Agents
An agent is an AI worker with a role, a model, and a scoped set of tools and resources it may touch. This page shows how to create one, start it, keep it safe when nobody is watching, give it memory and a budget, delegate work to it, and find out why it stopped.
What an agent is
An agent bundles a System Prompt (its role), a model, the tools and resources it is allowed to use (tables, workflows, interfaces, sub-agents, applications, files, skills), its limits, and the ways it can be started (chat, webhook, schedule, chat widget). Each time it is started it runs a tool-calling loop: read the request, pick a tool, run it, read the result, and repeat until it gives a final answer or hits one of its limits.
The model can be a regular API model or a CLI agent (Claude Code, Codex, Gemini CLI, or Mistral Vibe) that runs through a bridge. Which ones you can pick depends on what your administrator has set up; see Models & providers.
The Agents page
Open Agents in the sidebar. The page has six tabs:
| Tab | What you do there |
|---|---|
| Agents | List, search, and delete your agents. Create one with Create Agent, or start from Use a template. Click an agent to edit it. |
| Skills | Manage reusable instruction sets and assign them to agents. See Skills. |
| Memory | Read, add, correct, pin, deactivate, or delete the long-term facts agents keep for this workspace. See Long-term memory below. |
| Fleet | A full-screen canvas of your agents and their sub-agents, tools, and resources. Select an agent to inspect its configuration, recent executions, and each execution’s tool calls. Edit mode lets you disconnect a tool or resource from an agent. |
| Metrics | Totals (executions, tokens, average duration, success rate) for all agents and for Orbi, per-agent performance, tool statistics, and daily activity over the last 7, 30, or 90 days. |
| Settings | Agent & Orbi defaults: the settings every new conversation starts with. This is the only place to edit them: the Chat defaults link in Settings > Overview opens this tab. |
Delegated tasks are not on this page: they live on the task board, under Board > Tasks. See Tasks & board.
Create an agent
You can ask the assistant in the chat to create an agent for you, or use the editor. The editor has three steps:
- Basic Info
Give the agent a name, a description, and a System Prompt that states its role.
- Configuration
Pick the Model Provider and Model Name, the tools and resources it may use, its skills, its Credit Budget, and its limits. Open Advanced mode for temperature, the per-turn loop guards, Generation, Mailbox, and context compaction.
- Integration
Optional ways to start and reach the agent: Reach me outside the app (a chat channel), Webhook, Schedule, and Chat Widget (embed a chat on your website).
How an agent is started
| Started by | What happens |
|---|---|
| Chat | You send a message in a conversation with the agent. One message starts one run. |
| Webhook | An external HTTP call hits the agent’s webhook URL. Optionally it sees its previous webhook conversations. |
| Schedule | A cron schedule fires with the Scheduled Task message. If tasks are waiting in its inbox, it gets its task list instead. |
| Chat Widget | A visitor chats with the agent on your website. |
| Workflow | An AI Agent node in a workflow runs the agent as a step. |
| Another agent | A parent agent calls it as a sub-agent with execute. Its task inbox is added to the prompt. |
| A task | A task is assigned to it with the default start mode, or a task waits for its review. |
Model & reasoning effort
Model provider and model name are both optional. Leave them empty and the agent uses the platform default model. An unknown provider and model pair is replaced by the default and reported back as model_substituted, so saving does not fail on a model that was removed. Saving an agent on a CLI agent you are not allowed to use is refused.
Temperature goes from 0 to 2 (default 0.7): lower is more predictable, higher more creative.
