# Building AI Apps and Agents

> An online, self-paced AI course from ARFA, the TIBLOGICS AI Academy. Advanced level, about 23 hours, in English and French, with a verifiable certificate.

Web page: https://tiblogics.com/learning-box/ai-apps-agents · All tracks: https://tiblogics.com/learning-box.md

## Key facts

- Level: Advanced
- Time: about 23 hours including hands-on work (6 modules, 27 lessons, 8 labs); self-paced, no deadline
- Price: $897 one time for lifetime access to this track, or every track for $89 a month (cancel anytime)
- Certificate: TIBLOGICS Certified AI App and Agent Builder, with a public verification page
- Languages: English and French

## About

Getting a model to produce something impressive once takes an afternoon. Building an AI feature that is reliable, safe, affordable and understandable by the next developer is engineering, and that is what this track teaches. You will call models from code the professional way (messages, system prompts, tokens and cost, streaming, retries with backoff, keys kept on the server), get structured output you can trust, give models tools and run the agent loop with proper stop conditions, connect tools and data through the Model Context Protocol, handle images, documents and audio with a validated extraction pipeline, build retrieval-augmented generation with citations and access control, and decide when an agent is the right design at all. Then you will prove it works with eval sets and regression tests, defend it against prompt injection and data exfiltration, run a 30-door pre-launch security audit on the whole app (keys, access, input, webhooks, tools, agent configs, spending and recovery), and ship and operate it with sensible architecture, cost control, monitoring and handover. It is vendor-neutral, with examples from several providers and open-source models, and hands-on throughout: Code Studio labs where you build a retry-safe client, a JSON validator with repair, a tool-calling loop with a step budget and a mini RAG pipeline against mock models, plus design reviews and an evaluation plan. The capstone is a small AI feature or agent of your own, documented with an eval set, a security review, a cost estimate and a system map, reviewed by a person. Skills this track builds also appear in cloud AI engineer associate certifications and AI developer courses from model providers. This track is independent: it is not affiliated with any vendor and is not official exam preparation.

Who it is for: Developers and technical builders who are comfortable with basic JavaScript or Python and want to build reliable AI features and agents: product engineers adding AI to an app, technical founders, data and automation engineers, and solution builders.

## What you will be able to do

- Call model APIs from server code with correct messages, sensible parameters, retries with backoff and cost tracked from token usage
- Get structured output you can trust, and design tools, agent loops and MCP connections with clear stop conditions and least privilege
- Build retrieval-augmented generation with sound chunking, hybrid search, citations and access control, and evaluate retrieval and generation separately
- Choose between workflows and agents, and add memory, human approval, guardrails and budgets so agents fail safely
- Evaluate AI features with eval sets, calibrated judges and regression tests, and defend them against prompt injection and data leaks
- Run a 30-door pre-launch security audit on an AI app: keys, server-side auth and ownership, webhooks, tool limits, agent configs, spending caps, log redaction and tested restores
- Ship and operate AI features with the right architecture, cost controls, monitoring, incident response and a system map for handover

## Curriculum

### Module 1: Calling Models from Code

What actually happens when your code calls a language model: messages and roles, system prompts, parameters, tokens and cost, streaming, and the errors, rate limits and retries every production call must handle, with keys kept on the server.

- How a model call works: messages, roles and system prompts (26 min)
- Parameters, tokens and what a call costs (27 min)
- Streaming and the user experience (24 min)
- Errors, rate limits, retries and keeping keys server-side (28 min)
- Module quiz

### Module 2: Structured Outputs and Tools

Get output your code can trust: JSON with validation and repair, tool (function) calling, the agent loop that runs tools until the job is done, and how to design tools and connect them through the Model Context Protocol (MCP), and how to handle images, documents and audio as inputs.

- Structured outputs: JSON you can trust after you validate it (27 min)
- Tool calling: letting the model ask your code to act (28 min)
- The agent loop: call, act, return, stop (29 min)
- Designing tools a model can use well, and connecting them with MCP (26 min)
- Images, documents and audio: multimodal inputs and extraction (27 min)
- Module quiz

### Module 3: Retrieval-Augmented Generation

Answer from your own documents rather than the model's memory: chunking, embeddings, vector and hybrid search, grounding with citations, evaluating retrieval separately from generation, keeping data fresh and enforcing access control on documents.

- Why retrieval, and how to chunk documents (27 min)
- Embeddings, vector search and hybrid search (29 min)
- Grounding, citations and saying "I don't know" (26 min)
- Evaluating, refreshing and securing a RAG system (28 min)
- Module quiz

### Module 4: Agents That Work in Production

Move from demo to dependable: choose a workflow or an agent on purpose, plan multi-step tasks, give agents the right memory, put humans at the right checkpoints, add guardrails, budgets and timeouts, and treat multi-agent designs with caution, seeing the loops and failure modes as a system.

- Workflow or agent? Choosing the least autonomy that works (27 min)
- Planning, multi-step tasks and memory (28 min)
- Human approval, guardrails, budgets and timeouts (29 min)
- Multi-agent patterns and how agent systems fail (28 min)
- Module quiz

### Module 5: Evaluation, Safety and Security

Prove an AI feature works and keeps working: eval sets and automated checks, LLM-as-judge used with care, regression testing on every change, defences against prompt injection and data exfiltration, output filtering, and logging that respects privacy.

- Eval sets and automated checks (28 min)
- LLM-as-judge and regression testing (27 min)
- Prompt injection and data exfiltration (30 min)
- Output filtering, logging and privacy (26 min)
- The 30 doors before launch, part 1: keys, access, input and webhooks (30 min)
- Module quiz

### Module 6: Shipping and Operating AI Features

Run AI features reliably and affordably: server routes, queues and caching, prompt caching and batch processing, choosing the cheapest model that does the job, monitoring quality and cost, responding to incidents, and handing over documentation and a system map.

- Architecture: server routes, queues and caching (28 min)
- Cost control: prompt caching, batching and model routing (28 min)
- Monitoring quality and cost, and responding to incidents (27 min)
- Documentation, handover and your system map (25 min)
- The 30 doors before launch, part 2: models, tools, agents and recovery (30 min)
- Module quiz

## How you are assessed

- A quiz after each module (80% to pass, retakes allowed).
- A timed final exam: 35 questions in 60 minutes, 75% to pass, 90% for distinction, 3 attempts.
- A capstone project reviewed by a person against a published rubric (70% to pass).
- Each certificate has a public page at https://tiblogics.com/certificates/<reference> that anyone can open to check it.
