Skip to content

Expert driven recommendations for hosted and remote instances #8566

Description

@cstns

Description

Why

Most customers deploy their flows and then leave them alone. They don't know their palette has packages with known advisories, that a flow could be restructured to stop falling over, or that half of what they've built could be exposed through MCP so the Expert's Insights mode can answer questions they're currently answering by hand. Nobody goes looking for this on their own. We should go to them.

We already have most of the pieces. The Expert understands flows, palette and context. We know what's installed on every hosted and remote instance. We have in-app notifications and email. What's missing is something that looks at all of it by itself, tells the customer what it found, and then offers to do it for them.

What we want

Look at each hosted instance and remote instance on a schedule, and on demand, and produce recommendations. Things worth fixing, upgrading, restructuring, or exposing through MCP. Collect them per instance and per device so there's one place that answers "what's worth doing here", tell people when something new shows up, and let them act on it with a click.

There are really two kinds of findings here, and it might be worth keeping the producers separate:

  1. Plain checks in code. Outdated or vulnerable packages, deprecated nodes, missing error handling, settings that are obviously costing something. Cheap, repeatable, no surprises.
  2. Expert analysis. Design patterns, restructuring suggestions, and the MCP angle: spotting flows that hold data worth querying and suggesting they'd be worth wrapping as an MCP server so Insights mode can use them.

Might be worth starting with the first kind while the second is being figured out, since it ships without needing anything new from the Expert service.

Categories

Each recommendation gets a category, so people can filter and so we can decide what's worth emailing about:

  • security
  • improvement
  • optimization
  • qol with mcp

Probably fine to keep this a short fixed list now and grow it once we see what actually comes out.

Where it shows up

  • A list on each instance and each device, showing what was found, why it matters and what to do about it.
  • A team level roll-up so someone with twenty devices doesn't have to click through all of them.
  • Per recommendation: dismiss, mark as done, or open it in the Expert so the conversation starts with the finding already loaded.
  • Fix this for me. One click hands the finding to the Expert, which already has the flow building and platform tools to carry it out. The finding needs to carry enough context that the Expert can pick it up cold and knows what "done" looks like.

Notifications

  • Security findings go out as their own email when they land.
  • Everything else rolls into a digest, so nobody gets one email per finding.
  • In-app notification for all of them.
  • Team owners can turn the volume down or off.

Things we still need to work out

  • The Expert is chat driven today. There's no way to ask it for an analysis with no user and no session in the loop. That path has to exist first and it's the biggest unknown here, probably worth a spike before sizing the rest.
  • How far "fix this for me" goes. Landing the change for review versus deploying it to something running are quite different levels of trust, and remote instances can be offline when the button gets pressed. Might be worth making that a team setting rather than picking one for everybody.
  • Cost. Running this across every instance and device weekly adds up. Could run the Expert pass only when flows actually changed, and let the plain checks run regardless.
  • Consent. Today the customer hands the Expert their flows by choosing to. This reads them on a schedule instead. Feels like it wants to be team opt-in behind a team type flag, so customers who don't want it never get it.
  • Self hosted only works where the Expert is enabled, so this covers a subset of installs.
  • Quality. A recommendation that's wrong or obvious burns trust quickly, and one that gets applied automatically burns it faster. We probably want to see what's being generated before customers do.

Rough breakdown

  1. Spike: can the Expert run an analysis headlessly, and what does it need from us
  2. Storage and API for recommendations (per instance, per device, category, status)
  3. Deterministic scanner for packages and common flow smells
  4. Weekly sweep plus "analyze now"
  5. Expert analysis pass
  6. MCP-ification recommendations
  7. UI: per instance/device list, team roll-up, dismiss and open in Expert
  8. "Fix this for me": handing a finding back to the Expert to carry out
  9. Notifications and digest email
  10. Team opt-in and feature flag

Where this goes later

Richer tags beyond the four categories, trends over time so you can see whether an instance is getting better or worse, a fleet wide view for large teams, and the Expert taking on more of the fixing without needing to be asked each time.

Which customers would this be available to

Everyone

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicA significant feature or piece of work that doesn't easily fit into a single release

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions