Set what your agent can read and do
The model writes the sentence. Your configuration decides which sources it may read, which actions it may take, and the exact conditions under which it stops and a person takes over.
What happens when a customer writes
Each turn follows four recorded steps. Open the run to inspect an answer and the steps that led to it.
It reads the message as data
Customer text and retrieved passages enter the request as untrusted parts. They are bounded in length and redacted on the way in, and they can never occupy the slot your policy instructions sit in.
It answers from sources you approved
Retrieval runs over the knowledge sources selected for that agent and returns a small set of excerpts. An agent with no usable excerpt hands over instead of improvising.
It calls only the actions you enabled
An action runs when it is registered, allowed for this agent, and its arguments match a closed schema. Every effect carries an idempotency key and a deadline.
It records what it learned
Profile facts are written only for the keys you listed, and each one keeps the message and the turn it came from, so a stored value can be traced back to what the customer actually said.
Nothing is indexed implicitly
Create and index each knowledge source, then choose which agents may use it.
- Five kinds of source
- An article from this bot's knowledge base, pages of your own site, an uploaded document, a short policy instruction you write yourself, or a single stored fact. A draft article produces no searchable content at all.
- You can see what it will find
- Test retrieval shows the excerpts an agent would receive for a question you type, before a customer ever asks it.
- Answers name their sources
- Answers cite their sources. Analytics shows how often each source is retrieved, including sources that were never used.
What it may do, and where it stops
Set the agent's allowed actions and stopping rules in one place. The server checks them on each run.
What it may do
- A fixed catalog of actions
- An agent may hold at most eight actions, chosen from the ones the platform registers. A name outside that catalog is rejected before the request is even built.
- Confirmation on side effects
- Anything that writes outside the conversation carries an explicit confirmation decision, and can be narrowed further to named resources.
- Closed argument schemas
- Arguments must match a schema that forbids unknown fields. The model never supplies a bot, a customer, a URL or a credential; those come from the server context.
Where it stops
- Low confidence
- Below the confidence threshold you set, the agent does not answer on its own. It hands the conversation over instead.
- Outside working hours
- Against the schedule you set, one of three behaviours: answer as usual, prepare a draft for an operator, or hand over immediately.
- Instructions hidden in content
- Text from a customer or an indexed page is data. Authority-looking fields in model output are stripped, and the shape of the response is generated by the server, never chosen by the model.

Choose an AI provider
The agent talks to an OpenAI-compatible endpoint that you configure. Change the provider and the journey logic around the agent does not change with it.
- Your own provider key
- Add an AI integration with a base URL, a model name and your key. It is stored encrypted, and the same integration produces the embeddings that index your knowledge sources.
Validate, simulate, apply, and replay
Check the agent's configuration before activation and inspect recorded runs afterward.
Validate
The launch check refuses to activate an agent whose settings are invalid, whose channel is already taken by another active agent, whose source or operator group is missing, or that has no AI integration.
Simulate
The agent check runs a safe pass that does not call the model, does not send a message, and does not run an action or create a booking. It reports which effects it suppressed.
Apply
Activation stores the whole configuration as a version. Editing an active agent creates the next one, and conversations already under way keep the version they started on.
Replay
A run is recorded step by step. Reopen it, read why each step happened, run it again against recorded fixtures with a fixed clock so two runs are identical, and save it as a regression case.
Hand over with a summary and sources
A handoff opens the ordinary support dialog, sets the operator group, and appends a redacted summary with the reason, the facts collected and the sources cited. While a conversation is handed over the agent stays silent, and it resumes only when the dialog asks it to.

Start with one agent on one channel
Point it at a handful of sources, give it one action, and set the condition that hands everything else to a person. Widen it once you have watched it run.
Build your first journey