Agentic execution
Bound the model’s next-step decisions and inspect tool-assisted evidence
Agentic execution lets a model choose successive actions within a configured step budget. It can refresh the pinned evidence query, call configured specialist HTTP endpoints or tool plugins, revise its assessment and finalize a structured forecast. It does not gain arbitrary access to workspace tools or external URLs.
Equipment example without external tools
Use an active equipment probability forecaster with a published evidence query, a failure event/window prompt and a probability/confidence/rationale output schema. Apply this executionConfig through Edit → Execution config or forecaster_update:
{
"mode": "agentic",
"maxSteps": 4,
"httpModels": [],
"pluginTools": [],
"budget": {
"maxDurationMs": 120000,
"maxTotalTokens": 30000,
"maxExternalCalls": 0,
"allowedHttpHosts": [],
"allowedPluginTools": []
}
}The empty registries and allowlists deliberately expose no HTTP/plugin tool. Query refresh still uses the forecaster's pinned query and the run's subject. This example verifies bounded orchestration; it does not assert that extra model reasoning yields better forecasts.
Decisions and completion
Supported decisions are query_evidence, call_http_model, call_plugin_tool, revise and finalize. Query refresh requires explicit queryInput and replaces the agent's current evidence with its result. It cannot change the run's reserved subject_ref, horizon or nested params.
Finalization must supply an object matching the output schema. If the agent exhausts its steps without finalizing, a finalizer model call attempts the structured answer; token/duration budgets still apply. Inspect that condition in the trace rather than treating a bounded loop as proof of sufficient evidence. Configured maxSteps is positive and at most 12.
Add a specialist service deliberately
To add an HTTP specialist, configure a named httpModels entry with id, HTTPS url, method/body and protected environment-backed authentication where needed. Add the hostname to budget.allowedHttpHosts and allow enough external calls. The agent selects a configured id, not an invented URL. The service must exist and have an agreed request/response contract.
The HTTP runtime accepts HTTPS only, refuses redirects and blocks listed private/local address forms. Credentials can be resolved with auth.type bearer_env/env or headerEnv. Do not paste real secrets into prompts or copied examples. A host allowlist permits the call; it does not validate the specialist's prediction quality.
Tool plugins are a separate capability
pluginTools entries identify runtime tool plugins and configured params. The exact tool identifier must appear in budget.allowedPluginTools. The runtime checks that the loaded manifest is kind tool. A Postgres read installation or data endpoint is not automatically a tool plugin callable here. Do not advertise an internal connector as an agent tool without a supported tool manifest.
Inspect the result
Review the trace, tool outputs, current evidence, final prompt/output and usage. External operations are tracked and can require reconciliation after uncertain completion; cancellation does not undo an already completed service side effect. Start with read-only specialists and evaluate outcomes before using generated recommendations operationally.