4 ready-to-build workflows

AI agent workflows for Mental wellbeing & healthy routines

Reminders, your own journalling prompts, and better-prepared appointments — a logistics aid that supports professional care and never pretends to be it.

Each recipe below is expressed only in VegaDūta's real workflow building blocks — Trigger, Agent, Knowledge, Condition, Approval, Output, Tool (MCP), Voice, Device, Loop, Code and Parallel — so it maps 1:1 to something you can assemble in the Workflow designer. Consequential actions always pass a human Approval step.

1. End-of-day reflection, in your own words, kept to yourself

You jot a line about how the day went into a notes app, or into a chat with yourself, and then never look at it again. The prompts you meant to answer are in a book on a shelf; the app you downloaded wants a subscription and a mood score out of ten. By the time you next see a professional, three weeks have blurred together and you can't remember what you wanted to say.

Trigger: Scheduled (evening) → WhatsApp / Telegram / SMS

How the workflow runs

  1. Trigger

    A scheduled nudge, at a time you set. A scheduled trigger fires on the days and at the hour you chose, on the channel you chose (WhatsApp, Telegram or SMS). You can pause or stop it from the same thread — this is a reminder you own, not a streak you owe anyone.

  2. Knowledge

    Your own prompt set. A Knowledge node holds the reflection prompts YOU wrote or pasted in — for example the homework a therapist actually gave you. The agent asks your prompts. It does not generate therapeutic exercises of its own.

  3. Agent

    Asks the prompts, records the answer verbatim. An Agent node asks one or two of your prompts in plain language and writes your reply down as you said it. It does not score, rate, interpret or reply with an assessment of how you seem — it is taking dictation for you, nothing more.

  4. Condition

    Crisis wording → hand off immediately. A Condition node checks for wording that suggests risk of self-harm, suicide or abuse. On any match it stops the reflection flow at once and hands to the crisis sub-workflow. It never continues the journalling conversation and never tries to talk you through it.

  5. Sub-workflow

    Crisis path (see the escalation recipe). A Sub-workflow node calls the safe-escalation route. That path is never gated by an Approval node and never rate- or cost-limited — it always runs.

  6. Output

    Filed privately, in your tenant. An Output node stores the entry in your own tenant, visible only to you. Nothing is shared with a family member, a clinician or anyone else unless you send it yourself through an explicit Approval step.

Channels & connectors

  • WhatsApp
  • Telegram
  • SMS / Twilio
  • Knowledge base
  • Sarvam (Indian languages)

Outcome

A short, private record in your own words that you can actually find later and take to an appointment. It is a diary, not a clinical assessment, and no part of it is a diagnosis or an opinion about your mental health.

Why it helps

The mechanism is memory and friction, not treatment: the prompt arrives on a channel you already read, the answer is captured before the day blurs, and it is stored where you can retrieve it. Whether that is useful to you is between you and a professional.

Build spec

1 agent1 reflection agent that asks your prompts and records the answer. The crisis check is a Condition node; the escalation is a Sub-workflow node; the schedule and the private write are workflow nodes. · Pattern: Scheduled prompt → verbatim capture → hard crisis branch → private store

System prompt (paste-ready)

You help {{user}} keep a private end-of-day note. Ask ONE or TWO of the reflection prompts stored in Knowledge — these are the user's own prompts; never invent a therapeutic exercise, never substitute your own. Record the answer VERBATIM in the field 'entry'. You must NOT diagnose, interpret, score, rate, or comment on the user's mental state, mood or progress. Do not analyse anyone else the user mentions. Do not discuss medication, dosage or whether to take anything. If the user asks you for therapy, counselling or a clinical opinion, say plainly that you cannot give one, that you are a note-keeping tool, and that a professional is the right place for it. If any wording suggests risk of self-harm, suicide or abuse, STOP: do not counsel, do not reassure, do not ask follow-up questions to gauge how serious it is — hand straight to the crisis sub-workflow.

Agent roles & model tiers

  • Reflection scribe (once per evening) Economy tier — this is a short, structured capture, not a reasoning task

    Ask the user's own stored prompts; write the reply down word for word; add no interpretation, no summary judgement, no score. Never diagnose, never counsel, never mention medication. On any crisis wording, stop and hand off.

