AI agents
AI Agent Development: Hire an AI Agent Developer
I am a freelance AI agent developer for hosting and SaaS businesses. An AI agent is a language model that can use tools within rules you set: answering tickets from your own knowledge base, updating WHMCS tickets through the API, triaging abuse reports and passing anything uncertain to a person.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
What is an AI agent, in plain terms?
An AI agent is a language model that can use tools, within rules you define. The model reads a request and decides the next step: search the knowledge base, look up an order, draft a reply. My code runs that step, checks it is allowed and returns the result to the model, which continues until it has an answer or hands off.
A chatbot, by contrast, answers questions, usually from retrieved documents, and changes nothing in your systems. An agent also calls tools that can read or change things in other systems. The model never touches your systems directly. It can only ask for the tools I give it, and each tool does one narrow job.
What can an AI agent do for a hosting or SaaS business?
It can take over the repetitive, well-documented parts of support and operations and pass everything else to your staff. These are the uses that suit the technology best.
| Use | What the agent does | What stays with a person |
|---|---|---|
| Ticket answers | Searches your knowledge base, drafts a reply with the source article, escalates when nothing matches. | Outages, refunds, upset customers, anything undocumented. |
| WHMCS ticket handling | Opens, updates, categorizes and annotates tickets through the API, for example with OpenTicket, AddTicketReply and AddTicketNote. | Billing disputes and exceptions. |
| Abuse report triage | Extracts the domain, IP and URL, finds the account, summarizes the evidence and proposes an action. | The decision to suspend or terminate. |
| Lead qualification | Asks a few fixed questions, scores answers against your criteria, routes the lead with a summary. | Pricing exceptions, contracts, the sales conversation. |
| Internal assistant | Answers staff questions from runbooks, price sheets and resolved tickets. | Production changes. It reads, it does not run server commands. |
How is an AI agent built?
An agent has seven parts, and the model is only one of them. Most of the work, and most of the safety, sits in the other six.
- Model. The OpenAI or Anthropic Claude API, picked by testing both on your examples. A thin adapter keeps the choice reversible.
- Retrieval. Your documents are split into passages and indexed. For each question the agent fetches the closest passages and answers from them, with the source shown. Weak retrieval is a common cause of bad answers.
- Tool calling with strict schemas. Each tool declares its arguments as a JSON Schema. My code validates every call before running it, and tools are read-only unless a write is truly needed.
- Human hand-off. Weak retrieval, certain topics or an angry tone route the conversation to a person, with a summary of what the agent already tried.
- Logging. Every request, retrieved passage, tool call, answer and cost is stored, so any decision can be audited.
- Evaluation set. A fixed collection of real past questions with correct answers, rerun after every change.
- Cost limits. Caps on tokens, tool calls per run and spend per day, with an alert before the cap is hit.
What are the risks of an AI agent, and how are they handled?
The main risks are wrong answers, prompt injection, data exposure and runaway cost. Each can be reduced and watched. None can be reduced to zero.
| Risk | What it looks like | How I handle it |
|---|---|---|
| Wrong answers | A fluent, confident reply that is false or out of date. | Answers must come from retrieved sources and show them. When retrieval is weak the agent says so and escalates. The pilot runs in draft mode. |
| Prompt injection | Text in a ticket, email or web page tells the model to ignore its rules or reveal data. | Customer text is treated as data, never as instructions. Permissions are enforced in code, not in the prompt, so a tricked model still cannot use a tool it was not given or reach another customer's account. |
| Data privacy | Personal data goes to a model provider or sits in logs. | Send only the fields the task needs, strip card data and credentials, check the provider's data terms and set a retention period for logs. |
| Runaway cost | A loop of tool calls or very long documents produces a surprise bill. | Limits on steps, tokens and daily spend, alerts, and a cheaper model for simple triage steps. |
| Harmful actions | A tool changes or deletes something it should not. | Narrow tools, a minimal-permission API credential, human confirmation for anything destructive, and repeat-safe operations. |
What should not be automated with an AI agent?
Anything where a wrong action is costly or hard to undo should stay with a person. I would not automate:
- Refunds, credits and any other movement of money.
- Suspending or terminating an account after an abuse report.
- Replies to legal notices, takedown requests and security incidents.
- Password resets or access changes based only on a chat message.
- Deleting data or running commands on production servers.
- Any decision you could not explain to the customer afterwards.
How do I know it works before customers see it?
You see it work on your own past tickets first. After the prototype I run the agent against the evaluation set and send you every failure alongside the successes. A limited pilot follows: one ticket category or one group of customers, in draft mode, with every answer logged. Only then do we discuss widening the scope. I give no accuracy percentage in advance, because it depends on the quality of your documentation and on the questions you receive.
Do you use AI tools to write the code for my project?
