What an AI agent actually is
Workshop · 3 of 7 · A chatbot answers. An agent acts.
A chatbot takes your words and gives words back. An agent takes your words and does things — reads files, searches, writes, books, sends — then comes back with the result. That single difference changes everything about how you should think about it.
Not just a smarter model
An agent is a model plus three things: tools (what it can reach — your files, the web, your calendar), memory (what it can retain between steps and sessions), and boundaries (what it is allowed to do without asking you). The model supplies the reasoning; the tools supply the hands; the boundaries supply the trust. Take away any one and you don't have an agent — you have either a chatbot, an amnesiac, or a liability.
The boundaries are the product
This is the part most people get backwards. What makes an agent safe to use is not that it's smart — it's that its authority is explicit. A well-built agent can tell you what it may touch, what it must ask before doing, and what it will never do. Reading is safe; sending is not; anything irreversible should require your explicit yes. When you evaluate any AI product, ask one question first: can it show me its limits? If the answer is no, the intelligence doesn't matter.
Agency is a dial, not a switch
The simplest agent executes exactly what you specify. A step up, it chooses between options you defined. Higher still, it plans its own sequence of steps toward your goal. At the top, it revises its own plans as it learns. More agency is not better — it's more delegation. Give a task the lowest level of agency that reliably does the job, the same way you'd delegate to a new hire: tightly at first, more loosely as trust is earned — and trust is earned with receipts, not vibes.
We hold our own systems to this standard: every agent behind this site declares its purpose, its permissions, and its prohibited effects, publicly, at /agents/index.json — and nothing deploys if the code and the declaration disagree.