AI Agents
An agent is an AI colleague that works when you aren't there. Where Chat and the Assistant answer while you're in the conversation, an agent is woken by events or a schedule, does a job on its own, and leaves you things to review. Agents are real members of your workspace: they have an identity, appear in team lists, can be mentioned and messaged, and show up in Firm member rosters alongside your human team.
Operators use agents to take routine, well-scoped jobs off their plate: drafting replies to incoming email, summarizing meetings, chasing overdue invoices, triaging a support inbox. An agent never decides on its own to start working outside the ways you configure, and its permission level decides how far it can go without you.
Where to find it
Agents in the dock. It's also available inside a client, under the AI group, scoped to that client's agent activity.
Key concepts
- Soul: the standing instructions that describe who the agent is, what it's responsible for, its judgment calls, and its tone. Write it like you'd brief a new hire.
- Skills: written playbooks attached to one agent ("How we triage the support inbox"). The agent sees each skill's name and a one-line cue on every run, and opens the full playbook only when a job calls for it.
- Memory: short, durable facts an agent learns on its own from its runs and conversations: your preferences, corrections you made, recurring clients and how to handle them.
- Workflows: a saved, multi-step graph of AI steps (built in AI Chat) an agent can run when a wake-up matches.
- Permissions: one of three levels per capability: Read (look only), Propose (stage a change for your approval), Execute (commit the change itself).
- Wake-ups: the events and routines that start a run: incoming email, a finished meeting transcript, a recurring schedule, or your manual poke.
- Routines: recurring schedules you set on the agent ("every weekday at 8am, review yesterday's unanswered client email").
- Proposals: changes an agent prepares but hasn't committed. They wait in your notifications and on the agent's page until you approve or reject them.
- Visibility: Personal (only you see it), Shared (you own it, the firm sees its activity), or Team (a full team member, no single owner).
Create an agent
- Open Agents from the dock and start a new agent, optionally from a template.
- Give it a soul: its whole personality and brief.
- Set its visibility: Personal, Shared, or Team.
- Set its permissions (see below).
- Optionally add routines: recurring schedules that wake it.
- Save. The editor then also lets you write skills, attach workflows, and fine-tune its wake-ups.
You can also describe the agent you want to an AI Chat: the assistant can create it, set its soul and permissions, add routines and skills, attach workflows, and set its spend cap, with each change arriving as a proposal you approve.
Skills, memory, and workflows
Write skills in the agent's editor: a name, a one-line "when to use it" cue, and the playbook content. A skill's enable switch hides it from the agent without deleting your writing. The soul says who the agent IS; a skill says HOW a specific job is done.
Open Memory from the agent page's ⋯ menu to see every fact it has learned, rewrite anything it got wrong, delete anything, or turn learning off entirely with the Keep learning switch. Memory is learned automatically: you don't write it.
Attach saved workflows in the editor's Workflows section: the agent sees each one's objective, and when a wake-up matches, it runs the whole graph as bounded steps, with every change a step prepares arriving as a proposal. Click an attached workflow's row to expand its graph diagram before granting it, and use the expand button for a full-screen view. Agents can also fan out plain sub-agents on their own for large parallelizable jobs; those sub-workers can read and stage but never commit anything themselves.
Permission levels
Every capability you grant an agent carries one of three levels, and the difference is the whole safety model:
| Level | What it can do |
|---|---|
| Read | Look, and nothing else. |
| Propose | Prepare a change (draft the email, stage the task) but not commit it. The change waits for your approval. |
| Execute | Commit the change itself. |
Grant permission by capability, so an agent can be trusted to send email but only propose changes to your books. You can also scope an agent to specific clients. Start agents at Propose, watch what they produce for a while, then raise the capabilities you're comfortable with to Execute.
How an agent gets woken
Only in ways you configure:
- Events: activity in the areas it has read access to (new mail arriving, a meeting transcript finishing, and so on). By default an agent wakes on every event its permissions let it see: grant it email access and it wakes on every inbound message.
- Routines: recurring schedules you set on the agent. Each routine row also has a Run now button that fires it immediately, outside its schedule, without disturbing the next scheduled occurrence. The routine must be enabled (and the agent active) for the button to work.
- Run now: your manual poke, in the agent page's ⋯ menu: wakes the agent immediately to review its responsibilities and act on anything pending.