Reasoning effort is an optional setting with six levels: minimal, low, medium, high, xhigh, max. It is a level, not a token budget. Only three consumers honor it: Claude Code, Codex, and the direct Anthropic API. Every other provider ignores it, and the editor hides it for them. Inherit (model default) leaves the choice to the model’s own default.
| Consumer | How the level is applied |
|---|---|
| Claude Code | Accepts low, medium, high, xhigh, and max; minimal is raised to low. |
| Codex | Accepts minimal, low, medium, high, and xhigh; max becomes xhigh. On a model that is not a codex-max variant, xhigh and max are lowered to high. |
| Anthropic API | Uses the level as is. |
| Everything else | Ignored. Gemini CLI and Mistral Vibe have no effort setting. |
When several levels are set, a per-conversation choice wins over the agent’s value, which wins over the default an administrator set for the model.
Limits & timeouts
Four independent limits can stop a run. The editor shows the same defaults the platform applies.
| Limit | Default | Range | What happens |
|---|---|---|---|
| Max Tokens | 16000 | Lowered automatically to the model’s own output ceiling | The model’s answer for one turn is cut at this many output tokens. |
| Max Iterations | 100 | 1 to 1000 | The run stops with MAX_ITERATIONS after this many tool-call rounds. |
| Execution Timeout (s) | 3600 | 10 to 7200 | The run stops with TIMEOUT when its total time runs out. |
| Inactivity Timeout (s) | 300 (5 minutes) | 10 to 7200, or 0 to turn it off | The run stops with INACTIVITY_TIMEOUT when the agent produces nothing at all for this long. |
Three more guards, under Advanced mode, stop a runaway agent:
| Guard | Default | Range |
|---|---|---|
| Identical-loop stop | 15 identical tool calls, then LOOP_DETECTED | 2 to 100 |
| Consecutive-loop stop | 40 tool calls in a row, then LOOP_DETECTED | 4 to 200 |
| Max per-resource / turn | 5 calls per turn on each kind of resource (agent, skill, sub-agent, interface, workflow, table) | 1 to 100 |
A sub-agent started with executegets a timeout: the value the calling agent passes, otherwise the sub-agent's own execution timeout, otherwise 600 seconds. Whatever the source, it is kept between 10 and 7,200 seconds.
Tools & scope
Integration tools (the catalog of external APIs) are chosen with Available integration tools:
| Choice | tools_mode | Behavior |
|---|---|---|
| All integration tools (default) | all | The agent may call every catalog tool. |
| Custom selection | custom | Only the tools you pick, up to 30. |
| No integration tools | none | No catalog tools; the built-in tools (tables, web search, and so on) stay available. |
| No tools at all | off | Every tool is off, built-in ones included: a pure reasoner. Resource grants are ignored. |
Resource Access is a separate choice. A new agent has no access to your workflows, tables, interfaces, sub-agents, or applications until you grant it, one family at a time: all of them, none, or a custom list. Web Search is the one capability that starts on.
Each family also has a read or write mode. write (the default) allows everything; read allows only reading actions, for example get, list, and query_rows on a table, or get, runs, get_run, and wait_run on a workflow. File Access and Long-term memory have their own read or write mode too.
Two capabilities are off until you turn them on, because they act on the outside world:
| Setting | Default | What it allows |
|---|---|---|
| Generation | Off | Create images, videos, audio, voices, and music. Each asset is charged in credits at the model’s rate. See Studio. |
| Mailbox | Off | Read and send email on the account’s connected mailbox (IMAP to read, SMTP to send). Mailbox permissions: Full access or Read-only. |
An agent that creates or edits another agent can only switch these on for it when it has them itself; otherwise it leaves them off and asks you to enable them.
Permissions: when an agent asks before acting
Some actions are sensitive: running a workflow or a catalog tool, calling a sub-agent, installing an application, sending or deleting an email, resolving a paused approval, putting a workflow live or taking it off, and giving an agent a schedule.
In the chat
In a chat with Orbi (the general assistant, no agent selected), a sensitive action shows a permission card, for example Run this action?, Send this email?, or Put this workflow live?. The action waits on the card: Authorize lets it run and the agent continues in place, Decline stops it. Tick Don't ask again in this conversation to stop being asked for that kind of action in this conversation. If you answer after the agent has stopped waiting, your answer starts its next turn.
