
Support investigation workflow in Cursor
- Company
- Cursor
- Approach type
- Agent
- Work
- Support
- Human involvement
- Drafts reviewed
- Invocation
- Interactive, Background
- Interfaces
- Cursor, Slack
- Deployment stage
- Deployed
- Evidence strength
- Limited primary
- Entry reviewed
Purpose
Cursor's technical support team runs customer investigations inside Cursor itself, configured for support work: multi-root workspaces over the product repositories, MCP servers that reach customer databases, event logs, Slack, the ticket tracker, and internal runbooks, plus slash commands, Rules and Skills, and four named subagents whose merged output an engineer reviews before sending.
How it works
Representative workflow: Customer report through an Ask Mode investigation over code, logs, prior threads, and runbooks to a reviewed escalation, customer reply, or documentation pull request. Research details
The investigation typically starts in Ask Mode pointed at the symptom, tracing backward through the relevant product behavior with indexed semantic search over product code, docs, and internal tooling
Datadog MCP pulls the relevant logs and traces into the investigation thread to narrow whether the problem is reproducible or transient and whether it failed client-side, at the API edge, in a downstream dependency, or in auth
Searches across the support platform and Slack start from hard identifiers such as error strings and request IDs, broaden if needed, and look for the newest thread carrying a current status, a workaround, and an owner
Notion MCP pulls the relevant runbook into the thread to cross-reference what the engineer is seeing, then either confirms the behavior or supports a clearer escalation
The Linear MCP turns the material gathered during the investigation into a formatted escalation without leaving the thread
When several customers hit the same question, a mention of the Cursor agent in Slack with what needs updating sends a cloud agent to open a pull request against the docs repository
Where people stay involved
Each scope pairs its normal attention boundary with supporting evidence. See the supervision definitions for the level mapping and limits.
Reported: A support engineer drives the investigation session, and the merged subagent output is reviewed before it is sent; documentation changes return as a pull request.
customer symptom → root cause, inside a Cursor investigation session
Continuous steering · Level 2parallel subagent run → merged escalation, customer reply, or docs pull request
Work-product review · Level 3
Catalog interpretation: Level 2 for customer symptom → root cause, inside a Cursor investigation session; human attention boundary: continuous-steering.
Observed in March 2026
Catalog interpretation: Level 3 for parallel subagent run → merged escalation, customer reply, or docs pull request; human attention boundary: work-product-review.
Observed in March 2026
Implementation details
- Model
- Not reportedThe post names Ask Mode, subagents, and cloud agents, but no model or model version anywhere.
- Harness
- Cursor's own editor and agent product configured for support investigations: multi-root workspaces over several repositories, Ask Mode investigations, MCP servers for support systems, slash commands, Rules and Skills, subagents, and a Slack-triggered cloud agent that opens documentation pull requests
- Sandbox
- Not reportedThe codebase is described as available locally and a cloud agent opens docs pull requests, but no execution isolation boundary is described for either; the legacy unknown claim stays in research details.
- Tool access
- MCP servers reach customer databases holding subscription tier and team and privacy settings, streamed event logs covering services used, telemetry errors, and network issues, Slack threads, engineering ticket platforms, an internal documentation service of runbooks and troubleshooting guides, and an account management service; the named integrations are Datadog for logs and traces, the support platform and Slack for prior cases, Notion for runbooks, and Linear for escalations
- Knowledge
- The full codebase is available locally, and Cursor indexes and semantically searches product code, docs, and internal tooling in the same session; runbooks and troubleshooting guides, Slack threads, and past support conversations arrive through MCP servers
- Context management
- One Cursor session collapses code, logs, team knowledge, and past conversations; multi-root workspaces keep related repositories together so a question spanning frontend logic, backend policy checks, and docs stays answerable in a single thread; subagent results merge into a single output
- Credentials
- Not reportedThe post lists the systems the MCP servers reach, including customer and account management data, but never says how the session authenticates to them or whose permissions apply.
- Interfaces
- cursor, slack
Mechanisms
Code, logs, team knowledge, and past conversations come together in a single Cursor session, which the team describes as removing the context-gathering bottleneck for most of its work
MCP servers bring customer databases, streamed event logs, Slack, engineering ticket platforms, an internal runbook service, and an account management service into the investigation instead of making the engineer search each tool separately
Slash commands cover the most frequently repeated steps of the process, and Rules and Skills automate common processes in support investigations; the captured page does not list the individual commands, rules, or skills
LogInvestigator searches Datadog for the failure point and supporting evidence, KnownIssueMiner scans Slack and Notion for prior threads and workarounds, TicketWriter formats the evidence into a complete escalation, and CustomerReplyDrafter writes the customer response with internal details stripped out; the results merge into a single output
Reported observations
The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.
Adoption output · Reported measurement · Share of Cursor support interactions running through Cursor itself and the reported support engineer throughput multiple, both stated in March 2026 without a period, denominator, or method
“Cursor reports that over 75% of its support interactions run through Cursor itself and that support engineer throughput increased 5-10x; the post gives no measurement period, denominator definition, or method.”
- Reported by
- Cursor
- Scope
- Cursor support interactions and support engineer throughput, as stated in March 2026
The source does not report the denominator of this figure.
Observed in March 2026
Effectiveness · Estimate · Team estimate of support productivity against traditional multi-tool approaches, hedged with 'as much as' and reported separately from the throughput range
Cursor estimates the combined workflow makes its support team as much as an order of magnitude more productive than traditional approaches that require jumping between tools and across teams
- Reported by
- Cursor
- Scope
- Productivity of the support team against traditional approaches that require jumping between tools and across teams
- Method
- Team estimate; the post gives no method
The source does not report the denominator of this figure.
