Augmented LLM
At the core of most agents is the Augmented LLM pattern: take a base LLM and equip it with three complementary capabilities:- Retrieval — fetch relevant external knowledge (embeddings, vector search, or document stores).
- Tools — execute actions (APIs, browser automation, shell commands, calculators).
- Memory — persist and recall context across sessions or tasks.

Pattern 2 — Tool selection
When an agent can call multiple tools, reliable tool selection is essential. The agent chooses tools based on the descriptions and interfaces you provide, so invest in precise tool manifests. Poor tool manifests are ambiguous and lead to wrong decisions:- Use concise, explicit descriptions that explain purpose and limits.
- Define parameter types and validation rules.
- Provide an explicit return schema to make parsing predictable.
- Include guidance about when to use the tool (and when not to).
Pattern 3 — Structured output
When agent outputs feed downstream systems (APIs, databases, analytics), enforce machine-readable structure. Structured output improves predictability, simplifies validation, and reduces error-prone parsing. Use strict schemas (JSON Schema or equivalent) and validate model responses before acting on them. Example JSON Schema:- Provide the schema to the model in the system prompt and instruct: “Always respond with valid JSON conforming to the provided schema.”
- Parse and validate the model output; re-prompt or use fallback logic if validation fails.
- When possible, use model-provider features that enforce response schemas or typed outputs.
Pattern 4 — Guardrails
Guardrails are automated checks and rule systems that constrain agent behavior. They protect against prompt injection, harmful content, data leaks, and other undesired actions. Implement guardrails both before and after the agent runs.- Input guardrails: sanitize and validate user requests (prompt-injection detection, authorization checks, scope enforcement).
- Output guardrails: validate and sanitize agent responses (format enforcement, hallucination detection, PII redaction).

Always validate both inputs and outputs. Guardrails are critical for any user-facing agent or agent that handles sensitive data.
Pattern 5 — Human-in-the-loop
Not every decision should be fully automated. For irreversible, costly, or legally-sensitive actions, require explicit human approval. Human-in-the-loop patterns insert checkpoints so people can review and confirm high-stakes operations. Example flow:- Agent: “I found a flight for $280 at 2:30 p.m. on Friday. Should I book it?”
- User: confirms
- Agent: proceeds only after confirmation

Require explicit confirmations for actions that are destructive, costly, or privacy-sensitive — and log those approvals for auditability.
Pattern 6 — Model fallback
Models and providers can experience outages, rate limits, or degraded performance. Implement model fallback so the agent stays available and responsive when a primary model fails. A simple fallback chain example:- Try Anthropic Claude —> if unavailable,
- Try OpenAI GPT-4 —> if unavailable,
- Try Google Gemini.

Combining patterns
These patterns are complementary and commonly used together in production agents:- Augmented LLM: always start here.
- Tool selection: necessary when the agent exposes multiple action primitives.
- Structured output: required when downstream systems consume agent output.
- Guardrails: must be present for user-facing or sensitive workflows.
- Human-in-the-loop: use for irreversible or high-risk actions.
- Model fallback: add when uptime, resilience, or cross-provider diversity matters.
Patterns quick reference
Links and references
- JSON Schema: https://json-schema.org/
- Anthropic Claude: https://www.anthropic.com/claude
- OpenAI GPT-4: https://openai.com/research/gpt-4
- Google Gemini: https://ai.google/discover/gemini
- OpenClaw course: https://learn.kodekloud.com/user/courses/ai-agents-for-beginner-openclaw-case-study