Ask the agent: self-configuration, magic links and admin tools¶
Every agent can reconfigure itself when asked to in a conversation — on any surface, the simple chat view included — and can hand a person a magic link whenever a browser is needed. AgentFather can do the same for the whole deployment. This is the default way to connect, configure and operate Olano: an agent never asks you to open a terminal, and there is no command line to learn.
Ask a bot to:
- "Connect yourself to Notion" — every connection starts with the finder: the bot lists the supported ways to reach the service (a channel, an MCP server from the directory, a built-in toolkit — see MCP servers), adds the one you pick to itself, and hands you the sign-in: a Connect button card in the dashboard chat, a tappable link on messaging channels. You sign in from your own browser — Olano's app, your own OAuth app, or a code you type on your phone; the connection completes on its own and the bot's new tools appear after that. API keys are collected through a secure page and stored in the vault — never pasted into the chat or a config file. Something the bot cannot find in any catalog is external: it will read the project's page and tell you what it is before anything is installed, and it will never sign it in for you.
- "Get yourself on Telegram" — it sends you one link whose page walks you through the bot token (validated live) or, for WhatsApp and WeChat (Weixin), shows a QR code to scan — in the dashboard chat and on messaging channels alike. The channel and the token land in its config and vault, and it restarts to go live.
- "Switch to a cheaper model" / "Rewrite your instructions to always answer in Spanish" / "Add a research assistant" — it lists real options, saves the change, and restarts itself when you say so. Prompt edits land in Config → Revisions under the agent's name, ready to roll back.
- "What could you become?" — it browses the archetype library of ready-made experts and teams and suggests specialists worth adding.
- "Which skills do you have?" / "Stop using the spreadsheet skill" — it lists its skills with their on/off state and switches individual ones off (or back on) for itself. Only a switch: it never installs, edits or deletes a skill, and turning off a common skill leaves every other agent's copy alone. See Switching a skill on or off.
Magic links — the default whenever a browser is needed¶
A magic link is a short-lived, PIN-protected page the agent sends into the
chat; whoever opens it finishes one task on their own phone or laptop, and the
chat is told the outcome (magic_links:
has the knobs). Every agent has these tools by default:
| Ask | Tool | What the person sees |
|---|---|---|
| Sign in to a service, an MCP server or an official connector (GitHub, Google, OpenAI Codex, Microsoft 365, Slack, Notion, …) | magic_link_connect_service |
the provider's own consent screen, or a one-time code to type on the provider's device page — whichever method the service offers and the bot picked (Olano's app, your own OAuth app, a code, or a secure form for a key); an MCP server that needs an OAuth app of your own (HubSpot) first asks for its Client ID and secret on the same page, or offers Composio instead (MCP servers); the connection serves the service's tools, MCP servers and the git tools at once, no restart |
| Hand over an API key, token or password | magic_link_request_secret |
a secure form; the value goes straight into the vault, the bot only learns its name |
| Connect a messenger | magic_link_connect_channels |
one page per platform: QR for WhatsApp/WeChat, a validated bot token for Telegram/Discord/Slack |
| Edit the bot's instructions | magic_link_edit_instructions |
a one-page editor; saving applies live, no restart |
| Edit a file | magic_link_request_file_edit |
a one-page editor showing the file's current contents |
| Open the dashboard on a phone | magic_link_open_dashboard |
a one-time sign-in focused on a section (prompt, vault, connections, providers, config, files, overview) |
| Check a link you sent | magic_link_status |
— |
Only the bot's owners can ask for a link (on a messenger, the channel's allowed-users list), group chats are refused, and on the stricter security profiles every link raises an approval card first. Never paste a key into a chat — if a bot asks you to, it has been misconfigured; the link is the route.
