Skip to content

What an AI agent actually is — and how it differs from a workflow and a tool

Tool, agent, workflow, and pack in buyer language: who sits at the desk, what runs on a trigger, and what only wires systems together. No fifth type.

nox.markets8 min read
  • taxonomy
  • agents
  • workflows
  • tools
  • packs

"Agent" is doing too much work in the market. Vendors use it for a chat box, a Zap with an LLM step, a canvas you configure for three weeks, and a worker that actually watches a mailbox at 2am. Buyers then argue about autonomy while buying four different products.

nox.markets uses four product types, and only four. The slugs are tool, agent, workflow, and pack. They are delivery shapes for one promise: a named job, not a model. If a listing does not fit, it does not get a fifth type. It gets a no.

This article is the taxonomy in buyer language. It is not a research paper on planning loops. If an ops lead would have to search a word in the headline, it does not belong here.

Tool: a desk you sit at

A tool is a hosted, single-purpose web app the customer uses directly. You open it. You pick the customer and the line items. You review the PDF. You click send.

Ledgerline is a tool: customer invoices that leave the building the same day the work is done. You are still in the loop for the commercial judgment. The product fills terms, tax, and bill-to from the last invoice to that customer, sends from your domain, and posts the same document to QuickBooks Online or Xero. It does not chase payment. That is a different job.

Bidline is a tool: a quote the customer can sign that matches what you will later invoice. Floatcast is a tool: a 13-week cash view from the bank and the books. Outlay is a tool: receipt in, coded expense report out.

What a tool will not do: run unattended on a schedule as its main contract. If nobody opens it, nothing happens. That is not a defect. It is the type. Adoption risk lives almost entirely in tools, which is why setup time and hours-at-a-stated-volume belong on the card. If week one misses the hours at your volume, cancel it.

Deployment for a tool is often hosted (it runs on nox.markets) or connected (it runs here and writes to your books through OAuth you can revoke). self-hosted is the path when the file must not leave the network.

Agent: a worker on a trigger or schedule that acts

An agent is an autonomous worker that runs on a trigger or a schedule and acts. You do not sit in it all day. You authorize a mailbox or a queue, set the rules, and the work shows up in a tool your team already opens — a draft bill, a reminder from the AR mailbox, a ticket already routed.

Billtray is an agent: it watches an AP mailbox, proposes GL from that vendor's last 12 months, flags duplicates, and opens a draft in Bill.com or QuickBooks. It will not pay the bill. New vendors sit in exceptions until someone maps them.

Duesday is an agent: past-due invoices get the email your AR clerk would have sent, on the day they said they would. Cadence you set. Note written back on the invoice. It stops when paid, voided, or handed to a named owner. You still make the awkward call on accounts that ignore email.

The word "autonomous" here does not mean "no human, ever." Every agent states an autonomy level. For finance-backoffice, human approval exists and is the default. The agent drafts. A named person clicks. Anyone who tells you hallucination is solved is lying; the structural answer is confidence, citation, approval, and a published error rate.

An agent is also not a chat seat. A seat makes a person faster while they type. An agent runs when nobody is typing. If the good prompt lives in one employee's head, you bought a tool-shaped habit, not an agent.

Workflow: multi-step automation across systems, often with no UI of its own

A workflow wires systems together in a sequence. It is the job as a path: this object in system A becomes that object in system B, then a check, then a write. It often has no desk of its own. You do not "open the workflow" the way you open Ledgerline. You see the result in Gusto, QuickBooks, the HRIS, or the ticket queue.

Payready is the catalog example: payroll prep as a path across systems, not a new place to live. The pipes metaphor from automation platforms is useful here, and incomplete. Zapier, Make, and n8n are good at deterministic plumbing and huge connector lists. You are still the architect, the QA, and the on-call. An AI step bolted into a flow carries no evaluation and no accuracy number unless someone built that harness. The flow dies with whoever built it.

A nox.markets workflow is supposed to be the appliance already plumbed and already tested: named steps, named failure mode, setup time as a promise, off switch, exportable log. It is not a canvas. If you need a canvas, use a workshop product and staff it.