MCP connectors

  • None. This runs on first-party channels only (WhatsApp / Telegram / SMS) and the tenant's own Knowledge base — a private journal is not a good place to add third-party systems.

Built-in tools

  • knowledge_search (the user's own reflection prompts, and nothing generated by the platform)

Guardrails

  • NOT A THERAPY PRODUCT: the agent does not diagnose, does not provide therapy or counselling, and gives no advice on medication or dosage — ever, under any phrasing of the request
  • It does not assess or interpret the user's mental state, assign a mood score, or judge progress; and it never analyses a THIRD party's mental health from the user's description of them
  • It is a logistics and reflection aid — reminders, organisation, journalling prompts the user chose, and preparation for real appointments. It supports professional care; it never replaces it and must never be used to delay it
  • Nothing it produces is a clinical assessment, and the entry is labelled as a personal note wherever it is shown
  • Crisis wording is never counselled, de-escalated or graded here — the Condition node hands straight to the crisis sub-workflow, which is never behind an Approval node and never rate- or cost-limited
  • PRIVACY: this is among the most sensitive data a person has. Entries stay in the user's own tenant, are never used for marketing or model training, and are never shared with a family member or clinician without an explicit Approval step the user takes themselves
  • CONSENT: the schedule is the user's own and can be paused or deleted from the same thread. No other adult is monitored, notified or reported to by this workflow

Cost strategy

Economy tier is the right and honest choice: one short call per evening, no batch, no reasoning burden. Deliberately keep the crisis Condition node OUTSIDE any cost or rate cap — the escalation path is the one place where budget controls must not apply.

Output & delivery

The scheduled trigger sends your own prompts on your channel → the agent records your answer verbatim → the Condition node hands any crisis wording straight to the escalation sub-workflow → an Output node files the entry privately in your tenant, shareable only by you, through an explicit Approval step.

2. Sleep, hydration, movement and medication REMINDERS (reminder only)

The pharmacist's advice is on a folded slip in a drawer. The physio's exercises were done twice. You set three phone alarms, learned to swipe them away without reading them, and turned them off in week two. Nobody is tracking whether the water bottle got refilled, and the tablet you take at night is remembered or not depending on how the evening went.

Trigger: Scheduled (per routine) → WhatsApp / SMS / Voice

How the workflow runs

  1. Trigger

    Each routine on its own schedule. Scheduled triggers fire per routine — a wind-down nudge, a water reminder, the physio set, the evening tablet reminder — each at the time you set, on the channel you picked.

  2. Knowledge

    Your reminder text, exactly as you entered it. A Knowledge node holds the reminder wording YOU entered (or copied from a prescription label or a physio sheet). The agent repeats that text. It never composes medical instructions and never restates a dose in its own words.

  3. Voice

    Optional voice or local-language delivery. For a reminder that gets missed as text, an ElevenLabs voice call or a Sarvam-rendered message in your own language can carry it instead. Same words, different channel — no added advice.

  4. Tool (MCP)

    User-defined tool: check-in streak band (neutral). A tenant-authored user-defined tool — a SpEL expression over the tool's JSON input, e.g. checkin_streak_band: input.daysLogged >= 7 ? 'STEADY' : 'PATCHY'. It is a data-transform/formula tool, sandboxed by construction (no method calls, no constructors, no bean or type references, no loop in the grammar) — not a scripting engine. It counts logged days. It must NEVER be used to score severity, risk or symptoms.

  5. Condition

    A medication QUESTION is not a reminder. A Condition node catches anything that is a question rather than a tick — 'should I double up?', 'can I skip tonight?', 'is this dose right?'. The agent answers none of them. It says so plainly and points to the prescriber or pharmacist.

  6. Output

    A tick, and a private log you can read back. An Output node records a simple done / not-done against the routine, in your own tenant. That log is yours to read — and yours to take to a professional if you want to.

Channels & connectors

  • WhatsApp
  • SMS / Twilio
  • Voice / Call
  • ElevenLabs (voice)
  • Sarvam (Indian languages)
  • Knowledge base

Outcome

The reminders you meant to keep actually arrive, in your words, on a channel you read — plus a plain done / not-done log. It is a reminder and a tick-list, not treatment, not monitoring, and not a clinical assessment.

