Custom AI agents that act, not just answer | Lior Zabari

AI agents for businesses that act, not just answer.

A chatbot answers a question. An agent receives a goal, checks your systems and performs an action. I build the second kind, with clear permission boundaries and a human approval point exactly where a mistake costs money.

A reply from me personally, usually within the hour during Israel working hours.

700,000 conversations answered by AI, without a human on the line 15 years in the field A human approval point in every agent

Last updated:

In short

I build you one AI agent that handles one process that's bleeding in your business today: answering a customer who writes at 11:40 pm, following up on a quote that went unanswered, sorting incoming inquiries. It doesn't only answer, it checks your systems and performs an action.

The difference from a chatbot is permission: an agent is allowed to write into a system, so it's built with an approved list of actions and a point where a human approves. I'm Lior Zabari, and behind me is a system that answered 700,000 conversations without a human on the line.

We start from one process An approved list of actions Human approval where it's needed
01What I build

The four agents I run most often

These aren't ideas from a slide deck. These are the processes where an agent pays for itself fastest, because they repeat every day and have a result that can be measured.

A first reply that keeps working at night

A customer writes on WhatsApp or on the website at an hour when nobody is available. The agent answers to the point, collects what's needed to price the job and leaves you a clean inquiry for the morning.

Following up on quotes

A quote that was sent and went unanswered is the easiest money to recover. The agent follows up, reminds at the right time and in the right channel, and flags who is really warm.

Sorting and routing inquiries

What's urgent, what's support, what's not relevant at all. Instead of one inbox everyone is afraid to open, every inquiry reaches the person who should handle it.

Repetitive work inside the systems

Updating a status, opening a ticket, producing a report, syncing between two systems that don't talk. The things that eat an hour a day and nobody counts.

02What it looks like

One run, from message to action

This is what a single inquiry that comes in at night looks like for a client who has an agent. The stage marked with an exclamation mark, "stops before sending a price", is the point where the agent waits for your approval.

Goal: handle a new inquiry that came in on WhatsApp11:41 pm
Reads the message and understands what they want

Identifies that this is a quote request and not support.

Checks the system for a known customer

Read-only. Finds that they already bought a year ago and refers to it in the reply.

Asks the two missing questions

Quantity and target date. No form, inside the same conversation.

Opens a ticket and writes a summary

Writes to the system, within the permission defined for it. The ticket is waiting for you, filled in.

Stops before sending a price

The quote is ready and waiting for your approval in the morning. An agent doesn't price on its own, because a mistake here costs real money.

Logs the run

What it did, based on what, and how much it cost. A log you can open and see exactly what happened.

Every step here is an action from the list of actions you approved in advance. An agent doesn't invent new actions for itself, and that's deliberate.
03The difference

The difference between a chatbot, automation and an agent

These three things are sold today under the same term, and the real difference between them is simple: what it's allowed to do.

The practical test: does it only produce text, or is it allowed to write into a system
What we checkChatbotAutomationAI agent
What it doesAnswers in textRuns a sequence you wrote in advanceChooses an action and performs it
What happens in an unfamiliar situationGives a generic answerBreaksHandles it, or hands over to a person
Access to systemsUsually noneYes, by rigid rulesYes, by a list of actions and permissions
Who is responsible for the resultYouYouYou, which is why there's an approval point
When it's enoughFrequently asked questionsA process that doesn't changeA process with judgment
And what about a "digital employee": it's a metaphor that's convenient to sell with and I don't use it. An agent is not an employee. It has no judgment, no responsibility, and it doesn't remember why a certain rule was set. It's a process with a set of permissions, and the moment you treat it that way you stop failing with it.

Want to see what it looks like on your process?

Send me a WhatsApp message Tell me what repeats itself in your business. Or by phone +972 52-877-5515
04Boundaries

What an agent may do on its own, and what stops for approval

This is the table we fill in together in the first meeting, and it's what separates an agent that works from a horror story. My default is strict: every action that touches money or goes out to a customer in the business's name stops.

Example permissions. For you it will be set by the risk of each action
ActionMy defaultWhy
Reading data from the systemAutomaticNo risk, and it's what makes the answer relevant
Answering a general questionAutomaticThe wording is defined in advance and the answer doesn't commit you
Opening a ticket or updating a statusAutomaticReversible and documented in the run log
Sending a quoteRequires approvalA price that goes out by mistake is a commitment to a customer
Committing to a delivery dateRequires approvalDepends on your inventory, your supplier and your workload
Charging, refunding or changing an orderBlockedMoney does not pass through an agent. Period
05How it doesn't fail

Most pilots in the world never reach production

An MIT study reported in August 2025 found that the overwhelming majority of organizations that ran generative AI pilots saw no return from them, and that only one in twenty pilots reached production. I know the reasons, and this is how I build so it doesn't happen to you.

We don't start from a demo

A demo works on twenty examples and breaks on the twenty-first. I build on your real process, with its annoying cases.

Write permission comes last

First the agent only reads and suggests, you approve manually, and only when it's right again and again does it get permission to write on its own.

There's a fallback path to a person

Every agent has an "I don't know" scenario that hands over to a person with the full context. Without it, a customer at two in the morning stays stuck.

