Marketing automation

AI agents for business

AI agents that read a request, check your CRM, inbox and other systems, and prepare the next action for a person to approve. For UK businesses whose staff spend their time gathering facts from several screens before they can decide anything.

An AI agent is software that is given a goal, a set of tools and a set of rules, and works out for itself which steps to take. A normal automation follows the same path every time. An agent reads the request in front of it, looks things up in your systems, decides what should happen next and prepares that action. I design and build agents for UK businesses on one condition: a person approves anything that leaves the business or changes a record that matters.

If you only want an AI model added at one step of a fixed process, my AI automation service is the closer fit. For an assistant that answers staff questions from company documents, see custom GPT and AI assistant development.

What an agent does that a fixed workflow cannot

Most business automation is a chain of fixed steps: a form is submitted, a contact is created, an email goes out, sales get a notification. That works when every case looks alike. It breaks down when the right next step depends on what the request says and on what your systems already know. Is this person an existing customer? Do you cover their postcode? Is the item in stock? Is last month’s invoice still unpaid?

An agent handles that kind of request by calling tools. Each tool is a small, defined capability, such as “find this contact in the CRM” or “list free slots in the diary”. The agent, built on a large language model, chooses a tool, reads what comes back and decides what to call next. The mechanism is usually called function calling, and the Model Context Protocol is a newer standard for exposing tools to a model. In practice, a member of staff stops collecting facts from four screens and starts reviewing a prepared case with a recommendation attached.

Who this suits, and when an agent is the wrong tool

An agent is worth considering when the same kind of request arrives often enough to cost real staff time, when deciding what to do means checking two or more systems, and when the judgement involved can be written down clearly enough for a new employee to follow.

It is the wrong tool more often than the sales pitches suggest. If the steps never change, a fixed workflow is cheaper, quicker to run and easier to audit, and I will say so. If your core systems cannot be reached by software at all, the agent has nothing to work with. And if every case carries legal, medical or financial risk for the person on the other end, the human review becomes the whole job and the agent adds little.

Agent, chatbot, assistant or workflow

OptionWhat it doesTakes actions?Suits
Fixed workflowRuns the same steps in the same order every timeYes, only the ones you definedRepetitive tasks with clear rules
Workflow with an AI stepUses a model at one point to classify, extract or draft, inside fixed stepsYes, only the ones you definedMessy text inside a known process
ChatbotAnswers customer questions in a conversationRarely, beyond booking or passing to a personRepeat questions on a website or WhatsApp
Internal assistantAnswers staff questions from company documentsNoFinding policy, product or process information
AI agentChooses its own steps towards a goal, using only the tools you allowYes, within set permissions and with approvalVaried requests that need facts from several systems

Jobs I would consider giving an agent

These are examples of the shape of work agents handle well, not a menu. The right first job is usually the one your staff grumble about most.

Enquiry triage across inbox, CRM and diary

A trades business or professional practice receives enquiries by email and web form. The agent reads each one, checks whether the sender is already in your CRM, checks the postcode against the area you cover and looks for free appointments. It then drafts a reply offering times. A person reads the draft and sends it, edits it or bins it.

Research before a B2B sales call

Before a first call, the agent pulls the company’s filing details from the public Companies House register, reads its website, checks your CRM for any past contact and writes a one-page brief for the salesperson. Nothing is sent to the prospect.

Order problems in an online shop

Late parcels, damaged items and change-of-address requests rarely follow one pattern. The agent checks the order, the courier’s tracking status and your returns policy, then proposes a refund, a replacement or a reply. Any refund waits for a person to approve it.

The limits written into every agent

The design question I spend longest on is what the agent must not do. These limits, usually called guardrails, are enforced through permissions and code, not only through instructions to the model, because instructions on their own can be ignored or overridden.

  • No money moves without a person. Refunds, payments, discounts and credit notes are proposed by the agent and carried out by a human.
  • Nothing external goes out unapproved at first. Every email or message waits in an approval queue, which is the human-in-the-loop step. Whether any type of message can later go automatically is your decision, made on evidence from the logs.
  • Read-only unless writing is essential, and no deleting. Each tool gets the narrowest access that does its job, through its own key. An agent can flag a record for removal but cannot remove one.
  • Incoming text is data, never instructions. Emails, attachments and web pages can contain wording designed to steer a model, a technique known as prompt injection. The agent’s tools and permissions are set so that such text cannot widen what it is allowed to do.
  • Hard stops on steps and spend. Each task has a ceiling on tool calls and cost, so a confused agent hands over to a person instead of going round in circles.
  • Decisions that affect people stay with people. UK GDPR has specific rules for decisions made solely by automated means that have legal or similarly significant effects on someone, such as turning down a job applicant or refusing credit. The safeguards include a route for the person to get human review and to contest the outcome. I design agents so that this kind of decision is always made by a person, with the agent only preparing the case. The Data (Use and Access) Act 2025 amends these rules, so check the ICO’s current guidance on automated decision-making for your use.

