---
title: AI agents for staffing agencies — alluvo
description: Automate workflows in your staffing business with alluvo AI agents. Define tasks, control approvals and trace every run.
url: https://alluvo.ai/en/agents
---

alluvo agents

# Agents. With an employment contract.

What is in it, you decide.

AI agents for staffing agencies that take over real work in alluvo, with clear capabilities, clear limits and a log for every run.

An agent is not a chat window that gives advice. It reads records, creates drafts, answers requests, scores profiles, in the same system, with the same rights as the person it belongs to.

Three kinds · Seven triggers · One log

The three kinds

## Three kinds. One principle.

What sets the three apart is the trigger: the first are spoken to, the second run on a schedule, the third work invisibly alongside. What unites them: every action that has an effect outside is set to **Off**, **Propose** or **Execute**.

**ConversationalAssistants that talk.**

Four named assistants[1] talk to candidates and employees, in chat, over WhatsApp and on the phone. When it gets personal, they hand over to a named person; escalation is built in, not an add-on.

- Talent Hub Assistant Guides candidates through the Talent Hub, from the first question to the application.
- Profile assistant Fetches missing details into the profile without anyone chasing by phone.
- Employee support Answers employees' questions about assignments, hours and documents.
- Requalification assistant Reaches out to candidates whose data has gone stale and brings them up to date.

**AutomationThe ones you build yourself.**

In Agent Studio: set capabilities, write instructions, choose where it works. After that the agent runs on a schedule, in the inbox or as a step in a workflow, and finishes its task in one go instead of waiting for the next question.

No programming. What you write are sentences; what you tick are permissions.

**Task29 quiet specialists.**

29 task agents[2] work in the background without anyone starting them: classifying requests, reading résumés, scoring profiles, sorting texts. Each of them can do exactly one thing, and does it well.

They are not invented or removed, only configured. That is why you find a list here instead of a toolkit: what exists, what it does, and whether it is on.

Agent Studio

## Configure instead of program.

An agent comes together in four steps, and all four are on one page: what it may do, what it knows, where it works, what it has done. Model and base prompt are maintained; you control capabilities and instructions.

Example view · Agent Studio Automation agent

Call follow-up

**Kind**

Automation

**Model**

maintained by alluvo

**Run as**

Sales team lead

**Status**

Active

Tab 01 · Capabilities

### What it may do.

Schreiben

- Create task Creates follow-up tasks with context, on the right record, not in a list. Eingestellt: Ausführen
- Write email draft Words the reply and saves it as a draft. Eingestellt: Vorschlagen
- Propose appointment Finds free times and prepares the invitation. Eingestellt: Vorschlagen
- Prepare contract draft Fills the draft. Sending is not open to this capability. Eingestellt: Vorschlagen
- Write to clients Not intended for this agent; it works inward. Eingestellt: Aus

Lesen

- Read conversation notes Reads what was logged after a call. Eingestellt: Ausführen
- Read client and contact data Only the excerpt for the task, not the database. Eingestellt: Ausführen

**Off**: the capability does not exist for this agent. **Propose**: the run stops until a person decides. **Execute**: the agent does it itself and keeps a record. This is the [leash](https://alluvo.ai/en/security#die-leine) from the security page, broken down here to the single action.

Dozens of regulated actions are available[3], and most of them only know the state **Propose**. There is no switch that makes them autonomous.

Tab 02 · Instructions

### What it knows.

Base prompt maintained by alluvo

Who the agent is, which system it works in and how it handles data. Readable, but not changeable; too much depends on it.

Law & disclosure not removable

Underneath is the layer nobody can switch off: that the agent identifies itself as AI, that it hands over responsibility when things get personal, and what it must never write.

Brand voice Building block · in 4 other agents

Written once, attached everywhere. Change the block and every agent that carries it changes.

Form of address & tone Building block · in 6 other agents

How your house speaks to clients and how to employees. Two different things, two paragraphs.

Your instructions free

"Summarise every conversation in five sentences at most. Only derive a task if an appointment, a commitment or a deadline came up in the conversation."

