AI agents and tool calling: what I apply in production
I design agents that operate real systems through tools. This page covers how I did it in AgendaGo, which is in production, and in Nux, which is still in construction.
What tool calling is
In tool calling the model executes nothing: it returns which tool it wants to call and with which parameters. The system validates that call, runs it and hands the result back, and the loop repeats until the model answers. An agent is that loop plus the rules that bound it.
What matters in the design is not the prompt but the set of tools: what the model can read, what it can propose and what only a person can do.
AgendaGo: two agents in production
The dashboard assistant has 21 tools: 11 read, 2 simulate or explain and 8 propose. The WhatsApp agent has 9: availability, booking, hours, address, services, coverage, requirements, re-ask and hand-off to a person. Both run in Supabase Edge Functions and call OpenAI over direct HTTP, with no SDK, behind a provider abstraction.
- Each assistant turn has at most 4 tool rounds and 700 tokens, plus a per-turn spend cap and a monthly budget per business.
- Runs can be cancelled, and the response streams from the Edge to the frontend.
Design decisions and what they cost
- The propose tools never write. They create a proposal with the diff and its consequence, which expires after 15 minutes, and a human click applies it. It costs one more step per change; in exchange, the model has no direct path to writing.
- Applying is protected in the database, not in the prompt: a SECURITY DEFINER function for the admin role, with a row lock and an atomic step.
- Booking over WhatsApp goes through three barriers: the slot comes from the availability engine in the same turn, the customer cannot have another booking that day and a database trigger blocks overbooking.
- A deterministic router answers about 44% of messages without calling the model.
- The business comes from the JWT, never from the model, and forbidden parameters are stripped.
Nux: in construction, with the LLM switched off
Nux is the Bonuxo dashboard assistant and it is in construction. Its agent uses tool calling with 19 tools: 12 read, 5 confirm and 2 strong-confirm. Writes need human confirmation and respect the user’s permissions. There are at most 8 tool rounds per turn.
The provider is interchangeable between OpenAI and Anthropic, and there are per-plan cost caps and a usage log. The LLM layer is built and tested but switched off in production; Nux’s deterministic part is live for all tenants.
Related stack
- OpenAI
- Anthropic
- Supabase Edge Functions
- WhatsApp Cloud API
- TypeScript