SHEN YIFull-Stack & AI

Paris • Singapore • Shanghai

AI Engineering Lab · 19-episode course

Build a read-only SaaS support copilot, episode by episode.

SaaS Support Copilot is a completed build-along course. Step by step, you create an AI assistant that answers usage, bug, and feature-feasibility questions from docs, code, Git history, the database, and logs—with citations, role-based access, and honest refusals.

$ course --status
▸ format    build-along, one tested change per episode
▸ episodes  19
▸ languages EN · FR · ZH
▸ status    complete
● read → cite → refuse

Course syllabus

Build a read-only support copilot, one tested change at a time.

SaaS Support Copilot is a self-paced build-along. Across 19 episodes plus one method lesson, you grow a copilot for a fictional ticketing SaaS—from the first typed data model to a capstone demo against a real model.

Format
19 build-along episodes, one focused, tested change each
Languages
English, French, and Chinese—every episode fully translated
Stack
Python, FastAPI, SQLite or MySQL, optional MCP server
Sample app
Loopline, a fictional ticketing SaaS invented for this course

Course mission

Build a read-only copilot that answers usage, bug, and feature-feasibility questions about a SaaS application by reading its help docs, source code, Git history, database, and logs. Answers cite their sources, respect the caller's role, and refuse anything the evidence does not support. The copilot never performs actions; the course teaches the engineering around that boundary.

How the course works

  1. Read the episode's learning objective and talking points.
  2. Implement the change and run it locally—no paid API key required.
  3. Watch the failure case, then run the tests that prove the fix.
  4. Try the exercise before moving on to the next episode.

Recommended order

Each episode builds on the previous one, so 0 → 18 is the easiest first pass. “Prompting this build” is a companion to the whole course: read it once you have a few episodes behind you.

Phase 1 · Episodes 0–3

Foundations

Frame the problem, set up typed Python foundations, make the smallest LLM call, and turn model output into structured data.

Phase 2 · Episodes 4–7

Routing, tools & the loop

Classify each question, give the agent safe read-only tools, drive a bounded loop, and keep conversation state.

Phase 3 · Episodes 8–13

Evidence & safety

Build RAG and a call graph from scratch, enforce permissions in retrieval, plan feasibility answers, refuse commands, and defend against prompt injection.

Phase 4 · Episodes 14–18

Ship & prove it

Add the HTTP boundary, evaluation and observability, local deployment, a production-readiness review, and a capstone demonstration.

What you will be able to do

  • Explain when a workflow is enough and when an agent is worth it, and design the boundary between them.
  • Build read-only tools with safe contracts and drive them from a bounded agent loop.
  • Combine keyword, embedding, and call-graph retrieval, and enforce role-based access before the model sees a document.
  • Refuse command-shaped requests, treat retrieved text as data, and test the copilot against a golden question set.
  • Say precisely what separates a prototype from a production deployment.

Episode library

19 episodes, plus the method behind them

Every episode opens on GitHub, next to the code it builds, in English.

00 · Foundations

What we're building

Model versus application versus agent, workflow versus agent, and a tour of the Loopline sample app.

Read episode

01 · Foundations

Python project foundations

Typed data models and tests, so every later episode hands data around without guessing.

Read episode

02 · Foundations

The smallest useful LLM call

A provider-neutral message interface with a fake client, built before touching a real API key.

Read episode

03 · Foundations

System prompts and structured output

Turn free-text model output into typed, validated values, with a retry on malformed output.

Read episode

04 · Routing, tools & the loop

Decisions, routing, and workflows

Decide what kind of question it is first—usage, bug, feature, or ambiguous—then route it.

Read episode

05 · Routing, tools & the loop

Tools and safe tool contracts

Read-only tools over docs, source, Git history, the database, and logs, called through a registry with timeouts.

Read episode

06 · Routing, tools & the loop

The agent loop

A loop the model drives—observe, decide, act—choosing one step at a time between calling a tool and answering.

Read episode

07 · Routing, tools & the loop

Conversation state and memory

Bounded conversation context and per-session memory, without confusing “this chat” with “this user”.

Read episode

08 · Evidence & safety

RAG fundamentals

Chunking, BM25, embeddings, and combining rankings—built from scratch so RAG stops being a black box.

Read episode

09 · Evidence & safety

Knowledge graphs for code relationships

A call graph that answers “what would changing this function break?”—a question text search can't.

Read episode

10 · Evidence & safety

Permission-aware search

Make the caller's role a first-class input to retrieval, enforced before the model sees any document.

Read episode

11 · Evidence & safety

Planning and multi-step work: feature feasibility

A plan-first workflow for feasibility questions: decide what evidence would settle it before spending a tool call.

Read episode

12 · Evidence & safety

Human approval and refusal

Recognize command-shaped requests and refuse them honestly, with zero model calls.

Read episode

13 · Evidence & safety

Prompt injection and data-exfiltration defense

Treat retrieved text as data, not instructions, and see an injected command blocked twice over.

Read episode

14 · Ship & prove it

FastAPI application boundary

An HTTP boundary with validated requests, shared resources, request IDs, and clean errors instead of tracebacks.

Read episode

15 · Ship & prove it

Evaluation and observability

A golden question suite run against a real model, plus latency, token usage, and structured logs to catch regressions.

Read episode

16 · Ship & prove it

Local deployment and reproducibility

Docker Compose with MySQL, secrets kept out of source control, and a standalone MCP server for database access.

Read episode

17 · Ship & prove it

Prototype versus production architecture

Draw the line between what the prototype has and what production needs; close one real gap, document the rest.

Read episode

18 · Ship & prove it

Capstone demonstration

One running system and a real model: the same question answered or refused depending on one header's role.

Read episode

Bonus · Method

Prompting this build: how the 19 episodes got written

How an AI coding agent wrote every line: one focused, tested change per prompt, verified before it is written down.

Read episode

Current status

A completed 19-episode course and a learning prototype.

Completed: 19 episodes · MIT-licensed code. Everything runs locally on fictional sample data. Loopline is invented for this course and does not represent any real company's product, code, or data. This is a learning prototype, not a production-security guarantee—Episode 17 lists exactly what a real deployment still needs.