All posts
2 min readby Romiel Inolino

LangChain's agents can now schedule their own follow ups and swap tools per run. The per run config idea is the one to copy

AI agentsLangChainSlack automationagent designaccess control

One agent serving five teams should not see all five teams' tools. LangChain just made that the default pattern.

What happened

LangChain released Managed Deep Agents v0.9, aimed at internal agents that live in Slack or other channels. Its docs say the product is in public beta on LangSmith Cloud in the US region only.

The first feature is agent created schedules. Through a new Schedules SDK, an agent can set up reminders, follow ups and recurring tasks during a conversation, such as remind me about this tomorrow. Each schedule runs as the person who asked, using their permissions and connections, and posts results back to the channel it came from. One-time schedules reply in the original thread.

The second is per run configuration. The agent is defined as a function that runs at the start of each run and chooses the model, instructions, skills, MCP servers and sandbox. LangChain's example is one Slack agent that loads billing skills for finance and an incident response MCP server for the platform team, based on the channel. Because the configuration is set before the model runs, the agent never sees tools outside it. LangChain says that keeps context small and doubles as access control.

The third is Slack reactions, so the agent acknowledges a message with an emoji right away while it works on the reply.

My take

The per run config is the part every automation builder should borrow, whether or not you use LangChain.

The common mistake I see is one big agent with every tool attached and a prompt that says only use the billing tool for finance requests. That asks the model to enforce access rules. It will usually comply, until it does not. Deciding the toolset in code, from who asked and where, removes that whole class of failure.

The scheduling feature is useful too, but treat it with care:

  • Make sure every agent created schedule has an owner, a visible list and an easy way to cancel.
  • Running as the requester is the right default. A schedule should never have more access than the person who set it up.
  • Log every scheduled run, so a forgotten daily task does not quietly burn tokens for months.

Small detail, big effect: the instant reaction. People trust an agent more when they can see it picked up the request.

More posts