Skip to main content
An Agent node on its own can only reason about what you type into it. Tools are what let it answer from your own material, call an outside system, check itself before it speaks, and pause for a person.

The tool and logic nodes

Only Agent and Classify spend credits. Every node on this page is free to run.

Answer from your own material

1

Add a File search node

Drag File search onto the canvas and connect it before the Agent node that will use its results.
2

Create a knowledge base

In the node’s panel, give it a Knowledge base name and paste your content — the box prompts you to “Paste FAQs, policies, protocols…”. Opening hours, preparation instructions, a returns policy and a referral protocol are all good candidates.
3

Point the Agent node at the results

The search writes its matches into the run. Reference them from the Agent node’s instructions so the model answers from your material rather than from general knowledge.
Keep one knowledge base per subject rather than one enormous one — a narrow search returns better matches, and you can retire a policy without rewriting everything else.

Constrain what the agent may say

Guardrails checks a value and sends the run down a pass or a fail path. Put one between the Agent node and anything that sends a message, and route fail to an End node or to a User approval step so a doubtful answer is seen by a person instead of a customer.

Put a person in the loop

User approval is the node to reach for whenever the agent is about to do something you would want to sign off yourself — sending a message on your workspace’s behalf, changing a record, or committing money. The run halts at that node until someone approves it, so an agent that would otherwise act at 3 a.m. simply waits.

Connect an outside tool server

An MCP node lets an agent call a system you already use.
1

Add the server

From the MCP node’s panel, or from under Connected tools (MCP), select Add MCP server. Enter a Name (e.g. Weather API) and the server’s address — the field shows the shape it expects, https://server.example.com/mcp.
2

Choose how it authenticates

Pick No auth, Bearer token, or OAuth. OAuth asks for the authorization endpoint, the token endpoint, a client ID, a client secret and a scope, then opens the provider’s own sign-in window.
3

Check it responds

No auth and Bearer token can be tested before saving: the test reports how many tools the server offers and names the first few, so you know you have the right address before you build against it.OAuth cannot be tested before saving, and the button says so — there is no token to authenticate with until you have been through the provider’s sign-in. Add the server, connect it, then use Test on its row in under Connected tools (MCP). That test works for every server, whichever way it authenticates, and is the one to reach for when a connection stops behaving later.
4

Pick the tools the agent may call

Select the server on the MCP node, then choose which of its tools this agent is allowed to use. Give an agent the one tool it needs, not the whole server.
Identifying details are stripped out of the arguments before anything is sent to a third-party server, so a connected tool sees the question but not the person it is about. That also means an outside tool cannot look someone up by name — design around it rather than trying to defeat it. See AI safety and patient data.

Let an agent work your mailbox

If your workspace uses Mail, an agent can be given the mailbox as a set of tools: Search mail, Read a mail conversation, Brief a mail conversation, Classify a mail conversation, Draft a reply and Send an approved draft. They appear under Mail in the tool picker. Four things are true of them however you wire the canvas, because they are enforced by the tools themselves rather than by the graph:
  • Classifying files, it does not move. An agent can apply your labels and raise Important. It cannot move a conversation to Trash, Spam or Archive, and it cannot delete one — so nothing an agent decides can make a message disappear before a person sees it.
  • Drafting never sends. Draft a reply writes into Drafts, marked AI-assisted, and stops.
  • Sending needs a person’s yes, every run. Send an approved draft refuses unless a User approval step earlier in the run was actually approved — removing the approval node from the canvas does not remove the requirement. It can only send a draft an agent wrote; it cannot compose a new message, address a new recipient, or send a draft one of your team wrote themselves.
  • An agent is held to your clinic’s sending rules. Blocked-sender list, sending limits, storage — all the same. The one place it is treated more strictly than a person: where you would get a warning about sending identifiable patient information to an outside address, an agent is refused. That is a judgement call, and an agent has no judgement to exercise and no accountability to carry.
Ready-made: the Inbox triage template in the gallery. It is deliberately not given the send tool at all — it labels and drafts, and a person sends.
Whatever an agent can do with the mailbox, it is bounded by what the mailbox itself can do — including whether sending is available to your workspace yet. See the note at the top of Read your mail.
None of the mail tools can be used by an agent published as a public page. An anonymous visitor must never be able to make an agent read your mailbox, so they are not on the list a public agent may hold.

