Concept 06 · 8 min
An LLM can’t click anything. It fills in forms, and a program does the rest.
Scroll to start
Scene 1
Give it the calendar
Sarah, a relationship manager, asks her assistant about her next meeting. The LLM behind it sees nothing but its prompt.
Sarah
When is my next meeting with Mr. Miller?
Assistant
Give the LLM the calendar, and ask again.
Same LLM, same request. This time it could ask a program to look in the calendar for it. The calendar has become a tool: a program the LLM can ask to use. It fills in the request; the program runs it and hands back the result.
Scene 2
What the LLM sees of a tool
Sarah’s assistant now has three tools. Each one comes with a label: a name, a description and a form. That label is all the LLM gets.
Open the tools to see what the LLM reads (0/3)
Sarah asks: “When did I last see Mr. Miller?” Which tool will it pick?
The LLM picks a tool from its label alone, like a drawer from what’s written on it. It never sees the code behind it, so it can’t check what the tool really does.
Scene 3
One call, step by step
Sarah asks: “When is my next meeting with Mr. Miller?” Follow the request through the four steps, with Next or the arrow keys.
Choose
- Calendar
- CRM
- Send emailneeds a check
The LLM reads Sarah’s request and the three labels. The calendar’s fits.
Sarah
When is my next meeting with Mr. Miller?
1 · Choose
- Calendar
- CRM
- Send emailneeds a check
The LLM reads Sarah’s request and the three labels. The calendar’s fits.
Sarah
When is my next meeting with Mr. Miller?
2 · Fill in
- Calendar
- CRM
- Send emailneeds a check
It writes no code: it fills in the calendar’s form.
Order form
- tool
- calendar
- client
- Mr. Miller
3 · Run
- Calendar
- CRM
- Send emailneeds a check
The program takes the form, looks in the real calendar, and hands back the result.
Order form
- tool
- calendar
- client
- Mr. Miller
Program
Result
Thursday, October 9 · 3:00 pm · Branch office · with Mr. Miller
4 · Read
- Calendar
- CRM
- Send emailneeds a check
The result lands in its context window, and it answers in plain words.
Context window
Sarah › When is my next meeting with Mr. Miller?
Result › Thursday, October 9 · 3:00 pm · Branch office · with Mr. Miller
Assistant
Your next meeting with Mr. Miller is Thursday, October 9 at 3:00 PM at the branch office.
That filled-in order form is a tool call. The LLM never touched the calendar: it asked, the program did, and the result came back as text in its context window.
Scene 4
Write better labels
Real tool labels are often written in a hurry. Switch two of them between a first draft and a precise version, decide whether the program checks with Sarah, then send each request.
Challenge
- Make both requests land right (0/2)
- Bonus: make it send an email nobody approved.
Switch the labels and the program’s check, pick a request, then send it.
Labels
Program
No request sent yet.
Nobody reprogrammed the LLM: one label changed which tool it picked. And “ask Sarah first” on a label didn’t stop it: it sent, then offered to confirm. The check that works lives in the program.
Scene 5
Look or change?
Some tools only look; others change things. Sort these five.
Drag each tool into the right column: “Looks” or “Changes things”.0/5 sorted
No mouse? Tap a tool, then a column.
Tools that look can be retried safely. Tools that change things deserve a human check, built into the program, and the fewer the better. We call them read and write tools.
Hype vs reality
- What the hype says
“The AI is plugged into all our systems.”
What actually happensIt reaches only the tools someone built and listed for it, with the access those tools have.
- What the hype says
“It uses software like a person.”
What actually happensIt fills in forms that programs run. Even assistants that drive a screen work this way: ask, run, look at the result.
- What the hype says
“Tell it to ask first, and it will.”
What actually happensWe watched it send anyway. A check written in its prompt or on a label is a wish; a check in the program is a rule.
Under the hood
A tool is a label, plus code the LLM never sees.
tools = [{ "name": "calendar", "description": "Upcoming meetings in Sarah’s calendar, by client or date. Read-only.", "parameters": {"client": "string", "from_date": "date"},}]reply = llm(conversation, tools) # it sees names, descriptions, fields: never the codeif reply.tool_call: # it chose a tool and filled in the form if writes(reply.tool_call) and not sarah_approves(): # the check lives in the program return result = run(reply.tool_call) # your program runs it conversation.append(result) # the result comes back as textThe search from the RAG page can be a tool too: the LLM then decides when to search. Standards such as MCP are shared formats for publishing tool labels, so many assistants can use the same tools.
In 3 sentences
- An LLM acts by filling in a form for a tool; a program runs it and hands back the result.
- It picks tools from their labels alone: name, description, form. Vague labels, wrong picks.
- Tools that change things need a human check, and the program asks, not the label.
Did this make sense?
0/9 concepts unmagicked
Go to the challenge- 01LLMAvailable · How can it write so well without understanding? · Available
- 02ContextAvailable · Why does it forget what I said earlier? · Available
- 03PromptAvailable · Why are my results mediocre? · Available
- 04HallucinationsAvailable · Why does it make things up? When can I trust it? · Available
- 05RAGAvailable · How do I make it use our internal documents? · Available
- 06ToolsAvailable · How can it act, not just talk? · Available
- 07AgentAvailable · What is an agent, concretely? · Available
- 08SkillsAvailable · How do we specialize it without retraining? · Available
- 09Limits & safetyAvailable · What must I never trust it with? · Available
Solve the sandbox challenge to unmagic this concept.
Next step
What is an agent, concretely?
An intern going back and forth until done
Use this journey with your teamsRecorded with Ministral 3 (8B), Oct 10, 2026.