Blog · 6 October 2026 · 7 min read

Agentic Workflows: What Actually Runs Without You

Agentic workflows let an AI tool take several steps on its own. What that actually looks like for one person, a worked example, and what to check.

Steps run. Tools used. You check.

Most of what gets called "agentic" is one of two much smaller things: a tool following a fixed script with no AI involved at all, or an AI answering one question well. An actual agentic workflow sits between those — the tool decides what to do next itself, can call on a tool or search mid-task, checks its own intermediate result, and keeps going without you typing a new message at every step. The useful version of this for one person at a desk is much narrower than the enterprise-platform pitch, and worth separating from the hype before you rely on it for anything that matters.

What makes a workflow actually agentic

Three things distinguish it from a single chat reply. First, more than one step happens before you see the final result — it reads something, decides what that means, then acts on the decision. Second, it can use a tool mid-task — searching the web, running a calculation, reading a file — rather than only working from what you typed. Third, it can notice a dead end and try something else rather than stopping at the first wrong turn. Anthropic's own documentation on tool use describes this as the model choosing when and how to call a tool as part of reasoning through a task, rather than a person wiring each call by hand — that's the actual mechanism behind the word "agentic", not a marketing description of autonomy.

That's worth separating from two neighbouring terms that get used loosely. A plain automation — a rule that forwards an email matching a certain subject line, say — follows a fixed path every time and makes no decisions at all; nothing about it is agentic even if it runs on a schedule with nobody watching. Full autonomy, at the other end, would mean the tool choosing its own goal and acting on real-world accounts or money with no checkpoint before or after. An agentic workflow sits in between: it decides the path through a task you defined, inside a scope you set, and the result still comes back to you before anything outside the chat window happens. Most of what's sold as "agentic" today lives in that middle category, not the autonomous end of it.

A worked example

Weak request: "research my competitors' pricing."

Better: "Find the current publicly listed pricing for these four companies: [names]. For each one, search their site, find the pricing page, and list the plan names and monthly prices in a table. If a company doesn't publish pricing, write 'not public' rather than guessing. Note the date you found each price."

Run through a tool that can actually search and read pages, that request is a real agentic workflow at a small, checkable scale: it searches, opens a handful of pages, decides which numbers are the actual plan prices rather than a quoted testimonial figure, and assembles the table — several decisions made along the way, not one lookup. What makes the request itself good is the same thing that makes any request to one of these tools good: a defined scope, a named list rather than "my competitors", and an explicit instruction for what to do when the information isn't there, so an absence gets reported as absence rather than filled in with a guess.

Where the extra steps add a new way to fail

A single wrong answer in a chat reply is one thing to check. A multi-step run can be wrong in several places at once, and nothing in the final summary tells you which step it was — it might have read the wrong pricing page, misread a number on the right one, or silently skipped a company it couldn't find anything for. Fluent, confident output carries no guarantee the underlying step was actually done correctly, a documented property of how these models generate text in general, and a workflow with five steps gives that property five more places to show up unnoticed, compounding rather than cancelling out.

There's a second, more mundane failure that has nothing to do with accuracy: an unscoped request can simply run longer and call more tools than you intended, because nothing told it when to stop. Asking it to "keep researching until you're confident" has no natural end point, and a request like that can burn through a lot more time and usage than the four-company version above for a result that isn't meaningfully better — the fix is the same hard boundary that makes the output checkable in the first place, not a separate setting to tune.

Professional use of agentic tools reflects exactly this caution rather than ignoring it. EY's own description of agentic AI across its audit practice and KPMG's rollout of AI agents inside its Clara audit platform both frame the agents as doing first-pass work — vouching expenses, searching records — that a qualified auditor still reviews and signs off on. The step count went up. The requirement for a person to check the output did not go away.

Checks before you trust a multi-step run

  1. Ask for the intermediate steps, not just the final table — which page it read, what it searched for — so you can spot-check two or three before trusting the rest.
  2. Treat any 'not public' or 'unclear' result as the useful part of the output, not a gap to fill in yourself from memory — that's the tool correctly reporting what it couldn't verify.
  3. Click through to one or two of the actual sources it cites and confirm the number matches what's really on the page — a plausible-looking price is not the same claim as a verified one.
  4. Give the task a hard boundary before it starts — a fixed list of four companies, not 'find my competitors' — so there is a defined point where the workflow is actually finished rather than one that could keep expanding.
  5. Keep a note of what ran and when it was checked, the same habit NIST's AI Risk Management Framework sets out for any AI-assisted output feeding a decision — useful at the scale of one research task, not only a deployed system.

What to do Monday

Pick one task you'd normally break into several manual steps — researching a short list of named companies, comparing a handful of documents, pulling the same figure from several sources — and give it the same scoped, named, absence-handling request as the example above. Ask for the intermediate steps before you trust the summary. Agentic AI vs generative AI covers the distinction behind why this kind of task even needs a different approach than a single chat question, and AI agent builder and no-code process automation cover setting up the same kind of multi-step tool for a task you run often rather than once.

If the task genuinely repeats every week rather than being a one-off, intelligent process automation covers when that repetition actually justifies the setup cost, and agentic AI project ideas and deep research prompts are worth reading next for more of the same scoped-request discipline applied to other tasks. Coursium teaches exactly this kind of practical judgement — what to hand a tool, and what to check once it hands something back. Stay ahead of AI by learning the tools on your phone.

Coursium

Stay ahead of AI — learn the tools on your phone.

Get the app