I tell you plainly on the scoping call if and how AI tools are used on your project. Whatever tool produced a change, I read, test and take responsibility for it before it ships, and I do not paste credentials or customer data into third-party tools. This is separate from the agents I build for you.
Which AI agent projects do I decline?
I do not promise accuracy figures, train new models, or build agents that move money or administer servers without a person approving the step. I do not build bots for mass messaging or for scraping sites against their terms. Agents are most useful when they sit beside your existing tools, so see WHMCS API integration and WHMCS support and maintenance for the systems they connect to, or SaaS development if the assistant belongs inside a product.
How long does an AI agent project take, and what does it cost?
It depends on scope. A prototype on one ticket category comes first, so you see results before committing to the full build. I quote a fixed price after a free scoping call, or work hourly at $55 to $65 per hour. Model usage is a separate running cost paid to the provider. The terms are on how I work.
Who this is for
- Hosting companies with a ticket queue full of repeat questions
- SaaS founders who want an assistant that actually knows the product documentation
- Support managers who want triage and drafted replies, with a person still approving
- Teams that tried a chat widget and found it answered from guesses
What is included
- Agent built on the OpenAI or Anthropic Claude API, picked by testing both on your examples
- Retrieval over your own documents, with the source shown for every answer
- Tools with strict argument schemas, for example WHMCS ticket actions
- Hand-off rules and a summary note written into the ticket on escalation
- Logging of every request, retrieved passage, tool call and cost
- An evaluation set built from your real past tickets
- Spending limits per request, per day and per customer
- Written handover covering prompts, tools, settings and how to update the knowledge base
How the work runs
-
1
Scope
I learn which questions and tasks cost you the most time, what documentation exists and which actions the agent may take. You get a short written scope that also lists what it will not do.
-
2
Prototype
I build a working agent on a small slice of your material, for example one ticket category, so you can try it on real questions before a full build.
-
3
Evaluate on real examples
I run the prototype against past tickets and the answers your staff gave. You receive the failures as well as the successes, and we fix retrieval, prompts or documents before going further.
-
4
Limited pilot
The agent runs in draft mode on one category or one group of customers, with a person approving every reply and every action logged.
-
5
Hand over
You get the code, the prompts, the evaluation set and a guide to updating the knowledge base. Two weeks of support follow.
Frequently asked questions
What is the difference between an AI agent and a chatbot?
A chatbot answers questions, usually from retrieved documents, and changes nothing in your systems. An agent can also call tools: search your knowledge base, look up an invoice, open a ticket. The model decides which tool to use, my code runs it, and the result goes back to the model. Because the tools return your real data, the agent can answer and act from it, and every action is limited to the tools I give it.
Can an AI agent reply to customers without a person checking?
It can, but I do not start there. The first stage is draft mode, where the agent writes a reply and a staff member approves it. Only when the logs show reliable results on real tickets do I switch specific, low-risk categories to automatic replies. Refunds, suspensions and security matters stay with people.
Will my customer data be sent to OpenAI or Anthropic?
Only what the agent needs for the request is sent, and I remove card data, passwords and unneeded personal fields first. Both providers publish data-use terms for their business APIs, and you should read the current ones for your plan and region. Where possible I do the sensitive lookups in your own code, so the data never enters the prompt.
How do you check that the agent answers correctly?
I build an evaluation set from your real past tickets, with the answer your staff gave. Every change to the prompt, model or knowledge base is run against that set, and I review the failures by hand. This shows the error rate on your own questions rather than a vendor's figure. It cannot prove the agent will never be wrong, which is why hand-off and logging stay on after launch.
Can the agent work with WHMCS?
Yes. The WHMCS API has actions to read and open tickets, post replies, add internal notes and change a ticket's status or department. I wrap the ones needed in narrow tools with checked arguments, using a dedicated API credential restricted to those actions. The agent never receives your admin login. Details depend on your WHMCS version and API access rules.
What does an AI agent cost to run?
There are two costs. Building it is quoted as a fixed price after the scoping call, or hourly at $55 to $65. Running it is billed by the model provider to your account, based on how much text is processed. I set per-request and daily spending limits and report the cost per ticket during the pilot, so you can compare it with your current support cost.
Related services
-
AI Chatbot Developer for Websites, Support and WHMCS
I'm an AI chatbot developer. I build custom chatbots that answer from your own documents, are built to say 'I...
-
WHMCS API Integration and Automation
I connect WHMCS to your CRM, Slack or Telegram, SMS, accounting and control panels with the API, localAPI() an...
-
SaaS Developer: Build a SaaS Website or Product
Freelance SaaS developer for SaaS websites, MVPs and customer portals on Laravel and Filament, with Stripe, Pa...
-
How I Work: Process, Rates and Payment
How a project with me runs: free 30-minute scoping call, written quote within one business day, $55-$65 per ho...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.