Can an AI-native marketer build custom agents for a small business?
Yes. An AI-native marketer can build a custom agent for one repeated job inside tools the company already runs, with its rules and a person on anything a customer sees or cannot undo. A chatbot, one prompt, and a fixed automation are different buys. A public product or a private API needs an engineer. A payment stays with a person.
One marketer can ship one agent
An AI-native marketer can build a custom agent for one repeated task, in tools the company already runs, if a person approves anything a customer can see or that cannot be undone.
OpenAI’s guide says an agent does the task on your behalf: the model runs the workflow, knows when it is done, can correct itself or hand control back, and picks tools inside guardrails. See what an AI-native marketer does.
An agent acts. A chatbot only replies.
A chatbot, a single-turn call, and a sentiment classifier are not agents. OpenAI’s guide says so, because the model is not running the workflow. Anthropic’s December 2024 note separates a workflow (a path you drew) from an agent (the model chooses the steps), and flags its tooling description as older than the current stack. A comparison of the three treats chat, a fixed path, and an agent as layers in one system.
| Layer | Who picks the next step | Main miss |
|---|---|---|
| Chatbot | A person is talking. The model only replies. | A wrong answer |
| Workflow | You drew the branches, including the failure. | A bad rule |
| Agent | The model picks the next step from a short tool list. | A wrong step that writes |
Keep the known steps as a workflow, and the agent only on the step you cannot draw. That comparison keeps the extra layer only when the same tests, including a conflicting input, beat the simpler path. Leaving manual chat is the first move.
Anthropic prefers the simplest setup that works, often one call plus retrieval and a few examples in the prompt, because agent-style systems are slower, heavier to run, and can compound errors, so test them in a sandbox. OpenAI’s three fits are a complex decision (judgment, an exception, or a context-sensitive call), rules that have become too brittle to maintain, and unstructured data such as language, a document, or a conversation. If the job is none of those, a deterministic path may be enough.
Custom is your loop, not a trained model
Custom means this company’s trigger, sources, allowlist, and stop rules. It does not mean a model you trained.
| Build | Lives in | You change | First owner |
|---|---|---|---|
| CRM or email setting | That product | Fields, rubric, approval | The marketer in the tool |
| Workspace or automation agent | The company’s login | Instructions, apps, a test before publish | The marketer, in that login |
| Workflow with one model step | A tool you can open | Classify, draft, or extract in one box | The marketer who draws the path |
| Agent in code | A server you control | Tools, state, approvals | An engineer, on a job the marketer wrote |
Workspace agents are a research preview on ChatGPT Business, Enterprise, Edu, and Teachers. They can run on a schedule, use apps, and require approval before a send or a record change. Admins set who builds and which tools are allowed. That is an internal build for those plans, not a site widget.
Zapier’s help center is the no-code path: trigger, tasks, apps, test, then publish. It belongs to the owning account, cannot be embedded, and is moving to AI by Zapier. A site widget is Zapier Chatbots. That page does not call the product Zapier Central. The Agents SDK starts when your server owns deployment, tools, state, and the approval. OpenAI’s solutions page puts team workflows on workspace agents, and puts a customer-facing agent and a specialized internal agent on the API.
A fixed path comes before an agent
Same fields and the same route are a workflow plus an alert on failure. Text that changes, with a fixed action, is one model step in that workflow. An agent is only for the next step you cannot list. Whether to automate at all comes first.
A missing connector is not yet a server project. OpenAI’s guide names computer use through the product’s own screens, and the solutions page names apps and MCP on the hosted side. Do not start there: a click can send, pay, or delete, and you cannot review the click the way you review a draft. Add an engineer when the agent must run inside your product or call a private API.
OpenAI says to maximize one agent before you add another. Split when instructions are a thicket of conditions, or when tools overlap. Some implementations manage more than 15 distinct tools. Others struggle with fewer than 10 that overlap. Clearer tool descriptions come before a second agent.
The marketer stops where the server starts
The marketer owns the outcome, the instructions, the sources, the approval rule, and the weekly read of the log. An engineer owns the runtime once the work leaves a hosted product.
An AI-native marketer or an automation consultant is that split. Keep a person on the action when the key can pay, refund, or delete, when several agents would hand work around on day one, or when a customer on the site is the surface. The guide tells you to add a relevance check, a safety check, and an output scan for personal data, on top of access control you already have. None of those checks chooses which fields enter the prompt.
