HOW AI WORKS - FRAME BOOK
VOL. 01·SEP 2026

THINK. ACT. OBSERVE.

A MODEL CAN'T CLICK, FETCH OR BOOK. IT WRITES A STRUCTURED REQUEST; YOUR APP RUNS IT AND FEEDS THE RESULT BACK. REPEAT UNTIL DONE.

Task: Book 2 seats for tonight's black hole show.

Answer: Booked: 2 seats, 19:30, Into the Black Hole (BK-7731).

THINKACTOBSERVEMODELsearch_eventsbook_ticketsget_weathersearch_docssend_emailASK USERAPPROVEDSTEP 0 / 10STEP 1 / 10STEP 2 / 10STEP 3 / 10

AN AGENT IS A LOOP.

EACH LAP ADDS A TOOL RESULT TO THE CONTEXT. TOOLS PLUG IN THROUGH A STANDARD (MCP); PERMISSIONS AND STEP LIMITS KEEP THE LOOP IN BOUNDS.

01TOOL DEFINITION

FUNCTION CALLING
{
  "name": "search_events",
  "description": "Find shows by topic and day",
  "parameters": {
    "type": "object",
    "properties": {
      "query": { "type": "string" },
      "day":   { "type": "string" }
    },
    "required": ["query"]
  }
}
tools=[ search_events, book_tickets, … ]\text{tools} = [\,\texttt{search\_events},\ \texttt{book\_tickets},\ \dots\,]

THE APP DESCRIBES EACH TOOL TO THE MODEL.

02TOOL CALL

FUNCTION CALLING

MODEL OUTPUT

{
  "name": "search_events",
  "arguments": {
    "query": "black hole",
    "day": "today"
  }
}
call∼pθ( ⋅∣context, tools)\text{call} \sim p_\theta(\,\cdot \mid \text{context},\ \text{tools})

THE MODEL WRITES A CALL. IT RUNS NOTHING.

03EXECUTE

FUNCTION CALLING
APP(your code)EVENTS APIvalidate200 OKThe app validates the call, sends it to the events API, and receives the result: 200 OK.
const fn = tools[call.name];
const result = await fn(call.arguments);

YOUR CODE RUNS THE TOOL, NOT THE MODEL.

04RESULT to CONTEXT

FUNCTION CALLING
{
  "events": [{
    "id": "EVT-2041",
    "title": "Into the Black Hole",
    "time": "19:30",
    "seats_left": 12
  }]
}
USERCALLRESULT
context←context⊕call⊕result\text{context} \leftarrow \text{context} \oplus \text{call} \oplus \text{result}

THE RESULT IS APPENDED TO THE CONTEXT.

05AGENT LOOP · REACT

AGENT
  1. THOUGHTFind tonight's black hole show first.
  2. ACTIONsearch_events(query="black hole", day="today")
  3. OBSERVEEVT-2041 · Into the Black Hole · 19:30 · 12 left
  4. THOUGHTSeats available. Booking needs the user's OK.
  5. ACTIONASK USERAPPROVEDbook_tickets(event_id="EVT-2041", seats=2)ASK USERAPPROVED
  6. OBSERVEconfirmed · booking BK-7731
  7. THOUGHTDone. Summarise for the user.
  8. ANSWERBooked 2 seats, 19:30 · BK-7731.
LAP 1LAP 2
ht+1=ht⊕(rt, at, ot)h_{t+1} = h_t \oplus (r_t,\ a_t,\ o_t)
r = reasoning · a = action · o = observation

REASON, ACT, OBSERVE — REPEAT UNTIL DONE.

06MCP · TOOL REGISTRY

AGENT
HOST APP(chat app, IDE…)clientclientclientplanetariumsearch_events ·book_ticketscalendarfilestools/calltools/list
tools/list returns [search_events, book_tickets, …]
tools/call returns { name, arguments }

ONE STANDARD PLUG FOR ANY TOOL.

07GUARDRAILS

AGENT
CALLTOOLsearch_eventsbook_ticketsAllow booking?AllowDenyallow: search_eventsask first: book_ticketsSTEP 0 / 10 · MAX 10STEP 1 / 10 · MAX 10STEP 2 / 10 · MAX 10STEP 3 / 10 · MAX 10
stop if  done ∨ t=Tmax⁡\text{stop if } \ \text{done} \ \lor\ t = T_{\max}

PERMISSIONS AND LIMITS KEEP THE LOOP SAFE.

Tool Use & Agents

Think, Act, Observe

THE MODEL DECIDES WHAT TO DO; SOFTWARE AROUND IT DOES IT. AN AGENT IS THAT EXCHANGE ON REPEAT — WITH A PERSON'S OK FOR ANYTHING THAT CANNOT BE UNDONE.

MODEL(decides)APP / HOST(executes, checks)TOOLS(act on the world)ANSWER

Three stacked plates: the model on top, the app or host in the middle, the tools at the bottom. A loop runs down the left side — the call, checked at a gate by the app — and back up the right side with the result; after two laps it leaves upward as the answer.

TOOL CALL

{ name, arguments }\{\ \texttt{name},\ \texttt{arguments}\ \}

CONTEXT

ht+1=ht⊕(rt, at, ot)h_{t+1} = h_t \oplus (r_t,\ a_t,\ o_t)

STOP

done ∨ t=Tmax⁡\text{done} \ \lor\ t = T_{\max}

T_max = 10

MCP

tools/list · tools/call

MODEL CONTEXT PROTOCOLOPEN STANDARD · ANTHROPIC, 2024

GUARDRAILS

  • Least privilege — only the tools a task needs.
  • Ask before side effects (pay, send, delete).
  • Cap steps, time and cost.
  • Tool output is data, not instructions.