AI assistant
Tools and actions
The tools the AI uses to look things up and act, how to connect external data with MCP and publish skills, plan limits, and what the AI can and cannot change.
Last updated: 2026-09-29
The AI does not make things up from memory. It calls tools: small, controlled functions that read your data or perform one specific action. This page lists what it has, what you can add, and what is deliberately impossible.
Platform tools#
These are built in. You do not create them, but you can see and switch some in the dashboard.
| Tool | What it does | Effect |
|---|---|---|
| Knowledge search | Searches the knowledge base | Read only |
| Branches | Returns your published branches, addresses and hours | Read only |
| Catalog search, product details, inventory | Finds products or dishes, prices and availability | Read only |
| Offers | Returns published offers and their conditions | Read only |
| Delivery fee | Looks up the fee for an area from your delivery settings | Read only |
| Order status | Reads the status of the customer's orders | Read only |
| Customer profile | Reads what Sela knows about this customer | Read only |
| Prepare order quote | Builds a priced quote for the customer to confirm | Saves a quote, not an order |
| Hand off to human | Escalates the conversation with a reason and priority | Changes conversation status, notifies your team |
| Set cooldown | Pauses a conversation after repeated abuse | Temporary pause |
Which tools a turn gets depends on your Environment (General business, Restaurant, Store, Appointments) and on the capabilities enabled for your workspace. Restaurant and Store workspaces get catalog tools. A general workspace gets knowledge search and handoff, and cannot quote products until a catalog is in use. See Catalog and products.
What the AI can and cannot do#
| It can | It cannot |
|---|---|
| Answer from KB, catalog, published branches and offers | Take or send payments (there is no payment tool) |
| Prepare an order quote, and create the order only after the customer's explicit confirmation | Book, move or cancel appointments |
| Check delivery fees and order status | Issue refunds or change prices |
| Escalate to a person with a summary | Edit contacts, CRM records or settings |
| Pause an abusive conversation | Run HTTP calls you wrote yourself, or write to outside systems |
An order created by the AI lands in your team's queue as a request that staff approve or reject. The AI tells the customer the request was sent to the team, never that it is confirmed. See Orders and payment links.
Tools page#
Open Automation → Catalog & AI → AI tools (page title "Assistant tools and skills"). It has three tabs: MCP connections, Skills and Existing tools. You need the AI Assist add-on and an owner or admin role with permission to manage settings.
Existing tools#
Lists your workspace's tool definitions. Each has an approval mode (auto run, needs approval, never auto run) and an Enabled for AI switch. Bootstrap Registry adds the defaults for your environment. Switching off the knowledge, catalog, order, handoff or cooldown entry removes the matching tools from the AI. The order entry is also where confirmed orders are queued for approval.
MCP connections#
An MCP (Model Context Protocol) connection lets the AI read public business data from a server you or a partner run, for example a public product feed or store locator.
- On MCP connections, add a name, an HTTPS endpoint and the authentication: none, a bearer token, or one custom header. OAuth, stdio and local servers are not supported.
- Run Discover tools. Discovery lists metadata only, and every discovered tool starts disabled.
- Open a tool and review its schema. Set any fixed inputs (they are hidden from the AI), choose the exact public output fields to expose, and confirm the data is public.
- Choose the channels where it may be used (none selected means all), enable it, save, and press Test. The test makes a real call and shows only what the AI would see.
Safety rules:
- The server must declare the tool read only, and must not declare it destructive. Others are refused.
- Only fields you select are passed to the AI. Everything else is dropped.
- Results are treated as untrusted external data. They can never set catalog prices, stock or order effects, and cannot reveal private account facts.
- Editing a connection disables its tools. Rediscover and enable them again.
| Limit | Value |
|---|---|
| Connections | 5 |
| Tools per discovery | 25 |
| Exposed output fields per tool | 30 |
| Projected output size | 16 KB |
| Operation time | 12 seconds |
Skills#
A skill is a short set of instructions for a procedure, for example "how to explain our warranty". The AI sees only the names and descriptions of published skills, and opens a skill's full text when it is relevant.
- On Skills, add a title (80 characters), a description (300), when to use it, and the instructions. The body is limited to 6,000 characters in total.
- Save the draft, then Publish. Edits keep the previous published version until you republish.
- Or import a single
SKILL.mdfile (up to 24,000 bytes) withnameanddescriptionin its header. Files with scripts, includes or allowed-tools are rejected.
You can save up to 20 skills and publish up to 10. Skills rank below platform rules: they cannot add facts, tools, permissions or actions. Use them for how to talk about something. Put facts in the knowledge base.
Plan gating#
| Plan | Custom AI tools (MCP) |
|---|---|
| Sandbox, Inbox | Not available |
| Operations | Up to 5 |
| Scale, Enterprise | No plan limit, with an overall cap of 20 active custom tools |
All AI features also need the AI Assist add-on. Prices are on Plans and billing.
Staying in control#
- Every action that changes something (quote, handoff, cooldown) follows fixed rules you cannot bypass from persona text.
- Handoff and cooldown can be switched off in Existing tools, and the whole AI with Disable AI replies.
- To see why the AI acted a certain way, read the conversation and the AI quality report. See Improving answer quality.
Can't find what you need? Contact support.