Agents for developers: wiring tools, memory and guardrails
An AI agent doesn’t just answer: it takes steps for you, like searching, booking or filing. Here’s what that means, and why the safety catches matter.
Agents chain model calls with real actions. You can build simple ones without code; the craft is in giving them the right access and the right limits.
A production agent is a loop with typed tools, scoped credentials, durable state and evals. Here’s the minimum architecture, and the guardrails that stop real incidents.
Most of the time, an AI replies and you decide what to do next. An goes further: you give it a goal, and it takes the steps itself. It might search the web, fill in a form or update a spreadsheet.
That’s powerful, and it needs safety catches. A good agent asks before it does anything you can’t undo, like paying or deleting. It only gets access to what it needs. And it’s careful with instructions hidden in web pages or emails, a trick called .
If you try an agent, start with low-stakes jobs, like research or drafting, and watch what it does.
An loops: the model decides on a step, calls a tool, reads the result and decides again until the goal is met. The tools might be web search, your calendar or a spreadsheet, wired up through .
No-code agent builders and automation platforms let you set this up with forms rather than code. The decisions that matter are the same either way: which tools it can use, what it can see, and where a person approves the next step.
Watch for : a web page or email can contain text that tries to redirect your agent. Keep sensitive actions behind approval, and don’t let an agent that reads untrusted content also send email on your behalf without a check.
Define tools with strict schemas and validate every argument server-side; the model proposes, your code disposes. Scope credentials per tool and per user, so a compromised step can only reach what that tool needs. Make irreversible actions (payments, deletions, outbound email) require explicit human approval, and make the rest idempotent so retries are safe.
For memory, separate the working context of the current task from durable state you store yourself. Summarise long histories rather than replaying them, and keep the facts the agent relies on in your database, not only in the context window.
For guardrails, assume : treat tool outputs and fetched content as untrusted data, never as instructions, and don’t combine untrusted input, sensitive data and an outbound channel in one unsupervised step. Trace every call, build evals from real failures, and cap loops by steps, time and spend.
Try it yourself 2 minutes
- Find the agent or ‘research’ mode in your AI app.
- Give it a low-stakes goal:
Find three highly rated walks near me under five miles. - Watch the steps it takes, and check its sources.
Try it yourself 2 minutes
- List one repetitive task that takes four or more steps.
- Write down which tools an agent would need for it.
- Mark the step where you would want to approve before it continues.
Try it yourself 2 minutes
- Take one tool your agent calls and write its argument schema.
- Add a server-side check that rejects anything outside it.
- Add a step and spend limit to the loop.
Spotted a mistake? Tell us and an editor will check it.