An AI agent without integrations is just a chat. The value shows up when it reads from and writes to your company’s systems: it checks the CRM, updates a spreadsheet, opens a ticket, sends an email. This guide covers the ways to connect an agent to your stack, from the simplest to the most robust, and the security measures you cannot skip.
How an agent “uses” tools
Current models support function calling (also called tool use). You describe the available tools, with name, purpose and parameters, and the model decides when to call each one. The actual call is executed by your code or your automation platform, never by the model directly.
{
"name": "get_customer",
"description": "Returns profile data and open orders for a customer by email",
"parameters": {
"type": "object",
"properties": { "email": { "type": "string" } },
"required": ["email"]
}
}
A good tool description is half the battle: say clearly when to use it, what it returns and what it does not do.
Four ways to integrate
1. Automation platforms (Zapier, Make, n8n)
The fastest route. The platform receives the trigger (new email, form, message), calls the AI model and sends the result to the next system. n8n has the advantage of running on your own server, which helps when sensitive data is involved.
Best for: linear flows, prototypes and companies without a development team.
2. Direct APIs and webhooks
When the flow involves multi-step decisions, it is worth writing the agent in code (Python with LangChain or the model provider’s SDK) and calling the systems’ APIs directly. Webhooks let a system notify the agent when something happens, without constant polling.
Best for: processes with their own rules, high volume or a need for fine-grained control.
3. Databases and documents (RAG)
To answer from company information, the agent queries:
- relational databases through prepared views and a read-only user;
- documents (policies, manuals, proposals) indexed in a vector store, which returns the most relevant passages for each question.
Avoid letting the model write free-form SQL against the production database. Prefer pre-approved, parameterized queries.
4. MCP (Model Context Protocol)
MCP is an open standard for connecting AI assistants to data sources and tools. Instead of building an integration for each assistant, you expose a system once, as an “MCP server”, and any compatible client can use it. Ready-made servers already exist for databases, file systems, code repositories and many SaaS tools.
Best for: companies that want to standardize how AI accesses internal systems and reuse integrations.
Reference architecture
Channels Orchestration Tools
───────── ─────────────── ─────────────────────────
WhatsApp ─┐ ┌─► CRM (read/write)
Email ─┼──► Agent + rules ────────────┼─► ERP / finance (read)
Teams/Slack─┤ │ (n8n or code) ├─► Power BI (DAX query)
Form ─┘ │ ├─► Document base (RAG)
▼ └─► Calendar / email (send)
Logs + queue for human review
Security: what you cannot skip
- Least privilege: every integration with the minimum permission. Read-only wherever reading is enough.
- Secrets outside the code: API keys in a vault or environment variables, rotated periodically.
- Human approval for sensitive actions: payments, deletions, bulk messages and contract changes go through a person.
- Limits: a maximum number of actions per run and per hour, to avoid loops and surprise costs.
- Protection against malicious instructions: external text (emails, web pages, documents) may contain hidden commands. The agent must treat it as data, never as orders, and critical tools should require confirmation.
- Full logs: input, tools called, parameters and result, for auditing and improvement.
- Privacy: map which personal data flows through the agent and keep its legal basis up to date under the applicable data protection laws.
Checklist before going to production
- Every tool has a clear description, validated parameters and an automated test.
- There is a test environment with fictional data.
- API errors are handled (timeouts, rate limits, missing data).
- There is a way out to a person at every step.
- Cost per run is measured and has a limit alert.
- Someone on the business side owns the agent and reviews its answers.