See the difference between responding and acting
Until recently, using AI meant having a conversation: you write a question, it returns text. If the text is bad, you delete it and ask again. Nothing in the world changed.
Now the same AI can have "hands": read your email, open the customer spreadsheet, schedule an appointment, send a WhatsApp message. When it does that, it stops being just a assistant and becomes a agent.
🆕 New here? Three words the whole course uses
- Language model — the “brain” that runs behind an AI chat. It reads text and writes text. That’s all.
- Assistant — an AI chat that responds. You read the response and decide what to do with it.
- Agent — an assistant that received tools and can act on its own: send, change, delete, pay.
How to read the diagram: the same request comes in from both sides. On the left, the output is text and stops on the screen. On the right, the blue arrows go from the AI straight to email, the calendar, and the spreadsheet — there’s no one in the middle to check.
responds with text
uses tools
what it can use
where the action happens
Recognize an agent’s tools
A tool is anything the agent can use without you pressing a button: an app, a file, an account. Every tool you connect is another door it can open.
To connect a tool, you give the agent a access: logs in for you, pastes a key, or clicks "allow." From then on, it acts with the your name.
🆕 New here? What are “access” and “connector”?
Access It's authorization to view or change something — like a key to a room. Connector (or integration) is the "cable" that connects the agent to an app, such as Gmail, Google Calendar, or WhatsApp Business. When the screen asks, "Allow this app to read and send emails?" you're handing over a key.
| Tool | Can read | Can edit or send | If it makes a mistake… |
|---|---|---|---|
| all messages | reply, forward, delete | wrong message to the customer | |
| 📅 Calendar | times and names | schedule, reschedule, cancel | patient without an appointment |
| 📊 Spreadsheet | customer data | edit, delete rows | lost sign-up |
| conversations | send a bulk message | wrong promotion for everyone | |
| 💳 Payment | balance and statement | charge, issue a refund, pay | money that doesn’t come back |
What to look for in the table: The "If it goes wrong…" column gets more costly as you go down. That’s why, in module 3.1, payment is the last key you hand over—if you hand it over at all.
💡 Practical tip
Whenever a screen asks you to “allow access,” read what comes after “to”: read e send, see e delete. The second half is where things can go wrong.
a room key
the cable to the app
it acts as you
grows with the tool
Track an agent’s cycle
An agent doesn't take just one step. It works in cycle: receives the request, decides what to do next, uses a tool, checks the result, and decides again—until it thinks it’s done.
Every turn of the cycle is a chance to get it right—and also to make a mistake without anyone seeing. You only find out at the end, if you look.
🆕 New here? What is a “loop”?
Loop is repetition: the agent returns to the beginning of the cycle as many times as it thinks necessary. A good loop finishes the task. A bad loop keeps going—and if each pass costs credits, the bill climbs without you noticing (we’ll return to this in module 4.3).
How to read the diagram: the blue arrows are the moments when the agent interacts with the world (step 3). The red circle marks the weak point: between runs, with no logging, nobody knows what it did.
Renata requests
“Confirm tomorrow’s appointments.” Renata owns an aesthetics clinic and connected the agent to the calendar and WhatsApp.
The agent plans
“I need tomorrow’s list, followed by one message for each patient.”
Use the tools
Reads the schedule (12 patients) and sends 12 messages through the clinic’s WhatsApp.
See the result and decide
Two patients ask to reschedule. If it has write access to the calendar, it reschedules on its own—without Renata knowing.
plans, acts, observes, repeats
can spin too much
you only see the end
it chooses the next step
Measure the size of the error
The underlying model is the same. It makes mistakes in the same way. What changes is where the error ends up.
When an assistant makes a mistake, the error stays on the screen, right in front of you. When an agent makes a mistake, the error has already gone out: it's in the customer's inbox, the spreadsheet, the statement.
💬 Assistant error
- ✓Incorrectly priced text appears on the screen.
- ✓You read it, notice, and fix it before using it.
- ✓Cost: a few minutes.
🦾 Agent error
- ✗A promotion with the wrong price goes to 300 patients.
- ✗You find out when the clients respond.
- ✗Cost: money, reputation, and a day spent apologizing.
🧠 The same error, three destinations
- •Stays on the screen — assistant. You’re the filter.
- •Stays in a draft — agent with approval. You’re still the filter, just later.
- •Take it out into the world — agent without approval. There’s no filter.
⚠️ Attention
Some actions can’t be undone: a payment made, a message read, a file deleted without a backup. For those, control needs to come before — afterward, all that’s left is to apologize.
Take inventory of access
Before turning on any agent, find out what’s already turned on. Many people clicked "allow" in an AI app and forgot about it.
The exercise is simple: for each AI tool you use, list what it can read, change e send. Use any AI chat to organize the list with you.
Paste into the AI chat you already use (ChatGPT, Claude, Gemini). Replace what's inside < >.
Quero fazer um inventário dos acessos que dei a ferramentas de IA no meu trabalho. Meu negócio: <ex.: clínica de estética com 2 funcionárias>. Ferramentas de IA que uso ou pretendo usar: <ex.: chat de IA, assistente do e-mail, robô de WhatsApp>. Me faça uma pergunta por vez sobre cada ferramenta, até descobrir: 1. o que ela pode LER (e-mail, agenda, planilha, conversas, arquivos); 2. o que ela pode MUDAR ou ENVIAR em meu nome; 3. se alguma delas mexe com dinheiro ou dados de clientes. No fim, monte uma tabela com as colunas: ferramenta | lê | muda/envia | dinheiro? | dados de clientes? Não invente acessos: se eu não souber, escreva "verificar".
💡 Marcos’s example
Marcos, an accountant, found three things he’d forgotten about: an email assistant that could send (not just suggesting), a browser extension with access to "all sites," and a test WhatsApp bot still connected to the office number. They turned off the latter two that same day.
Keep the rule that runs through the course
If you remember just one sentence, make it this one: The more the agent can do on its own, the tighter the limits need to be.
And you decide what to automate, what it can access, and whether it worked—not the agent, not the app provider.
How to read the diagram: each level is a track and depends on the one before it. You choose the controls (T3) only after you know which pain you'll address (T2), and you measure the result (T5) only after you set up the safety barriers (T4).
Quick test (optional): which of these situations is an example of agent?
grow with the capability
what, how much, whether it worked
one depends on the other
what you take away at the end
🎓 Module summary
Next module:
1.2 — More capable, more limits