Product

How Autonomous Agents Work, and Where You Stay in the Loop

Eighteen agents watch your store continuously. None of them can spend a cent. Here is the permission model, the approval queue, and the four things "switching an agent on" does not do.

Marcus Johnson · Operations LeadAugust 5, 202611 min read

How Autonomous Agents Work, and Where You Stay in the Loop

The scary version of an AI agent is one that wakes up at 3am, decides your prices are wrong, and rewrites them all. The useful version tells you at 9am that it thinks three prices are wrong, and why.

Most of the design work in Synton's agents is about the distance between those two, and about being precise where marketing copy is usually vague. So here is the honest version, including the parts that are not finished.

Three different things get called "AI"

Synton does work for you in three ways. The difference is who starts the work, and what happens when it finishes.

Chat. You type, it answers, the conversation ends. Nothing keeps running after you close the window.

An agent you run. A named specialist with a fixed job. You click Run, it collects data, thinks, and produces findings and recommendations. Running an agent is a job, not a conversation.

An agent that runs itself. The same agent, left switched on.

The eighteen that run continuously

Eighteen agents are built to run continuously rather than once. Each watches a single slice of your store, forms an opinion, and reports back. You will find them in the Agents app under Fleet Overview.

  • Inventory Intelligence. Predicts stockouts and optimizes inventory levels.
  • Shipping Optimizer. Analyzes shipping costs and suggests optimizations.
  • Price Monitor. Monitors competitor prices and suggests optimizations.
  • Bundle Optimizer. Suggests profitable product bundles.
  • Visual Watcher. Screenshots competitor homepages and flags visual changes.
  • Origination. Surfaces matter-origination opportunities from court, regulatory and news signals.
  • SEO Health. Audits technical SEO and content optimization.
  • Review Response. Drafts responses to customer reviews.
  • Content Quality. Improves product descriptions and titles.
  • Email Health. Checks SPF, DKIM and DMARC configuration.
  • Meta Pixel. Checks Meta Pixel configuration.
  • Social Monitor. Monitors brand mentions and social engagement.
  • Fan CRM. Ranks superfans and surfaces commerce opportunities.
  • Cart Recovery. Analyzes cart abandonment patterns.
  • Performance. Monitors page speed and Core Web Vitals.
  • Churn Prediction. Identifies at-risk customers.
  • CRO Optimizer. Analyzes and improves conversion rates.
  • Fraud Shield. Monitors orders for fraud patterns.

One note on that list: Origination is built for professional-services workspaces such as law firms. It will run on any workspace, but on a store its signals will be empty.

Beyond these there is a much larger on-demand roster covering specialist commerce work plus packs for non-ecommerce industries, and which of those appear depends on your industry. A hotel does not need a merchandising agent and a law firm does not need one for shipping. You do not need to learn the names. Ask in chat for the outcome you want.

What switching an agent on does not do

This is the single most important paragraph in this post, and it is the one most likely to be glossed over elsewhere.

Enabling an agent does not by itself give it a clock. Enabling records that the agent is allowed to run and lifts it out of read-only. The work is then triggered in one of three ways: you click Run on its row, Autopilot's scan reaches it while looking for opportunities, or a recurring schedule you created fires.

If you want an agent to run every night whether or not you open Synton, you have to give it a schedule. Enabling and scheduling are two separate switches, and only the second one makes an agent wake up on its own.

Second: the first time you enable an agent, it is created at the "suggest" setting. It will draft actions and wait for you rather than acting on its own. Raising that is a separate, deliberate step under Permissions. Nobody gets surprised by an agent acting alone because they flipped one toggle.

Third: Pause stops an agent running on its own. It does not stop you running it by hand, and it does not stop a run already in flight. A paused agent is held at read-only regardless of its autonomy setting, and does nothing when its schedule fires. Pausing does not delete the schedule.

The four autonomy settings

Set these in the Agents app under Permissions, in the Mode column.

  • monitor. Reads and reports. Never writes anything, ever.
  • suggest. Drafts a change and stops. A person has to approve it before anything happens.
  • auto, low-risk. Acts directly on things that are reversible and bounded. Nothing at this level needs a restore from backup to undo.
  • autonomous. Acts without waiting for approval, everywhere below the ceiling.

You will see the same ladder named differently in different places, which is worth knowing before it confuses you. The agent tier chips call them Observer, Assistant, Operator and Director. The team roles screen calls them read-only, suggests you approve, acts on reversible things, and acts independently. Same four rungs.

Agents hold permissions the same way people do

A person has a role. An agent has an autonomy setting. Both resolve into the same list of 48 capabilities, and both are checked by the same code on every single action. There is no separate, looser rulebook for agents.

The capability counts climb with the tier: 4 at read-only, 4 at suggest, 9 at acts-on-reversible-things, and 14 at acts-independently. The top tier adds publishing content, publishing to social, managing a channel, and reading the audit log.

You can read the whole matrix yourself in the Team app under Roles and permissions, on the Agents tab. It is computed from the permission matrix every time the page renders, so it is never a hand-written table that can drift away from what is actually enforced.

