Use the Tool variant of the node
A node attached to an AI Agent must use the tool variant of its type. With the plain type the editor imports the node and silently drops the ai_tool connection, so the agent runs without the tool and improvises an answer instead of calling anything. It is the single most common reason an agent workflow looks connected and does nothing.
Fix what you know, let it choose what varies
Put the account, the provider and the safety rules in the node; let the model choose the recipient text or which conversation to read. Parameters marked from AI are filled by the model, the rest stays under your control — which is how you keep an agent from deciding to message someone you never meant to contact.
Give it reads generously and writes sparingly
Listing conversations, reading a thread, resolving a person: harmless, and the more of them the agent has, the better its answers. Sending, inviting, posting: one at a time, behind an explicit step. An agent with five read tools and one write tool is far more useful than one with eleven writes.
“Which conversations from this week still need an answer from me?”
“Find the right person at this company and tell me what we last discussed.”
The system prompt is not a safety mechanism
Asking the model to be careful is a suggestion. The refusals that matter are in the tools: an ambiguous recipient blocks the write, a stale identifier returns a corrective error naming what to call again, an ambiguous failure is not retried, and the daily budget is enforced server-side. Those hold whatever the prompt says or whatever the model decides.
Memory and the account are different things
Agent memory keeps the conversation with you; it does not know what happened on the account. Before answering a thread the agent should read it, not rely on what it remembers saying — which is also what stops it from replying twice when you already answered from your phone.
Common questions
Why does my agent ignore the Nilyo node?
Almost always the node type: the tool variant is required for an ai_tool connection, and with the plain type the connection is dropped on import without an error.
Which tools should I attach?
Reads generously, writes sparingly. The agent gets better with more context and more dangerous with more ways to send.
Can it use several accounts?
Yes. Each tool names the account it runs on, so one agent can hold LinkedIn, WhatsApp and a mailbox at once.
How do I stop it sending the wrong thing?
The tools refuse ambiguous writes and do not retry failed ones, and the daily budget is enforced outside the workflow. Put the write behind a human approval when the message is public-facing.
How LinkedIn works with Nilyo
Connection. Secure hosted sign-in (your LinkedIn credentials go to LinkedIn, never to the agent). Sales Navigator and Recruiter are detected automatically when your account has them.
What your agent can do. People and company search, profile lookup from a name or URL, your network and invitations, private conversations (classic, Sales Navigator, Recruiter inboxes), posts, comments and reactions, job postings and applicants, Recruiter projects.
Pacing and safety. About 100 actions per day per account, profile views and searches included; calls are serialized so an agent can never run LinkedIn requests in parallel.
- Profile URLs are resolved to stable profile IDs before any action.
- Invitations carry an optional note of up to 300 characters.
- Private or restricted profiles return an explicit “not accessible” result instead of a retry loop.
All LinkedIn guides
Related guides
Give Nilyo to your agent.
Paste one setup link. Your agent can guide OAuth, account connection and the first useful action.