How I run an agent build

  1. Map the decision. I sit down with whoever does the work today and write out how they decide, including the exceptions they handle from memory. I also gather a set of real past cases, with personal data removed or kept to the minimum, to test against later.
  2. Design on paper. A short specification lists every tool, the access each needs, the points where a person approves, what is logged and when the agent must stop and hand over. You sign it off before anything is built.
  3. Build in a test environment. The agent runs on test data or read-only connections. The platform follows what you already use: an agent step inside n8n or Make, or code that calls a model provider directly.
  4. Test against past cases. I run the agent on the collected cases and compare its recommendations with what your team actually did. Where they differ, you and I work out whether the agent or the original decision was wrong, and adjust.
  5. Run it alongside your staff. The agent works on live requests but only proposes, while your team carries on as normal and compares the two. This is where confident but wrong answers surface, and where the instructions get their final edits.
  6. Go live with approval. Staff approve each proposed action from a queue in the inbox or chat tool they already use.
  7. Review the log, then hand over. After the first weeks of live use, you and I go through what was approved, edited and rejected. That record decides whether any step can safely become automatic.

Where agent projects go wrong

  • Starting from a demo, not a process. An impressive run on a handful of tidy examples says nothing about the awkward cases that make up real work.
  • No record of what happened. Without a log of each step and the reason for it, nobody can answer a customer complaint or a subject access request about the agent’s work.
  • No owner. Prices, policies and staff change. If nobody is responsible for updating the agent’s instructions and tools, its advice drifts out of date.
  • Personal data sent to a model provider unchecked. You remain the controller of your customers’ data, and the provider normally acts as your processor under its data terms; the split is explained in data controller and data processor. Where data is processed, how long it is kept and whether it is used for training all need checking before go-live, not after.

What you receive

  • A map of the decision process and the signed-off specification, including the permission list for every tool
  • The working agent, connected to your systems through accounts and keys that you own
  • The test set of past cases and the results of running the agent against it
  • An approval queue and a complete activity log
  • A runbook covering how to pause the agent, change its instructions, replace its keys and add a badly handled case to the test set
  • A description of the data flows to support your data protection impact assessment
  • A handover session for the person who will own the agent day to day

Cost and pricing

There are two separate costs. The build is priced once the mapping stage has shown how many tools and approval points the agent needs, and the quote is written in pounds sterling and agreed in writing before the build starts. The running cost is what the model provider charges for usage, plus any platform subscription. Providers bill per token processed, often in US dollars, so the monthly figure moves with volume and the exchange rate. I estimate it from the test runs before you commit, and set a spending limit in the provider account.

Next step

Book a free 30-minute call and bring one example of a request your team handles every week. I will tell you whether it suits an agent, a simpler workflow or neither, and what a first version would need. You can call me on +44 7352129369, email contact@sudeshnathapa.com or use the contact form.

Frequently asked questions

Is it safe to connect an AI agent to our CRM and inbox?

It can be made reasonably safe, though never risk-free. Each connection uses its own key with the narrowest access that works, every action is logged, and anything that writes to a record or reaches a customer waits for approval. If something looks wrong, revoking one key cuts the agent off from that system immediately without affecting anything else.

Will an AI agent replace a member of staff?

In the agents I design, a person still approves every action that matters, so the role shifts from collecting information to checking and deciding. Whether that frees enough time to change how you staff the work is a business decision, and not one I would base on a pilot alone.

Which AI model do you use, and where does our data go?

I choose the model on how it performs against your test cases and on its data terms, not on brand. Before any personal data is involved, I check in writing whether the provider uses business data for training, how long it keeps prompts and outputs, and where processing takes place. Those answers go into the specification you sign off.

What happens when the agent gets something wrong?

Because the agent proposes rather than acts, a bad recommendation is caught at the approval step. Rejections are logged with a reason, the case is added to the test set, and the instructions or tools are adjusted and re-tested so the fix does not break other cases. If one type of request keeps going wrong, it is routed straight to a person instead.

Do we need a data protection impact assessment?

Often, yes. The Information Commissioner's Office treats innovative technology, including AI, as one of the factors that can make processing high risk, and an agent that reads customer records at volume usually tips the balance. As the controller, you complete and sign the assessment. I provide the data flow description and the risks I can see, but I am not a lawyer, so take legal advice for anything sensitive.

Can an agent work with Microsoft 365 or Google Workspace?

Yes, where the mail, calendar or files it needs are available through the platform's interfaces for software, which both offer. Access is granted through an app or service account with limited permissions that your administrator approves. I do not build agents that sign in as a member of staff using their password.

Ready to talk about your project?

A straight answer about what would move the numbers, and a written proposal if we are a fit.