Build your own agent

Create a Praxis agent for one job by describing what it should do, then keep it to yourself or share it across your organization.

A custom agent is a Praxis agent you shape for a specific job. It starts from the same base agent that powers Praxis, and you add your own instructions, a model, the built-in tools it may use, and the data it may reach. Once it exists, you chat with it, delegate to it, @-mention it in Slack, or put it on a schedule, the same ways you use the agents that ship with Praxis.

What a custom agent is

A custom agent packages a few things into one persona: a system prompt that sets its instructions and boundaries, a model that decides how it reasons, the tools it is allowed to use, and the data it can reach. It is not a skill or an app. A skill is a procedure any agent loads on demand, and an app is a packaged product surface with its own screens. An agent is the persona that puts skills and tools to work. For how the three relate, see How Praxis works.

Teams build custom agents to capture one job: an agent that knows a single repository and answers questions about that code, one that queries a specific database on request, or one that audits an environment on a schedule and reports back. Each carries only the instructions, tools, and data its job needs, so it behaves predictably.

You create and manage custom agents from Settings, under Agents. Your agents and the built-in ones share this page; a filter separates them, and the built-in ones are tagged as System.


Create one by describing it

You create a custom agent by describing what you want, not by filling in a long form. Start the Hire New Agent flow and tell Praxis, in a sentence or two, what the agent should do. You can also say whether it needs access to your code and whether it should work from a Slack channel. You do not write a system prompt or choose tools yourself; when you finish, Praxis assembles the agent from your brief.

You can do the whole thing in conversation instead, on the web console or the Praxis CLI: describe the agent you want, let Praxis set it up, then refine it the same way. Later you can ask Praxis to widen its tools, change its model, or attach a repository, without opening the settings form.

Tip: You can also create and manage agents programmatically. See the API Reference for details.


Configure and refine it

Once an agent exists, you can open it and tune every part, in the settings form or by asking Praxis.

Its instructions are a free-text system prompt, up to 100,000 characters, holding the agent's job, tone, and rules. They layer on top of the base agent, so you describe the job rather than re-explaining how to drive tools or follow the safety rules. For the model, you pick a tier: Intelligent for reasoning that spans several steps, or Fast for quick, high-volume, lower-cost work. The exact model behind each tier is set per deployment, so it can change without you touching the agent.

You then choose what the agent can reach. Turn on the built-in tools its job needs: querying cloud accounts across AWS, GCP, and Azure, read-only Kubernetes access, New Relic, and the Facets Control Plane. Loading skills, remembering across sessions, and working with an attached repository stay on for every agent. To go beyond the built-ins, attach any connected MCP servers, the standard way an agent drives an outside system as a tool; custom Python functions are managed separately. See Connect a Tool.

For data, attach one or more shared databases and the agent can query them during a chat; a database can be shared across several agents. Attach a connected repository and you choose its branch, how Praxis signs in (a personal access token or a GitHub App installation), and whether the agent uses it for code work, for long-term memory, or both. Connecting the repositories themselves is covered in Repositories.

Finally, you can give the agent trigger keywords: hints for when a request is its kind of work. When one appears in your message, Praxis suggests handing the request to that agent instead of answering itself. Matching is a case-insensitive substring on every message, so keep the list tight, or the agent you are chatting with gets nudged constantly. The suggestion only fires when the agent you are talking to is allowed to delegate to others.

Turn on only the tools and data an agent's job needs. A narrower agent is easier to trust and easier to reason about when you review what it did.


Share and manage it

Every custom agent is either personal to you or shared with your whole organization. You set this when you create it; new agents are shared with the organization unless you make them personal. Who can change an agent follows from that: the creator can always edit or delete their own, and an organization admin can manage any organization-shared agent. Built-in agents are read-only and cannot be edited or deleted.

Deleting an agent is permanent. It removes the agent along with its run history and chats, and it disconnects any Slack channels the agent was linked to, so Praxis has you type the agent's name to confirm.

Deleting an agent cannot be undone, and it also removes the agent's history and chats and disconnects any Slack channels linked to it. Check what depends on the agent before you delete it.


Put it on duty

You can hand a custom agent standing work: put it on duty and it runs on its own and reports back what it finds. A duty can run on a schedule, watch a Slack channel, or fire from a webhook. Whichever kind you choose, a duty only ever looks; it never changes your infrastructure. See Duties for how to set one up and how it runs.


Export and import an agent

You can move an agent between organizations or keep it as a file. Exporting an agent produces a JSON package, optionally including the MCP servers and repository settings it uses; only placeholder references to your credentials go in the file, never the secrets themselves. Importing that file elsewhere previews what it will create, lets you rename or overwrite when the name already exists, and lets you link the agent to a repository on the new side. You reconnect any credentials it needs after importing.


Access and safety

A custom agent runs under the same model as the rest of Praxis. It executes server-side under your organization's stored credentials, every tool call is audited, and infrastructure access is read-only by default: anything that would change a system drops into a plan-and-approve step first. Turning on a built-in tool widens what an agent can reach, not what it can do without approval, and it never bypasses the Facets Control Plane's own access controls. For the full model, see How Praxis works.


  • How Praxis works - The shared architecture, permissions, and safety model
  • Connect a Tool - Attach MCP servers and custom Python tools to an agent
  • Repositories - Connect the code an agent reads and remembers
  • Duties - Put an agent on recurring, unattended work
  • Skills - Reusable procedures your agents load on demand