Tools are your real systems
An agent's tools are the same 3,585 integration nodes your flows use. No bespoke plumbing per model.
An agent is just a flow with judgement. It reasons about what to do next, then acts through the nodes you gave it. Give it real tools and it does real work, and it can only ever use the tools you gave it.
Sales
Customer Success
Finance
Product
Socialstock.levels210mssales.velocity340mssuppliers.lookup120mspurchase_order.createapprovalFour nodes, so four tools. There is no fifth thing it can reach for.
Nobody has to open Flomation to use an agent. Channel access is configured in the flow like everything else, so one agent can answer in Slack for ops and by email for suppliers without building it twice.

An agent's tools are nodes in its flow. If Xero is not in the flow, the agent cannot touch Xero, however anyone asks it to. There is no rogue action because there is no action outside the flow.
Add a node and the agent gains a tool. Take it out and the tool is gone. Nothing is granted by prompt, so nothing can be talked out of it.
Put an approval gate in the flow and the agent stops there, mid run, until someone ticks it. It waits rather than guesses.
Reasoning, tool calls, inputs and outputs, step by step and replayable. The same view you already use for your flows.
An agent's tools are the same 3,585 integration nodes your flows use. No bespoke plumbing per model.
Bring your own provider, or run a local model on your own runners for sensitive work.
When the judgement's done, deterministic work belongs in a flow. Agents call them directly.
Wire an agent to the systems it needs, drop it into Teams, Slack or email, and people can simply ask it for things.
Every run is in the Execution view next to the reasoning that produced it, so widening its remit is a decision you make with the evidence in front of you.