Why it helps

The mechanism is delivery and record-keeping: the nudge reaches a channel you already use rather than a dismissed alarm, and the tick is captured at the moment rather than reconstructed later. It makes no claim about health outcomes, because we cannot make one.

Build spec

1 agent1 reminder agent. The schedules, the medication-question gate, the streak-band formula tool and the private log are workflow nodes and tenant configuration. · Pattern: Scheduled reminder → verbatim delivery → question gate → private tick log

System prompt (paste-ready)

You deliver {{user}}'s own routine reminders. Send the reminder text EXACTLY as stored in Knowledge — you may add nothing to it. For a medication reminder you may only say that it is time for the item as the user labelled it; you must NEVER state, confirm, convert, adjust or discuss a dose, a frequency, an interaction, a side effect, or whether to take, skip or double anything. If the user asks any of that, reply that you cannot advise on medication and that their prescriber or pharmacist is the right person, then stop. Do not diagnose, do not interpret how the user is doing, do not comment on their mental state, and do not analyse anyone else. Record only done / not-done and any free-text note the user chooses to add, verbatim. If any wording suggests risk of self-harm, suicide or abuse, hand straight to the crisis sub-workflow — do not counsel and do not assess.

MCP connectors

  • None required. If a clinic or pharmacy system holds the schedule, it reaches the workflow as an inbound Webhook and/or a Tool (MCP) node — there is no first-party connector for it, and it is labelled as such wherever it appears.

Built-in tools

  • knowledge_search (the user's own reminder wording — never platform-generated medical text)
  • user-defined tool checkin_streak_band (SpEL): input.daysLogged >= 7 ? 'STEADY' : 'PATCHY' — a neutral count of logged days, never a severity, risk or symptom score

Guardrails

  • NOT A THERAPY PRODUCT: the agent does not diagnose, does not provide therapy or counselling, and gives no advice on medication or dosage — ever. It reminds; it never instructs
  • It does not assess or interpret the user's mental state, and it never analyses a THIRD party's mental health from someone else's description
  • MEDICATION IS REMINDER-ONLY: the agent repeats the user's own stored wording and may never state, convert or adjust a dose, discuss frequency, interactions or side effects, or answer whether to take, skip or double anything. Every such question is refused and routed to the prescriber or pharmacist
  • The user-defined SpEL tool is a data-transform/formula only (no method calls, no constructors, no bean or type refs, no loop in the grammar). It bands a count of logged days. It must NEVER be used to score severity, risk or symptoms — that would be a clinical judgement dressed as arithmetic
  • It is a logistics aid supporting professional care; nothing it produces is a clinical assessment, and it must never be used to delay seeing someone
  • Crisis wording is never counselled or graded — it hands straight to the escalation sub-workflow, which is never behind an Approval node and never rate- or cost-limited
  • PRIVACY: the routine log is among the most sensitive data a person has. It stays in the user's own tenant, is never used for marketing, and is never shared with family, employer or clinician without an explicit Approval step
  • CONSENT: this is the user's own routine, set up by them and stoppable by them. It never reports adherence to another adult, and no other adult is monitored by it

Cost strategy

Economy tier throughout — these are short, templated deliveries, and volume is a handful of calls a day. Voice (ElevenLabs) costs more per delivery, so reserve it for the one or two reminders that genuinely get missed as text. The crisis branch sits outside every cost cap and rate limit by design.

Output & delivery

Each routine fires on its own schedule → the agent delivers your own wording on WhatsApp, SMS or voice → any medication question is refused and pointed at your prescriber → the tick is written to a private log in your tenant, with a neutral streak band from the SpEL tool and no clinical interpretation attached.

3. Before and after an appointment: your questions, and what was agreed

The appointment is at 3pm and you remember it at 2:40. You had three things you wanted to raise and you leave having raised one. A week later you cannot recall whether the next review was six weeks or eight, or what you agreed to try in the meantime — so you do neither, and the next appointment starts from scratch.

Trigger: Scheduled (before appointment) + Webhook (clinic/booking system, labelled) / Email

How the workflow runs

  1. Trigger

    Appointment is coming up. A scheduled trigger fires ahead of the appointment. If the date comes from a clinic or booking system, it arrives as an inbound Webhook and/or is read via a Tool (MCP) node — there is no first-party connector for those systems, and it is labelled as such.

