Tool calling
Tool calling gives a model a list of available tools, each with a name, a description and an input schema, and lets it decide during its own reasoning which one to call and with what arguments, then read the result back before deciding what to do next. It is what turns a model from something that only talks into something that can look something up or actually do something.
That capability is also exactly where risk enters: a tool call can touch a real system, send a message, run a query, take an action, not just produce a sentence. What an agent can call is the real, practical boundary of what it can do, more than anything written in its instructions.
An agent calls a CRM lookup tool mid-answer to check a real order's actual status, instead of producing a plausible-sounding guess about what the status probably is.
In Dynamiq, any workflow node, including another agent, can be attached to an Agent node as a tool, drawing from web search, code execution, databases, HTTP calls, 2,100+ app integrations, and Model Context Protocol servers. The model only ever sees a tool's name and description, and runtime values that must never reach the model are injected separately, invisibly to it, at the moment the tool actually runs.

See an agent on your own workflow.
Bring a process and its documents. Our engineers will show you how Dynamiq runs it, in your environment or ours.