This explainer is editorial interpretation. It describes a pattern, not any particular product.
What makes a workflow agentic?
Three features usually appear together: a goal rather than a single question, multiple steps that the system chooses, and tools it can use to act on the world, such as running code, searching, or editing documents.
Where do agentic workflows fail?
- A wrong step early on carries through later steps.
- The agent reports success when the task did not succeed.
- It takes an action you did not intend.
- It reads untrusted content that contains instructions, an attack known as prompt injection.
What controls matter?
- Least privilege: only the access the task needs.
- Approval gates for consequential actions.
- Logs you can review after the fact.
- Spending and usage limits.
How should I evaluate one?
Use a task whose result you can check, run it several times, and record failures and their visibility. Results vary between runs, so one success says little.
See the agents category, what is an AI coding agent, and the glossary.
Frequently asked questions
Is every AI chatbot an agent?
No. A chatbot answers a message. An agent pursues a goal across several steps and uses tools such as search, code execution, or other applications.
Why are agentic workflows riskier than single prompts?
Errors can compound across steps, and the agent may take actions with real effects. Narrow permissions, approvals, and logs reduce that risk.
How do I evaluate an agentic workflow?
Define a task with a checkable success condition, run it several times, and record how often it fails, how visibly, and what it cost. See the agents category criteria.
Sources
This article is editorial analysis. It cites no external sources and contains no product performance claims, benchmark figures, or policy facts.