  2. Knowledge

    Your own notes since last time. A Knowledge node retrieves what YOU logged — your reflection entries, your routine ticks, the things you noted to raise. Only your own material; nothing inferred about you and nothing about anyone else.

  3. Agent

    Draft a question list — your words, tidied. An Agent node assembles your own noted points into a short list you can take in with you. It groups and orders them; it does not add clinical questions of its own, does not rank them by importance, and does not suggest what the answer might be.

  4. Output

    Facts you logged, stated as facts. Alongside the questions, an Output node can surface your own logged patterns plainly — for example 'on 6 of the 9 days you marked hard, you had also logged under 6 hours of sleep'. That is a count of what you wrote down. It is information for YOU to take to a professional, explicitly not an interpretation, a correlation claim or a diagnosis.

  5. Output

    After: what was agreed, in your words. After the appointment the agent asks what was agreed and records your answer verbatim — the next review date, anything you said you would try. It does not evaluate the plan, does not restate a dose, and does not offer an opinion on it.

  6. Condition

    Follow-ups scheduled from your answer. A Condition node turns a stated next-review date into a reminder, and anything left open into a single follow-up nudge. If nothing was agreed, nothing is invented.

Channels & connectors

  • Webhook (clinic / booking system — no first-party connector)
  • Tool (MCP → clinic / EHR / booking system)
  • Email
  • WhatsApp
  • Knowledge base
  • Sarvam (Indian languages)

Outcome

You walk in with the list you meant to bring and walk out with the next date and what you said you would try, both in your own words. None of it is a clinical assessment — it is your notes, organised, for a professional to work from.

Why it helps

The mechanism is recall, not insight: the questions were yours and are simply in front of you at the right moment, and what was agreed is captured while you still remember it. The counts we show back are counts of what you logged — nothing is inferred, and any meaning in them is for a professional to judge.

Build spec

1 agent1 preparation agent, run twice — once before the appointment, once after. The retrieval, the follow-up scheduling and the private store are workflow nodes. · Pattern: Pre-appointment assembly → post-appointment verbatim capture → follow-up scheduling

System prompt (paste-ready)

You help {{user}} prepare for and record a real appointment with a professional. BEFORE: assemble the points the user themselves logged into a short, plain question list, grouped and ordered for a short appointment. You may reorder and de-duplicate the user's own words; you may NOT add clinical questions of your own, rank the items by importance, or hint at what an answer might be. You may also state counts drawn strictly from the user's own logs (e.g. 'on 6 of the 9 days you marked hard, you had also logged under 6 hours of sleep'), labelled clearly as a count of what they wrote, NOT a finding, a correlation or an explanation. Draw no conclusion from it. AFTER: ask what was agreed and record the answer VERBATIM; capture a next-review date if one was given. Never evaluate, endorse or question the plan; never restate a dose or discuss medication; never diagnose or interpret the user's mental state; never analyse anyone else. If any wording suggests risk of self-harm, suicide or abuse, hand straight to the crisis sub-workflow without counselling or assessing.

Agent roles & model tiers

  • Preparation agent (pre-visit) Standard tier — it is grouping and ordering the user's own text, and the failure mode to avoid (adding content of its own) is worth the better instruction-following

    Group and order only what the user logged. Add nothing clinical. State counts as counts, never as findings. No ranking, no interpretation, no suggested answers.
  • Capture agent (post-visit) Economy tier — verbatim capture plus a date

    Record what the user says was agreed, word for word, and extract a next-review date if stated. Do not comment on the plan, do not restate any dose, do not summarise it into advice.

MCP connectors

  • Clinic / EHR / booking system (appointment date, and only if the user has connected it) — via inbound Webhook and/or a Tool (MCP) node; no first-party connector exists and it is labelled as such
  • Email / WhatsApp — the reminder and question-list channel

Built-in tools

  • knowledge_search (the user's own logged notes and reminder history — their material only)
  • http_request (read the appointment date from a connected clinic/booking system, if the user set one up)

