The smallest useful definition
A practical agent contains a goal, a decision component, a set of permitted tools, state, an execution loop, and a stopping rule. Remove the tools and execution loop and you usually have an assistant. Remove the boundaries and stopping rule and you have an operational risk.
The agent loop
A request enters the system. The model chooses whether to answer, ask for missing information, or call a tool. Application code validates that choice, checks authorization, executes the tool, and returns an observation. The model may take another bounded step or produce a final answer. The application—not the model—owns credentials, permissions, limits, and audit logs.
Where engineering begins
The difficult questions are outside the prompt: Which actions are reversible? Which require approval? What happens when a tool times out? How many steps are allowed? What evidence must accompany the answer? How does the system distinguish user instructions from untrusted document content?
A decision checklist
Use an agent only when the task benefits from choosing among actions or adapting a workflow. Prefer deterministic software for fixed rules, calculations, irreversible decisions, and workflows where every step is already known. The best design is often conventional code around one narrow model decision.
What to measure
Track task success, tool-selection accuracy, invalid tool arguments, total steps, latency, cost, escalation rate, and safety violations. A fluent answer is not proof that the workflow succeeded.