Thirteen things no setting ever reaches

There is a ceiling above the top tier. Thirteen capabilities are refused to every agent at every setting, in six groups:

  • Authority over your people. Inviting, removing or re-roling teammates. An agent that could do this could manufacture a human account with more reach than itself.
  • Your billing. Changing what you are charged and where funds land.
  • Your security posture. SSO and policy settings.
  • Autonomy itself. An agent cannot raise its own level or trigger an emergency stop. This is the one that holds all the others up.
  • Connecting a payment platform.
  • Irreversible destruction and bulk export. Deleting content or campaigns, exporting your data or your audit log. An agent may create and edit, but undoing a delete is a restore from backup, and that is your call.

The rule that stops agents becoming a side door

When you ask an agent to do something, two permissions are checked, and the lower of the two wins. It is not "either one is enough".

An owner asking a monitor-only agent to publish is refused. A team member with no ad permissions driving a fully autonomous agent is still refused. The point of an agent is to save you work, never to be a side door around your own team's permissions.

There is an important corollary. When nobody drove the run, there is no person to bound it, so the agent's own setting is the entire answer. That is exactly why a scheduled overnight run is worth setting more conservatively than one you are watching.

Everywhere else, unclear cases resolve to less authority rather than more. An unconfigured agent is treated as suggest. A paused agent is read-only. An agent whose configuration cannot be read holds nothing at all, and every action is refused.

Money is a separate consent, and today it is closed

Four capabilities commit real money: spending credits, spending ad budget, refunding an order, and paying an affiliate. No autonomy setting reaches any of them. An agent set to fully autonomous, allowed to act on everything else without asking, still cannot spend a cent.

The reasoning is that "act on its own" and "spend my money" are two different consents, and merchants do not read them as one.

Being straight about the current state: the spending-grant system is designed but not yet shipped. No grant can exist today, which means every agent is refused every money action, at every autonomy setting, on every store. The check is written so that a failed lookup answers no. A grant that cannot be read is not a grant, and an error is never treated as permission to spend.

If you want an agent's judgment on something that costs money today, set it to suggest. It drafts the action and files it in Approvals, which gives you the agent's reasoning with your signature on the money.

The approvals queue

Agents app, Approvals tab. The heading reads "Actions waiting on a human yes", and there are two distinct things on the screen.

At the top, questions waiting on you. An agent can pause mid-run and ask you something in plain language. You type an answer. Nothing is approved or denied by answering.

Below that, the table of actions needing a yes or no. Each row tells you why it stopped, in a plain sentence rather than an error code:

  • "This agent hasn't used [capability] before. Approve it once and it can carry on."
  • "Synton was not confident enough about this step to run it unsupervised."
  • "This step could move revenue, so it waits for your go-ahead."
  • "This step would reach a lot of customers at once, so it waits for your go-ahead."
  • "This step drifts from your brand voice, so it waits for you to read it first."
  • "Two agents recommended opposite things here, so this one is yours to call."
  • "You have set this kind of work to manual, so every step waits for you."

A whole agent run is reviewed as a single unit, so approving once covers the set. A run proposing more than 25 actions rolls over into a second review row, rather than growing into something nobody can read.

Timings you should know. Most approvals expire after 7 days. A step parked mid-run expires much sooner, often in 4 hours. On expiry the action is simply not performed. Agent-asked questions never expire on their own, but the agent itself only waits about four minutes, eight at the outside, before reporting what it managed to do. Answering later is not wasted: the answer is stored and reused for seven days, so the next time that agent asks the same thing it gets your answer immediately.

Batch approve and reject are capped at 50 at a time. Two sharp edges worth flagging: with nothing selected, the buttons read "Approve all" and "Reject all" and act on every row on the page, and Approve has no confirmation dialog while Reject always confirms.

Nothing an agent does is untraceable

Every agent run is recorded: what went in, what the agent did at each step, what came out, how long it took, and what it cost.

The Activity tab shows everything the fleet did, newest first, with credits and duration per run and an Open trace link. Run Trace gives you the step-by-step trajectory, with the steps on the left and an inspector on the right carrying Input, Output, State, Directive and Logs tabs. For a step that changed something, it shows before and after. Steps that modified your store are chipped as Changed.

If a run failed, read the first failing step. Later steps usually fail because that one did.

Two things that surprise people. Retrying is a brand new run, not another attempt at the old one, so there is no attempt counter anywhere: a retry is free to take a different path. And stopping a run terminates it immediately but does not roll back work already completed. Use the History app to reverse individual changes.

Credits are metered once for the whole run, which is why the per-step cost column is always a dash. A dash there means unknown, not zero.

Practical advice

From the first-week guidance in the docs, and it is right: agents are the reason to be here, but turning on twelve of them on day four is how people end up ignoring all twelve.

Pick one agent that matches a goal you actually have. Leave the rest alone. Check the Today app once a day, which shows what happened, what needs a decision, and what is scheduled. If that takes more than ten minutes, you have too many agents running.

Share:

Related Topics

autonomous AI agentsAI agent permissionshuman in the loopecommerce automationAI approvals

Ready to Automate Your Shopify Store?

19 operations keep running between your decisions, so less waits on you.

Start for Free