SEAHAVEN SLACK BOT — REMAINING TASKS
======================================

DEPLOY (in progress)
---------------------
[ ] npx cdk deploy — completes the full stack
    - AOSS collection + vector index (created automatically by @cdklabs construct)
    - Bedrock Knowledge Base + S3 docs bucket
    - Bedrock Agent (Claude Sonnet + QBO + Google Maps action groups)
    - Slack webhook Lambda + processor Lambda
    - API Gateway → bot.seahaven.com
    - DynamoDB conversation table


AFTER DEPLOY
------------
[ ] 1. Upload knowledge base documents to S3
        - Bucket name printed in stack outputs as "KBDocsBucketName"
        - Drop in: SA8000 compliance docs, SOPs, employee handbook (PDF/DOCX/TXT)

[ ] 2. Trigger first KB sync
        aws bedrock-agent start-ingestion-job \
          --knowledge-base-id <KB_ID from stack outputs> \
          --data-source-id <DS_ID> \
          --region us-east-1

[ ] 3. Configure Slack app Event Subscriptions
        - Slack app dashboard → Event Subscriptions → enable
        - Request URL: https://bot.seahaven.com/slack/events
          (also printed in stack outputs as "SlackWebhookUrl")
        - Subscribe to bot event: message.im
        - Save changes

[ ] 4. Verify Slack app scopes are saved and reinstall if prompted
        - Required scopes: chat:write, im:history
        - App Home → Messages Tab enabled

[ ] 5. Test the bot
        - DM the bot in Slack
        - Try: "find me a plumber" → should hit QBO first
        - Try: a policy question → should hit KB
        - Check DynamoDB table for logged conversations


FUTURE / FOLLOW-UP
------------------
[ ] QBO refresh token rotation
      - QBO refresh tokens expire after 100 days of inactivity
      - Need to add a Lambda or scheduled job to refresh and update
        the seahaven/qbo/oauth secret automatically

[ ] Enable Bedrock model access (if not already done)
      - AWS Console → Bedrock → Model access
      - Enable: Claude 3.5 Sonnet v2, Amazon Titan Embed Text V2


SECRETS ALREADY STORED (Secrets Manager)
-----------------------------------------
[x] seahaven/slack/credentials     { botToken, signingSecret }
[x] seahaven/qbo/oauth             { clientId, clientSecret, refreshToken, realmId }
[x] seahaven/google/maps-api-key   { apiKey }
