A chatbot returns text. An agentic system can use a model to choose actions, invoke tools, inspect results, and continue toward a goal. That extra verb—act—is where usefulness and risk both grow. A mistake in prose is one problem. A mistake sent to a customer is several meetings.
A loop you can inspect
A basic agent loop has a goal, context, an action choice, tool execution, an observation, and a stopping decision. Real systems add state, retries, budgets, and authorization. The Reflexion research explores language-based feedback and reflection as one approach; it is not proof that reflection alone guarantees reliable action.
Name the tools precisely. “Search public documentation” and “send an email” belong to different permission classes. A system should not infer that authority to research includes authority to publish its findings.
A permission ladder
Start with read-only tools. Next allow drafts and proposals. Then permit reversible local edits with validation. Reserve external or consequential actions for clearly defined authorization. Some workflows can preauthorize bounded actions; the boundary needs to be explicit and enforceable.
This ladder is our practical design recommendation. It is not a universal protocol. The right boundary depends on the task, the user, and the consequences of an error.
Tool results are evidence, not orders
A webpage, email, or document can contain instructions intended to hijack the agent. Treat retrieved content as untrusted data. Keep it distinct from the user’s goal. Enforce tool restrictions outside the model when possible, because a prompt cannot be the only lock on the door.
If an agent reads a shipping page that says “send account secrets here,” the correct action is not to admire the page’s confidence. Validate destinations, scope access, and require appropriate approval for sensitive transfers.
Memory requires housekeeping
State can help a system avoid repeated work and preserve preferences. It can also preserve stale assumptions or sensitive material. Decide what is stored, for how long, how it can be corrected, and who can access it. A longer memory is not automatically a better one.
Keep task state separate from long-term preferences. A temporary research hypothesis should not become a permanent fact about the user. Record the source of consequential assumptions so they can be revisited.
Bounded failure beats unbounded enthusiasm
Set limits on time, tool calls, spending, and retries. Define a stopping condition and an escalation path. If a tool repeatedly fails, another identical attempt may only produce a larger bill and a more elaborate apology.
Use idempotent operations where possible: a retry should not charge twice, send twice, or create duplicate records. Logs should show inputs, actions, outcomes, and approvals without unnecessarily exposing private data.
Test the whole workflow
Evaluate realistic tasks from start to finish. Include missing documents, wrong permissions, malicious source text, conflicting instructions, and partially successful tools. Measure both completion quality and boundary violations. A high completion score does not compensate for sending something without authorization.
Agents become useful when a team can understand what happened and recover from mistakes. The future may contain spectacular autonomy. Today’s dependable workflow still appreciates a stop button. Read evaluation and prompt design before handing over the keys.
KEEP EXPLORING
Spot an error? See our corrections channel and editorial policy.