Every run is measured

How many inquiries were handled to the end, how many went to a person and how much it cost. Without these numbers you can't decide whether to expand or stop.

06Real cost

How much does an AI agent cost, and what's left out of the price list

In the Israeli market, the price for the same term ranges today from a few hundred shekels a month (under $100) to tens and hundreds of thousands for a project (roughly $10,000 to $100,000). That gap isn't fraud, it's that three different things are sold under the same name. More important than the price itself is what goes into the bill:

Orders of magnitude to get your bearings: at the cheap end there are subscriptions of a few hundred shekels a month (under $100), and at the other end projects of tens and hundreds of thousands (roughly $10,000 to $100,000). One agent on one process, built and connected to the systems, sits in the middle. I give the exact number after one call in which we see how many systems are involved.

The cost components of an agent running in production
ComponentWho gets paidWhat affects it
Build and implementationMeHow many systems are connected and how many actions it's allowed to perform
Monthly supportMeMonitoring, improving the answers and adjustments when the process changes
Model usageTo the model providerThe length and number of conversations. A long conversation costs more than a short one
The messaging channelTo Meta or to the SMS providerPayment per message, by message type and by country. A reply to a customer who contacted you in the last 24 hours is free, and what adds cost is messages you initiate
Infrastructure and runningTo the cloud providerAvailability and volume. Usually the small component
Two things no price list mentions: an agent that enters a loop and tries again and again costs real money, and a conversation that drags a long context gets more expensive as it goes. I set ceilings for both and show you the actual cost in the monthly report.
07What nobody answers

Who is responsible when the agent is wrong

The responsibility is the business's

What the agent says in the business's name is as binding as what an employee says. That's exactly why actions that commit you stop for approval.

The data stays with you

The systems and accounts are in the business's name, and I get permission, not ownership. I also define what the agent doesn't see at all.

It can be switched off immediately

One toggle that moves everything to people. If something looks wrong to you, you don't need to wait for me.

The customer knows they're talking to a system

No pretending to be a person. It's both right and works better, because the customer knows what to expect.

08Who it's not for

When I say no

When the process isn't written anywhere

If nobody can explain how it works today, there's nothing to give an agent. We'll start by putting the process in order.

When the volume is too small

Three inquiries a week don't justify an agent. They justify a good reply template, and that can be done in an hour.

When the goal is to replace people

I build agents that reduce load, not ones that replace a team. Anyone looking for that will be disappointed.

When there's nobody to approve

An agent needs an owner in the business who looks at the log and approves what stops. Without that it gets stuck.

09Recurring questions

Questions about AI agents

What is the difference between an AI agent and a chatbot?

A chatbot produces text. An agent receives a goal, checks data and performs an action in a system. The practical test is permission: if it's allowed to write into a system, it's an agent. If it only answers, it's a bot, and that's perfectly fine when that's what's needed.

What is the difference between an AI agent and automation?

Automation runs a sequence you wrote and breaks the moment reality doesn't match it. An agent chooses on its own which action to take from a list you approved, so it handles situations that weren't defined in advance. Automation is cheaper and enough for a process that doesn't change.

How long does it take to launch a first agent?

A first agent on one process usually goes live within two to four weeks, depending mainly on how fast we get access to the systems. In the first weeks it works with approval on every action, and only afterwards does it get permission to act alone on what it has proven itself on.

Does the agent really write well, in Hebrew or English?

Yes, and the writing in each language is part of the work, not something the model does on its own. I write the wording, what it must never say, and what happens when it didn't understand. Behind me is a system that answered 700,000 conversations without a human on the line.

What happens if the agent tells a customer something wrong?

The responsibility is the business's, exactly as with an employee. That's why actions that commit you, like a price or a delivery date, stop for approval by default, and why there's a log that shows exactly what was said and based on what. You can also switch the agent off with one toggle.

Where is customer data stored?

In your systems, in accounts in the business's name. I define in advance which fields the agent can access and which it can't, and I prefer it doesn't see what it doesn't need. Before going live we go over together what is kept and for how long.

Can it connect to WhatsApp Business?

Yes, and it's the most common channel among my clients. Worth knowing how Meta charges: payment is per message, by its type and by country, and a reply to a customer who contacted you themselves in the last 24 hours costs nothing. What does cost is messages you initiate. I show this separately so you're not surprised.

Will this replace my employees?

No, and that's not the goal. An agent takes the part that repeats itself and the hours nobody covers, and leaves people what requires judgment. Businesses that approach this as a replacement for staff usually find they bought a new problem.

How is this page different from the AI solutions page?

The AI solutions page is for the question of where to start at all: an assessment, prioritizing processes and a work plan for the whole business. This page is for the stage after that, when it's already known which process is bleeding and an agent needs to be built on it.

Can we start small?

It's the only way I work. One process, measurement, and only then expand. Anyone who tries to launch five agents at once usually finds that none of them is good enough to trust.

10The next step

Tell me which process is bleeding in your business

You don't need to know whether it's an agent, a bot or automation. Describe what repeats itself and I'll tell you what fits, even if the answer is cheaper than you thought.

Prefer to talk? +972 52-877-5515

WhatsApp me

Accessibility menu