Whetstone.
Building a Deep AgentWhat a deep agent actually is
Module 1, Lesson 120 min

What a deep agent actually is

A deep agent is an agent with a filesystem, memory, skills and the ability to delegate. deepagents packages that pattern so you do not have to wire it yourself.

Three layers, strictly stacked

LangGraph is the graph runtime. LangChain’s create_agent is a minimal agent harness on top of it. Deep Agents is a more opinionated harness on top of create_agent.

Not three competing products. Not three ways to do the same thing. Each layer is literally built out of the one below, which has a consequence people get wrong constantly: the higher layers have no powers the lower ones lack.

The mechanical truth

create_deep_agent is create_agent plus a fixed middleware stack, in this order:

The deep agent middleware stack
Skills -> Filesystem -> SubAgent -> Summarization -> PatchToolCalls -> your middleware -> tail

Plus six extra parameters on top of the entire create_agent surface:

What create_deep_agent adds
subagents     # delegable child agents, invoked through the task tool
skills        # on-demand SKILL.md capabilities (module 3)
memory        # always-loaded instruction files (module 3)
permissions   # filesystem access rules (module 2)
backend       # where the filesystem and execution live (module 2)
interrupt_on  # which tools pause for human sign-off (lesson 7)

Plus eight default tools already registered: ls, read_file, write_file, edit_file, glob, grep, execute, task, with delete joining the filesystem set in v0.7.

That is the entire product. Read the three lines above and you have read the library.

Currency: the v0.7 boundary

deepagents v0.7 shipped 29 July 2026 and changed a default that older material still assumes. In its own words: “TodoListMiddleware is now opt-in… we removed the write_todos tool from the base harness.”

The rest of v0.7, briefly: base system prompt now empty, tool descriptions trimmed by roughly 43 percent, base input tokens down roughly 65 percent, backend factories removed, delete added to the default filesystem tools.

Know both states. Through v0.6, planning was in the base harness. From v0.7, it is opt-in. If a question implies write_todos is present by default, the honest read is that the question was written against the older behaviour, not that you have misremembered. That is a genuinely useful thing to be able to think under time pressure, because the alternative is second-guessing a fact you actually know.

Why “assembly, not capability” keeps coming back

You will meet this claim in four more places: the tools lesson, the execution environment, the skills and memory split, and delegation. Every one of them is the same shape. A deep agent parameter is a shortcut to a middleware you could have imported yourself.

Hold that and the whole course reads as one idea with five faces, rather than five features to memorise separately.

Practice

Try it yourself

Recall

The three-layer sentence

This is the single most quotable line in the domain. A surprising number of questions collapse into it, so it is worth being able to say cold rather than reconstruct.

Describe the relationship between LangGraph, LangChain's create_agent, and Deep Agents, in one sentence each.

Reveal answer

LangGraph is the graph runtime. LangChain's create_agent is a minimal agent harness on top of it. Deep Agents is a more opinionated harness on top of create_agent. Each layer is built out of the one below, so nothing higher up has powers the lower layer lacks. It simply ships more assembled.

Quiz

The fixed middleware stack

A deep agent is create_agent plus a fixed middleware stack. One of these orderings is the real one.

Candidate orderings
A. Filesystem, Skills, SubAgent, Summarization, PatchToolCalls, yours, tail
B. Skills, Filesystem, SubAgent, Summarization, PatchToolCalls, yours, tail
C. Skills, Filesystem, Summarization, SubAgent, yours, PatchToolCalls, tail
D. yours, Skills, Filesystem, SubAgent, Summarization, PatchToolCalls, tail
  1. AOrdering A
  2. BOrdering B
  3. COrdering C
  4. DOrdering D
Show answer

Correct answer: B — Ordering B

The stack is Skills, Filesystem, SubAgent, Summarization, PatchToolCalls, your middleware, then the tail. Ordering D is the genuinely tempting one, because most middleware systems you have used put your own handlers outermost so they can wrap everything. Here your middleware slots in near the end, after the built-ins, which changes when your hooks fire relative to theirs.

Quiz

Which one is inherited

create_deep_agent takes the entire create_agent surface plus a specific set of additions. One of these is not an addition.

  1. Astore
  2. Bsubagents
  3. Cpermissions
  4. Dinterrupt_on
Show answer

Correct answer: A — store

store is already a create_agent parameter, handed through from the graph runtime, so it is inherited rather than added. The additions are subagents, skills, memory, permissions, backend and interrupt_on. store is a good trap because long-term persistence feels like exactly the sort of heavyweight machinery a long-running-agent product would introduce, so it pattern-matches to the advanced constructor.

Quiz

The v0.7 planning change

deepagents v0.7 shipped on 29 July 2026 and moved a default that older study material still assumes. What exactly changed?

  1. Awrite_todos was renamed to plan_tasks and kept in the base harness
  2. BTodoListMiddleware was deleted from the library and cannot be re-added
  3. CTodoListMiddleware became opt-in, and write_todos left the base harness
  4. DTodoListMiddleware became mandatory and can no longer be removed
Show answer

Correct answer: C — TodoListMiddleware became opt-in, and write_todos left the base harness

v0.7 made TodoListMiddleware opt-in and removed write_todos from the base harness. The middleware still exists and you can still ask for it. Deletion is the tempting reading because the release note says the tool was removed from the base harness, but that is a statement about the default stack rather than about the library. Removed from a default and removed from existence are different claims, and the exam can test either direction.

Recall

The default tool set

Worth having cold, because it tells you what a deep agent can reach for before you register a single tool of your own.

Name the tools a deep agent ships with by default, and say which one depends on the backend.

Reveal answer

ls, read_file, write_file, edit_file, glob, grep, execute and task, with delete added to the default filesystem tools in v0.7. execute is the one that depends on the backend, because in Deep Agents sandboxes are backends and the backend is what grants execution. task is the subagent handoff tool. That is a filesystem, a search facility, an execution facility and a delegation facility, out of the box.

Check

Hand-assemble one on paper

In a scratch file, write the create_agent call you would need in order to reproduce a deep agent yourself, listing the middleware in stack order.

You should see

Your middleware array is in the documented order, your own middleware sits after the built-ins rather than first, and you can state in one sentence what capability you gained that create_agent lacked. The correct answer to that last part is none.

Sign in to track your progress →