Running AI agents on Google Cloud: keep the tools outside the agent
An architecture for company agents that people use from Slack and Airflow, that query the warehouse, and that stay safe to change.
A common request I get now sounds like this: "We want an assistant in Slack that can answer questions about our data, and we want the same thing inside our Airflow jobs." It sounds like one feature. In practice it is a small platform, and the shape you choose early decides how painful the next year will be.
The requirements behind the request
- People talk to the agent in Slack, and each person has their own conversation memory.
- Airflow DAGs call the same agent as a step in a pipeline.
- The agent can query the data warehouse, search, and fetch web pages.
- Access rules decide who can see what.
The one decision that matters most
Run every tool as its own service, outside the agent.
The agent service only decides what to do. It calls tools over a simple API. Web fetch, search and the warehouse query each live in their own small service, for example on Cloud Run, with their own permissions, timeouts and scaling.
Why bother? Four reasons.
- Smaller blast radius. The warehouse tool has a read only account and a row limit. Even a confused agent cannot drop a table.
- Independent changes. You can fix the search tool without redeploying the agent.
- Testing. Each tool can be tested like any normal API, without a model in the loop.
- Cost control. A slow web fetch does not hold an expensive agent process open.
Where state lives
The agent service itself stays stateless. Conversation memory and access rules live in Postgres, keyed by user and thread. That makes the agent easy to scale and easy to restart, and it means Slack and Airflow can share the same service with different settings.
I like typed tool definitions for the same reason I like typed APIs. With a library like Pydantic AI the model gets a clear schema, and bad tool calls fail early with a readable error instead of somewhere deep in a pipeline.
Things that bite later
- Timeouts. Slack expects a quick response. Acknowledge fast, then post the answer when it is ready.
- Retries. Tools must be safe to call twice. Airflow will retry, and so will the agent.
- Logging. Log every tool call with its input, output and duration. When someone asks why the agent said something, this is your only real answer.
- Permissions. Check access in the tool, not in the prompt. A prompt is a suggestion. A permission check is a rule.