Let an agent handle appointment reminders

Three scheduling tools work with the reminder settings on a client’s record — the same Upcoming appointments, Cancellations and Incomplete documents switches you see under Notifications when you edit a client (see Add your first client). What holds however you wire the canvas, because the tools enforce it themselves:
  • “Not chosen yet” is not “off”. A switch nobody has ever set is reported as not chosen yet, defaults apply — the client is reminded 24 hours before and still gets cancellation and incomplete-document emails. The agent does not mistake an untouched setting for a client who said no.
  • Changing settings needs a person’s yes. Change reminder settings refuses unless a User approval step earlier in the run was approved, and changes only what it was asked to. Whatever it sets is recorded as the client’s choice, and the change appears in the audit log as made by an AI agent.
  • Only the five timings exist. An agent cannot invent “3 days before” — anything else is refused.
  • A reminder respects the client’s settings. If the client’s Upcoming appointments switch is off, your clinic’s Email appointment reminders switch is off, or email notifications are off for that appointment, Send appointment reminder refuses and sends nothing.
  • One reminder per appointment. If the automatic reminder has already gone — or an agent already sent one — nothing more is sent, even with an approval. The automatic reminder likewise skips a client an agent has already reminded. To tell a client something else, use a message tool instead.
  • “Not sent” is never reported as sent. Where messages cannot go out, the tool says so.
None of these three can be used by an agent published as a public page.

Let an agent manage appointments and the calendar

Appointments. Check availability and Book appointment offer and book only times your booking page would offer — a time inside Out of Office is never offered, and one the agent names without checking is refused. For a visit that already exists: Both Reschedule appointment and Cancel appointment follow your online cancellation rules — the notice window in your client portal settings — because an agent acts for the client. A class booking, or a visit that is completed or in progress, is refused. Events, tasks and Out of Office — for agents your team uses, never for a public agent: What holds however you wire the canvas:
  • An agent acts as the person who built it. It creates what that person could create in this clinic, and an agent whose builder is no longer on the team cannot change the calendar. Blocking colleagues, rooms or the whole clinic, and cancelling Out of Office, need an agent built by an owner or manager.
  • Cancelling appointments for Out of Office always takes two steps. The first call changes nothing and returns how many appointments and classes would be cancelled. Only a second call with the same details and the confirmation it was given goes ahead — show those numbers to a person first.
  • Nothing is done twice. Each of these tools acts once per run for the same details, and a retried create returns what was already made.
  • Every date and time is your clinic’s. Results say which time zone they are in.
  • Messages that cannot go out are reported as not sent.
A public agent cannot hold any of these calendar tools, and each one refuses a public visitor even if it were added. A public agent may hold Get away dates, which says only when the clinic — or a provider the visitor asks about — is away: the dates and times, never why.

Reusable instructions and regression checks

Two sheets in the canvas top bar are worth knowing about early:
  • Playbooks hold instructions you want more than one agent to follow, so a wording change lands everywhere at once instead of in six separate nodes.
  • Evals record the answers you expect and re-check them after you edit. Build a handful for anything you deploy — otherwise “I improved the prompt” is a guess.

Let other systems call your agents

Your deployed agents can themselves be offered to another system as tools, from Expose as MCP (“let other agents call your agents”) under . Each endpoint is rate-limited, capped per month and revocable, and you choose which published agents it exposes. This is a Team feature.

Check it worked

  • The File search node names your knowledge base, and a Preview run quotes something only your own material could have said.
  • The MCP node lists the connected server’s tools in its picker.
  • A run that hits User approval appears on the Runs page waiting rather than finished.

If something goes wrong

Check the File search node actually runs before the Agent node — a node that is on the canvas but not connected never executes. Then check the Agent node’s instructions refer to the search results; the model does not read them automatically.
Test the address before saving. A trailing path matters — most servers expect the address to end in /mcp. If it authenticates with a token, confirm the token is current; if with OAuth, look for a Reconnect badge on the server and reconnect it.
That is the de-identification working. Names and identifying details never leave your workspace, so an outside tool cannot match on them. Do the lookup inside ClinikEHR and send the outside tool only what it genuinely needs.
User approval blocks the run until someone acts. If nobody is watching, move the approval to only the branch that needs it, or replace it with Guardrails for the cases that can be decided automatically.

Build an AI agent

The canvas, triggers, and why Deploy is the step that matters.

AI safety and patient data

What leaves your workspace, and what never does.