- Being invoked: you, or another agent you've granted the right to, can call it directly.
Two permissions cover meetings and the difference matters: Meetings › View transcriptions wakes the agent when a call you recorded in Bitment finishes transcribing, while Fireflies › View Fireflies sync wakes it when a new transcript arrives from your connected Fireflies workspace. Granting one doesn't grant the other. To fine-tune wake-ups without revoking a permission, open the editor's Wake-ups section (under Access): each event trigger has its own switch, so an agent can keep reading email on demand while no longer waking per message. Routines and Run now always fire regardless.
Chat with an agent
Every agent has its own conversation, reachable from its page. It can attach files the same way any AI chat does: the paperclip, or paste a screenshot with Cmd+V / Ctrl+V. The agent's main chat can also read its own run history: ask it "tell me about this morning's brief" and it looks up the run and reads the real transcript before answering. Turn on the audit toggle in the chat header to see what it looked up during each reply, plus the conversation's ID and its running AI cost. The agent page's ⋯ menu can export the open chat as a shareable PDF.
Review what an agent did
Everything an agent proposes lands in your notifications for approval, and the agent's own page shows its full activity. A drafted email proposal reviews in a full compose card right in the feed: pick the sending mailbox, edit the recipients and message with the email composer's formatting toolbar, and see the account's signature exactly as it will append. Approve & send sends what you see, edits included; Reject discards the draft. Clicking a Drafted email entry opens the Emails app on that draft.
Every completed routine firing and manual Run now also appears in the activity feed as a Ran entry, even when the agent concluded nothing needed doing. Clicking it opens that run's full transcript in the audit trail, showing the run's duration, its AI cost, and, when it retried, the attempt count. A run that finished without taking an action shows the agent's own closing summary rather than a bare label. A single wake-up isn't limited to one action: a routine sweeping a whole inbox can stage a reply to every thread that needs one, up to a per-run cap.
While a run is still working, its transcript is live: each reasoning step and tool result appears as it happens. You don't have to wait for it to finish to ask questions: a follow-up composer works mid-run, and the agent answers from what it has done so far. A Stop button ends a run early. A single run is bounded automatically, stopping at roughly a fixed AI-spend cap and a 10-minute run time, and it says so in its outcome line if it's cut short. A run interrupted by a server restart or crash recovers on its own within a couple of minutes, either retried or marked failed with an explanation.
If an agent is doing the wrong thing, the fix is usually its soul (clearer instructions) or its permissions (narrower scope), not turning it off.
Cost control
Agents spend AI tokens whenever they run. There's a per-agent spend cap you set in the editor, and the Tokens app shows exactly what each agent has cost, filterable by agent name.
Per-firm ownership and billing
An agent belongs to exactly one firm (or to no firm at all, as a Personal agent), and that ownership decides which firm's connected AI credentials pay for its work, the same way picking a model in a chat picks which firm bears the cost. A Personal agent bills against your own personal credential. Changing the model an agent uses can transfer which firm's credential bills it, since the credential you pick is what decides ownership. A per-firm filter on the agent roster, and a firm badge on each agent card, make this visible at a glance if you operate in more than one firm.
On a phone
The roster is a list of rows. Filters (top right) holds the status and firm narrowings; search has its own row. Pull down to refresh, swipe a row left to archive it, and tap + to create an agent. To archive several at once, choose Select agents from the ⋯ menu.
An open agent has Activity and Chat tabs. Activity shows a count when the agent is waiting on your approval. Its ⋯ menu holds Edit, Run / Pause, Run now, Memory, Activity audit, and Archive. A pulsing icon beside the name means the agent is working right now; tap it to watch the run. Past chats with the agent are behind the speech-bubble button above the conversation.
The editor is Soul | Setup | Access: the instructions, then the name / avatar / status / model / spend cap, then permissions, skills, workflows, wake-ups, and routines. Tap Save when you're done; leaving with unsaved edits asks first.
Tips
- Start every new agent at Propose. Raise a capability to Execute only after you've watched it get that job right consistently.
- Use skills for the specific, changeable procedures ("how we word a late-payment reminder"), and reserve the soul for the agent's durable identity and judgment.
- Review Memory occasionally: it's the fastest way to see what an agent has quietly concluded about your preferences.