BrandMCP by Tu NguyenBrandMCP by Tu Nguyen

BrandMCP

Tu Nguyen

Tu Nguyen

Bảo mật Technical Product Lead · System Architecture Technical Product Lead · System Architecture

BrandMCP

Governed brand knowledge as a source of truth for AI, teams, and systems Knowledge brand có governance — source of truth cho AI, team và hệ thống ngoài
BrandMCP
Tổng quan
BrandMCP started from a brief to connect AI clients to the right brand knowledge and run predefined workflows. The real design work was governance: ownership, access, and trust — then retrieval and orchestration on top. The platform evolved from a conventional MCP server into a governed knowledge layer consumed through MCP and an integration gateway. Client names and internals stay under NDA. BrandMCP bắt đầu từ brief kết nối AI client với đúng knowledge của từng brand và chạy workflow có sẵn. Phần thiết kế thực sự là governance: ownership, access và trust — rồi mới tới retrieval và orchestration. Nền tảng đi từ MCP server thông thường thành governed knowledge layer, consume qua MCP và integration gateway. Tên khách và phần internals giữ dưới NDA.
Kiến trúc và thông tin khách hàng là bí mật kinh doanh — không chia sẻ kể cả khi ký NDA.
Vấn đề
Brand knowledge already existed — across documents, PDFs, guidelines, and internal files — but it could not be used consistently. Embedding everything into a vector store would make it searchable. It would not answer who owns it, who may use it, whether extraction has been approved, or whether a workflow needs a precise field versus related context. Brand knowledge đã tồn tại — rải trong document, PDF, guideline và file nội bộ — nhưng không dùng được nhất quán. Embed hết vào vector store thì search được. Nó không trả lời data thuộc về ai, ai được dùng, extraction đã được duyệt chưa, hay workflow cần đúng một field hay chỉ cần ngữ cảnh liên quan.
Kiến trúc
AI clients External systems \ / MCP Integration gateway \ / Governed knowledge layer ├ ownership (Company → Brand → Category) ├ access (RBAC / groups) ├ trust (draft → review → approve) ├ retrieval (structured + semantic) └ orchestration AI clients Hệ thống ngoài \ / MCP Integration gateway \ / Governed knowledge layer ├ ownership (Company → Brand → Category) ├ access (RBAC / groups) ├ trust (draft → review → approve) ├ retrieval (structured + semantic) └ orchestration
Những việc mình đã làm
1

Ownership before retrieval Ownership trước retrieval

Established a Company → Brand → Data Category hierarchy so knowledge is never global context. Designed user groups and RBAC so the same platform can serve internal users and clients without leaking across brand boundaries. Thiết lập hierarchy Company → Brand → Data Category để knowledge không bao giờ là global context. Thiết kế user group và RBAC để cùng một nền tảng phục vụ user nội bộ và client mà không lẫn ranh giới brand.
2

Ingested is not trusted Ingest chưa phải trusted

Designed the ingestion lifecycle so extracted knowledge stays draft until human review. Only approved data enters production retrieval — AI workflows cannot silently promote a bad extraction into official brand knowledge. Thiết kế vòng ingestion để knowledge vừa extract ở trạng thái draft đến khi có human review. Chỉ data đã approve mới vào retrieval production — AI workflow không tự biến extraction sai thành official brand knowledge.
3

Precision and discovery together Precision và discovery đi cùng

Combined structured retrieval for known fields with semantic search for related context. Schema stays a contract for consistency; extra signals found during extraction can be suggested for review instead of being dropped or auto-promoted. Kết hợp structured retrieval cho field đã biết với semantic search cho ngữ cảnh liên quan. Schema là contract để nhất quán; tín hiệu ngoài schema khi extract được suggest để review — không im lặng bỏ, cũng không tự lên trusted knowledge.
4

Simple client, controlled orchestration Client đơn giản, orchestration kiểm soát

Moved workflow execution server-side. Users talk in native chat; the platform resolves the workflow, checks inputs, retrieves approved knowledge, and returns the output. The AI client does not drive the internal toolset. Kéo thực thi workflow về phía server. User dùng native chat; nền tảng resolve workflow, kiểm tra input, lấy approved knowledge và trả output. AI client không điều khiển bộ tool nội bộ.
5