A chat with a specific agent does not ask, unless that agent has Ask my permission before a sensitive action turned on (see below).
In runs nobody is watching
By default, an agent started by a schedule, a webhook, or a task runs its actions without asking. To make it ask, open the agent, go to Integration, turn on Reach me outside the app, and turn on Ask my permission before a sensitive action. From then on:
- The request is sent with approve and reject buttons (links to a confirmation page on Microsoft Teams) to the chat channel chosen as the agent’s Destination (the workspace default if you leave it empty). See Chat channels.
- If nobody answers in time, the run ends without doing the action. A later approval authorizes that exact action (same tool, same arguments) for the agent’s next run. It does not approve other actions of the same kind.
- The agent does not send the same request twice while one is waiting. Unanswered requests expire after 24 hours, and the agent may then ask again.
- With no working channel, nothing is sent, and the action is not done. The editor warns you: This agent asks permission before sensitive actions, but has no channel to ask on.
Turning Reach me outside the app off also turns off the permission setting: the agent’s questions are then answered by assumption, and sensitive actions in unattended runs are not done.
Questions the agent asks you
With the ask_user tool, an agent can put one to four multiple-choice questions to you (two to four options each). You can always type your own answer instead of picking one.
| Where the agent runs | What happens |
|---|---|
| A chat you are in | A question card appears, one question at a time. The agent waits up to about 4 minutes (about 2.5 minutes on Claude Code, Codex, and Gemini CLI). If you answer later, your answer starts its next turn. Skip lets it continue without an answer. |
| Schedule, webhook, or task | The question is sent to the agent’s chat channel, and the agent is told where it went. Your answer reaches its next run. Unanswered questions expire after 6 hours. |
| No channel connected | The agent is told nobody can answer, decides with what it has, and states its assumption. |
| Workflow node | The agent is told nobody can answer, at once. |
| Sub-agent | The question goes back to the agent that called it. |
Long-term memory
Long-term memory holds durable facts that agents keep between conversations and runs: your preferences, corrections, project decisions, useful references. It is different from conversation history and from skills: a skill says how to do something, a memory says what is true here.
- Each entry has a Title, a one-line Summary, optional Details, and a Type (About the user, Feedback, Project, Reference).
- The summaries of active entries are added to every agent’s context in the workspace, on every run. The details are read only when an agent needs them. An entry marked Always in context (pinned) sends its full details every time, so keep that for rules that must never be missed.
- Memory belongs to the workspace: switch workspace and you see that workspace’s memory. An entry can also be private to one agent (One agent); other agents do not see it, but workspace members still do on the Memory tab.
- Agents save entries as they work. You can add, edit, or delete one on the Memory tab. Deactivate makes agents stop using an entry while keeping it; an agent saving the same fact again does not reactivate it.
- Set an agent’s Long-term memory to Recall only for an agent that should use the workspace facts without changing them.
| Memory limit | Default |
|---|---|
| Summary length | 240 characters |
| Details length | 8000 characters |
| Entries per workspace | 200 (deactivated entries count) |
| Entries private to one agent | 50 |
| Summaries added to context | Up to 40 |
| Pinned entries added in full | Up to 3 |
Context compaction
Compaction replaces the oldest part of a long conversation with a summary so it keeps fitting in the model’s context window. Three settings under Advanced mode control it, and each can inherit the default:
| Setting | Meaning |
|---|---|
| Context compaction | On, off, or inherit (the conversation’s setting, then the platform default). |
| Compact after N turns | The minimum number of new turns between two summaries. It applies when the platform decides by turn count, which is the default. |
| Summariser model | The model that writes the summary. Empty means the agent’s own model. |
Credit budgets
Credit Budget caps what an agent may spend. Empty means unlimited. Credits are the real metered cost of each model call (priced per model and per token), not a fixed amount per iteration.