Observed in March 2026
Lessons
Cursor's support engineers search prior cases by hard identifier first, such as an error string or request ID, broaden the search only if that fails, and take the newest thread that carries a current status, a workaround, and an owner.
Cursor keeps the repositories a support question spans in one multi-root workspace, so a question about frontend logic, backend policy checks, and documented expected behavior stays answerable in a single thread.
Cursor's support team treats several customers asking the same question as a documentation gap and files the fix itself, mentioning the Cursor agent in Slack to get a pull request opened against the docs repository.
Sources and research details
Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.
Question coverage and scope
- purpose
- Reported
- workflow
- Reported
- human involvement
- Reported: A support engineer drives the investigation session, and the merged subagent output is reviewed before it is sent; documentation changes return as a pull request.
- implementation
- Reported
- validation
- Unreported: The post names review of the merged output before sending, but no correctness check, evaluation, test, or accuracy measurement for the investigation result.
- observations
- Reported
- lessons
- Reported
Research details for every claim on this page
- Summary
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 10-12, 18, 24-31, 59-72
- Headline claim
- Statement type
- Metric
- Provenance
- Reported
- Confidence
- Low
- Confidence reason
- Cursor states both figures in one sentence of its own blog post with no measurement period, no definition of a support interaction, no denominator, and no method; 'over 75%' is a floor and '5-10x' is a range, and neither is independently verified.
- Reported by
- Cursor
- Scope
- Cursor support interactions and support engineer throughput, as stated in March 2026
- Denominator
- Not reported
- Method
- Not reported
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 12
- Sandbox
unknown
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The post says the full codebase is available locally and that a cloud agent opens docs pull requests, but documents no execution isolation boundary for either; unknown does not mean absent.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16, 53
- Harness
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16-18, 22, 53, 59-67
- Interfaces
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16, 53
- Tool access
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 26-31, 37, 41, 45, 49
- Knowledge
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16, 28, 30, 41, 45
- Context management
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 10, 18, 74
- Collapse support context into one session
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 10
- Trace the symptom in Ask Mode
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16, 18
- Connect the support systems through MCP servers
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 22, 26-31, 33
- Identify where the failure occurred
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 37
- Track down similar cases
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 41
- Decide bug or expected behavior
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 45
- File the escalation from the same thread
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 49
- Request a documentation fix from Slack
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 53
- Slash commands, Rules, and Skills for repeated steps
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 57-63
- Subagents run steps in parallel
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 67-74
- Key observation
Cursor reports that over 75% of its support interactions run through Cursor itself
Duplicate representation of Headline claim. Component of the compound headline: the same over-75% share of support interactions, with the same missing period and denominator.
- Statement type
- Metric
- Provenance
- Reported
- Confidence
- Low
- Confidence reason
- The share is a self-reported floor with no measurement period and no definition of a support interaction, so the true value and the base it is taken over both stay open.
- Reported by
- Cursor
- Scope
- Share of Cursor support interactions that run through Cursor itself
- Denominator
- Not reported
- Method
- Not reported
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 12
- Key observation
Cursor reports that running support through Cursor increased support engineer throughput 5-10x
Duplicate representation of Headline claim. Component of the compound headline: the same 5-10x support engineer throughput range, with the same missing method.
- Statement type
- Metric
- Provenance
- Reported
- Confidence
- Low
- Confidence reason
- Cursor reports a 5-10x throughput range without saying what throughput counts, over which period, or against which baseline, so the range cannot be reduced to a point estimate.
- Reported by
- Cursor
- Scope
- Support engineer throughput after support work moved into Cursor
- Denominator
- Not reported
- Method
- Not reported
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 12
- Key observation
- Statement type
- Metric
- Provenance
- Reported
- Confidence
- Low
- Confidence reason
- The closing section marks this figure as the team's own estimate, bounds it with 'as much as', and compares it to unspecified traditional approaches, so it is a hedged self-assessment rather than a measured result.
- Reported by
- Cursor
- Scope
- Productivity of the support team against traditional approaches that require jumping between tools and across teams
- Denominator
- Not reported
- Method
- Team estimate; the post gives no method
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 78
- Lesson
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- Medium
- Confidence reason
- The known-issue section states the search order and the three properties the team wants in the thread it picks; it reports the team's practice and does not measure how often that search succeeds.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 41
- Lesson
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- Medium
- Confidence reason
- The post gives the multi-root workspace rationale with a worked example, a disabled button spanning frontend, backend, and docs; it reports the arrangement without comparing it to separate workspaces.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 18
- Lesson
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- Medium
- Confidence reason
- The documentation-updates section states the trigger, the Slack mention, and the cloud agent pull request; it describes the routine and reports no volume or acceptance rate for those pull requests.
- SupportsHow technical support at Cursor uses CursorPreserved content.md, line 53
- Operating model assessment
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The post describes an engineer opening the session, pointing Ask Mode at the symptom, and pulling each MCP source into the thread step by step, which places attention with the engineer throughout the investigation; it never describes an investigation running without one.
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 16, 22, 37, 41, 45
- Operating model assessment
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The subagent section states that the parallel results merge into a single output that the team reviews and sends, which locates the return of attention at the merged work product; the post does not say how long the parallel run proceeds unattended.
- Observation date
- 2026-03
- SupportsHow technical support at Cursor uses CursorPreserved content.md, lines 67-74