Internal Agents Map

Support investigation workflow in Cursor

Company
Cursor
Approach type
Agent
Work
Support
Human involvement
Drafts reviewed
Invocation
Interactive, Background
Interfaces
Cursor, Slack
Deployment stage
Deployed
Evidence strength
Limited primary
Entry reviewed

Purpose

Cursor's technical support team runs customer investigations inside Cursor itself, configured for support work: multi-root workspaces over the product repositories, MCP servers that reach customer databases, event logs, Slack, the ticket tracker, and internal runbooks, plus slash commands, Rules and Skills, and four named subagents whose merged output an engineer reviews before sending.

Check the reviewed sources and claim details.

How it works

Representative workflow: Customer report through an Ask Mode investigation over code, logs, prior threads, and runbooks to a reviewed escalation, customer reply, or documentation pull request. Research details

Trace the symptom in Ask Mode

The investigation typically starts in Ask Mode pointed at the symptom, tracing backward through the relevant product behavior with indexed semantic search over product code, docs, and internal tooling

Identify where the failure occurred

Datadog MCP pulls the relevant logs and traces into the investigation thread to narrow whether the problem is reproducible or transient and whether it failed client-side, at the API edge, in a downstream dependency, or in auth

Track down similar cases

Searches across the support platform and Slack start from hard identifiers such as error strings and request IDs, broaden if needed, and look for the newest thread carrying a current status, a workaround, and an owner

Decide bug or expected behavior

Notion MCP pulls the relevant runbook into the thread to cross-reference what the engineer is seeing, then either confirms the behavior or supports a clearer escalation

File the escalation from the same thread

The Linear MCP turns the material gathered during the investigation into a formatted escalation without leaving the thread

Request a documentation fix from Slack

When several customers hit the same question, a mention of the Cursor agent in Slack with what needs updating sends a cloud agent to open a pull request against the docs repository

Where people stay involved

Each scope pairs its normal attention boundary with supporting evidence. See the supervision definitions for the level mapping and limits.

Reported: A support engineer drives the investigation session, and the merged subagent output is reviewed before it is sent; documentation changes return as a pull request.

  • customer symptom root cause, inside a Cursor investigation session

    Continuous steering · Level 2
  • parallel subagent run merged escalation, customer reply, or docs pull request

    Work-product review · Level 3

Catalog interpretation: Level 2 for customer symptom root cause, inside a Cursor investigation session; human attention boundary: continuous-steering.

Observed in March 2026

Catalog interpretation: Level 3 for parallel subagent run merged escalation, customer reply, or docs pull request; human attention boundary: work-product-review.

Observed in March 2026

Implementation details

Model
Not reportedThe post names Ask Mode, subagents, and cloud agents, but no model or model version anywhere.
Harness
Cursor's own editor and agent product configured for support investigations: multi-root workspaces over several repositories, Ask Mode investigations, MCP servers for support systems, slash commands, Rules and Skills, subagents, and a Slack-triggered cloud agent that opens documentation pull requests
Sandbox
Not reportedThe codebase is described as available locally and a cloud agent opens docs pull requests, but no execution isolation boundary is described for either; the legacy unknown claim stays in research details.
Tool access
MCP servers reach customer databases holding subscription tier and team and privacy settings, streamed event logs covering services used, telemetry errors, and network issues, Slack threads, engineering ticket platforms, an internal documentation service of runbooks and troubleshooting guides, and an account management service; the named integrations are Datadog for logs and traces, the support platform and Slack for prior cases, Notion for runbooks, and Linear for escalations
Knowledge
The full codebase is available locally, and Cursor indexes and semantically searches product code, docs, and internal tooling in the same session; runbooks and troubleshooting guides, Slack threads, and past support conversations arrive through MCP servers
Context management
One Cursor session collapses code, logs, team knowledge, and past conversations; multi-root workspaces keep related repositories together so a question spanning frontend logic, backend policy checks, and docs stays answerable in a single thread; subagent results merge into a single output
Credentials
Not reportedThe post lists the systems the MCP servers reach, including customer and account management data, but never says how the session authenticates to them or whose permissions apply.
Interfaces
cursor, slack

Mechanisms

Collapse support context into one session

Code, logs, team knowledge, and past conversations come together in a single Cursor session, which the team describes as removing the context-gathering bottleneck for most of its work

Connect the support systems through MCP servers

MCP servers bring customer databases, streamed event logs, Slack, engineering ticket platforms, an internal runbook service, and an account management service into the investigation instead of making the engineer search each tool separately

Slash commands, Rules, and Skills for repeated steps

Slash commands cover the most frequently repeated steps of the process, and Rules and Skills automate common processes in support investigations; the captured page does not list the individual commands, rules, or skills

Subagents run steps in parallel

LogInvestigator searches Datadog for the failure point and supporting evidence, KnownIssueMiner scans Slack and Notion for prior threads and workarounds, TicketWriter formats the evidence into a complete escalation, and CustomerReplyDrafter writes the customer response with internal details stripped out; the results merge into a single output

Reported observations

The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.

Adoption output · Reported measurement · Share of Cursor support interactions running through Cursor itself and the reported support engineer throughput multiple, both stated in March 2026 without a period, denominator, or method

Headline claim

“Cursor reports that over 75% of its support interactions run through Cursor itself and that support engineer throughput increased 5-10x; the post gives no measurement period, denominator definition, or method.”

Reported by
Cursor
Scope
Cursor support interactions and support engineer throughput, as stated in March 2026

The source does not report the denominator of this figure.

