A PRACTICAL BUSINESS GUIDE

AI agent or workflow: start with the decisions the job requires.

Break down the process before selecting technology. AI can interpret a request while rules continue to govern permissions, amounts and changes to business records.

The useful distinction is who chooses the next step

A workflow follows predefined paths: an event arrives, conditions are checked and expected actions run. It can include an AI model, for example to classify a message. An agent can also let the model choose tools and their sequence. Anthropic describes this architectural distinction; it is not a quality ranking.

For a business team, the first question is practical: do people follow the same steps, or must they decide how to investigate each case? Write down three ordinary cases and three exceptions. If you can describe the path unambiguously, test a workflow first. If paths genuinely vary, identify the specific part that needs flexibility.

Compare three approaches on the same task

A product label does not reveal its architecture. Ask the supplier which decisions the model makes, which the software checks and which remain with a person. A demonstration should make those boundaries visible.

Scroll the table to compare all columns.

Suggested operational decision criteria
ApproachUseful whenControl to retain
Rules and integrationsInputs are structured and the path is stableData validation and failure handling
Workflow with an AI stepText varies but subsequent actions are predictableOutput schema, allowed categories and review of ambiguous cases
Agent with limited toolsInvestigation or sequencing depends on what is foundPermissions, execution budget, stopping conditions and approvals

Illustrative example: a delivery status enquiry

A workflow with AI may cover this task. An agent becomes a testable option when investigation spans several sources and the next search depends on previous findings. Even then, permission to change the order is separate from permission to read it.

  1. Interpret the request

    A customer writes a free-form message. An AI step identifies the topic and proposes an order reference without inventing one when it is absent.

  2. Read an authorised source

    An integration looks up that reference and checks whether the requester may receive the information. Message content does not determine permissions.

  3. Prepare the response

    The system drafts a reply using verified status. A missing delivery date stays missing; a complaint or address change goes to a person.

Design a test that can disprove the choice

  • Use the same cases to compare a simpler solution with the more autonomous option.
  • Count correct results, human interventions, prohibited actions, total elapsed time and cost per successful case.
  • Include missing references, conflicting information, unavailable tools and malicious instructions inside documents.
  • Inspect the full execution path: a plausible final answer can conceal an incorrect read or action.
  • Decide before testing what improvement would justify the added complexity.

Do not rely only on prompt wording for spending limits or authorisation. Enforce them in the software that performs actions.

Finish with a bounded decision

The analysis should produce a testable sentence: “AI classifies and drafts; rules retrieve and validate; a person approves changes.” Attach it to the integration map and permissions matrix. It is more actionable than a general request for an autonomous agent.

If testing does not improve the process, retain the simpler option or repair the process first. More autonomy can later be added to a specific step after its errors have been measured and its stopping mechanism defined. Include an owner for the decision so the boundary does not drift when new requests arrive.

FROM IDEAS TO A BRIEF

A template to work from.

Business process inventory

A verifiable process map with a beginning, an end, an accountable owner and a baseline. Attach it to your project brief.

Download the Markdown template

System integration map

One connection record containing field mappings, permissions, duplicate handling and a reconciliation check.

Download the Markdown template

AI permission matrix

An identity–resource–operation matrix with justification, approver, negative tests and a revocation procedure.

Download the Markdown template

Practical questions

Is a workflow with AI less modern than an agent?

No. The useful test is whether it completes the task at acceptable quality, speed and cost. An explicit sequence can be the best fit for repeatable work.

Can one system use both?

Yes. An agent can investigate a bounded question within a workflow, while validation, record changes and approvals follow explicit rules.

Does the agent need access to every business tool?

No. Start with only the necessary operations. Distinguish read access, draft preparation and actual changes, using separate credentials and controls where appropriate.

References and method

Anthropic — Building effective agents

Technical distinction between workflows and agents. The examples and decision exercise here are Stolen Orbit operational proposals.

OWASP — LLM06:2025 Excessive Agency

Reference on risks from excessive tools, permissions and autonomy.

Which process should improve first?

Start with a concrete process, the systems you use and the people who will operate it every day.

Let’s discuss your process