Protocol is an interface, not the product Protocol là interface, không phải sản phẩm

MCP remains how AI clients consume the platform. An integration gateway lets other systems do the same under the same ownership, access, and trust rules. The governed knowledge layer is the source of truth. MCP vẫn là cách AI client consume nền tảng. Integration gateway để hệ thống khác làm điều tương tự dưới cùng rule ownership, access và trust. Governed knowledge layer mới là source of truth.
Quyết định kỹ thuật chính
Why start with ownership, access, and trust? Vì sao bắt đầu từ ownership, access và trust?
A brief that says “build an MCP” names a protocol, not an architecture. Who owns the data, who may use it, and which data is trusted decide domain boundaries, authorization, and the approval lifecycle — before embeddings or models matter. Brief “build một MCP” gọi tên protocol, không phải architecture. Data thuộc về ai, ai được dùng, data nào được tin — quyết định domain boundary, authorization và vòng duyệt — trước khi embeddings hay model có ý nghĩa.
Why not treat uploaded files as source of truth? Vì sao không coi file vừa upload là source of truth?
Extraction can be wrong, sources can be stale, and a schema never covers every useful fact. Draft isolation plus human approval is what makes a knowledge layer governed — ingested is not the same as trusted. Extraction có thể sai, nguồn có thể cũ, schema không cover hết. Tách draft và human approval mới khiến knowledge layer có governance — ingest không đồng nghĩa với trusted.
Why both structured retrieval and semantic search? Vì sao vừa structured retrieval vừa semantic search?
Semantic search answers “what knowledge is related?” Structured retrieval answers “give me this known field.” Production workflows need both precision and discovery — not a single “nearest chunk” path. Semantic search trả lời “knowledge nào liên quan?” Structured retrieval trả lời “đưa đúng field này.” Workflow production cần cả precision lẫn discovery — không chỉ đường “chunk gần nhất”.
Why not let the AI client orchestrate internal tools? Vì sao không để AI client orchestrate tool nội bộ?
Client-side tool picking makes quality depend on whichever model the user happens to use. Native chat should carry intent; the platform should resolve the workflow, retrieve approved knowledge, and keep business logic under its control. Để client tự chọn tool thì chất lượng phụ thuộc model user đang dùng. Native chat chỉ cần mang intent; nền tảng resolve workflow, lấy approved knowledge và giữ business logic trong tầm kiểm soát.

Why MCP plus an integration gateway? Vì sao MCP kèm integration gateway?

MCP is how AI clients reach the knowledge layer. Other systems need the same guarantees without speaking MCP. An integration gateway keeps one source of truth — protocol is an interface, not the product. MCP là cách AI client tới knowledge layer. Hệ thống khác cần cùng bảo đảm mà không nói MCP. Integration gateway giữ một source of truth — protocol là interface, không phải sản phẩm.

Why Docker + CI/CD from the start? Vì sao Docker + CI/CD từ đầu?

Multi-service architecture (Laravel + Python) needed reproducible environments across dev, staging, and production. Docker locked dependency parity; CI enforced test gates before deploy — so shipping did not depend on a hidden ops ritual. Kiến trúc đa dịch vụ (Laravel + Python) cần môi trường tái tạo được xuyên suốt dev, staging và production. Docker khoá sự nhất quán dependency; CI kiểm soát test trước deploy — ship không phụ thuộc một ops ritual giấu trong máy ai đó.
Kết quả
Operates as a governed knowledge and orchestration platform: AI clients consume via MCP, other systems via an integration gateway, with permissions, retrieval, and trust held in one place. Client identities and implementation internals remain private. Vận hành như governed knowledge và orchestration platform: AI client consume qua MCP, hệ thống khác qua integration gateway, với permission, retrieval và trust nằm một chỗ. Danh tính khách và internals implementation giữ riêng.
Công nghệ
Laravel 13 Filament v5 Tailwind CSS v4 Python MCP Protocol RAG PostgreSQL (pgvector) LLM APIs Docker
#MCP #RAG #Laravel #Python #AI #Governance #Confidential
Like this project

Posted Sep 22, 2026

Governed brand knowledge platform (MCP) with ownership, RBAC, ingestion lifecycle and RAG retrieval; operates as a governed knowledge & orchestration platform for AI clients.