Create and manage agents
Build a custom agent with allowed tools and limits, test it, switch agents on and off, and understand how an agent narrows access.
Required permission: ai.configure
Before you begin
- Agents must be on in Applications > AI Assistant > Features.
- You need ai.configure to create, change, test or delete agents. Everyone with ai.use can see the list and choose an agent in a chat.
- An agent can only narrow what a user may do. The tools an agent finally offers are the user's own permissions intersected with the agent's allowed list. An agent can never give someone access they do not already have.
Steps
Create an agent
- Open AI Assistant > Agents and select New agent.
- On the General tab, enter the Agent name (up to 80 characters) and, for a new agent, the Code. If you leave the code blank it is made from the name, in lower case with only letters, digits and underscores, up to 30 characters.
- Set Status (Active or Disabled), Visibility (Company or Private) and the Purpose (up to 300 characters; the Fields setting can make it Hidden, Optional or Required).
- Add System instructions (up to 8,000 characters), for example 'Always show amounts in AED and mention the due date.' They are used with Claude, not by the built-in engine.
- Choose a Model, or Company default. Tick the Allowed modules and the Allowed MCP servers.
- Open the Allowed tools tab. Tick the tools the agent may use, or use Block beside a tool to forbid it. An empty allowed list means every tool the user may use.
- Open Approval & limits. Choose the Confirmation level (Standard or Strict) and Max execution steps (1 to 12; default 6).
- Select Save. The message is 'Agent saved.'
Test the agent
- Open the Test console tab and enter a prompt such as 'Show overdue invoices above 5000'.
- Read the trace. A read tool shows its result. A write tool shows 'would propose (confirmation required)' and nothing is written. A tool outside the agent shows 'not allowed for this agent or user'.
Switch an agent on or off
- Set Status to Disabled to remove it from the composer list. Chats fall back to the General ERP Agent.
- To delete a custom agent, open it and select Delete. Standard agents cannot be deleted; they can only be disabled.
What happens next
- The agent appears as a tile showing Standard or Custom, Active or Disabled, the number of tools you can use, the approval level, modules and model.
- Users pick the agent from the selector in a chat, or type
/code, for example/collections. - If a user asks an agent for something it blocks: 'The Sales Agent agent isn't allowed to use that. Try the General ERP Agent.' If the user lacks permission: 'You don't have permission to see that, so I can't answer it.'
Worked example. You create 'Read-only sales' with the tools search_customers and sales_summary and block create_quotation. A Sales user asks it 'Show sales this month' and gets an answer. Asked for a quotation, it declines and suggests the General ERP Agent. If you disable the agent, the user's next message goes to the General ERP Agent.
Good to know
- Codes are unique: 'An agent with this code already exists.' A blank name: 'An agent needs a name.' A code that reduces to nothing: 'An agent needs a code.'
- Tool names must exist: 'Unknown tool: drop_db.'
- 'Steps must be between 1 and 12.' When the limit is reached, the answer may be partial.
- Two administrators saving at once: 'Somebody else changed this agent. Reload and try again.'
- Choosing Private visibility does not hide the agent from other users yet; they can still see and select it.
- Ticking Allowed modules is stored but does not limit the tools; use the tool list for that.
- An agent with no MCP servers ticked uses every enabled outside server, so tick the servers you want when you restrict an agent.
- The Strict confirmation level is stored; the confirmation card does not look different today.
- A model name you type is accepted up to 60 characters; an invalid one makes the chat fail with 'temporarily unavailable'. Use the list.