Agents and Agentic Systems
Inside an Agent: The Core Anatomy
Every agent shares the same structural blueprint. At the centre sits an LLM acting as the reasoning brain — it interprets the goal, decides next actions, and evaluates outcomes. Four elements surround it. (1) Trigger: what starts the agent — user input, a scheduled time, or a system event. (2) Planning loop: the cycle that runs until the goal is satisfied — observe (gather context from memory and tools), plan (decide the next action), act (execute a tool call, produce output, or spawn a subagent), reflect (compare result to goal; loop again or terminate). (3) Memory: in-context memory (the active window — retrieved context, conversation history, tool results) and persistent memory (vector databases, files, session summaries — survives across runs). (4) Goal evaluation: the success criteria that terminates the loop. Without a well-defined goal, the agent cannot decide when to stop.
What Makes Something an Agent
Three things: (1) goal-directedness — pursues an objective rather than answering one prompt, (2) tool use — can take actions in the world, not just produce text, (3) autonomy — decides next steps based on outcomes, with iteration. Anything missing those is not really an agent, marketing claims notwithstanding. The planning loop (observe → plan → act → reflect) is the mechanical expression of all three: it iterates toward a goal using tool results, with the LLM making each routing decision.
Guardrails, Human-in-the-Loop, and the Integration Layer
Two cross-cutting control bands run across the entire agent anatomy. Guardrails (safety, scope, policy) constrain every action — they are not agent code; they are enforced at the execution boundary as hooks that intercept before actions fire. Human-in-the-loop (HITL) intercepts when confidence is low, stakes are high, or a defined threshold is crossed. Both operate as pre/post hooks in the execution pipeline, not as logic inside the LLM. Below the agent sits the integration layer: MCP connectors, A2A coordination, external APIs, vector databases, sandboxes, orchestration frameworks, and hooks/skill managers. The integration layer is infrastructure — agent logic above it should never contain hardcoded knowledge of how tools are physically connected.
Orchestrator-Subagent Pattern
The most common enterprise architecture: one orchestrator agent receives the high-level goal, decomposes it into tasks, and delegates to specialized subagents. The orchestrator manages state and decides when the goal is satisfied. In SecOps: an orchestrator receives an alert, delegates enrichment to an IOC-lookup subagent, delegates sandbox analysis to a malware subagent, then synthesizes findings. This is why "agent" as a single monolithic loop rarely scales.
Where Multi-Agent Adds Risk
Each agent handoff is a trust boundary. If the orchestrator blindly trusts subagent output without validation, a poisoned subagent response can corrupt the entire investigation chain. Security design must treat inter-agent messages with the same skepticism as user input — especially in security-sensitive workflows. This is not theoretical: it is the same confused-deputy pattern that plagued service-to-service calls in microservices architectures.
Try It Yourself
The anatomy is easier to remember once you have found it in the wild. Any product that claims to "do tasks for you" will show you all the parts — or reveal that some are missing.
Pick one AI product from your own work or feed that claims to act for you — a deep-research mode, a coding assistant, an email or scheduling agent — and map it against the anatomy: what triggers it, which tools it can use, and how it decides it is done. Then note where a human approves anything, if anywhere.
- You can name the trigger, at least two tools, and the stopping rule
- You can say whether it is genuinely an agent or a single-prompt tool with agent marketing
- You identified where a human stays in the loop — or noticed that nowhere does
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.