n8n Agents are here: why your existing workflows just became your safest agent tools
n8n shipped a native Agents feature, and the design choice that matters most for operators is how it treats your existing workflows.
What happened
On September 25, n8n announced Agents. You describe what the agent should do, choose a model, and give it the tools and workflows it can use. The same agent can be reached in Slack, run on a schedule, or called from any workflow through a new Message an Agent node. The existing AI Agent node is unchanged.
Every agent comes with memory, sessions, channels (Slack, Telegram, Linear, Discord), versions and approvals built in. Tools can be MCP servers, configured n8n integrations, or whole workflows you have already built. You can mark a tool as sensitive so the agent pauses for Approve or Reject, and each tool runs with its own attached credential, so the agent never holds the keys to your instance. Agents have a draft and a published version, and every session logs the tool calls, inputs and outputs.
On pricing, n8n says one turn with an agent counts as one execution, and tool calls to workflows and sub agents do not count separately. The feature is in Preview on n8n Cloud and runs on self-hosted with extra setup; n8n's docs say self-hosted Enterprise support is coming soon.
My take
The line from n8n's post I would underline: a workflow that "adds a note and does nothing else." That is the right way to give an agent access to a CRM. Instead of handing the model write access and hoping the prompt keeps it in the notes field, you hand it a narrow, tested workflow.
For client builds, this changes the architecture conversation:
- Keep the boring, fixed parts (enrich, score, route, write to CRM) as workflows.
- Let the agent handle the messy, back and forth part, like triaging a support email or answering "why did this account's usage drop?"
- Put approvals on anything that writes to a system of record or pages a human.
The versioning also matters. Editing a draft while the team keeps using the published agent is what makes this safe to run for a real business, not just a demo. Since it is still Preview, I would start with an internal Slack agent tied to one or two systems before putting it in front of customers.
More posts
- Meta gives every Muse user a cloud computer with credentials kept outside the agent. A blueprint worth copyingSep 27, 2026
- Google is testing a Buy button for Flipkart inside Gemini and AI Mode. Checkout is moving into the AI answerSep 27, 2026
- Having AI advice available nearly wiped out people's willingness to say I don't know, even when the AI was wrongSep 27, 2026
