Same Chat Screen, Different Machine: How to Tell an Agent From an Assistant

It’s important to know the difference between agentic AI and a well-dressed chatbot. Missing the distinction could cost you if you get it wrong.

Avatar photo
By Heather Yurko, VP Agentic HR Innovation
Trulli
Contents
  1. 01 Why you can’t tell by looking at the text box
  2. 02 So, what are the tells?
  3. 03 What this means if you’re the one signing off

On August 24, Okta made something generally available that quietly changed the ground rules: single sign-on for AI agents. Agents now get registered in the corporate directory next to human employees and issued short-lived, governed credentials instead of static API keys. Okta’s own reasoning was blunt: “most agents today operate as anonymous traffic with no owner, no policy, and no audit trail”. Only about a third of organizations apply the same security controls to their AI agents that they apply to their people.

But here’s the critical shift: nobody issues a corporate identity to software that only talks back.

That single fact says more about the agent-vs-assistant question than any product demo will. And it points to the real problem many of us are running into right now: the interface has stopped being a reliable signal. A chat window is a chat window. Whether you’re talking to a scripted FAQ bot, a general-purpose copilot, or a system that’s about to change a record in your HR platform without asking twice, it looks the same — a text box, a blinking cursor, a friendly reply. Forrester’s 2026 read on the market has a name for the confusion this creates: “agentish” chatbots, tools dressed in agent language that never actually leave the prompt-response loop. Gartner calls the marketing version of the same problem “agentwashing.” Today, three out of four enterprise leaders say they’re adopting agentic AI; however, far fewer can point to a system that actually is one.

If you sit anywhere near a buying decision, this isn’t a semantic quibble. It’s the difference between paying for a slightly smarter search box and paying for something that can take real, unsupervised action inside your business (freeing your people up to do people work), but also bringing everything that implies for risk, governance, and what your team needs in place before go-live.

Why you can’t tell by looking at the text box

Assistants and agents share the same front door on purpose. It’s the best interface anyone’s found for natural-language interaction (and it reduces the number of places employees need to go to get work done), so both categories use it. But the box only shows you the last conversation. It doesn’t show you what’s happening underneath – whether the system is retrieving an answer or executing a plan, whether it’s stateless (forgetting what you already talked about) or carrying context from three weeks ago, or whether the response “I’ve updated it” means a record actually changed or means the model is simply claiming it did.

I’ve seen this with enterprise teams piloting HR agents: employees start typing into a chat box expecting it to route them to the right specialist (the way a receptionist would), and then get confused when it doesn’t. The confusion isn’t a UX bug so much as proof that the interface genuinely doesn’t disclose what’s behind it. You can’t design your way around this with a friendlier avatar or new design. The tell has to come from somewhere other than the interface.

So, what are the tells?

None of these are visible in the transcript, but all of them *are* visible if you know to look for them.

Initiative. An assistant waits. You open the box, you ask, it answers. An agent notices something and starts the conversation itself — a succession pipeline that’s quietly degrading, a skills gap opening up in a business unit, a review that’s overdue — and reaches out without being prompted. It’s common now for buyers to ask for exactly this: not a one-time report generator, but an always-on system that monitors a condition and speaks up when it changes. That’s different software than a Q&A chat, even when the message it sends reads identically to something a person typed.

Memory that survives the session. Ask an assistant something it answered last week and, unless the product bolted on a workaround, it starts from zero. A genuine agent has memory that persists: it knows what it already tried, what it learned, what it’s still waiting on, and can do this across sessions and long periods of time. That’s also what makes agents worth governing: that persistent state is exactly what accumulates risk over time.

Whether a record actually changed. This is the cleanest test there is, and the one fewest buyers ask for in a demo. Don’t ask a vendor to show you a conversation. Ask them to show you the system of record before and after — did a field update, a workflow trigger, an approval route to the right person — or did you just receive a well-written paragraph describing what could happen. A chatbot can describe an action all day. An agent actually performs one.

Whether it can refuse, with a reason. Compliance requests, edge cases, ambiguous instructions — an assistant will generally attempt an answer regardless. A system built for governed autonomy can decline, and can tell you why: which policy it hit, what evidence was missing, what threshold wasn’t met. That refusal capability is a feature, not a limitation, and its absence is one of the more honest signals that you’re looking at a conversational layer rather than an operational one.

Who owns its credentials. This is the newest tell, and it’s what the recent announcement put a spotlight on. Does the system operate under its own governed identity, with scoped, short-lived access and a real audit trail — or is it quietly using a shared service account, a stored password, someone’s borrowed API key? If nobody can tell you what the agent is allowed to touch and what it’s already touched, you’re not looking at something ready to act on your behalf unsupervised, whatever the marketing page calls it.

What this means if you’re the one signing off

The interface won’t do this evaluation for you, so the burden shifts to the buying process. A few things worth insisting on before you sign that contract:

Ask to see the changes, not the conversation. In every demo, make the vendor show you a before-and-after in an actual system of record. If they can only show you chat transcripts, you’re evaluating a UI, not a capability.

Ask where this sits on the autonomy spectrum, and how that can shift. Most credible agentic deployments start narrow: suggest, don’t act, on day one. The real question is what evidence is required before an action graduates from “recommend” to “execute automatically,” and who owns that decision. If a vendor can’t describe that path in specifics, they haven’t built it yet.

Ask about the kill switch and the audit log before you ask about the roadmap. Regulators are already writing this requirement into law in some markets; your own AI governance board or Security function will ask for it, regardless. Can someone stop this agent mid-task within minutes? Is every action it takes logged in a way your compliance team can actually read? These used to be nice-to-haves. They aren’t anymore.

Bring IT, AI Governance and Security in earlier than feels natural. This is the pattern showing up across enterprise deals right now: the conversation starts in HR or OPS, but the timeline gets set by infrastructure readiness, data maturity, and AI Governance/Security sign-off — not by whether the tool works. Treat that as the real critical path from day one, not a late-stage approval step.

Be suspicious of the word “agent” on its own. It’s on almost everything right now, including plenty of software that never leaves a single-turn prompt-response loop. Ask what the system was doing a minute before you opened the chat window, and what it will do a minute after you close it. An assistant has no answer to that question. An agent does.

Just looking at the chat box was never going to tell you what’s happening behind the scenes;  that was true before this wave of AI and it’s still true now. What’s changed is that the answer is knowable: in the identity the system carries, in the persistent state it holds, in the records it’s allowed to touch, and its capacity to say no. Using this guidance as a litmus test to inform your decisions will give you needed confidence, protecting your organization – and your investment. 

Related