The distinction
A chatbot answers. An agent finishes.
Ask a chatbot to reschedule a delivery and it explains how. Ask an agent and it reads the route plan, finds a slot, moves the job, notifies the driver and updates the order — then tells you what it did.
The capability that separates them is tool use: the model is given a defined set of operations it may call against your systems, and a loop in which it can observe what happened and correct itself. Everything useful and everything dangerous about agents comes from that loop.
The loop, concretely
- Goal — a scoped objective, not an open instruction
- Plan — decompose into steps it can actually perform
- Act — call one permitted tool with validated arguments
- Observe — read the real result, including the failure
- Correct — retry, re-plan, or escalate to a human
- Report — a record of every call, in order, with outcomes
How we build them
Autonomy is a dial, not a switch.
The failure mode in agentic projects is granting broad autonomy early, watching it do something expensive, and banning agents entirely. We start narrow and widen on evidence.
Suggest
The agent proposes the action and a person executes it. You gather accuracy data with zero exposure.
Approve
The agent prepares the action fully; a person clicks once to release it. Most business processes are correctly parked here permanently.
Act
The agent executes within hard limits — value caps, allowed record types, reversibility — and escalates anything outside them.
Controls we insist on
The parts that keep it out of trouble.
- Least-privilege tools. An agent that only needs to read a calendar does not get a token that can delete one.
- Typed arguments, validated server-side. The model proposes; your API decides what is legal. Never trust the model to stay in range.
- Idempotency keys. A retry must not create a second purchase order.
- Hard stops on consequence. Money, contracts, safety and anything irreversible keep a human in the loop regardless of measured accuracy.
- Full trace logging. Every prompt, tool call, argument and result stored, so an incident can be reconstructed rather than guessed at.
- Cost ceilings per run. A looping agent is a billing event; cap it.
Where agents are the wrong answer
We will tell you this before we quote, not after.
- The process is already deterministic — a script is cheaper, faster and more reliable
- The rules change less than once a quarter and fit on a page
- Every error is expensive and none are recoverable
- The underlying systems have no API and no route to one
Next step
Have a process an agent could close end to end?
Describe it in a paragraph. We will tell you which autonomy level it belongs at and what would have to be true before it moves up one.
Start the conversation →