Tools: How Agents Reach Outside the Chat
A language model on its own lives inside a text box. It cannot check today's weather, open your calendar, or send an email. Every useful thing an agent does in the world happens through a tool.
Understanding tools explains a lot: why one agent can book a meeting and another cannot, why agents sometimes ask for permission, and what people mean by "function calling" and "MCP." This lesson covers all of it without any code.
What You'll Learn
- What a tool is and how an agent "uses" one
- What function calling means in plain language
- Common types of tools and what they let agents do
- What MCP is and why connectors matter
- Why permissions are the most important setting in any agent
What a tool really is
A tool is a piece of normal software that the agent is allowed to use. Each tool comes with a short description, written by the people who built the agent, such as:
search_web: Searches the internet. Input: a search phrase. Returns: a list of results with titles, links, and short snippets.
The model reads these descriptions like a menu. When it decides a tool would help, it writes a structured request: which tool, and what input. The software around the model sees that request, runs the real tool, and hands the result back.
- Model reads the tool menuNames, descriptions, inputs
- Model writes a tool requestWhich tool, what input
- Software runs the toolThe real search, email, or file action
- Result goes back to the modelIt decides what to do next
This is what function calling or tool calling means. The model does not run anything. It fills in a request form, and the software does the work. That split is important for safety: the software can check, limit, or block a request before it runs.
It also explains a common failure. If a tool's description is vague, the model may pick the wrong tool or give it the wrong input, the same way you might order the wrong dish from a confusing menu.
Common kinds of tools
What an agent can do is limited to the tools it has been given.
| Criteria | Lets the agent | Example use |
|---|---|---|
| Search | Find current information | Latest prices or news |
| Browser | Open pages, click, fill forms | Book a table on a website |
| Files | Read and write documents | Summarize a folder of reports |
| Code | Run calculations or scripts | Analyze a spreadsheet |
| Apps | Use email, calendar, chat, CRM | Draft replies, schedule meetings |
Lets the agent
- Search
- Find current information
- Browser
- Open pages, click, fill forms
- Files
- Read and write documents
- Code
- Run calculations or scripts
- Apps
- Use email, calendar, chat, CRM
Example use
- Search
- Latest prices or news
- Browser
- Book a table on a website
- Files
- Summarize a folder of reports
- Code
- Analyze a spreadsheet
- Apps
- Draft replies, schedule meetings
A computer-use or browser agent is an agent whose main tool is a screen: it looks at screenshots and clicks, types, and scrolls like a person. It is flexible because it can use almost any website, but slower and more error-prone than a direct connection. AI Browsers & Computer-Use Agents covers these tools hands-on.
Connectors and MCP
Every app has its own way of being connected to. In the past, every AI product had to build a separate connection for every app. That does not scale.
MCP, the Model Context Protocol, is a shared standard for these connections. Think of it like a universal plug. An app or service offers an MCP "server" that describes its tools in a standard way, and any AI assistant that supports MCP can plug into it.
For you as a user, this shows up as connectors or integrations: a list of apps you can connect to your AI assistant, such as your email, documents, calendar, or project tracker. Once connected, the agent can see those tools on its menu.
You do not need to understand the technical details to use connectors. If you want to go deeper, the blog post What Is MCP? explains the standard, and MCP Fundamentals is a hands-on developer course.
Permissions: the setting that matters most
A tool gives an agent power. Permissions decide how much. Before you connect an agent to anything, ask:
- Read or write? Reading your email is very different from sending email as you. Many connectors let you choose.
- Ask first, or act alone? Good agent products pause and ask before actions that are hard to undo: sending messages, spending money, deleting files, submitting forms.
- How much access? Connect one folder, not your whole drive. Connect one calendar, not every account.
- Can you see what it did? A clear log of every tool call lets you check the agent's work and spot mistakes.
Decision
Should the agent act without asking?
- If Reading or searching only
Usually fine to allow
Nothing changes in the world
- If Drafting something you will review
Fine to allow
You still press send
- If Sending, buying, deleting, or submitting
Require your approval
Hard to undo
A simple rule: give an agent the least access that still gets the job done, and keep approval on for anything you could not easily undo.
Key Takeaways
- A tool is normal software an agent is allowed to use, described to the model like a menu item.
- Function calling means the model writes a structured tool request, and the surrounding software runs it.
- An agent can only do what its tools allow: search, browse, files, code, and apps are the common types.
- MCP is a shared standard for connecting AI assistants to apps, which you see as connectors or integrations.
- Permissions matter most: prefer read-only access, require approval for actions that are hard to undo, and connect only what is needed.

