PTENES
MODULE 3-5

🤝 Agents — the loop that works on its own

So far, you’ve given Jarvis channels, identity, tools, and skills. But what makes it a agent — and not just a clever chat — it’s the autonomous loop: the ability to think, act, read the result, and keep going on its own until it finishes. In this module, you’ll understand this loop, how to delegate work to subagents, when it makes sense to have multiple agents, how it wakes up at the right time, and where to put safeguards so all of this is safe.

6
Topics
~50
Minutes
Intermediate
Level
Anatomy
Type
1

🔁 Agent = loop + autonomy

A typical chatbot does one thing: you ask, it answers, and that’s it. An agent and is different—it doesn't stop at the first response. It receives a request, thinks what to do, uses a tool (searches the web, reads a file, sends an email), reads the result of this tool, and decides whether it is done or needs to take another step. This back-and-forth that repeats on its own until the task is ready is what we call agentic loop.

New here? A agent and an AI model (the text "brain" you saw in Track 1) that gained hands — the tools — and permission to use them in a loop. “Loop” is just the word for “repeat a cycle.” “Autonomy” here doesn’t mean it does whatever it wants; it means it chains several steps without needing you to type each one.

In Track 1, you first saw this loop as a idea. Here it becomes a anatomy layer: the piece that turns “model + tools” into an assistant that gets things done. Without the loop, you’d have to orchestrate every call by hand (“now search,” “now summarize,” “now send”). With the loop, you state the goal and it figures out the sequence of steps itself.

THE AGENTIC LOOP request thinkswhat's missing? toolsearches · reads · sends read resultand evaluates if it’s not finished yet, go back and think (repeat) readyresponds

Read the diagram from left to right: the agent thinks, calls a tool, read what came back and decides. While something is still missing, the dashed arrow takes it back to "think." When it’s done, it exits on the right through "ready". This self-closing loop is the heart of any agent.

Key concepts

Agent

An LLM that can use tools in a loop to achieve a goal.

Agentic loop

Think → act → read the result → decide; repeat until finished.

Autonomy

Chain several steps together on its own, without you typing each one.

Delegate > ask

You state the goal; it figures out the sequence.

2

🧑‍🚀 Subagents: delegate and come back refreshed

Every Jarvis conversation lives inside a context window — its working memory, limited like a computer's RAM (you saw this in Track 1). If a task is large—reading 30 pages, searching an entire repository, researching 15 sources—it clogs this window with raw text, and the main agent gets slow, confused, and expensive. The elegant solution is the sub-agent.

New here? A sub-agent and a second agent that the main agent creates just for a demanding task. It opens the own context window, does the grunt work (reads everything, processes it, discards the junk) and returns only the clean answer. The mess stays in its head; the main agent receives only the summary.

📦 The intern analogy

Imagine you’re a busy manager. A task comes in: “read this 200-page report and tell me the 3 main points.” You don’t read all 200 pages and fill your own head — you ask an intern to read it. They spend the time its with all 200 pages and comes back with a 3-line note. Your desk stays clean. The sub-agent is exactly that intern.

  • •The sub-agent burns the own context with the raw material.
  • •It only returns the distilled answer — not all the material.
  • •The main session stays lightweight, focused, and inexpensive.

✓ When to use a sub-agent

  • ✓A task that generates A LOT of intermediate text (broad search, long reading).
  • ✓Isolatable task: it has a clear request and returns a clear result.
  • ✓You want to keep the main conversation from becoming a mess.

✗ When it’s NOT worth it

  • ✗A quick task — starting a subagent costs more than doing it directly.
  • ✗Steps that depend on a lot of back-and-forth with you along the way.
  • ✗When you NEED to see the raw material, not just the summary.

Key concepts

Subagent

Auxiliary agent that does the heavy lifting and returns only the answer.

Context window

The agent’s limited working memory (its “RAM”).

Context isolation

The mess stays in the sub-agent; the main one doesn’t get contaminated.

Distilled response

Only the essentials come back—saving context and costs.

3

🐝 Multi-agent: a team of specialists

If a sub-agent is an intern, the multi-agent and a whole team. Instead of one agent doing everything, you set up several specialists — one that only researches, one that only writes, one that only reviews — and an orchestrator that distributes the parts and combines the result. Each specialist has its own context, its own focus, and can even use a different brain (a low-cost model for search, a powerful one for writing).

MULTI-AGENT PATTERN orchestratordivides and combines researchsearches for sources writingdrafts reviewcheck the parts come back, and the orchestrator combines them into a single result

O orchestrator splits the task between specialists and then ties everything together. More parallelism and greater focus—but also more parts to coordinate and a higher chance of one failing. That's why multi-agent setups are only worthwhile when the task is large enough to justify the complexity.

⚠️ The “more agents = better” trap

It’s tempting to build an army of agents for everything. Almost always, that’s overkill. Each extra agent adds coordination, cost, latency, and new points of failure—if the “review” agent misinterprets what the “writing” agent delivered, the error spreads. Practical rule: start with a single agent and the loop. Only split into multiple agents when a real task is too big or requires specializations that truly don't fit in the same mind.

Key concepts

Multi-agent

Several specialist agents working together on a task.

Orchestrator

The agent that divides up the work and combines the results.

Specialization

Each agent focuses on one thing (research, writing, review).

Coordination cost

More agents = more pieces to align and more possible failures.

