An AI model generates an output from an input. An AI agent is a system that uses a model, tools and an execution process to pursue a task. The distinction matters because producing a plausible answer and taking a reliable action require different controls.

An agent combines reasoning with controlled execution
  1. 01Receive a task
  2. 02Read relevant context
  3. 03Choose a permitted tool
  4. 04Check its result
  5. 05Complete or escalate

Illustrative process. The exact components and controls depend on the workload.

Follow an order-status request

A model can explain a supplied order record. An assistant connected to an authorised order API can look up the current status. An agent may decide which lookup to perform, interpret the result and choose a permitted next step.

If the customer asks to change delivery details, the system needs identity checks, business rules and an action API. The model should not be the only component deciding whether that change is allowed. Permissions and validation must also exist in the application and underlying systems.

A workflow may be sufficient

A predictable process can use fixed steps: receive a request, classify it, retrieve a record and produce a draft for review. An agent is more useful when the route depends on information discovered during the task.

Start by drawing the steps a capable employee follows. Mark where judgement is needed and where a deterministic rule works. Adding autonomy to a process that is already well defined can increase cost and failure modes without improving the outcome.

What surrounds the model

  • Tools expose specific information or actions with defined inputs and outputs.
  • State records what has happened and what remains to be done.
  • Permissions limit what the system can read and change.
  • Evaluation checks whether the task was completed correctly.
  • Human review handles ambiguous or consequential decisions.

“Memory” is not a magical understanding of the company. It is information stored and supplied by the surrounding application. Decide what is retained, for how long and who can inspect or delete it.

Common mistakes

Giving an agent broad credentials because it might need them makes mistakes more consequential. Letting it repeat a failed write without an idempotency mechanism can duplicate transactions. Assuming a successful tool call means the business task succeeded can hide incomplete work.

For a delivery change, verify the resulting order record and communicate the confirmed state. If an API response is ambiguous, stop and reconcile rather than guessing that the request failed and trying again indefinitely.

Choose a bounded first agent

A useful starting point is preparing a support response or assembling an internal research brief from approved sources. Define completion, tool limits and review. Add write actions only after you can observe and evaluate the read-only workflow. The goal is a dependable job outcome, not the largest possible collection of tools.

Sources & further reading

Primary references for the technical background and regional statements in this guide. Planning examples and checklists are Novacom’s practical guidance; examples are illustrative unless explicitly identified as project experience.

FROM UNDERSTANDING TO A WORKING SYSTEM

Apply this to your organisation.

Bring your workflow, data boundaries and existing systems. We’ll help define a useful scope and the evidence needed to evaluate it.