Lesson 24 / 25

Case Study: An Expense Assistant

Design an assistant that answers expense questions and files reimbursements with approvals.

Design choices

Tools: search_expenses (read), get_policy (read), submit_reimbursement (write, idempotent, needs approval). The agent loop has a step cap and a token budget. The database user for read tools cannot write. Policy documents come in through retrieval and are wrapped as untrusted. An eval set of thirty requests checks the tool path (no submission without the policy check), outcomes and cost before each release.

A complete tool-using agent

Combine tool design, safety, a loop and evals into one small agent you could actually ship.

Four parts: tools, loop, safety, evals.
Figure 8.1 — Tools, loop, safety and evals.

The design on one page

Each line maps to a section of this course. If you can explain every line, you have the main ideas.

Autonomy    agent loop, max 10 steps, token budget       (Sec 1)
Tools       search_expenses, get_policy, submit_reimbursement (Sec 2, 3)
Retrieval   policy docs via get_policy, wrapped untrusted   (Sec 4, 5)
Safety      read-only DB user, approval for submit          (Sec 5)
Evals       30 cases: path, outcome, cost                   (Sec 6)
Sharing     optional MCP server for other apps              (Sec 7)

Quick check: Which tool in the case study needs human approval?

  • search_expenses
  • get_policy
  • submit_reimbursement
  • None of them
Answer

submit_reimbursement — It changes state and moves money, so it sits in the write tier with approval.