Pick the job by the harm of a miss
Start where a miss is a draft in a queue. OpenAI’s lead example scores against your rubric and still sends outreach, with approvals. The content example stops at drafts for team review. The feedback example creates tickets and does not mention an approval. Keep the send, the publish, and the ticket write for a person anyway.
| Job | May | A person still | Not first |
|---|---|---|---|
| Lead score | Read named sources, score on your rubric, file a note | The send, and any stage sales will act on | A rubric the prompt invents |
| Content | Draft from one brief or transcript | Publish | A calendar that posts itself |
| Readout | Pull defined numbers and recommend a step | A change to a live campaign or to spend | An order to optimize |
| Questions and feedback | Draft from a page you marked current | The reply, any money, and a ticket the team will act on | The only support desk |
| Ops check | Alert on a missing field or follow-up | Nothing, if the alert is the action | Auto-editing records |
A draft a person can throw away is not a decision with legal or serious consequences. The Dutch data protection authority, explaining the GDPR, says a company may not simply make an automated decision with legal or other serious consequences. Fully automated means no one assesses the data or checks the conclusion. If a score moves someone into a stage the company will act on, the reviewer has to look at the named sources and be able to reject it. A queue that is always accepted is the computer’s decision. Name the fields and the purpose first. A prospect’s name or email in the prompt is personal data even in a draft.
OpenAI names two handbacks: retries are used up, or the action is sensitive, irreversible, or high stakes, such as canceling an order, a large refund, or a payment. Count unapproved actions, duplicate writes, handbacks, and drafts shipped unchanged. Time saved, conversion, and a satisfaction score do not show whether an unapproved action went out. Start from repetitive work you can still throw away.
Specify the loop, then attach one tool
Write a spec a colleague can run, then connect the smallest set of tools.
- One trigger and one done state. A new form row and an unsent scored note is a job.
- Name the source of truth before any score.
- Mark each tool read or action. OpenAI rates a tool by whether it writes, whether you can undo it, whose permission it uses, and whether money moves. Pause the high-risk ones.
- Turn a trusted document into instructions, including a missing field, a duplicate, a down tool, and an off-topic request.
- Set an exit: a structured result, a step cap, or a handback. OpenAI caps retries. Anthropic caps the number of steps.
- Replay past cases, and publish only when failures show in the log.
The agent lives in the account that owns it. Zapier says a shared template only makes a copy. A second person at the company must be able to open the instructions, the keys, and the log.
Demand the failed run, not the tour
Ask for a run that broke. A marketer who builds meets the same bar: something you can click, in an account the company owns.
- Trigger, tools, stop, and one tool error.
- Which action waits, and where is the queue?
- Who else can open the instructions, the keys, and the log?
- Which job did you refuse, and why?
- Why one agent, not a team?
Leave the agent off in these cases
Leave it unbuilt when done is undefined, a notification would do the job, nobody will read the queue, the offer is still moving, or the file is duplicates with no owner.
What I put in your accounts first
I leave one agent in your accounts. It reads sources you named, drafts against a rubric you already use, stops after a set number of steps, writes a log, and waits before anything leaves the building.
I am one person, Poldermarketing, and I work fully remote in Dutch and English. A freshly funded startup anywhere can hire me freelance, or for a few days a week, as one marketer for the marketing, the AI, and the automation, from the first message to the first customers, without a separate specialist for each piece. I build and run the work. I do not only advise.
Google Ads and Meta Ads are newer for me. I can set them up and review them. I will not hand either account to an agent, and I am the wrong hire when scaling that spend is the job.
If the site still does not say who the offer is for, I clear that before connecting anything. The free growth scan shows how the current site reads. How I work is the shape of an engagement, and positioning and messaging is where I start when the sentence is the constraint.
Questions people ask
Can a marketer build an agent without writing code?
For one internal job, often yes. You write the trigger, the instructions, and the apps, then test before publish. Put an approval on anything a customer can see or that cannot be undone. Zapier's help center describes the build, and says those agents cannot be embedded as a website chat. Once the agent must run on your server or call a private API, the marketer writes the job and an engineer owns the runtime.
How is a custom agent different from a website chatbot?
A chatbot answers whoever opened the window. OpenAI's guide says a model that does not control the workflow is not an agent. A custom agent is one company job: named sources, a short tool list, and a stop you wrote. A site widget that books a calendar is a public product, and it should not be the first build. Zapier's agent docs say that product cannot be embedded. A website chatbot is separate.
What should the first agent be allowed to do?
Let it read, draft, and file a note a person can throw away. Do not let it email a prospect, change a live campaign, issue a refund, or move money. OpenAI's guide holds sensitive, irreversible, and high-stakes actions for a person until confidence in the agent's reliability grows. Trust the log only after those runs show the agent stopping itself.
When does this build need a developer too?
Add an engineer when the agent must run inside your product or call a private API. A missing connector is not that test. The guide's other option is computer use through the product's screens, which you should not start with, because a click can send, pay, or delete. OpenAI's SDK is the path where your server owns deployment, tools, stored state, and the approval. Until then, a marketer can ship one agent with a short allowlist.