Agents
Configured, scoped and reversible. Not dispatched.
An agent in MADDOX is a definition you author rather than a black box you switch on: a name, a type, the instructions it answers with, the data it is scoped to, the guardrails you write for it, and a switch. You build it, you try it against a real question in a sandbox, and you can deactivate it instantly — which cancels anything in flight with your name on the cancellation. Sixteen capabilities across data access, actions and analysis are there to be granted or withheld one at a time, so the scope of what you have built is something you can read rather than something you hope. What no agent does is act. Nothing in the product sends an email, creates a record, updates a field or reassigns an owner because an agent decided to — and we would rather write that sentence here than let you infer the opposite from a page that carefully never mentions it.
How it works
What you actually get
Three real things, described as exactly what they are.
A builder
Name it, choose its type, write its instructions, and tick which of the sixteen catalogued capabilities it is scoped to. They sit in three categories, not two: data access, actions and analysis. Five of them are named for actions — create a task, update a record, send an email, create a deal, assign an owner — and no agent performs any of them. You will meet those tickboxes the moment you open the builder, so we would rather name them here than have you find them and draw the obvious conclusion. The guardrail fields are recorded intent: they are stored with the definition and nothing enforces them yet. The capability list is a declaration of scope — a statement of what this definition is for — and not a grant of power to go and do it.
A sandbox
Ask it something and read the answer. The reply is a real model answer against the instructions you wrote, so you can judge the wording before anyone relies on it. Beneath the reply the sandbox lists capabilities the question may relate to. That list is a rough preview of scope rather than a match indicator — a question matching none of them still shows the first one or two — it is labelled as simulated, and it is not a record of anything having happened, because nothing did.
A kill switch
One control deactivates an agent and cancels anything still in flight, recording who stopped it. A deactivated agent is refused rather than ignored: asking it anything returns an error, from every path, until somebody reactivates it. That is the property that makes the rest of this page safe to offer.
In the product
The definition, and the switch.

Who it is for
For the person who has to say yes to this
Agentic AI is the loudest claim in the category and the one most often bought on trust. This page is written for the reader who intends to check.
- An owner who wants the productivity without software making commitments to customers.
- An IT manager whose first question is what happens when it goes wrong at 2am.
- A sales leader who wants a scoped helper, not an unattended one.
- Anyone comparing us with a vendor whose agents claim to act — this is the honest side of that comparison.
Related
Questions
The things people actually ask.
Will an agent email my customers?
No. No agent in MADDOX sends an email, creates a record, updates a field or assigns an owner. If you want an email to go out on a trigger, that is a campaign journey or a sequence — deterministic automation you configure step by step, and which we describe as exactly that.
Then what is an agent for?
Answering, in a defined voice, against a defined scope, without a person having to re-explain the context every time. That is genuinely useful, and it is a smaller claim than the one the category makes.
What does the sandbox action list mean?
Less than it looks like, and we would rather say so. It lists capabilities the question may relate to, matched on words in their labels; a question that matches none of them still shows the first one or two, so it is not proof that the scope you set is the scope you meant. The percentage beside each row is a placeholder figure, not a model’s confidence in anything. It is labelled simulated because that is what it is. Nothing on that list happened.
What does the kill switch actually stop?
It deactivates the agent, cancels anything still running with a note naming who stopped it, and makes every subsequent request to that agent fail rather than quietly succeed. Reactivating is a separate deliberate action.
Where does the assistant fit in?
Ask Maddox is the surface most people should use, and it is read-first by construction — the model cannot change your data through the conversation at all. When something does need changing it is proposed to you, and you approve it.
Build one, then switch it off.
The second half of that sentence is the part worth testing.