Skip to content
Module
Module 5 of 6Lesson 1 of 2~14 min

Specify the assistant's tools and actions

As soon as an assistant acts on the user's behalf, every action needs a frame: what it can read, change, and when it must ask for confirmation. This lesson teaches you to specify your assistant's tools and decide whether it needs a controlled workflow or a true agent.

Lesson objective

By the end of this lesson, you will be able to specify an assistant's tools (name, description, inputs, read or write, confirmation, permissions) and justify the choice between a workflow and an agent.

Topics covered

  • tool calling
  • AI assistant actions
  • MCP
  • workflow vs agent
  • permissions

In the glossary

Full glossary

Where it fits

Actions and guardrails

What can the assistant do, and how do you stop it from doing what it shouldn't?

Lessons in this module

  1. Specify the assistant's tools and actions (this lesson)
  2. Design layered guardrails

What you will learn in the course

This lesson is part of the course Build an AI assistant for your product

  • Identify a use case that justifies an AI assistant and write its framing brief (problem, users, allowed actions, out of scope, success criteria).
  • Design the conversational experience: entry point, tone, handling uncertainty, handoff to a human and response format.
  • Choose and justify a knowledge strategy (instructions, injected context, RAG, fine-tuning) and a conversation memory strategy.
  • Specify the assistant's tools and actions (data read, actions written, confirmation, permissions) and choose how to build it.
  • Identify the risks (injection, leaks, excessive actions, costs) and design layered guardrails that go beyond the prompt.
  • Design an evaluation plan with a reference dataset, criteria, grading methods, release thresholds and a regression rule.
  • Define production metrics (product, quality, cost, latency), alert thresholds and the loop from user feedback to the evaluation set.