Guardrails

  • NOT A THERAPY PRODUCT: the agent does not diagnose, does not provide therapy or counselling, and gives no advice on medication or dosage — ever. It prepares you to talk to someone who can
  • It does not assess or interpret the user's mental state. Patterns are shown as literal counts of what the user logged, explicitly not as findings, correlations, causes or a diagnosis — they are information to take TO a professional, and the copy says so
  • It never analyses a THIRD party's mental health from the user's description, including a clinician, a family member or anyone discussed in the appointment
  • The question list contains the user's own points only — the agent may reorder and de-duplicate, never add clinical questions, rank them by importance, or suggest what the answer will be
  • What was agreed is recorded verbatim and never evaluated, endorsed, questioned or converted into instructions. No dose is ever restated by the agent
  • It supports professional care and must never be used to replace or delay it; nothing it produces is a clinical assessment
  • Crisis wording is never counselled or graded — it hands straight to the escalation sub-workflow, which is never behind an Approval node and never rate- or cost-limited
  • PRIVACY: appointment notes are among the most sensitive data a person has. They stay in the user's own tenant, are never used for marketing, and are never sent to a clinic, an insurer, an employer or a family member without an explicit Approval step
  • CONSENT: this workflow is run by and for the person attending the appointment. It never monitors another adult and never reports attendance or content to anyone

Cost strategy

Two short runs per appointment — a standard-tier assembly pass and an economy-tier capture pass. There is no batch and no multiplier, so total spend is trivial; put the reasoning budget in the pre-visit pass, where adding content that was not the user's is the real risk. The crisis branch is outside all cost caps.

Output & delivery

A short question list in your own words before you go in, an optional plain count of what you logged (labelled as a count, not a finding), a verbatim record of what was agreed afterwards, and a reminder for the next review — all stored privately in your own tenant.

4. Crisis wording → official help and a real human, immediately

Someone types something frightening into a chat at 1am. Today, whatever is on the other end either keeps talking to them — which is the wrong thing for software to do — or does nothing at all. The number for the national helpline is somewhere in a browser tab from six months ago, and the friend who said 'call me any time, seriously' has never actually been called.

Trigger: Any inbound message on any configured channel (always on, never gated)

How the workflow runs

  1. Trigger

    Any inbound message, on any channel. This path sits in front of every wellbeing workflow — the evening reflection, the routine reminders, the appointment prep — and on any channel the tenant has configured (WhatsApp, SMS, Telegram, Voice, Email).

  2. Condition

    Wording match → route. No grading, no judgement call. A Condition node routes on wording that suggests risk of self-harm, suicide or abuse. It does NOT rate severity, estimate intent or decide whether it is 'serious enough'. Any match routes, full stop. False positives are expected and acceptable — showing someone a helpline they did not need costs nothing.

  3. Knowledge

    The tenant's own official crisis resources. A Knowledge node returns the crisis resources the tenant stored in advance for the user's region — taken from the official current publication of that country's health authority or recognised helpline body. Many countries operate a national mental-health helpline; the tenant configures theirs. NO NUMBER IS HARDCODED in this guide, in the prompt or in the model, and the agent may never recall one from memory: numbers vary by country and change over time, and a wrong number is worse than none. Set this up while well, and review it on a schedule.

  4. Output

    Surface the official resources, verbatim, at once. An Output node returns the stored resources exactly as written, immediately, in the user's language (Sarvam for Indian languages). The message says plainly that this is software, that it cannot help with this, and who can. It does not ask a follow-up question.

  5. Output

    Reach the human the user chose in advance. In parallel, an Output node contacts the trusted person or professional service the user nominated while well — by SMS, a voice call, or both. They are told the user asked for them now; the content of the message is not forwarded unless the user set it up that way.

  6. Output

    Tell the user who was contacted, then stop. The user is told plainly who has been notified. The agent then stops talking. It does not counsel, does not de-escalate, does not attempt to keep the person talking, and does not follow up with questions — every one of those is unsafe and out of scope for software.

Channels & connectors

  • WhatsApp
  • SMS / Twilio
  • Voice / Call
  • Telegram
  • Email
  • Knowledge base (tenant's own official crisis resources)
  • Sarvam (Indian languages)

Outcome

Official, tenant-verified help is on screen within seconds and a real human the user chose is contacted straight away. This is a routing step, not care and not a clinical assessment — the help comes from the helpline and the person, never from the agent.

Why it helps

The mechanism is speed and pre-commitment: the decisions that are hard at 1am — which number, who to call — were made in advance while well, and the software only executes them. It makes no claim to help anyone through a crisis, because software cannot and must not try.

