If you have ever tried to build a Slack helper in n8n that answers "why did this client's orders drop?", you know the problem. The question is different every time, the next step depends on the last answer, and your canvas turns into a maze of IF nodes that still misses half the cases. On 25 September 2026, n8n shipped a different way to handle that job.
It is called n8n Agents, and it lets you describe the job in plain language instead of drawing every branch. This guide explains what changed, when an agent beats a workflow, how to write the brief that makes or breaks it, and a safe first build you can finish this afternoon.
What are n8n Agents and what changed on 25 September?
n8n Agents are a new, standalone object in n8n, separate from the older AI Agent node. You give an agent a model, written instructions, tools and channels, and it works out the steps itself. The same published agent can answer in Slack, run on a schedule, or be called from any workflow.
According to n8n's launch post by Ophir Prusak, each agent comes pre-assembled with the parts you used to wire up by hand: memory, stored sessions, channels (Slack, Telegram, Linear, Discord, a schedule), draft and published versions, and approvals. n8n compares it to buying a pre-built PC instead of assembling one. You can still open it up and add parts.
Three details matter for practitioners. First, the old AI Agent node has not changed, so nothing you built before breaks. Second, a new node called Message an Agent lets any workflow hand one step to a published agent and receive its answer. Third, you do not need to understand workflows to build an agent. You open the Agents tab, click Create Agent, and write instructions that read like a brief for a colleague.
Availability as of launch: n8n Cloud users on the latest stable version have it now, self-hosted instances can enable it with extra setup (Kingy AI's review notes version 2.32.3 or later), and Enterprise support is "coming soon". n8n labels the feature Preview, which means behaviour can still change between releases.
When should you use an n8n Agent instead of a workflow?
Use a fixed workflow when the steps are known and the order must be exact, such as validating a form and routing a lead. Use an agent when the next step depends on the last answer, such as investigating a client question. Use a workflow with a Message an Agent step when one judgment sits inside a fixed process.
The easiest way to decide is to ask one question: could you draw the process on a whiteboard before the request arrives? If yes, keep it as a workflow. Workflows are cheaper to audit, easier to debug and behave the same way every time. n8n's own post calls a good workflow "boring", and means it as praise.
If the honest answer is "it depends on what they ask", that is agent territory. Typical practitioner examples:
- Internal Q&A in Slack. "Which campaign drove last week's sign-ups?" needs a lookup, maybe a clarifying question, then a summary.
- Inbound lead research. Each company needs different sources checked before a useful summary is possible.
- Support triage. Read the ticket, decide whether account context is needed, draft a reply, escalate if urgent.
- Morning digest. On a schedule, look at what changed overnight and decide what is worth flagging.
The hybrid option is often the smartest. Your existing lead-intake workflow keeps control of the order, and a Message an Agent step handles only the fuzzy part, such as "write a two-line summary of this company and flag anything unusual". Because the node calls the published agent, updating the agent's instructions once updates every workflow that uses it.
How do you write agent instructions that behave consistently?
Treat the instructions field as a job brief with five parts: role, goal, tool rules, boundaries and output format. Vague instructions make the agent guess which tool to use and when to stop. Explicit tool rules and a fixed output shape are what turn a clever demo into something your team can rely on.
Most weak agents fail on the same point: the instructions describe a personality ("you are a helpful analyst") but never say which tool to call first, when to ask a question, or what a finished answer looks like. The model fills those gaps differently each time, which is exactly the inconsistency practitioners complain about.
The fix is the same discipline that makes ordinary prompts reliable, which we covered in our guide to output contracts for consistent AI results. Here is a complete brief you can paste into a new agent and adapt. It is written for a marketing team's Slack helper, but the structure works for any role.
Try this prompt (paste into the agent's Instructions field):
ROLE: You are the marketing team's reporting assistant. You answer questions about campaign performance for colleagues in Slack.
GOAL: Give a short, sourced answer the colleague can paste into a status update.
TOOL RULES:
1. For any question about numbers, call the "Get campaign stats" workflow first. Never estimate numbers from memory.
2. If the question does not name a campaign or date range, ask ONE clarifying question before calling any tool.
3. Use the "Search brand docs" knowledge only for questions about guidelines or messaging.
4. You may call "Log request" once at the end of every session. You may not call any other tool that writes data.
BOUNDARIES:
- If the data needed is not returned by a tool, say "I could not find this in the connected data" and stop.
- Do not give budget recommendations. Suggest the colleague asks the team lead.
- Reply in the language the colleague used.
OUTPUT FORMAT:
- Line 1: the direct answer in one sentence.
- Up to 3 bullet points with the supporting figures.
- Final line: "Source: [workflow or document name], data as of [date returned by the tool]".
Notice what the brief does. It tells the agent which tool is the source of truth, forces a question when the request is ambiguous, names the only write action it may take, and fixes the shape of the answer. Each of those rules removes a decision the model would otherwise make at random.
How do you build your first n8n Agent safely?
Start read-only. Build the agent with one or two lookup tools, connect it to a private test channel, turn on approvals for anything that writes, and review every session log for a few days. Only then add a single narrow write action, and publish a new version rather than editing the live one.
Here is a practical sequence for your first build:
- Open the Agents tab and click Create Agent. You can also describe what you want to the n8n Assistant, which drafts instructions, tools and channels for you. Building with the Assistant uses AI credits.
- Pick a model. Use any model you have credentials for, or n8n's Gateway credits if you do not want to set up an API key yet.
- Paste your brief into the Instructions field, using the five-part structure above.
- Add tools, narrowest first. n8n offers three kinds: MCP servers (fastest, gives the agent a whole service's tools at once, and you can exclude some), individual n8n nodes configured for one action, and whole workflows. If MCP is new to you, our explainer on what MCP connectors are covers the basics.
- Wrap write actions in a workflow. This is the most useful design idea in the launch. Instead of giving the agent CRM credentials, build a tiny workflow that only adds a note to a record. The agent decides when to call it. The workflow decides exactly what happens. Per-tool credentials mean the agent never holds the keys itself.
- Mark sensitive tools for approval. The agent then pauses for Approve or Reject before using them.
- Connect a test channel, test in the draft, and read the session log. Each session shows every step, which tools were called, and their inputs and outputs.
- Publish. Colleagues use the published version while you keep editing the draft. You can restore or unpublish if something goes wrong.
What are the common mistakes and limits of n8n Agents?
The biggest risks are giving an agent broad tools, trusting a preview feature with customer-facing writes, and ignoring cost. One agent turn counts as one execution against your existing quota, but model usage is billed separately. Long, looping conversations therefore cost more than they look.
- The "do anything" tool. A workflow that accepts any request and writes anywhere undoes all the safety of the design. Kingy AI's review makes the same point: workflows as tools only protect you if their inputs and permissions are genuinely narrow.
- Skipping the session log. The log is the only way to see whether the agent picked the right client or quietly summarised when it should have asked a question. Read it before you add privileges.
- Using an agent for fixed sequences. If the order must be exact every time, a workflow is more reliable and easier to audit. Agents add judgment, and judgment adds variance.
- Forgetting the cost model. n8n says tool calls to your workflows and sub-agents do not count as separate executions, and agents share your workflow execution quota. Model tokens, Gateway credits and Assistant usage are extra. Estimate from a few real sessions before rolling it out to a whole team.
- Treating preview as production. n8n itself advises testing before publishing and keeping approvals on anything sensitive while the feature matures.
What should you try in the next 20 minutes?
Build one read-only Slack or chat agent that answers a question your team asks every week. Give it one lookup workflow, paste the five-part brief, ask it three real questions, including one deliberately vague question, and read the session log to see whether it asked for clarification and cited its source.
If it guessed instead of asking, tighten the tool rules. If it answered in a different shape each time, tighten the output format. That loop, brief, test, read the log, tighten, is the whole skill. The model does the steps. You design the boundaries.
The launch makes one thing clear: the practitioners who get value from agents will not be the ones with the cleverest prompts, but the ones who give their agents the narrowest, best-labelled tools. We know AI's cold edges. We know your real challenges. 28 years with UD, turning technology into a partnership with warmth.
Reviewed by the UD AI team. Sources: n8n launch post (25 September 2026), Kingy AI review (27 September 2026).
Ready to hand a real job to an AI agent?
Once you have one agent answering questions reliably, the next step is a set of AI staff with clear roles, the right skills and safe boundaries. UD's AI Staff Solution sets up AI staff around your team's real tools and approval rules, and we'll walk you through every step, from choosing the first role to setup and daily use.