Tool use

Definition
Tool use is an AI agent reaching outside its own text to search, calculate, call an API or act, then folding the result back into what it does next.

Why it matters

An agent with no tools can only advise. Once it can search, calculate, call an API or act inside a live system, it becomes a worker that finishes a task rather than describing how to finish it. It can check live data instead of guessing, and complete work end to end.

That changes what a founder can safely delegate. More tools mean more reach, but also more ways to cause harm. So each tool is scoped tightly, access is read-only where possible, and anything irreversible, such as sending or deleting, gets an approval step.

How to apply it

  1. List the actions the agent truly needs. Give it only those tools, not a broad grab bag.
  2. Grant read access before write access. A mistake then shows up in a report rather than as a live change.
  3. Put approval in front of anything irreversible. Sending an email, deleting a record and charging a card all wait for a person.
  4. Log every tool call. A wrong answer can then be traced to the exact lookup that caused it.
  5. Review the tool list every few months. Remove any tool that nothing calls any more.

What it is

Tool use is an AI agent reaching outside its own text to do something: search the web, run a calculation, call an API, read a file. The model recognises that it needs information or an action it cannot produce from memory, chooses a tool, uses it, and folds the result back into what it does next.

Function calling is the technical mechanism by which a model asks for a tool to be run, with the name of the function and its arguments. Tool use is the wider capability: the loop of deciding, calling, reading the result and continuing.

Common mistakes

  • Giving the agent write access to everything on day one, because it was easier than choosing.
  • Vague tool descriptions, so the model picks the wrong tool or calls one without need.
  • No approval step on irreversible actions.
  • Not logging calls, so nobody can explain a wrong answer afterwards.
  • Trusting whatever a tool returns. Text fetched from a web page or an email can contain instructions, and the agent should treat it as data, not as orders.
Worked example

A ten-person B2B software company built a support agent in n8n. At first it wrote replies from memory and invented refund terms that did not exist. The team gave it two tools: a read-only call into the billing system and a lookup against the help centre.

The agent now checks a subscription's real status before it answers. When it proposes a refund, a person approves it before it reaches the payment provider. Over the next month the team reviews the tool-call log and sees that the help-centre lookup is called on most tickets, while a third tool they had considered adding would have been called on almost none, so they leave it out.

  1. Article

    Function calling

    The mechanism a model uses to request a tool call.

  2. Article

    Multi-agent system

    Several agents, each with its own role, working on the same problem together.