On 25 September n8n added a new type of agent: you describe the task, choose a model, tools and workflows, and the agent decides how to reach the result. Workflows can become its tools and so limit what it can touch. The old AI Agent node stays unchanged.
- The agent runs in Slack, Telegram, Linear, Discord, on a schedule or from a workflow via the new Message an Agent node.
- Memory, sessions, versions and approvals come built in; a sensitive tool can wait for a person's Approve.
- Each tool runs with its own credentials, so the agent never holds the keys to the system.
Anyone who has built an agent in n8n knows the picture: a chat trigger, a memory node, an AI Agent with a few tools attached and a workflow around it all to hold it together. It works. But you have been assembling your computer part by part.
n8n is now selling the pre-built computer. The agent comes with memory, sessions, channels, versions and approvals, and you write what it should do, as if writing a brief for a colleague.
The smartest part of the announcement
The note example. A support agent has to write a note into the CRM. Without a workflow in between, you would give it full write access and hope the instructions keep it to the notes field.
With a workflow, the agent never holds those rights at all. It holds a workflow that does one thing: adds a note. That is the right way to let a model near your real systems. Not to trust it, but to give it only as much as it needs.
They say it plainly themselves: for anything sensitive, start where the damage is small - limited tools, a test channel and approval for every action that writes to a real system.
The old agents keep working and nothing moves. The new ones are tried on a task where every request is different, and that is where the difference shows fastest.