AI Agents for Beginners: What They Are and a First Safe Setup

An AI agent is an AI model that can use tools, one step after another, to finish a job you gave it. What that means in plain words, what to hand one first and what not to, and a first setup with one tool and one board that you can check and switch off.

7 min read

An AI agent is an AI model that has been given tools and a job. Instead of answering one question and stopping, it decides on a step, uses a tool to take it, looks at what happened, and carries on until the job is done or it gets stuck. For a beginner, the safe way in is small and boring on purpose: one tool you already use, one small job you can check, one place where the work is written down, permission to read before permission to change, a prompt before every change, and a switch you know how to turn off. That is the whole setup below, and it takes under an hour.

If you want the bigger picture of the word first, what is agentic AI covers where it came from and eight examples, and the short definition is in the glossary. This page is for doing.

AI agents in plain words

Think of a capable new assistant on their first day. They are quick and well read, but they only know what you tell them, they can only open the doors you gave them keys to, and they will sometimes be confidently wrong. A chatbot is that assistant answering questions across a desk. An agent is the same assistant allowed to walk around the office and do things.

  • The model is the thinking part: Claude, GPT, Gemini and others. It reads, writes and decides the next step.
  • The tools are the keys: reading files, searching the web, adding a task, sending an email. Without tools a model can only write text. With them it can change things.
  • The loop is the walking around: step, look at the result, next step. Anthropic’s page on how Claude Code works (opens in a new tab) describes this as gathering context, taking action and verifying results, repeated until the task is done.
  • The permissions are you: which keys it holds, and which doors make it stop and ask first.

That is all an agent is. The parts are laid out in more depth, for when you want them, in AI agent architecture.

Good first jobs, and ones to leave for later

A good first job is small, easy to check, and cheap to get wrong. You should be able to look at the result and know in a minute whether it is right.

  • Good: “Read these meeting notes and list the action items as tasks.” You can compare the list with the notes.
  • Good: “Tidy the titles of the tasks in To Do so each starts with a verb.” Every change is visible and easy to undo.
  • Good: “Read this folder of error messages and tell me which ones repeat.” It only reads.
  • Later: anything that sends a message to a customer, spends money, deletes things, or touches a live website.
  • Later: long jobs with many steps where you would only see the end result.

More jobs you can hand over, with the review call for each, are in AI agent task examples.

What can go wrong

  • It is confidently wrong. It will report success on a job it half did. Check the result, not its summary.
  • It does more than you asked. Asked to fix one thing, it may “helpfully” change three. Small jobs and approval prompts catch this.
  • It follows instructions hidden in what it reads. A web page or an email can contain text written to steer an agent. This is called indirect prompt injection, and it is the reason not to let an agent read strangers’ text and act on it unsupervised.
  • It gets hold of secrets. Never paste a password or an access key into a chat, and never let an agent write one into a file.
  • It costs more than you expected. Long loops use more of your plan’s allowance. Stop a run that is going in circles.

Step 1: pick one tool

Use the assistant you already have. There is no need to learn a framework or write code to start; frameworks are for building your own agent later, and AI agent frameworks compares them when you get there.

  • You do not write code: Claude on the web or desktop, or ChatGPT, with a connector added in settings.
  • You write code: Claude Code, Cursor, or GitHub Copilot in VS Code, which already work as agents in your project folder. The Claude Code first hour walks through one.

Step 2: make it ask before it acts

Every agent tool has a setting for how much it may do without asking. As a beginner, you want it asking. In Claude Code this is the permission mode. Its permission modes page (opens in a new tab) says Manual mode asks before most actions that edit files, run shell commands or reach the network, and that on recent versions auto mode, where a second model reviews actions instead of you, is the built-in starting mode for terminal and VS Code sessions. So check, and choose Manual yourself:

Claude Code: start one session in Manual mode, or make it the default
claude --permission-mode manual

# ~/.claude/settings.json
{
  "permissions": {
    "defaultMode": "manual"
  }
}

The manual name needs a recent version; older ones use the config value default for the same mode. In a running session, Shift+Tab cycles the modes. Other tools have their own equivalent; look for words like “ask”, “approve” or “confirm” in their settings.

Step 3: give it one board, read-only first

An agent needs somewhere to take work from and report back to that is not the chat window, because the chat is gone when you close it. A task board works well for a first try: when the agent adds or changes a task, you can see it with your own eyes. Tools connect to boards and other apps through MCP, the Model Context Protocol; the glossary entry explains it in a paragraph.

Claude Code: add a board as an MCP server, then run /mcp to sign in
claude mcp add --transport http fenbs https://fenbs.ai/api/mcp

When the sign-in page opens, fenbs always grants “Read the board” and lets you tick “Add and change tasks” and “Comment”. For your first session, tick neither. Ask the agent who it is acting as and what is in To Do, and compare its answer with the board in your browser. Every other assistant, and the exact prompts to try, are in MCP for beginners.

Step 4: one small job, then check the record

  1. Once reading works, sign in again with “Add and change tasks” ticked.
  2. Give it the smallest real job you have, such as adding three tasks from a list of notes.
  3. Read each approval prompt before you allow it. You are checking that it is doing what you asked, and only that.
  4. Open the board’s History page. Each change made through an assistant is recorded with its name and yours, for example “Claude via Sam”.
  5. Find the off switch: the connection is listed under Settings, “Connect an AI assistant”, and revoking it stops the agent at once without affecting your own sign-in.

Writing a job so an agent can finish it without guessing is a skill of its own; how to write a task for an AI agent is the next thing to read.

Your first week

  • Day 1: the setup above, read-only, then one small write.
  • Days 2 to 3: the same kind of job each day. Note every time you had to correct it.
  • Day 4: write down, as a short list, what it may do alone and what it must ask about. On fenbs that list can go on the Decisions and rules page, which a connected assistant reads before it starts.
  • Day 5: try one slightly bigger job, still with prompts on. Only loosen a prompt for a kind of action it has done right many times.

Free courses when you want to go further

What the board does and does not do

On fenbs the agent is a member of the board: it acts as the person who connected it, never with more than that person’s role, narrowed by the boxes ticked at sign-in. It sees the same four lanes you do (To Do, Next Up, In Progress, Completed) and files work as features, enhancements or bugs. It cannot give itself more access, and a refusal names the permission it lacked. What fenbs does not have: due dates, sprints, or a way to assign a task to someone. If your first job needs those, a board is the wrong first tool.

Next steps

Connect step by step: MCP for beginners. Decide how much an agent may do alone: human in the loop for AI agents. What the sign-in boxes mean: assistant tokens and scopes. Setup for your assistant: Claude and Claude Code.

Questions people ask.

What is an AI agent in simple terms?

It is an AI model that can use tools, such as reading files, searching or adding tasks, one step after another to finish a job you gave it. A chatbot answers a question; an agent takes actions until the job is done or it needs you.

Do I need to code to use AI agents?

No. Claude and ChatGPT can act as agents through connectors you add in their settings, with no code. Coding helps when you want to build your own agent, and courses such as Microsoft’s AI Agents for Beginners and the Hugging Face Agents Course teach that for free.

What is a good first job for an AI agent?

Something small, easy to check and cheap to get wrong, such as turning meeting notes into a list of tasks or tidying task titles. Avoid anything that sends messages, spends money, deletes data or touches a live website until you trust it.

How do I stop an AI agent if it goes wrong?

Stop the current run in the tool you are using, then revoke the connection it used. Each service lists the apps and assistants connected to it, and revoking one cuts that assistant off without affecting your own sign-in. Find that switch before you need it.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.