The tool and logic nodes
Only Agent and Classify spend credits. Every node on this page is free to run.
Answer from your own material
1
Add a File search node
Drag File search onto the canvas and connect it before the Agent node that will use its results.
2
Create a knowledge base
In the node’s panel, give it a Knowledge base name and paste your content — the box prompts you to “Paste FAQs, policies, protocols…”. Opening hours, preparation instructions, a returns policy and a referral protocol are all good candidates.
3
Point the Agent node at the results
The search writes its matches into the run. Reference them from the Agent node’s instructions so the model answers from your material rather than from general knowledge.
Constrain what the agent may say
Guardrails checks a value and sends the run down a pass or a fail path. Put one between the Agent node and anything that sends a message, and route fail to an End node or to a User approval step so a doubtful answer is seen by a person instead of a customer.Put a person in the loop
User approval is the node to reach for whenever the agent is about to do something you would want to sign off yourself — sending a message on your workspace’s behalf, changing a record, or committing money. The run halts at that node until someone approves it, so an agent that would otherwise act at 3 a.m. simply waits.Connect an outside tool server
An MCP node lets an agent call a system you already use.1
Add the server
From the MCP node’s panel, or from under Connected tools (MCP), select Add MCP server. Enter a Name (e.g. Weather API) and the server’s address — the field shows the shape it expects,
https://server.example.com/mcp.2
Choose how it authenticates
Pick No auth, Bearer token, or OAuth. OAuth asks for the authorization endpoint, the token endpoint, a client ID, a client secret and a scope, then opens the provider’s own sign-in window.
3
Check it responds
No auth and Bearer token can be tested before saving: the test reports how many tools the server offers and names the first few, so you know you have the right address before you build against it.OAuth cannot be tested before saving, and the button says so — there is no token to authenticate with until you have been through the provider’s sign-in. Add the server, connect it, then use Test on its row in under Connected tools (MCP). That test works for every server, whichever way it authenticates, and is the one to reach for when a connection stops behaving later.
4
Pick the tools the agent may call
Select the server on the MCP node, then choose which of its tools this agent is allowed to use. Give an agent the one tool it needs, not the whole server.
Identifying details are stripped out of the arguments before anything is sent to a third-party server, so a connected tool sees the question but not the person it is about. That also means an outside tool cannot look someone up by name — design around it rather than trying to defeat it. See AI safety and patient data.
Let an agent work your mailbox
If your workspace uses Mail, an agent can be given the mailbox as a set of tools: Search mail, Read a mail conversation, Brief a mail conversation, Classify a mail conversation, Draft a reply and Send an approved draft. They appear under Mail in the tool picker. Four things are true of them however you wire the canvas, because they are enforced by the tools themselves rather than by the graph:- Classifying files, it does not move. An agent can apply your labels and raise Important. It cannot move a conversation to Trash, Spam or Archive, and it cannot delete one — so nothing an agent decides can make a message disappear before a person sees it.
- Drafting never sends. Draft a reply writes into Drafts, marked AI-assisted, and stops.
- Sending needs a person’s yes, every run. Send an approved draft refuses unless a User approval step earlier in the run was actually approved — removing the approval node from the canvas does not remove the requirement. It can only send a draft an agent wrote; it cannot compose a new message, address a new recipient, or send a draft one of your team wrote themselves.
- An agent is held to your clinic’s sending rules. Blocked-sender list, sending limits, storage — all the same. The one place it is treated more strictly than a person: where you would get a warning about sending identifiable patient information to an outside address, an agent is refused. That is a judgement call, and an agent has no judgement to exercise and no accountability to carry.
Whatever an agent can do with the mailbox, it is bounded by what the mailbox itself can do — including whether sending is available to your workspace yet. See the note at the top of Read your mail.
Let an agent handle appointment reminders
Three scheduling tools work with the reminder settings on a client’s record — the same Upcoming appointments, Cancellations and Incomplete documents switches you see under Notifications when you edit a client (see Add your first client).
