// verdict · checked 2026-08-11 · n8n AI Agent node, Tools Agent (1.x docs, 2026)

n8n AI Agent nodes

n8n

4/5
AGENT

A workflow graph with an LLM node is a flowchart, not a colleague.

CAPABILITY
4/5 AGENT
PROOF
OPERATOR INSPECTABLEYou can run it and read the steps yourself — the record exists for whoever runs it
TRACE ACCESS
OPERATOR-OWNEDWhoever runs it holds the record; nothing is published
LEASH
Not measuredno execution record scored — measure it yourself

Compare → Download the card Bring a trace →

01

The five questions

the rules →
LOOPSruns until doneyes Docs confirm the Tools Agent loops model+tool calls, iterating a task-varying number of steps until it judges the task done; Max Iterations (default 10) is a ceiling, which the rules say does not disqualify. OPERATOR INSPECTABLE source · confidence 9.5/10 · checked 2026-08-11 · ruled by hand
CHOOSESpicks its own toolsyes Docs state the Tools Agent "can understand the capabilities of different tools and determine which tool to use depending on the task" via LangChain tool-calling, looping up to Max Iterations (default 10). OPERATOR INSPECTABLE source · confidence 9/10 · checked 2026-08-11 · ruled by hand
ACTSchanges the worldyes Tool sub-nodes execute real operations the agent invokes: Custom Code Tool runs JS/Python, and app nodes like Gmail expose send/reply/label/delete as agent-callable tools. OPERATOR INSPECTABLE source · confidence 8/10 · checked 2026-08-11 · ruled by hand
RECOVERSfixes its own errorsno Documented recovery is builder-configured: node Retry On Fail / On Error and error workflows. OPERATOR INSPECTABLE source · confidence 4/10 · checked 2026-08-11 · ruled by hand
UNSUPERVISEDnobody watchingyes A published Schedule/webhook-triggered workflow runs end-to-end with no interaction; human review is opt-in and wired per tool, so unreviewed tools "execute directly based on AI decisions". OPERATOR INSPECTABLE source · confidence 8/10 · checked 2026-08-11 · ruled by hand

Capability decisions combine documented behaviour and execution evidence. The proof label on each row shows which of the two decided it, and Leash is reported separately, only when it was measured from an execution record. Primary source: docs.n8n.io. Tested against: n8n AI Agent node, Tools Agent (1.x docs, 2026). Our confidence in this dossier: 4/10.

02

Can you see it work?

the weakest of the five grades above

OPERATOR INSPECTABLE — You can run it and read the steps yourself — the record exists for whoever runs it. Trace access: OPERATOR-OWNED — Whoever runs it holds the record; nothing is published.

Executions view + REST API (includeData) export full per-node input/output per run

Where we looked: docs.n8n.io Public API execution.md (GET /executions?includeData=true), executions env-var config, and redact-execution-data page; confirmed per-node input/output + status/timestamps exportable · see the evidence →

03

Revision history

rss for this product
  1. 2026-08-11
    3/5 WRAPPER WITH AMBITION → 4/5 AGENTLOOPS corrected to yes: Docs confirm the Tools Agent loops model+tool calls, iterating a task-varying number of steps until it judges the task done; Max Iterations (default 10) is a ceiling, which the rules say does not disqualify.editorial correction — no case was filed
04

Badges

earned, never for sale

PASSES THE AGENT TEST OPERATOR INSPECTABLE VERDICT CORRECTED

These render from the live dataset, so a badge cannot outlive the verdict it claims. If the verdict changes the badge changes with it, and an unearned one returns 409 rather than an image. No sponsor can buy one, at any price.

05

Think this is wrong?

bring evidence, not opinion

Name the criterion and link a trace, a doc, or a recorded run that shows the behaviour. A verdict changed by evidence is the best thing that can happen to this site, and the change goes on the public record with your reason attached. Vendors are welcome, and a vendor's own filing is labelled as such rather than buried.