Build spec

1 agent1 minimal agent whose only job is to deliver stored text and trigger the notifications. It is deliberately the least capable agent in this section — there is no reasoning task here, and reasoning is exactly what must not happen. · Pattern: Always-on wording match → stored official resources + notify pre-chosen human → stop. No approval gate anywhere in this path.

System prompt (paste-ready)

You are a routing step, not a helper. If this path has fired, output the crisis resources retrieved from Knowledge EXACTLY as written, with no edits, no additions and no reordering, and state plainly: that you are software, that you cannot help with this, and that the listed service and the user's chosen contact can. You must NEVER counsel, reassure, de-escalate, empathise at length, ask how serious it is, ask what happened, or try to keep the user talking — all of these are unsafe and out of scope. You must NEVER assess risk or severity, and you must NEVER output a helpline number that is not in the retrieved Knowledge result; if Knowledge returns nothing, say the resources are not configured, urge the user to contact local emergency services or a trusted person now, and notify the configured contact anyway. Say who has been contacted. Then stop.

MCP connectors

  • None. Nothing in this path may traverse a third-party system: no external logging, no analytics, no CRM, no MCP tool. It stays in the user's own tenant and goes only to the people the user chose.

Built-in tools

  • knowledge_search (the tenant's own official, current, region-specific crisis resources — the ONLY permitted source of a number)
  • Notification to the pre-configured trusted contact / professional service over SMS, Voice or both

Guardrails

  • NO COUNSELLING, EVER: on any crisis wording the agent must NOT counsel, de-escalate, assess severity, ask what happened, or try to keep the person talking. Any such attempt is unsafe and out of scope. It surfaces help and routes to a human, then stops
  • NOT A THERAPY PRODUCT: no diagnosis, no therapy or counselling, no advice on medication or dosage — ever. It does not assess or interpret anyone's mental state, and it never analyses a THIRD party's mental health from someone else's description
  • It is a logistics aid — it delivers pre-stored information and contacts a pre-chosen person. It supports professional care and never replaces or delays it; nothing here is a clinical assessment, and the user-facing message says so in plain words
  • NO HARDCODED NUMBERS: helpline details come ONLY from the tenant's own Knowledge base, sourced from the region's official current publication and reviewed on a schedule. The model may never recall a number from memory, and none is written into this guide or the prompt — numbers vary by country and change over time, and a wrong number is worse than none
  • NEVER GATED: this path must not sit behind an Approval node, a rate limit, a quota, a cost cap or a plan tier. It always runs. This is the one place where 'add a human in the loop later' is the wrong design — the human here is the person being called, not an approver standing between the user and help
  • NO THIRD PARTIES: crisis content is never logged to, transmitted to or analysed by any external system, analytics tool, MCP connector or model-training pipeline. It stays in the user's own tenant and reaches only the contacts the user chose
  • The wording match routes; it does not grade. False positives are by design — the failure mode to avoid is missing one, not showing a helpline to someone who did not need it
  • PRIVACY: this is the most sensitive data the platform will ever hold. The trusted contact is told the user asked for them, not the content of the message, unless the user configured otherwise while well. Nothing is shared with anyone else without an explicit Approval step, and it is never used for marketing
  • CONSENT: the trusted contact and the escalation route are chosen by the user in advance, while well, and can be changed or removed by them at any time. No other adult is monitored, and no one is added to this path without the user's own agreement

Cost strategy

This path is NEVER cost-optimised and NEVER rate-limited. Economy tier is right for routine reminders elsewhere in this section; here, model choice, spend caps, quotas and plan tiers are all irrelevant by policy — the path runs regardless of budget state, and any cost control that could block it is a misconfiguration.

Output & delivery

Wording match → the tenant's own official crisis resources returned verbatim in the user's language, immediately → the pre-chosen trusted contact or professional service notified by SMS and/or voice → the user told who was contacted → the agent stops. No approval gate, no rate limit, no third-party system anywhere in the path.

Related industries

Build one of these in minutes

The sandbox gives you a live agent workspace — no account, no card. Or head back to the full catalogue and compare patterns across every industry.

See how VegaDūta compares to n8n, Dify and BotpressWhy VegaDūta's architectureEstimate your WhatsApp API costs