Assembled · around 2,500 tokens Copy everything

No text behind closed doors: the assembled prompt is shown in full, layer by layer, and can be copied in one go. Whoever wants to know why an agent wrote something does not have to ask anyone.

Tab 03 · Deployments

### Where it works.

- Posteingang Aktiv
  
  Reacts to whatever comes in. Five harmless actions are preset; replies, appointments and contract steps only come in if you switch them on one by one.
  
  **Run as**
  
  Sales team lead
  
  **Daily limit**
  
  200 runs, 5 per ticket[4]
- Workflow Aktiv
  
  One step among others. The schedule lives in the workflow, not in the agent: trigger, conditions, then the agent, and after it whatever follows from its result.
  
  **Controlled in**
  
  Workflow · read-only here
- AI follow-up Not active
  
  Kicks in as soon as something is logged: a call, a note, an appointment, a task, an email. The agent reads along and turns it into whatever you have allowed.
  
  **Trigger**
  
  Call, note, appointment, task, email

An agent can work in several places and have different permissions in each. What is allowed in the inbox does not have to be allowed in the workflow.

Tab 04 · Runs

### What it has done.

1. 09:12 Inbox Done 11 s Task created · email draft saved · timeline updated
2. 09:07 Schedule Waiting for approval — Contract draft prepared, stops until a person decides
3. 08:54 AI follow-up Done 9 s Conversation summarised · no follow-up step derived
4. 08:31 Workflow Failed 4 s Aborted: the owner may not create contract drafts
5. 08:02 Manual Done 14 s Two conversations followed up · one appointment proposed

30 days · 128 runs 3 approvals open Ø 11 s

Every run leaves a line: trigger, status, duration, every single step, the model cost and the calculated benefit: working minutes saved against the cost of the run.

Failed runs keep their real error and are not cleaned away. An empty result counts as an error, not as a success.

An agent can only do what a person has given it, and only for as long as that person may do it themselves.

Examples

## Real agents. Not a demo.

The following six run in alluvo, not in a preview. Two of them are always on, you switch on the others, or build your own next to them.

- Task Always on
  
  ### Call-Nachbereitung
  
  Reads a logged conversation and derives what follows from it: a task, an email draft, an appointment, a staffing demand, a contract draft.
- Task Always on
  
  ### CV-Extraktion
  
  Pulls master data, work experience, education, languages and credentials out of an uploaded résumé, structured, not as running text.
- Automation Vorschlagen
  
  ### Ticket-Antwort
  
  Words a reply to a support request in your house's tone. The capability is set to Propose: the run stops until someone approves.
- Automation Ausführen
  
  ### Outreach-Autor
  
  Writes the first outreach along brand voice and form of address, and reads the reply too: interest, decline, follow-up question, later again. The lead status follows.
- Task Always on
  
  ### Match-Scoring
  
  Scores how well an employee fits an open request and sorts by suitability, availability and shift preference. The AI core of scheduling.
- Conversational Produktiv
  
  ### Telefon-Assistent
  
  Takes calls and holds the conversation, the same mechanics as in chat, only spoken, with the same capabilities and the same limits.

**Two kinds of agents.** **System agents** are in your account from day one, such as the profile assistant that guides candidates through their own data, or the assistant in the Talent Hub. These agents belong to the product: you can switch them off, not delete them. **Custom agents** your team builds alongside.

**Both can be customised.** An agent's instructions are not a text field but around twenty blocks with different owners: legal and safety rules live in the code and nobody can edit them, the rules of your house (tone, language, qualification) belong to the account, a campaign brings its own conversation flow, and individual blocks belong to a single person. On the agent's page every block shows who owns it and whether you may change it.

**What does not exist is a template catalog.** No shelf of ready-made agents to pick from that someone else invented for a different house. What works in your account either belongs to the product or was built by your team, and in both cases your team can explain it.

Limits

## Limits that hold.

The detailed version is on the [security page](https://alluvo.ai/en/security). Here are the five statements that apply to agents; each one describes how alluvo is built, not what alluvo has set out to do.