What holds however you wire the canvas, because the tools enforce it themselves:
- “Not chosen yet” is not “off”. A switch nobody has ever set is reported as not chosen yet, defaults apply — the client is reminded 24 hours before and still gets cancellation and incomplete-document emails. The agent does not mistake an untouched setting for a client who said no.
- Changing settings needs a person’s yes. Change reminder settings refuses unless a User approval step earlier in the run was approved, and changes only what it was asked to. Whatever it sets is recorded as the client’s choice, and the change appears in the audit log as made by an AI agent.
- Only the five timings exist. An agent cannot invent “3 days before” — anything else is refused.
- A reminder respects the client’s settings. If the client’s Upcoming appointments switch is off, your clinic’s Email appointment reminders switch is off, or email notifications are off for that appointment, Send appointment reminder refuses and sends nothing.
- One reminder per appointment. If the automatic reminder has already gone — or an agent already sent one — nothing more is sent, even with an approval. The automatic reminder likewise skips a client an agent has already reminded. To tell a client something else, use a message tool instead.
- “Not sent” is never reported as sent. Where messages cannot go out, the tool says so.
Let an agent manage appointments and the calendar
Appointments. Check availability and Book appointment offer and book only times your booking page would offer — a time inside Out of Office is never offered, and one the agent names without checking is refused. For a visit that already exists:
Both Reschedule appointment and Cancel appointment follow your online cancellation rules — the notice window in your client portal settings — because an agent acts for the client. A class booking, or a visit that is completed or in progress, is refused.
Events, tasks and Out of Office — for agents your team uses, never for a public agent:
What holds however you wire the canvas:
- An agent acts as the person who built it. It creates what that person could create in this clinic, and an agent whose builder is no longer on the team cannot change the calendar. Blocking colleagues, rooms or the whole clinic, and cancelling Out of Office, need an agent built by an owner or manager.
- Cancelling appointments for Out of Office always takes two steps. The first call changes nothing and returns how many appointments and classes would be cancelled. Only a second call with the same details and the confirmation it was given goes ahead — show those numbers to a person first.
- Nothing is done twice. Each of these tools acts once per run for the same details, and a retried create returns what was already made.
- Every date and time is your clinic’s. Results say which time zone they are in.
- Messages that cannot go out are reported as not sent.
Reusable instructions and regression checks
Two sheets in the canvas top bar are worth knowing about early:- Playbooks hold instructions you want more than one agent to follow, so a wording change lands everywhere at once instead of in six separate nodes.
- Evals record the answers you expect and re-check them after you edit. Build a handful for anything you deploy — otherwise “I improved the prompt” is a guess.
Let other systems call your agents
Your deployed agents can themselves be offered to another system as tools, from Expose as MCP (“let other agents call your agents”) under . Each endpoint is rate-limited, capped per month and revocable, and you choose which published agents it exposes. This is a Team feature.Check it worked
- The File search node names your knowledge base, and a Preview run quotes something only your own material could have said.
- The MCP node lists the connected server’s tools in its picker.
- A run that hits User approval appears on the Runs page waiting rather than finished.
If something goes wrong
The agent ignores my knowledge base
The agent ignores my knowledge base
Check the File search node actually runs before the Agent node — a node that is on the canvas but not connected never executes. Then check the Agent node’s instructions refer to the search results; the model does not read them automatically.
The MCP server cannot be reached
The MCP server cannot be reached
Test the address before saving. A trailing path matters — most servers expect the address to end in
/mcp. If it authenticates with a token, confirm the token is current; if with OAuth, look for a Reconnect badge on the server and reconnect it.The outside tool cannot find the person I asked about
The outside tool cannot find the person I asked about
That is the de-identification working. Names and identifying details never leave your workspace, so an outside tool cannot match on them. Do the lookup inside ClinikEHR and send the outside tool only what it genuinely needs.
Approvals are piling up
Approvals are piling up
User approval blocks the run until someone acts. If nobody is watching, move the approval to only the branch that needs it, or replace it with Guardrails for the cases that can be decided automatically.
Related
Build an AI agent
The canvas, triggers, and why Deploy is the step that matters.
AI safety and patient data
What leaves your workspace, and what never does.