one new machine per chat so files persist.
Streaming: follow a run with `miosa run follow <run-id>` or client.runs.streamEvents(run.id), and steer or stop it with `miosa run steer` and `miosa run interrupt`.
Agents act as members: every run carries the asking member's id in `metadata`, uses credentials scoped to that member or team, and cannot exceed what the member may do.
Steps
1. Create the vector index.
miosa api POST /databases -d '{"name":"<product-name>-kb","engine":"qdrant"}'
Check: QDRANT_URL is available.
2. Ingest the corpus in a sandbox: pull docs from the sources you connect, split, embed, and upsert with the source URL and an access label in each payload.
miosa create <product-name>-box --template agent-python --wait
Check: The index count matches the documents ingested.
3. Answer in chat from retrieved chunks only, citing the page; filter retrieval by the asker's access label.
miosa prompt --sandbox <product-name>-box --harness osa --model <anthropic-model-id> --chat <chat-id> "Answer using only the provided chunks; cite them"
Check: A member sees only documents they may read, with citations.
4. Keep it fresh: re-ingest on a schedule and remove deleted documents from the index.
Check: An edited page changes the answer after the next ingest.
5. Control access: members and roles, and an audit trail of what agents did.
miosa member add dana@<product-name>.com --role member
miosa audit
Check: A removed member loses access immediately.
6. Publish the internal UI.
miosa deploy create --from-sandbox <product-name>-box --name <product-name> --dir /workspace --port 3000 --run-command "npm start" --wait
Check: Members can open it and nobody else can.
Limits and costs
Connectors are the real work: budget time for each source system's auth, rate limits and data shape.
Set `idle_timeout_sec` so unused team sandboxes pause.
Prefer read-only access by default; grant writes per task.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
Members see only their team's data and tools.
Every agent action is attributable to a member in the audit log.
Nothing consequential happens without the approval the guide describes.
Each customer is isolated in its own workspace and usage is metered against them.
Everything it created can be deleted with nothing left running.
What your choices added
- Build a product. a workspace per customer, per-customer metering and bill-to
- Agent suggests a name. proposes 3 product names and picks one; commands use <product-name>
- Harness: OSA. dispatches with `miosa prompt --harness osa`
- Model: Anthropic. your own provider key
- Prototype. one small machine, no extras, easy to delete
What you're building
an internal agent that answers questions over the company docs and cites the page
The company corpus is ingested into a vector store; the agent retrieves relevant chunks and answers, citing the source page.
Primitives you'll use: Sandbox · Qdrant vectors · Agent and harness · Deployment (App Engine)
- Answers over internal docs
- Cites the source page
- Members of the organization only
- Keeps the index fresh
This is a pattern, not a copy of one product. Start from the related MIOSA guide and build the smallest version that does the capabilities above.
What you need on MIOSA
Each row is one thing to create before you start. The number matches the step that uses it.
- Organization and API key Scopes every call; a workspace key is all a worker needs.
miosa api-key create app-key --preset agentDocs - Sandbox The isolated Linux workspace the agent writes code and runs commands in.
miosa create app-box --template nextjs --waitDocs - Qdrant vectors Managed vector store for search and embeddings, injected as QDRANT_URL.
miosa api POST /databases -d '{"name":"app-index","engine":"qdrant"}'Docs - A workspace per customer Isolates each customer’s machines, deployments, and data as they onboard.
miosa workspace create customer-1Docs - Branding and white-label Your name and slug on previews, deployments, and the desktop; customers never see MIOSA.
miosa orgDocs - Usage metering and bill-to Usage per customer, and which account pays for new machines.
miosa org billDocs - Agent and harness Turns a prompt into work: pick the harness and model a run uses.
miosa agent harnessesDocs - Deployment (App Engine) Publishes the app to an immutable, versioned URL with rollback.
miosa deploy create --from-sandbox app-box --name app --waitDocs
Architecture
How it maps onto MIOSA
Ingest and chunk the docs -> a MIOSA sandbox running the ingest job
Vector search -> managed Qdrant (`QDRANT_URL`)
Answers with citations -> agent runs (`miosa prompt`, client.runs) streaming events
Internal chat UI -> a MIOSA deployment (`miosa deploy create`), immutable and versioned
Data and storage
Keep application data in managed Postgres with a row-level owner (member id or team), and keep an append-only audit table for agent actions.
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create knowledge-base-agent-customer-1Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Agent loop
Harness: OSA is MIOSA's own harness and works with any model provider you connect, including your own model.
Model: Anthropic (Claude). Calls use my own provider key (`miosa connections add models`); MIOSA platform keys are never used.
Sessions: one chat per project or conversation, so the agent keeps its context. The first `miosa prompt` on a sandbox uses `--new-chat` (a chat id is printed); every later turn passes `--chat <chat-id>`. `--reuse chat` keeps one new machine per chat so files persist.
Streaming: follow a run with `miosa run follow <run-id>` or client.runs.streamEvents(run.id), and steer or stop it with `miosa run steer` and `miosa run interrupt`.
Agents act as members: every run carries the asking member's id in `metadata`, uses credentials scoped to that member or team, and cannot exceed what the member may do.
Steps
Create the vector index.
miosa api POST /databases -d '{"name":"knowledge-base-agent-kb","engine":"qdrant"}'Check: QDRANT_URL is available.
Ingest the corpus in a sandbox: pull docs from the sources you connect, split, embed, and upsert with the source URL and an access label in each payload.
miosa create knowledge-base-agent-box --template agent-python --waitCheck: The index count matches the documents ingested.
Answer in chat from retrieved chunks only, citing the page; filter retrieval by the asker's access label.
miosa prompt --sandbox knowledge-base-agent-box --harness osa --model <anthropic-model-id> --chat <chat-id> "Answer using only the provided chunks; cite them"Check: A member sees only documents they may read, with citations.
Keep it fresh: re-ingest on a schedule and remove deleted documents from the index.
Check: An edited page changes the answer after the next ingest.
Control access: members and roles, and an audit trail of what agents did.
miosa member add dana@knowledge-base-agent.com --role membermiosa auditCheck: A removed member loses access immediately.
Publish the internal UI.
miosa deploy create --from-sandbox knowledge-base-agent-box --name knowledge-base-agent --dir /workspace --port 3000 --run-command "npm start" --waitCheck: Members can open it and nobody else can.
Limits and costs
Connectors are the real work: budget time for each source system's auth, rate limits and data shape.
Set `idle_timeout_sec` so unused team sandboxes pause.
Prefer read-only access by default; grant writes per task.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
Members see only their team's data and tools.
Every agent action is attributable to a member in the audit log.
Nothing consequential happens without the approval the guide describes.
Each customer is isolated in its own workspace and usage is metered against them.
Everything it created can be deleted with nothing left running.