Requirements: resolve 70%+ of tickets without a human; escalate the rest cleanly; bound hallucination via tools.
Architecture: triage agent → researcher (RAG over the knowledge base) → action agent (refund API, ticket update, email send) → human handoff. The orchestrator hands off via structured state; each agent has its own tools and prompt.
Evals: resolution rate, escalation rate, CSAT, hallucination rate.
Monitoring: per-agent tool-call counts; the deflection funnel.
Cost/latency: short agent chains for simple tickets; escalate when confidence is low.
Depth signals: "an agent that performs a side-effect must require explicit human confirmation above a threshold."
Follow-up probes: How do you prevent agents from taking irreversible actions without confirmation?