# Building and Deploying a Real AI Agent
Join us for the Building and Marketing AI Applications Meetup, where we’ll go beyond prompts and prototypes and look at what it takes to build an AI agent that can actually do useful work—and do it within clearly defined boundaries.
For this session, we’ll demonstrate a working Gmail AI Agent designed to help handle customer email while keeping a human in control.
## The workflow
The basic workflow is intentionally simple:
Email arrives → Agent understands the request and sentiment → Agent determines whether it has the right tools and information → AI drafts a response → Human reviews → Human decides whether to send
But there is another important path:
Email arrives → Agent cannot safely or confidently handle it → Need Attention(Gmail Label) → Human takes over
The goal isn't to make the AI respond to every email.
The goal is to make the agent useful when the request falls within its capabilities—and predictable when it doesn't.
## More than generating an email
When an email arrives, the agent first needs to understand what it is dealing with.
- What is the customer asking for?
- What is the sentiment of the conversation?
- Is the customer frustrated, confused, satisfied, or escalating an issue?
- Does the agent have the information, policies, and tools necessary to respond appropriately?
The response should reflect both the request and the tone of the conversation. A frustrated customer shouldn't receive the same response style as someone asking a routine question.
But sentiment doesn't give the agent more authority.
The agent must still operate within the tools, data, policies, and permissions it has been given.
## Knowing when not to respond
This is one of the most important parts of the demo.
- The agent should not improvise when something falls outside its capabilities.
- If it needs information it cannot access, encounters an unsupported request, cannot reconcile the request with available policies, detects ambiguity or an unusual situation, or otherwise cannot produce a response within its defined boundaries, the message is routed to:
"Need Attention" Label - That gives us a safe landing zone for everything the agent isn't prepared to handle.
Instead of trying to make the model smarter enough to answer everything, we design the system so that uncertainty and unsupported actions fail safely into human review.
## Human-in-the-loop by design
Even when the agent successfully prepares a response, it does not send the email.
It creates a Gmail draft. A human reviews the proposed response and decides whether to send, modify, or reject it.
So there are two levels of human involvement:
Normal path: Agent drafts → Human reviews → Human sends
Exception path: Agent determines it cannot safely handle the request → Need Attention → Human handles it
Human review isn't an afterthought or fallback added to the demo. It is part of the agent's authority model.
## What makes this an agent?
The interesting part isn't simply calling an LLM and asking it to write an email.
The agent harness is the software surrounding the model that determines how the agent operates:
- what tools it can use
- what data and policies it can access
- how incoming requests are classified
- how customer sentiment influences the response
- how structured outputs are validated
- what actions the agent is authorized to take
- what happens when information is missing or ambiguous
- how failures and unsupported requests land in Need Attention
- where human approval is required
- how each run can be inspected afterward
During the demo, we'll walk through the architecture behind the Gmail agent, including Pydantic AI, Gmail API integration, structured model outputs, tool and permission boundaries, sentiment-aware responses, human-in-the-loop approval, run history, failure handling, and isolated agent execution.
We'll also explore using Firecracker microVMs as an execution boundary, giving agent workloads their own lightweight virtualized environment rather than allowing agent-controlled execution to run directly on the host.
## The bigger question
Building an AI agent demo is relatively easy.
Building one you're comfortable connecting to your email, databases, infrastructure, customer systems, or other business applications is a different engineering problem.
A production agent needs to know not only:
“Can I answer this?”
but also:
“Do I have the tools, information, and authority to handle this correctly?”
And when the answer is no, the system needs a predictable and safe place to land.
That's what this meetup is about:
How do we move from “the model can do this” to “this is a system I can safely deploy”?
Builders, founders, engineers, product teams, and anyone experimenting with AI agents are welcome.
Come see the Gmail agent run, examine the architecture, challenge the boundaries, and help us figure out what production AI agents should look like.
We examine 5 email in this demo and see how the agent responses:
EMAIL 1:
1. Positive / appreciative
Subject: Thank you — the onboarding session was great
Hi,
Just wanted to say thanks for the walkthrough yesterday. The team found it really useful and we're already using the dashboard daily. Could we set up a follow-up session in the next couple of weeks to go over the reporting features? Tuesday or Wednesday afternoons work best for us.
Best,
Priya
Expected: drafted. A warm reply that asks which day works, without picking a slot or confirming a booking for you.
---
EMAIL 2:
2. Frustrated / angry
Subject: Still no response — order #4471
This is the third time I'm writing about order #4471. I was charged twice and nobody has gotten back to me. I need this refunded this week. Honestly, this is really disappointing.
Mark
Expected: drafted. An empathetic reply that keeps the order number #4471, with no invented refund date and no promise of a refund on your behalf.
---
EMAIL 3:
3. Confused / uncertain
Subject: Not sure which invoice this is for?
Hello,
We received an invoice last week but I can't tell which project it relates to. The reference on it doesn't match anything in our system. Could you help me figure out what it's for? Sorry if I'm missing something obvious.
Thanks,
Elena
Expected: drafted. Asks for the reference or offers to check, without inventing invoice details.
---
EMAIL 4:
4. Urgent / anxious
Subject: URGENT — can't log in before our board meeting
Hi, our team can't access the account since this morning. We have a board meeting at 3pm today and need the report from it. Is there anything we can do right now? Please call or reply ASAP.
Jordan
Expected: drafted. Acknowledges the urgency and asks for details, without inventing a fix, a cause or a timeframe.
---
EMAIL 5:
5. Neutral / no reply needed
Subject: FYI — payment sent
Hi,
Just letting you know we sent payment for invoice INV-2209 this morning. No action needed on your side.
Regards,
Tom
Expected: noted, not drafted (guidance_do_not_answer). This shows the agent deciding not to reply.