Tools & agentic behavior
For questions that need outside data, IsonAI works agentically: it picks a tool, runs it, reads the results, then decides the next step — over several rounds if needed — before composing the answer.
Available tools
| Tool | Purpose |
|---|---|
| Web search | Finding current facts across search engines and Ison Search |
| Page reading | Opening URLs (from search results or ones you paste) and reading their contents |
| Knowledge search | The official IsonAI product knowledge base |
| Stock prices | Current market data, IDX and global |
| Local places | Curated Indonesian places and business data |
| Academic search | Journals and scholarly articles across many sources |
| Indonesian public services | Live official data (forest-fire hotspots, earthquakes, volcano levels, tax exchange rate, PDDikti) and government-portal guidance — see Public services |
| Document editing | Doc Edit for attached PDFs |
| Google connectors | Calendar, Gmail, and Drive — only after you connect them; see Connected services |
| MCP connectors | A reviewed read-only catalog; initial release: Ison Search Indonesia for Pro/admin |
While tools run, progress lines in the interface show what is being searched and read — the process is never fully hidden.
Recovery when tools fail
If a search or page read fails or returns irrelevant results, IsonAI tries another path — a different query or a different source. If the evidence remains inadequate, IsonAI states its limitations instead of making things up.
Consent boundaries (authority)
- Google connectors only activate after you grant permission through the official Google sign-in flow, and can be disconnected at any time from Settings.
- Regular chat does not perform Google writes. In Naya, supported Google actions stop at an approval gate with the exact target and content before execution.
- Payments, signatures, official submissions, and actions outside Naya's allowlist are not executed.
- MCP is read-only, opt-in, and limited to a reviewed catalog in this phase; arbitrary server URLs and write tools are rejected.
Privacy protections in tool use
Personalized tool use is protected by the following principles, enforced server-side:
- Personal data from your memory and history is never sent out through search queries or requests to external sites. Only what you write in the current message becomes search material.
- Web content and document contents are treated as data to analyze — instructions embedded in web pages or files are not followed as commands.
- Links that appear in answers are restricted to sources that were actually used and come from legitimate places.
The above is a behavioral contract, not a technical specification; the internal mechanisms are not published.
Limits
- The number of tool rounds per answer is capped to keep responses reasonable; genuinely broad research is better suited to Deep Research.
- The initial MCP catalog contains only Ison Search Indonesia; general third-party connectors are not open yet.
Related
- Connected services (Google)
- Search & grounding
- Naya — structured missions with approval gates.
- Memory & privacy
Last verified: