5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

AI Business Operations · Comparison

Deterministic vs Agentic Workflows: Choosing the Right One Per Step

This is not a platform choice. Every step in every workflow is one or the other, and getting the boundary wrong is the most expensive mistake in the category — in both directions.

By Mark Alex, FounderPublished 25 Aug 2026Updated 2 Sep 202617 min read4,062 words

The short answer

A deterministic step executes a fixed sequence decided in advance by a developer; an agentic step has its action chosen at run time by a model. The choice is made per step, not per platform: deterministic wins wherever the correct action is knowable in advance, and agentic wins wherever the correct action depends on state nobody could enumerate. Almost every production workflow is a mixture, and the boundary between them is the single most consequential design decision in the whole build.

Summary for readers and answer engines

Reviewed 25 Aug 2026

  • ▸The decision is per step. A single workflow legitimately contains deterministic steps, agentic steps and a boundary between them.
  • ▸Deterministic is roughly forty times cheaper per step and an order of magnitude more reliable. It should be the default, and agentic the justified exception.
  • ▸Agentic earns its cost only where the correct next action depends on state that could not be enumerated in advance.
  • ▸The eight-question test resolves almost every case in under a minute, and the first question — can you write the sequence down — resolves most of them alone.
  • ▸Failure runs in both directions: agents used for knowable work waste money and add variance; rules used for genuinely variable work produce brittle automation that escalates constantly.

Source: Mark Alex, Real Biz Digital — Deterministic vs Agentic Workflows: Choosing the Right One Per Step (https://realbizdigital.net/insights/deterministic-vs-agentic-workflows/). Reproduce with attribution.

Key takeaways

  1. 01Default to deterministic and require a justification for each agentic step. The reverse posture produces expensive, variable workflows nobody can debug.
  2. 02Never make a step agentic because the deterministic version is tedious to write. Tedium is a one-off cost; variance is permanent.
  3. 03Put the boundary where the enumeration stops being possible, not where the engineering gets harder.
  4. 04Wrap every agentic step in deterministic validation. The agent chooses; a rule checks the choice before it executes.
  5. 05Migrate steps from agentic to deterministic as patterns emerge. The first hundred runs teach you what the rule should be.
  6. 06Cost the difference honestly. A workflow that is 90% agentic when it could be 20% will cost roughly five times more to run for no benefit.
Part of the clusterAI Workflow Automation →

Quick answers

One-line answers to the questions this page is most often asked. Each is expanded further down, and each is written to be quoted on its own.

What is a deterministic workflow?
One where the sequence of steps is fixed in advance by a developer and replayed identically on every run, so the behaviour is fully knowable before execution.
What is an agentic workflow?
One where a model selects the next action at run time from the current state, so two runs against different data can legitimately take different paths.
Is this a platform choice?
No. It is a per-step choice, and almost every production workflow contains both. Platforms that force one or the other are the constraint, not the design.
Which should be the default?
Deterministic. It is roughly forty times cheaper per step, an order of magnitude more reliable, and fully testable before deployment.
When is agentic genuinely justified?
When the correct next action depends on state that could not have been enumerated in advance — variable document formats, ambiguous matches, exception handling, novel combinations.
What is the single best test?
Can you write the sequence down such that it will still be correct in six months? If yes, it is deterministic work and an agent adds cost and variance for nothing.
Can a step move across the boundary?
Yes, and it should. Steps start agentic while the pattern is unknown and migrate to deterministic once the first hundred runs reveal the rule.

The numbers behind the choice

Every figure below is defined and sourced further down. They are stated here so they can be quoted without reading the whole page.

8questions in the step-level decision test
~40×cost difference per step, deterministic vs agentic
99.9%+achievable reliability for a deterministic step
94–97%realistic steady-state for an agentic step
4hybrid patterns that compose both
2directions in which the choice fails

The eight-question step-level test

Run this per step, not per workflow. It takes under a minute and resolves most cases at question one.

Key facts

  • ▸Questions one and five are the load-bearing ones. If the sequence is writable it is deterministic; if the branches are unenumerable it is agentic. Everything else is refinement.
  • ▸Question four is the safety question. Anything whose failure mode is a misstatement should be a rule regardless of how convenient an agent would be.
  • ▸Question seven is the one that unlocks the most value: an agentic step with deterministic validation gets most of the flexibility at a fraction of the risk.
  • 01Can you write the sequence down and will it still be correct in six months? If yes: deterministic. This resolves the majority of steps on its own.
  • 02Is the input format stable? A fixed schema is deterministic work; forty vendor invoice layouts is agentic work.
  • 03Is there exactly one correct answer? Tax calculation, currency conversion and entity matching by key have one right answer. Deterministic, always.
  • 04Would a wrong result be a misstatement or a mistake? Misstatements have legal definitions and belong in rules. Mistakes have retries and can tolerate judgement.
  • 05Does the correct action depend on something you cannot enumerate? If the branch list is unbounded, no rule can cover it and agentic is the honest answer.
  • 06How many times will this step run per month? High volume amplifies the cost difference. Ten thousand agentic steps a month is a real bill for work a rule would do free.
  • 07Can the result be validated deterministically afterwards? If yes, agentic becomes much safer — the agent proposes and a rule checks.
  • 08Is a human already doing this by judgement? Work that currently requires a person to look and decide is the natural home for an agentic step.

Write the answers down next to each step in your workflow. The resulting map is the artefact that makes the build reviewable, and it usually shows fewer agentic steps than the team assumed.

What each actually costs and delivers

The comparison is frequently made in the abstract. These are the figures that matter when you are deciding about a specific step.

Per-step comparison
PropertyDeterministic stepAgentic step
Marginal cost per executionEffectively zeroModel inference plus tool call overhead
Relative cost1×~40× at typical step complexity
LatencyMillisecondsHundreds of milliseconds to seconds
Achievable reliability99.9%+94–97% steady state
TestabilityComplete before deploymentStatistical, over a corpus
DebuggabilityRead the codeRead the trace and infer
Handles unforeseen inputNo — failsYes — by design
Cost of a new branchEngineering changeNone
Explains its own decisionNot neededRequires a trace to reconstruct

Our verdict

Deterministic should be the default posture and agentic the justified exception. The forty-fold cost multiple and the two-orders-of-magnitude reliability gap mean an agentic step needs a reason, not an absence of objection. Where a step passes the test as agentic, it earns those costs comfortably — but the burden of proof runs that way round.

The forty-fold figure is at typical step complexity and moves with model choice and prompt size. The direction and rough magnitude have been consistent everywhere we have measured.

Where each belongs

Deterministic is right

  • ✓Fixed input schema with stable fields
  • ✓One correct answer exists (tax, rounding, key matching)
  • ✓Wrong result would be a misstatement
  • ✓High volume, low variance
  • ✓The sequence is writable and stable
  • ✓A regulator prescribes the order of steps

Agentic is right

  • —Input format varies unpredictably
  • —Correct action depends on unenumerable state
  • —A person currently does it by judgement
  • —Exception handling and recovery
  • —Novel combinations across many tools
  • —Low volume, high variance per case
One workflow, six steps, four different answers
Step 1

Read a fixed-schema webhook payload

Deterministic. The schema is contractual; an agent adds cost and a failure mode for no benefit.

Step 2

Extract terms from a supplier PDF

Agentic, with deterministic validation. Format varies; the extracted values are then range-checked and type-checked by rules.

Step 3

Compute the invoice total

Deterministic. One correct answer, and a wrong one is a misstatement.

Step 4

Decide which of three plausible customers this is

Agentic to surface candidates, human to decide. Never agentic to conclude — a confident wrong match is worse than an escalation.

Step 5

Post the journal

Deterministic. Posting is mechanical once the values are fixed.

Step 6

Handle a failure at any step

Agentic. The recovery path depends on which step failed, why, and what has already committed.

Notice steps two and four: both agentic, both bounded by something deterministic. That combination — agent proposes, rule or human disposes — is where most production value sits.

Four hybrid composition patterns

Pattern 01

Agent selects, rule validates

The agent chooses the action and arguments; a deterministic rule checks them against schema, ranges and policy before execution. Cheapest safety improvement available, and it converts a probabilistic step into a bounded one.

Use for: any agentic step whose output is checkable. Which is most of them.

Pattern 02

Deterministic spine, agentic exception branch

The happy path is a fixed sequence; the agent is invoked only when the deterministic path cannot proceed. Most runs cost nothing extra.

Use for: high-volume processes with a long tail of exceptions. This is the pattern that makes agentic economics work at scale.

Pattern 03

Agentic planning, deterministic execution

The agent produces a plan; every step in that plan is a deterministic, parameterised operation. Flexibility in sequencing, no flexibility in what an action means.

Use for: multi-system workflows where the order varies but the operations do not. The most common production shape.

Pattern 04

Deterministic first pass, agentic escalation

A rule attempts the work; anything it cannot resolve confidently escalates to an agent, and anything the agent cannot resolve escalates to a person. Three tiers, each cheaper than the next.

Use for: extraction, classification and matching, where a rule handles the clean majority.

Pattern three is the one most mature estates converge on, because it isolates the variance to sequencing while keeping every individual action fully deterministic and testable.

Both directions of failure

Mistake

Agentic where deterministic would do

A step with a stable schema and one correct answer is handed to a model because writing the rule felt tedious. Now it costs forty times more per run, occasionally produces a different answer, and cannot be tested before deployment.

Instead: Write the rule. Tedium is a one-off cost paid by an engineer; variance is a permanent cost paid by whoever operates the workflow at 3am.

Mistake

Deterministic where the branches are unenumerable

A rule engine accumulates conditions to handle document formats or matching edge cases. It reaches ninety branches, nobody can modify it safely, and it still escalates constantly.

Instead: Accept that the enumeration failed and make the step agentic with deterministic validation. Ninety branches is the system telling you the answer.

Mistake

Boundary drawn by engineering convenience

The line ends up wherever the existing platform made it easy, which means calculations sit inside agents and genuinely variable work sits inside rule trees.

Instead: Draw the boundary from the eight-question test first, then choose tooling that can honour it. A platform that cannot express both is the wrong platform.

Migrating a step across the boundary

Steps should move, and the direction is usually agentic to deterministic as patterns emerge. That migration is a sign of a healthy programme rather than an admission that the agent was unnecessary.

Step 01

Instrument the agentic step’s decisions

Record, for every run, what the agent chose and why. After a hundred runs you have the distribution, which is the rule you could not have written on day one.

Step 02

Look for concentration

If ninety percent of runs take three of the observed paths, those three are a rule and the remaining ten percent stays agentic. This is pattern two, discovered empirically.

Step 03

Write the rule for the concentrated cases

Deterministic handling for the common paths, with the agentic step retained as the fallback. Cost falls sharply and reliability rises on the majority.

Step 04

Shadow the rule against the agent

Run both, compare outcomes on live traffic, and promote only when the diff is understood. Same discipline as any policy promotion.

Step 05

Re-measure and repeat quarterly

Distributions drift as upstream systems change. A rule that covered ninety percent last quarter may cover seventy now, and the fallback rate is the signal.

The reverse migration — deterministic to agentic — happens too, and its trigger is branch count. When a rule tree passes roughly twenty conditions and is still escalating, the enumeration has failed and the step should move.

Next step

Plan agentically, execute deterministically

BarzelOps is built on pattern three: the agent plans and previews, and every action it plans is a fixed, parameterised business operation across accounting, CRM, email, calendar, documents and Slack. Free tier at 100 calls a day.

Where the framework is imprecise

Two honest caveats.

  • 01The fortyfold cost figure is indicative at typical step complexity and moves substantially with model selection, prompt size and whether the step retries. Measure your own; the direction holds, the multiple will differ.
  • 02Question four — misstatement versus mistake — requires domain judgement the framework cannot supply. Whether a wrong customer match is a misstatement depends on what happens downstream, and that is a conversation with the process owner rather than a property of the step.

Common misconceptions

Four claims we hear regularly that do not survive contact with a real estate. Each is stated as we hear it, then corrected.

Myth

Agentic workflows replace deterministic automation.

Actually

They do not, and the estates that treat them as a replacement end up slower, more expensive and less reliable than the systems they replaced. Deterministic execution remains correct for the large majority of steps, and the agentic layer earns its place specifically where enumeration is impossible.

Myth

If a workflow contains an agent, it is an agentic workflow.

Actually

The useful unit is the step, not the workflow. A workflow with twelve deterministic steps and one agentic extraction step is mostly deterministic, and describing it as agentic obscures the design and inflates expectations about what it can absorb.

Myth

Agentic steps cost roughly the same as deterministic ones.

Actually

At typical step complexity the difference is around fortyfold per execution, before accounting for retries. At ten thousand executions a month that difference is real money spent on work a rule would perform free and more reliably.

Myth

Making a step agentic removes the need to handle exceptions.

Actually

It changes which exceptions you handle rather than removing them. Agentic steps still fail on permission errors, upstream outages and genuine novelty, and they add a class of failure deterministic steps do not have: a confident wrong answer.

Frequently asked questions

What is the difference between deterministic and agentic workflows?

A deterministic step executes a sequence fixed in advance by a developer, identically on every run. An agentic step has its action selected at run time by a model from the current state, so different runs can legitimately take different paths. The choice is made per step, not per workflow or platform.

Should deterministic or agentic be the default?

Deterministic. It costs roughly fortyfold less per execution at typical step complexity, achieves reliability above 99.9% against 94–97% for agentic steps, and is fully testable before deployment. An agentic step should require a justification rather than merely an absence of objection.

What is the single best test for choosing?

Ask whether you can write the sequence down such that it will still be correct in six months. If yes, the work is deterministic and an agent adds cost and variance for no benefit. This question alone resolves the majority of steps.

When is an agentic step genuinely justified?

When the correct next action depends on state that could not have been enumerated in advance: unpredictable input formats, ambiguous entity matches, exception recovery whose path depends on what already committed, or novel combinations across many tools.

Can a single workflow contain both?

Almost every production workflow does, and should. A typical six-step workflow might have four deterministic steps, one agentic extraction with deterministic validation, and one agentic recovery path. Describing such a workflow as simply agentic obscures its design.

What is the agent-selects-rule-validates pattern?

The agent chooses the action and its arguments, and a deterministic rule checks them against schema, ranges and policy before anything executes. It is the cheapest available safety improvement and it converts a probabilistic step into a bounded one.

What is a deterministic spine with agentic exceptions?

The happy path runs as a fixed sequence and the agent is invoked only where the deterministic path cannot proceed. Most runs therefore cost nothing extra, which is the pattern that makes agentic economics viable at high volume.

Which hybrid pattern do mature estates use most?

Agentic planning with deterministic execution: the agent produces the plan and every action in that plan is a fixed, parameterised operation. It isolates variance to sequencing while keeping each individual action testable.

How do you know a rule engine should become agentic?

Branch count. When a rule tree passes roughly twenty conditions, nobody can modify it safely, and it still escalates frequently, the enumeration has failed. That is the system telling you the step belongs on the other side of the boundary.

Should agentic steps ever migrate to deterministic?

Yes, and it is a sign of a healthy programme. Instrument the agent’s decisions, and after a hundred runs the distribution usually shows heavy concentration in a few paths. Those paths become rules; the remainder stays agentic as a fallback.

Does making a step agentic remove exception handling?

No. It changes which exceptions you handle and adds one deterministic steps do not have: a confident wrong answer. Permission errors, upstream outages and genuine novelty all remain, and the confident-wrong-answer class is why deterministic validation matters.

What is the most common boundary mistake?

Drawing the line where engineering was convenient rather than where the eight-question test puts it. That produces calculations sitting inside agents and genuinely variable work sitting inside unmaintainable rule trees — both directions of failure in one workflow.

Glossary

Deterministic step
A workflow step whose action and sequence are fixed in advance and identical on every run.
Agentic step
A workflow step whose action is selected at run time by a model from the current state.
Step-level boundary
The line within a workflow separating deterministically executed steps from agent-sequenced ones.
Enumerability
Whether the set of possible correct actions for a step can be listed in advance.
Deterministic validation
A rule-based check applied to an agentic step’s chosen action before execution.
Deterministic spine
A fixed happy-path sequence with agentic handling reserved for exceptions.
Agentic planning
Using a model to produce an ordered plan whose individual actions are deterministic.
Branch count
The number of conditions in a rule tree, used as the signal that enumeration has failed.
Decision instrumentation
Recording what an agentic step chose and why, to discover the rule it could become.
Concentration
The degree to which observed agentic decisions cluster into a small number of paths.

Standards and entities referenced

Every named framework on this page resolves to a public definition. If you are checking our claims, start here rather than with us.

Sources and further reading

Primary specifications and standards this article relies on. Where a claim is our own operating judgement rather than something a standard states, the text says so.

  1. 01 · Object Management GroupDMN — Decision Model and Notation ↗Separating decision logic from process flow, which is what keeps agentic workflows reviewable.
  2. 02 · Object Management GroupBPMN 2.0 specification ↗The modelling standard business process orchestration vocabulary comes from.
  3. 03 · microservices.ioSaga pattern ↗Compensating transactions, which is all you get when distributed rollback does not exist.
  4. 04 · WikipediaIdempotence ↗Why safe retries require this property rather than hope.
  5. 05 · WorkatoWorkato — agent orchestration ↗Market reference: how a broad iPaaS vendor frames multi-agent workflow execution across applications.
  6. 06 · UiPathUiPath — agentic ERP with Deloitte ↗Market reference: agents, RPA and humans coordinated around ERP processes.
  7. 07 · NISTNIST — AI Agent Standards Initiative ↗Identity, authorization, auditing and non-repudiation framed as prerequisites for autonomous agents.
  8. 08 · GoogleGoogle SRE — Service Level Objectives ↗Why an estate needs objectives and error budgets, not just dashboards.

Last reviewed 2 September 2026 by Mark Alex. External links open in a new tab; we do not control their content.

Cite this article

Alex, M. (2026). Deterministic vs Agentic Workflows: Choosing the Right One Per Step. Real Biz Digital. https://realbizdigital.net/insights/deterministic-vs-agentic-workflows/

Try the mechanics on a live server

To see a governed tool surface respond before you point an agent at your accounting system — Barzel Scripture Intelligence is free and public at scripture-intelligence-server.mcpize.run: no signup, no key, 54 tools. Setup is in the reference.

Buy it on the marketplace

BarzelOps is this execution layer, sold as a running product

Forty tools covering capability discovery, workflow planning, preview before execution, run, trace, pause, resume and cancel, approval request and resolution, credential validation and connector health — across accounting, CRM, email, calendar, documents, Slack and storage. Opinionated workflows ship with it: customer onboarding, invoice follow-up, lead-to-invoice, pipeline cleanup, monthly close preparation and weekly operations briefings. The Free tier runs 100 calls a day.

PlanPriceIncludedRight for
FreeFree100 calls/day · 10 core tools: plan, preview, run, traceProving one workflow end to end before anyone signs anything
Pro$19/mo15,000 calls/mo · 26 tools including approvals and templatesOne operator automating their own recurring procedures
Team$49/mo50,000 calls/mo · the complete 40-tool surfaceAn operations team running cross-app workflows under approval
Enterprise$199/moUnlimited calls · deployment and connector scope by agreementMulti-team execution with audit and residency obligations

Sold on the MCPize marketplace · prices as listed 2 Sep 2026 · the listing is authoritative

The five Barzel servers, and which problem each one is sold for

One estate rarely needs all five. This is the honest mapping, so you buy the layer your problem actually lives in.

ServerSold forEntry priceWhere it sits
Barzel Central GatewayKnowing and governing the estate: inventory, registry, routing, risk scoring, approvals, evidenceFree, then $10–$149/moControl plane — decides what may be reached, and by whom
BarzelVaultStopping a specific dangerous action before it executes, with proof afterwards$199–$3,999/moDecision point — evaluates the individual call before execution
BarzelOpsRunning real business workflows across HubSpot, Xero, Gmail, Drive and Slack under approvalFree, then $19–$199/moExecution layer — does the work the policy allowed
Barzel FinOps AtlasAttributing AI spend to agents, tools and outcomes, then forecasting and capping itFree, then $29–$799/moEconomics layer — what the estate costs per outcome
Barzel Scripture IntelligenceA free, credential-free public MCP server to test clients and inspect real protocol trafficFree, unmetered, no signupReference implementation — safe place to learn the protocol

Written by

Mark Alex

Founder of Real Biz Digital and architect of the Barzel ecosystem — five MCP servers published and callable in public. Software developer, technology entrepreneur and mechatronics engineer, working across AI agent governance, MCP security, AI infrastructure, FinOps and intelligent operations.