If the sequence is one worker acting, it is an agent. If the sequence is several systems and several gates, it is a workflow. The distinction is the shape of the job, not how impressive the demo looks.

Pack: one job-to-be-done, several delivery shapes, one purchase

A pack is a curated bundle of tools, agents, and/or workflows sold as one unit for a job-to-be-done. Closeout is the catalog example: close prep as a bundle, not three vendors, three questionnaires, and three invoices.

The pack is the strategic unit because evaluation cost is the hidden tax on sprawl. Six point solutions for one close is six evals you do not have time to run. One pack collapses that to one vendor relationship, one bill, one security review — with the honest limit that a pack will not be the best possible tool for every sub-step. Buy a specialized product where it matters. For the other eight jobs, one review is the point.

Packs take longer to set up. Closeout is 120 minutes of setup on the card. That number stays on the card. We do not round it down to "under an hour." If setup needs a project plan, it still has to be a number you can hold us to.

Side-by-side, without fog

TypeYou do thisIt does thisFailure if you pick wrong
ToolSit at the desk, decide, clickFormats, fills, posts what you approvedYou bought a login nobody opens
AgentAuthorize, set cadence, approve exceptionsRuns on trigger/schedule, writes into existing toolsYou expected a dashboard; you got a worker
WorkflowConfirm the path and the gatesMoves objects across systemsYou expected a UI; the UI is QuickBooks
PackBuy the job onceSeveral of the above, scoped to one named jobYou wanted one SKU and got a program

Common mislabels

A chat window with memory is still a seat. You type; it answers; nothing writes to QuickBooks unless a person copies it. Calling that an agent trains the company to expect production work from a paste box.

A Zapier path with one model step is still a workflow you own. The model did not inherit an eval, an exception owner, or an audit export. If the person who built the zap leaves, you have pipes with no plumber.

A three-week configuration on an agent builder is a project. The canvas is real capability. It is also a workshop: you specify the job, you judge the output, you maintain it when models change. That can be the right spend when the job is your differentiator. It is not the same SKU as Billtray.

A bundle of unrelated discounts is not a pack. A pack is one job-to-be-done (close, AP intake, payroll prep), not a junk drawer of SKUs that share a coupon.

Pricing shape follows the type (usually)

A tool with a bounded job can be a one-time license: you own the machine; runs may still spend credits, because you do not own the inference. An agent or workflow that runs on a schedule is usually a subscription, because unattended work has a cost of goods. included is the plan mechanic: the product is covered from a named tier. usage is overage, never the headline price. A silent overage bill is a defect in the vendor's design.

None of that changes the type. A tool does not become an agent because it is billed monthly. An agent does not become a tool because you opened a settings screen.

What this is not

This is not a copilot. A copilot (as a category) sits next to a person. We are not that category.

This is not an agent framework. A framework is a workshop. The line we use without punch-up: that's a workshop. We're a store — build the agent yourself, or buy the one already built, with hours derived on the card rather than a measured eval we do not yet publish.

This is not a blank canvas we want you to live on. "Marketplace" means how you buy: browse, compare, buy, deploy. At launch the catalog is first-party. We do not imply a crowd of sellers.

How to choose on a real pile of work

Name the work first. "Vendor bills out of the inbox, coded, as drafts." That is an agent. "I need to issue invoices that match last time." That is a tool. "Payroll file must match time, deductions, and the GL before anyone clicks submit." That is a workflow, or a pack if several of those jobs are one close.

Then ask who is in the loop on a normal Tuesday. If a person must open a desk and decide, you want a tool. If a mailbox or a clock should start the work, you want an agent. If three systems must agree before a file is importable, you want a workflow. If the political problem is six vendors for one close, you want a pack.

Then read deployment: hosted, connected, or self-hosted. Then read whether human approval is the default. Then read the named failure mode. The type label is a filter, not the proof.

Categories on nox.markets stay the seven in the catalog: Finance & Back-Office, Sales & Revenue, Customer Experience, Operations & HR, Data & Intelligence, Marketing & Content, Industry Solutions. The type (tool / agent / workflow / pack) is orthogonal. Invoice assembly and dunning can share a category and still be different types. Do not shop by model name.

More from the blog