← Agentic Foundations
Foundations · Basics

What makes an AI system agentic?

Understand goals, tools and decisions, with one task explained as a chat response, a workflow and an agent.

An agentic AI system can choose steps toward a goal, use tools and respond to what those tools return. The model contributes decisions about the next step. Application code determines which actions are possible and permitted.

The word describes behavior. A product called an agent may have limited independence, while an application without that label may perform several model-directed steps. Ask what it actually does before relying on the name.

Three ways to complete the same task

Consider a customer who says an order has not arrived. These examples are illustrative designs, not claims about a vendor product.

Approach What happens Who determines the next step?
Chat response The system explains how you can check delivery. You carry out the work.
Fixed workflow Software looks up the order, checks tracking and sends a predefined message. The developer defines the sequence.
Agent The model looks up the order, notices missing tracking, checks another permitted source and prepares a reply. The model chooses within application limits.

A workflow can include AI. One step might classify the customer’s message without controlling the process. An agent can also sit inside a fixed workflow, with mandatory approval before a refund.

Anthropic distinguishes predefined execution paths from model-directed tool use. This is a useful architectural distinction, rather than a universal definition. Its article dates from 2024, so we use it here for the concept rather than current tooling. Anthropic: Building effective agents.

The five things to identify

Goal: the result to produce. “Investigate this delivery problem and prepare a reply” gives it a task. “Be useful” leaves too much unspecified.

Context: information available for the current decision, such as your request, retrieved records and previous tool results. It can be incomplete or outdated.

Tools: functions that read or change something outside the model. Looking up tracking is a read. Sending a message changes something outside the application.

Decision cycle: the model proposes a step, a permitted tool executes it and the result informs the next decision. The cycle can end after one call or continue across several.

Stopping rules: conditions that end work or return a decision to a person. Missing identity, exhausted runtime or a requested payment can require a stop.

Independence has several dimensions

An agent might choose which documents to read while having no permission to send email. Another might send approved reminders but have no access to payment records. Avoid treating independence as a single on/off setting.

Write down permissions separately for reading, preparing, changing and communicating. Define when each action is allowed. An instruction expresses intent; a backend access check must enforce restrictions that protect data or prevent unauthorized changes.

More independence creates more possible execution paths to test. For stable inputs and a known sequence, an ordinary function or workflow may be the better starting point.

What an agent cannot establish by itself

A fluent answer does not prove that a tool succeeded. “I updated the case” requires evidence from the case system. A plan does not prove execution. A generated citation does not prove that the source supports the claim.

Agents can misunderstand goals, choose unsuitable tools and carry errors into later steps. Good design makes those failures visible and limits their consequences. You need a way to assess the completed task.

Retrieval helps supply evidence but does not guarantee an accurate answer. Persistent memory can preserve useful context but can also preserve an error. Assess these capabilities against your actual task.

Your first checklist

  • Describe one observable result the agent must deliver.
  • List the sources and tools it may access.
  • Separate drafts from actions that change records or contact people.
  • Define how it handles missing or conflicting information.
  • Decide what evidence proves success and who receives failures.

Use the same checklist when comparing products. Ask a demonstrator to show the tool results and action record alongside the final response.

Continue reading

Using an agent and checking its work ↗

Give a clear task, understand its permissions and verify the result before you rely on it.

Prepared with AI assistance and checked against the linked documentation. Examples and numerical limits are illustrative unless stated otherwise. These guides do not report independent product testing. Check current documentation before choosing a tool.

Search the publication

Find a story by title, topic, or keyword.

Press Escape to close