**No agent sends a contract.**

An agent can prepare a contract. It cannot send it and cannot take it out of draft. The assignment notice that the law requires (§ 11 AÜG in Germany) only goes out through a person. For the AI the draft is the end of the line, not the last step before sending.

**Propose is a hard gate.**

If a capability is set to Propose, the run stops. Not "later again", not "it was fine before": status **Waiting for approval** until someone decides. Accepted, adjusted, skipped, withdrawn: each of these decisions is logged with its author.

**Permissions are checked at runtime.**

Every tool call runs against the real permissions of the person the agent belongs to, not against a copy taken once at creation. If a permission is missing, the run aborts and says which. It does not look for another way.

**The AI disclosure stays on.**

That an agent identifies itself as AI sits in the lowest layer of its instructions, the one nobody can remove, you included. And every record an agent touches carries the note that it was an agent. A machine cannot pass itself off as a human in your history.

**Daily limits, logged loudly.**

200 runs a day per deployment, five per ticket.[4] When a limit is reached, it appears in the log, as an entry you can find, not as a silent abort that someone wonders about later.

FAQ

## What you want to know beforehand.

If a question is missing, write to us: [info@alluvo.ai](mailto:info@alluvo.ai). We answer with what the product does, or with the sentence that we do not know yet.

**What is the difference between an agent, a workflow and a playbook?**

The workflow knows *when* something happens: triggers, conditions, steps, a fixed mechanism with no mind of its own. The agent decides *what* to do: instructions, skills, model. The playbook guides *you* through a task: a guided checklist for people, not automation.

The three interlock: a workflow can call an agent as a step, an agent can create a task that someone works through with a playbook.

**Do I need programming skills?**

No. You tick skills, write instructions in full sentences and pick locations from a list. The model and the base prompt are maintained, so there is nothing you have to decide about them.

What takes practice is not the technology but the instruction: describing precisely what an agent should and should not do. It is the same work as with a new colleague.

**Can an agent send contracts?**

No. An agent can prepare a contract. It does not get past the draft and does not send the assignment notice under section 11 of the German Temporary Employment Act (AÜG). From there it is manual work, and that stays that way.

**What happens when an agent makes a mistake?**

Then the run fails, visibly, with the real error in the row. alluvo does not pretend something was done: an empty or unusable result counts as an error, not as a success.

Failed runs are not cleaned up. And because every run records every step, you can read where it tipped over, not just that it did.

**Can I see beforehand what the agent will say?**

Yes. The assembled text is shown in full in Agent Studio (base prompt, fixed layers, building blocks, your instructions) and can be copied. If you change the instructions of a running assistant, alluvo shows a comparison first: what drops out, what is added.

**Can an agent answer the phone?**

Yes, and that is not an announcement: the phone assistant takes calls and holds the conversation. Underneath is the same mechanism as in the chat: the same skills, the same limits, the same log.

**What do agents cost?**

An agent is part of alluvo, not an add-on product. Its runs use credits from the shared pool of your account, like all AI work in alluvo. How the pool grows and what a top-up costs is on the [pricing page](https://alluvo.ai/en/pricing).

What each individual run cost is in the log, together with the working time it saved.

## Set up your first one.

You don't need a project for this. One agent, one capability set to Propose, one deployment, and after the first run you know whether it is any good. It takes no longer than a lunch break.

[Start for free](https://app.alluvo.ai/register?lang=en&market=en&utm_source=website&utm_medium=market&utm_campaign=en) Get to know alluvo

## Footnotes

1. Four named conversational agents: Talent Hub Assistant, profile assistant, employee support and requalification assistant. Counted in the source code of the alluvo application, as of August 2026. ↩
2. 29 task agents, counted in the source code of the alluvo application (registration of the task agents), as of August 2026. Task agents can be configured and switched off, but not created or deleted. ↩
3. The number of regulated actions grows with the product, which is why no fixed number is given here. As of August 2026, most of the actions registered in the source code only know the state "Propose". ↩
4. Default per deployment: 200 runs per day, plus at most 5 runs per ticket and day. Stored in the source code of the alluvo application, as of August 2026. ↩
