A man working on a laptop in a cozy, modern office space with a focus on technology.

Photo by Matheus Bertelli on Pexels

“Agentic” should describe software that can form or revise a plan, use external tools, observe the result and continue working without a person directing every step. A product that generates an answer, follows one fixed workflow or requires approval after each action may use AI, but it does not clear the full technical bar for agency.

Picture ten browser tabs, each carrying some variation of “AI agent.” The first promises autonomous research. The second routes support tickets. The third drafts emails. By tab six, the label covers everything from a chatbot with integrations to software allowed to change production systems.

The pages may look similar. The operational risks are not.

The technical bar has three parts

Planning is the first test. Give the system an outcome rather than a script, then ask whether it can break that outcome into steps. A capable agent should also revise those steps when evidence changes. A hidden prompt containing a fixed sequence does not demonstrate planning, even when the interface calls it reasoning.

Tool use is the second test. Tools let software retrieve records, query databases, run code, update tickets or trigger another service. Access alone proves little. The important questions concern selection and control: Can the system choose the appropriate tool? Can it construct valid inputs? Can it interpret errors? Are permissions restricted to the job?

Autonomous looping is the third test. After acting, an agent should inspect the result and decide what comes next. That loop might be plan, act, observe, revise and act again. It also needs a stopping rule. Without one, autonomy can become repeated calls, duplicate actions or escalating cost.

These three capabilities form a practical minimum. Memory, multiple agents and natural-language interfaces may help, but none substitutes for the ability to plan, act and adapt.

Ten product pages, four recurring claims

A useful way to audit ten “AI agent” pages is to record only what each page establishes. Do not award capability points for the word autonomous, an animated workflow diagram or a list of integrations.

Pages one through three often describe conversational assistants. They accept a request and return text, perhaps with retrieval from connected files. Unless the page shows multi-step planning and repeated action based on observed results, the evidence supports “assistant,” not “agent.”

Pages four through six commonly describe workflow automation. A trigger starts a predefined sequence: classify a ticket, fill fields, draft a response and send it for approval. AI may make one decision inside the flow, but the vendor or customer designed the route in advance. “AI-enabled workflow” is the clearer label when the system cannot change that route.

Pages seven and eight tend to show tool-using copilots. These products can search records, call an API or create an issue after a user asks. They cross the tool-use threshold. The remaining question is whether they can pursue an outcome through several cycles without waiting for the next instruction.

Pages nine and ten may make the strongest case for agency. Look for a demonstrated loop: the system creates a plan, invokes tools, checks outputs, handles a failed step, changes course and stops when a defined condition is met. Even here, the page must explain boundaries. Autonomy without permission controls, audit records and escalation paths creates exposure rather than evidence of maturity.

This review method produces four defensible classifications: assistant, AI-enabled workflow, tool-using copilot and agent. A page can move between them as the product changes. The classification describes demonstrated behavior, not vendor intent.

Control claims deserve the same scrutiny

Salesforce’s announced expansion of Headless 360 adds MCP servers, Data 360 functions, Slack integrations, reusable skills and developer tooling intended for authorized AI agents. Those components could give agents more ways to reach business data and perform work. They do not, by themselves, establish planning or autonomous looping.

“Authorized” matters because tool access turns a model’s output into an operational event. Reading a customer record, changing it and sending its contents elsewhere are three different permissions. Buyers should ask how identity is assigned, which actions require approval, how credentials are scoped and what appears in the audit trail.

The control question also extends beyond security. Who owns a mistake when an agent follows a reasonable plan toward a badly specified goal? Where does it stop after repeated tool failures? Can an operator reconstruct the plan, tool calls, observations and final decision?

That concern echoes the control problem examined in Europe’s AI conversations at TechBBQ. The more work software can perform independently, the less useful a broad capability claim becomes. Buyers need boundaries they can inspect.

A procurement test vendors can answer

Ask the vendor to run one realistic task in a test environment. Change a relevant condition halfway through. Make one tool return an error. Then inspect what happens.

A credible agent should expose its objective, planned steps, available tools, permission limits, retry behavior, stopping conditions and escalation path. The demonstration should show how it reacts when the original plan no longer works. A polished success path proves far less.

Record each claim as reported fact, vendor assertion or observed behavior. That separation prevents a product-page adjective from becoming a procurement assumption.

Then assign the narrowest accurate label. If the software drafts after every prompt, call it an assistant. If it follows a route you built, call it workflow automation. If it chooses tools but waits for instructions between steps, call it a tool-using copilot. Reserve “agent” for the system that plans, acts, observes and adapts inside explicit limits.

The next time ten tabs all promise agency, one failed tool call will tell you more than ten hero banners.

Sources

Salesforce announcement supplied in the reporting brief; no source URL was provided.

Comments

No comments yet.