The self_* tools — what a bot may change about itself¶
| Capability | Tools | Restart? |
|---|---|---|
| Know thyself | self_get_config (always on while any capability is) |
— |
| Browse archetype library | self_list_archetypes, self_read_archetype |
— |
| Change its own model | self_list_models, self_set_model |
yes |
| Edit its own instructions | self_update_prompt |
yes |
| Restart itself | self_restart |
— |
| Add subagents | self_list_subagents, self_add_subagent |
yes |
| Connect services | self_find_integration (every supported way to reach a service, ranked, with the exact next steps), self_add_toolkit, self_remove_toolkit, self_inspect_external (read an outside project's documentation before anything is installed); self_search_mcp_directory, self_list_mcp_servers (each server's live state, stored sign-in and what would bring it back), self_list_mcp_tools (every tool a server offers, switched-off ones marked), self_reload_mcp_servers (reconnect and re-bind tools without a restart), self_add_mcp_server, self_remove_mcp_server, self_authorize_mcp_server |
yes for a toolkit or server; a sign-in or a reload applies on its own |
| Be reachable from outside | self_set_external_access (publish itself over MCP / A2A with a public description — administrators only), magic_link_mint_access_token (send an admin a page that mints a caller token, shown once there) |
yes; the token link applies on its own |
| Connect messaging platforms | self_list_platforms, self_connect_platform, self_connect_whatsapp, self_connect_weixin |
yes |
| Manage its own skills | self_list_skills, self_enable_skill, self_disable_skill |
yes |
| Send magic links | the magic_link_* family above |
— |
What a bot may change about itself is controlled per capability — everything
on by default — in Config → Agent self-configuration (whole deployment)
and per agent under Agents → agent → Chat self-configuration (three-state:
Inherit / On / Off). See agent_autonomy:. A
single tool can also be switched off for one agent on its Tools tab, by
AgentFather (olano_update_agent with disabled_tools), or for every agent
with default_internal_tools: false. A bot never gains power over other
agents this way: each one can only touch itself. Agents in customer-service
mode inherit everything off.
Only the bot's owners can ask for a change. Whoever creates a bot owns it; deployment admins count as owners of every bot, and more owners are granted in Admin → Access. Someone who was merely given access to chat with the bot can still ask what it could do — list models, browse services and templates — but a request to actually change something comes back as a refusal telling them to ask an owner. On a messaging channel the bot's allowed users list plays the same role, so the person who set the bot up can still configure it from their phone.
AgentFather — the olano_* tools for the whole deployment¶
One agent, AgentFather, holds the tools that reach beyond itself. It is human-only (other agents cannot message it), every write raises an approval card, and it narrates what you are approving. Ask it to:
| Job | Tools |
|---|---|
| See and change any agent | olano_list_agents, olano_get_agent, olano_create_agent, olano_update_agent, olano_delete_agent; olano_start_agent / olano_stop_agent / olano_restart_agent |
| Build from the catalog | olano_list_builtin_agents, olano_list_archetypes, olano_read_archetype, olano_scaffold_archetype; olano_list_models |
| Tools and connections for any agent | olano_find_integration (every supported way to reach a service for an agent), olano_add_toolkit, olano_remove_toolkit, olano_inspect_external; olano_list_tools, olano_list_bundles, olano_list_integrations, olano_find_tools, olano_set_tool_enabled; olano_search_mcp_directory, olano_get_mcp_directory_entry, olano_test_mcp_server, olano_add_mcp_server, olano_remove_mcp_server, olano_authorize_mcp_server, olano_mcp_oauth_status; olano_list_platforms; the magic_link_* tools aimed at another agent |
| External access for any agent | olano_set_agent_external_access (publish or unpublish an agent over MCP / A2A and set its public description — administrators only); tokens are minted on the dashboard or with magic_link_mint_access_token |
| Skills and subagents | olano_list_skills, olano_list_builtin_skills, olano_create_skill, olano_install_skill, olano_repair_skill_names; olano_list_subagents, olano_add_subagent, olano_toggle_subagent |
| Teammates and access | olano_list_users, olano_get_user, olano_create_user (an invite link, never a password), olano_reset_user_password, olano_set_user_role, olano_update_user, olano_delete_user, olano_grant_agent_access, olano_revoke_agent_access, olano_access_overview |
| Diagnose | olano_diagnose_agent, olano_runtime_status, olano_agent_status, olano_agent_activity, olano_agent_errors, olano_recent_errors, olano_tail_log, olano_list_sessions, olano_read_session, olano_mcp_status, olano_doctor |
| Deployment settings, disk, memory, updates | olano_get_home_config, olano_update_home_config (every config.yaml block); olano_disk_report, olano_disk_monitor, olano_memory_report, olano_memory_monitor; olano_update |
| Another agent's files | olano_list_agent_workspace, olano_read_agent_file, olano_write_agent_file, olano_run_agent_command |
The playbooks AgentFather follows ship as two skills only it can see: olano-agent-builder (designing and building an agent from a conversation, Building agents from a conversation) and olano-admin (operating the deployment). Every other agent gets olano-agent (how to do the things above for itself — one finder, one ladder), olano-platform (the map of the platform) and olano-cloud (plans, credits and usage).