Observed in March 2026

Effectiveness · Estimate · Team estimate of support productivity against traditional multi-tool approaches, hedged with 'as much as' and reported separately from the throughput range

Key observation

Cursor estimates the combined workflow makes its support team as much as an order of magnitude more productive than traditional approaches that require jumping between tools and across teams

Reported by
Cursor
Scope
Productivity of the support team against traditional approaches that require jumping between tools and across teams
Method
Team estimate; the post gives no method

The source does not report the denominator of this figure.

Observed in March 2026

Lessons

Cursor's support engineers search prior cases by hard identifier first, such as an error string or request ID, broaden the search only if that fails, and take the newest thread that carries a current status, a workaround, and an owner.

Cursor keeps the repositories a support question spans in one multi-root workspace, so a question about frontend logic, backend policy checks, and documented expected behavior stays answerable in a single thread.

Cursor's support team treats several customers asking the same question as a documentation gap and files the fix itself, mentioning the Cursor agent in Slack to get a pull request opened against the docs repository.

Sources and research details

Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.

  1. How technical support at Cursor uses Cursorhttps://cursor.com/blog/cursor-supportEngineering blog · First party · Last source verification: 2026-09-21
Question coverage and scope
purpose
Reported
workflow
Reported
human involvement
Reported: A support engineer drives the investigation session, and the merged subagent output is reviewed before it is sent; documentation changes return as a pull request.
implementation
Reported
validation
Unreported: The post names review of the merged output before sending, but no correctness check, evaluation, test, or accuracy measurement for the investigation result.
observations
Reported
lessons
Reported
Research details for every claim on this page
  1. Summary
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  2. Headline claim
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    Low
    Confidence reason
    Cursor states both figures in one sentence of its own blog post with no measurement period, no definition of a support interaction, no denominator, and no method; 'over 75%' is a floor and '5-10x' is a range, and neither is independently verified.
    Reported by
    Cursor
    Scope
    Cursor support interactions and support engineer throughput, as stated in March 2026
    Denominator
    Not reported
    Method
    Not reported
    Observation date
    2026-03
  3. Sandbox

    unknown

    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The post says the full codebase is available locally and that a cloud agent opens docs pull requests, but documents no execution isolation boundary for either; unknown does not mean absent.
  4. Harness
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  5. Interfaces
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  6. Tool access
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  7. Knowledge
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  8. Context management
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  9. Collapse support context into one session
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  10. Trace the symptom in Ask Mode
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  11. Connect the support systems through MCP servers
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  12. Identify where the failure occurred
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  13. Track down similar cases
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  14. Decide bug or expected behavior
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  15. File the escalation from the same thread
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  16. Request a documentation fix from Slack
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  17. Slash commands, Rules, and Skills for repeated steps
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  18. Subagents run steps in parallel
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  19. Key observation

    Cursor reports that over 75% of its support interactions run through Cursor itself

    Duplicate representation of Headline claim. Component of the compound headline: the same over-75% share of support interactions, with the same missing period and denominator.

    Statement type
    Metric
    Provenance
    Reported
    Confidence
    Low
    Confidence reason
    The share is a self-reported floor with no measurement period and no definition of a support interaction, so the true value and the base it is taken over both stay open.
    Reported by
    Cursor
    Scope
    Share of Cursor support interactions that run through Cursor itself
    Denominator
    Not reported
    Method
    Not reported
    Observation date
    2026-03
  20. Key observation

    Cursor reports that running support through Cursor increased support engineer throughput 5-10x

    Duplicate representation of Headline claim. Component of the compound headline: the same 5-10x support engineer throughput range, with the same missing method.

    Statement type
    Metric
    Provenance
    Reported
    Confidence
    Low
    Confidence reason
    Cursor reports a 5-10x throughput range without saying what throughput counts, over which period, or against which baseline, so the range cannot be reduced to a point estimate.
    Reported by
    Cursor
    Scope
    Support engineer throughput after support work moved into Cursor
    Denominator
    Not reported
    Method
    Not reported
    Observation date
    2026-03
  21. Key observation
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    Low
    Confidence reason
    The closing section marks this figure as the team's own estimate, bounds it with 'as much as', and compares it to unspecified traditional approaches, so it is a hedged self-assessment rather than a measured result.
    Reported by
    Cursor
    Scope
    Productivity of the support team against traditional approaches that require jumping between tools and across teams
    Denominator
    Not reported
    Method
    Team estimate; the post gives no method
    Observation date
    2026-03
  22. Lesson
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    Medium
    Confidence reason
    The known-issue section states the search order and the three properties the team wants in the thread it picks; it reports the team's practice and does not measure how often that search succeeds.
  23. Lesson
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    Medium
    Confidence reason
    The post gives the multi-root workspace rationale with a worked example, a disabled button spanning frontend, backend, and docs; it reports the arrangement without comparing it to separate workspaces.
  24. Lesson
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    Medium
    Confidence reason
    The documentation-updates section states the trigger, the Slack mention, and the cloud agent pull request; it describes the routine and reports no volume or acceptance rate for those pull requests.
  25. Operating model assessment
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The post describes an engineer opening the session, pointing Ask Mode at the symptom, and pulling each MCP source into the thread step by step, which places attention with the engineer throughout the investigation; it never describes an investigation running without one.
    Observation date
    2026-03
  26. Operating model assessment
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The subagent section states that the parallel results merge into a single output that the team reviews and sends, which locates the return of attention at the merged work product; the post does not say how long the parallel run proceeds unattended.
    Observation date
    2026-03
Back to agents
Know an internal agent?

Share a resource or public mention, suggest an addition, or correct an existing entry. Pull requests are also welcome.