An agent that is already over its budget is refused before it starts, on every way of starting it (schedule, webhook, widget, workflow node), and a refused scheduled run does not count toward the schedule’s maximum number of runs.
Budgets cascade. When agent A calls sub-agent B, B’s whole budget is reserved from A and from every agent above A. A parent with a budget of 100 can never let its whole tree spend more than 100. A child that needs 50 credits cannot start under a parent with only 30 free: it stops with BUDGET_EXHAUSTED, scope parent_reservation. When the child finishes, what it really spent is charged up the chain and the rest of the reservation is released.
| Field | Meaning |
|---|---|
credits_consumed | Total spent by the agent, its sub-agents included. |
credits_consumed_from_subagents | The part of the total spent by its sub-agents. |
credits_reserved | Currently reserved for sub-agents still running. |
credits_free | Budget minus consumed minus reserved; empty when the budget is unlimited. |
Reset Mode decides when the count starts again. With Cumulative (the default) it never resets on its own; with Weekly it resets 7 days after the last reset; with Monthly it resets when the calendar month changes (in UTC). Reset Credits in the editor restarts it by hand at any time.
Task delegation
Agents can hand work to other agents, or to a shared backlog, as trackable tasks. You see and manage the same tasks on the task board (Tasks & board).
| start_mode | Behavior |
|---|---|
| execute (default) | Starts the assignee now and waits for the outcome. With a reviewer agent, it also waits for the review. |
| in_progress | Starts the assignee now and returns at once; the task runs in the background. |
| pending | Only creates the task. It waits until the assignee is started and picks it up. |
A task with no assignee goes to the backlog and is always pending. Only agents with Shared backlog participation on (off by default) and a way to wake up are offered backlog tasks and may claim them.
Every task follows the same lifecycle:
pending -> in_progress -> in_review -> completed | failed | cancelledA finished or rejected task always goes through in_review. With a reviewer_agent_id, that agent reviews it. Without one, you are the reviewer, and the task waits in review until you act (that is expected, not stuck). After max_review_attempts rejections (1 to 20, default 3), the task fails; it is never approved automatically.
| Role | Actions |
|---|---|
| Assignee | inbox, task_complete, task_reject |
| Reviewer | review_inbox, task_approve, task_reject_review |
| Creator | outbox, task_update, task_cancel, task_delete |
| Anyone with access | task_get_context, task_get_execution |
For recurring work, recurrence_create makes a cron template that creates a fresh task on each tick, without flooding missed ticks, managed with recurrence_list, recurrence_update, and recurrence_delete. A recurrence without a target agent posts to the backlog.
Guards: at most 5 assign calls per turn and a delegation depth of 5. Calls to sub-agents with execute are capped by Max per-resource / turn (5 by default). A sub-agent sees its last 20 messages by default, plus a list of the tasks in its inbox.
Skills
Skills are reusable instruction sets. An agent can have up to 10. Setting an agent’s skills from the chat replaces its whole list; use skill(action='assign') to add one without replacing the others. Skill access is write (default) or read (get, list, list_folders, help). See Skills.
Built-in tool modules
Besides catalog tools, an agent can use built-in tools, each described to it in one line of its system prompt. A module is present only when the agent has access to it.
| Module | What it does |
|---|---|
| catalog | Search and call external APIs (Gmail, Slack, and the rest). |
| table | Tables: rows, columns, filters, and vector columns for similarity search. |
| interface | HTML pages: forms, dashboards, multi-page apps. |
| agent | Configure and run sub-agents; manage tasks. |
| skill | Reusable instruction sets assigned to agents. |
| memory | Long-term facts: save, get, list, search, delete. |
| workflow | Build, run, inspect, and stop workflows. |
| application | Find, install, run, and publish marketplace applications. |
| web_search | Search the web, read a page, or drive a browser (see Browser Agent). |
| generation | Create an image, video, audio, voice, or music asset. Off unless Generation is on. |
| files | Browse and reuse workspace files. |
| mailbox | Read and send email on the connected mailbox. Off unless Mailbox is on. |
| wait | Pause 1 to 240 seconds between status checks instead of polling. |
| ask_user | Ask you a multiple-choice question (see Questions the agent asks you). |
| channel | Connect and manage the workspace’s chat channels (see Chat channels). |
When a tool call fails with a 401 or 403, the agent uses the credential tool (actions require, list, variables, set_variable). require shows you a card to connect or reconnect the service, with the missing scopes when the provider named them. set_variable writes a workflow variable that later steps read with {{$vars.name}}.