4

⏰ Cadence: it wakes up on its own

So far, the agent only acts when you talk to it. The cadence changes this: it makes Jarvis act at the right time, without anyone calling. At 7 a.m., it puts together a summary of your day; every 30 minutes, it checks your inbox; every Friday, it organizes your notes. All while you sleep, work, or—as the creators of these systems say—“with the laptop closed.”

New here? Cron and it’s a task scheduler that has existed on computers for decades: you write "run this every day at 7 a.m." and it obeys. Heartbeat ("heartbeat") is the same principle applied to the agent: a regular pulse that wakes it up from time to time to check whether there’s anything to do. Routines and it’s just the friendly name some systems give these scheduled tasks.

1

The clock triggers it

The scheduled time arrives (e.g., 7 a.m.). The scheduler wakes the agent — without you typing anything.

2

It runs the loop

The agent performs the scheduled task: reads the calendar, searches emails, and puts together the summary.

3

It alerts you through the channel

The answer arrives on Telegram (or the channel you use). You wake up with the work already done.

📊 Where this appears in real systems

  • •O OpenClaw popularized the heartbeat — a pulse that keeps the agent "alive" and checking things.
  • •O GravityClaw uses node-cron for scheduled tasks, keeping everything lean.
  • •In the "4 C" architecture (Track 4), this is the Cadence — “when it acts.”

Key concepts

Cadence

The layer that makes the agent act on schedule, without being called.

Cron

Classic scheduler: "run this at this time."

Heartbeat

A regular pulse that wakes the agent to check tasks.

Routines

Scheduled tasks with friendly names (7 a.m. summary, etc.).

5

🛡️ Loop limitations and security

An agent that acts on its own is powerful—and for that very reason, it needs guardrails. Without safeguards, the loop can run forever (and cost a fortune), or carry out a dangerous action without anyone noticing. Three safeguards address most of this: a iteration limit, approval gates and it’s a audit log.

New here? Iteration cap (or limit) and a maximum number of turns the loop can take before stopping (e.g., "no more than 15"). Approval gate and a "do you confirm?" prompt before a risky action. Audit log and a journal that records every step the agent took—a "forensic memory" you can review later to see what it did and why.

🔢 Iteration cap

Limits how many turns the loop can take. Prevents the agent from getting stuck “thinking” forever and wasting money.

✋ Approval gates

Dangerous actions (deleting files, spending money, running commands) stop and ask for your "okay" before they happen.

📜 Audit log

Every step is recorded. If something goes wrong, you can open the log and see exactly what it did and when.

⚠️ Why this isn’t optional

Remember Track 2: OpenClaw had 42,665 public instances, being 93.4% with no authentication, e 341 malicious skills in the community. An exposed agent without safeguards is an agent anyone can command to act. The right approach is zero-trust: treat every input as a potential attack (including prompt injection, when malicious text tries to give disguised orders to the agent).

The safe combination, repeated throughout the course: no exposed ports + only auditable MCP + whitelist of who can communicate + secrets in .env + the three safeguards above.

Key concepts

Iteration cap

Maximum number of loop iterations — prevents infinite loops and excessive costs.

Approval gate

Human confirmation before a dangerous action.

Audit log

A forensic record of every agent action.

Prompt injection

Malicious text that tries to give the agent disguised instructions.

6

🚀 Proactive vs. reactive: from assistant to partner

Bring together everything from this module—the loop, the sub-agents, the cadence—and you reach the biggest leap of all: Jarvis stops being reactive (only responds when you call) and becomes proactive (lets you know before for you to ask). Instead of asking “Is there anything important on my calendar today?”, it messages you at 7 a.m.: “You have a meeting at 10 a.m. and the report is due tomorrow—want me to prepare a draft?”

😐 Reactive (the assistant)

  • →Waits for you to start the conversation.
  • →Only knows what you just typed.
  • →Useful, but you still carry the mental load of remembering everything.

🤝 Proactive (the partner)

  • →Starts the conversation when it makes sense (cadence).
  • →Connects calendar, email, and memory to anticipate your needs.
  • →Takes the mental load off you—it becomes a partner, not a tool.

🧩 The recipe for the proactive leap

Proactivity isn’t magic—it’s the sum of the pieces you already know. Loop (it acts on its own) + cadence (it wakes up on schedule) + tools (it sees your calendar and email, from Trail 3-3) + memory (it remembers what matters, introduced in 3-6). Remove any piece and it becomes reactive again.

Be careful with the balance: an overly proactive agent becomes an annoying pest that interrupts all the time. Good proactivity is selective—it alerts you to what matters and stays quiet the rest of the time.

Self-check (optional): What is the best description of a subagent?

Key concepts

Reactive

Only acts when you call it—the "assistant" mode.

Proactive

It alerts you before you ask — the “partner” mode.

Mental load

The burden of remembering everything; the proactive approach takes that off your hands.

Selective proactivity

Alert you to what matters, stay quiet otherwise.

🎯 Module summary

✓
Agent = loop + autonomy — thinks, acts, reads the result, and decides; repeats on its own until it’s done.
✓
Subagents — the “intern” burns through its own context and returns only the answer; the main session stays light.
✓
Use multi-agent sparingly — a team of specialists + an orchestrator; it’s only worthwhile when the task justifies the complexity.
✓
Cadence — cron/heartbeat make Jarvis act on schedule, “with the laptop closed.”
✓
Loop safeguards — iteration limits, approval gates, and an audit log; a zero-trust posture.
✓
Proactive vs. reactive — loop + cadence + tools + memory = the leap from assistant to partner.

Next module:

Module 3-6: Brains — the engine that thinks and organized memory