To wait for a workflow run, workflow(action='wait_run') blocks until the run finishes, for up to 120 seconds by default and 240 at most. On timeout it returns timed_out=true and the run keeps going; the agent calls it again.
Related AI nodes
Guardrail and Classify are AI nodes you place directly in a workflow.
| Node | Purpose | Key outputs |
|---|---|---|
| Guardrail | Checks content against safety rules. | passed, violations, details, sanitized, tokens_used, model, provider |
| Classify | Puts the input in one of your categories and routes to its branch. | selected_category, selected_category_index, confidence, reasoning, probabilities (decision models only), tokens_used |
See the Node reference for every parameter and output.
Metrics & inspection
Each agent keeps running totals: executions, tokens, tool calls, successes, failures, total duration, and the time of its last run. The Metrics tab charts them. In the Fleet tab, select an agent to open its recent executions, and select an execution to see its conversation and every tool call with its arguments and result. From the chat, task_get_execution with include_tool_calls=true returns the same tool calls, with secrets redacted.
Troubleshooting: why did my agent stop?
Every run ends with one of ten stop reasons, in three outcomes:
| Stop reason | Shown as | Outcome | What to do |
|---|---|---|---|
COMPLETED | Completed | Success | Nothing: the agent gave its final answer. |
MAX_ITERATIONS | Iteration limit reached | Partial | Raise Max Iterations, or narrow the task. |
TIMEOUT | Timed out | Partial | Raise Execution Timeout (s), or split the work into tasks. |
BUDGET_EXHAUSTED | Credit budget exhausted | Partial | Read the scope: tenant (your account’s credits), agent (its own Credit Budget), parent_reservation (a parent agent could not reserve the budget), or browser (the browser-agent quota). |
LOOP_DETECTED | Tool loop detected | Partial | Look at its last tool calls in Fleet; fix the prompt or the failing tool. Adjust the loop guards only if the repetition is intended. |
STOPPED_BY_USER | Stopped by user | Partial | Someone pressed stop. |
CANCELLED | Cancelled by system | Failure | The platform cancelled the run (for example during a restart). Run it again. |
NO_TOOLS | No tools available | Failure | Check Available integration tools and Resource Access. |
ERROR | Execution error | Failure | Usually the model provider failed. Check the execution in Fleet, then retry or change model. |
INACTIVITY_TIMEOUT | Stopped (inactivity) | Failure | The agent went silent, often a slow tool. Raise Inactivity Timeout (s) or set it to 0. |
A Success or Partial stop leaves usable output; a Failure does not.
Other common problems
| Symptom | Likely cause |
|---|---|
| A scheduled agent never runs | It is over its Credit Budget (refused before starting), or the schedule reached Max executions. |
| An unattended agent never did the sensitive action | It asked for permission and nobody approved, or it has no working chat channel. Check Settings > Channels and the agent’s Destination. |
| The agent says nobody can answer its question | It ran unattended with no chat channel, or it ran inside a workflow node. |
| Delegated tasks sit in pending | The assignee is never started. Give it a schedule, or assign with the default execute mode. |
| A task stays in review | No reviewer agent was set, so you are the reviewer. Approve or reject it on the task board. |
| The agent cannot create images or send email | Generation or Mailbox is off for that agent. |
| Your saved model changed | The model was no longer available and was replaced by the default (model_substituted). |