The Amsterdam n8n meetup on 3 December 2025 was at a StartDock coworking space, in a small room that was packed by the start. In my autumn roundup I wrote that my photos showed nothing specific about the content. The recordings say otherwise, so this is the proper write-up of the two talks I recorded: a multi-agent marketing workflow built in n8n, and a âHack my Chatâ demo of guardrails.
I do not name the speakers. The event listings I could find for n8nâs Amsterdam meetups do not match these talks by date, and the names were not on any slide I photographed. Everything is my paraphrase of the recordings, and the figures are the speakersâ own.

The room at the start of the evening.
Eight agents building a book marketing campaign
The first speaker has no developer background. They said they worked as a bicycle courier when ChatGPT came out in November 2022, got hooked, started automating things with several platforms including n8n, and wrote about what they learned. That led to writing for a Dutch AI newsletter run by the tech entrepreneur Alexander Klöpping, and eventually to a request to build a demo for his television appearance: a team of AI agents producing a marketing campaign for a book, live on Dutch TV. The speaker said well over a million people watched, and that they had a video as backup. Dutch press coverage of the broadcast describes the same demo: an agent âagencyâ that produced a target-group analysis, strategy and visuals in about ten minutes (source).
The brief was awkward: about ten hours of work in the end, a week and a half before the show. The speaker proposed six to eight hours first, then estimated twenty to thirty in total, done in evenings and weekends next to a day job. They knew nothing about marketing campaigns, so they interviewed an LLM for the methodology of each role and turned the answers into seven long prompts.
The architecture
- Why multi-agent. Each agent gets one clean task and a thin context window. Ask one model to research the audience, design visuals, write copy and build the deck and the quality âwaters downâ; keep each agent on one job and you can push each further.
- The team. An orchestrator acting as campaign leader, plus a book expert, a creative strategist, a copywriter, a designer, a social and PR specialist and a quality reviewer. The campaign leader could call the other agents as tools. The output was a PowerPoint presentation.
- n8n structure. Each agent is its own workflow, and they call each other through the Execute Workflow tool. Prompts and instructions live in a database and are fetched at run time. The book was OCR-ed into text, so the workflow works with a real book, not a canned one.
- The show layer. Voice input came from an ElevenLabs agent that triggered a webhook. Discord was the visible channel where agents âtalkâ and tag each other. One bot changed its name and avatar per agent, which was easier than eight bots. The tags were purely visual, which the speaker called a trick, but also useful for seeing what is going on.
- Perceived speed. The book expert ran on Groq to bring answers from roughly 30 seconds to 7 to 10 seconds, according to the speaker. Different models were picked per task, and a small fast model posted an instant acknowledgement while the large one worked in the background.
What worked and what was hard
What worked: separation of concerns, visible collaboration for debugging, and flexibility from the visual builder compared with doing it in code. They also saw a model report that another provider was unreachable and carry on, which was nice to watch.
What was hard: prompt engineering per agent, sequencing so agents move the work forward without looping, and information degradation, the telephone-game effect when the same information is passed on step after step. Their fix was to let every agent ask the book expert directly at any time, and to keep follow-up questions inside the same conversation so the other model still has context.
Advice to beginners: start small. People had asked how to build a multi-agent crypto trader with it; the answer was please do not. And with models improving, multi-agent is not always the answer. It pays when you have specialised skills and reusable agents. Asked in the Q&A about the book, the speaker said loading the whole text into context worked well enough for a demo, though a RAG setup could also be used.
My take: the âthin context per agentâ argument is the strongest, and it matches multi-agent orchestration patterns I use with clients. The honest caveat they gave themselves is the useful one: for a real workload, start with one agent and split only when quality or reuse demands it.
Hack my Chat: guardrails in n8n
The second talk was an interactive session. A slide announced âHack my Chatâ, and the audience scanned a QR code to chat with an agent which had a secret it was told not to reveal, so people could try to jailbreak it before and after guardrails were added.

The âHack my Chatâ slide.
The presenter put guardrails between the chat input and the agent. Two kinds appeared:
- Rule-based sanitising with no AI. A hard-coded step that redacts secret keys, URLs and personal data such as email addresses before anything goes further, replacing them with placeholders (for example, the output says an email and an API key were removed). Putting it first means a later AI check never sees your secrets.
- AI-based checks, such as a jailbreak detector, and a scope check that only lets through topics the assistant should handle. The example was a real estate agent bot that should not answer where to get food: out-of-scope questions never reach the agent.
This matches the n8n Guardrails node documentation, which has a âcheck textâ mode and a âsanitize textâ mode, and separates rule-based guardrails (PII, secret keys, URLs, keywords, regex) from LLM-based ones (jailbreak, NSFW, topical alignment). After adding the jailbreak guardrail, the presenter said the agent would be much harder, but not impossible, to hack.
My take: layering cheap deterministic filters before an LLM judge is the right order: it is cheaper, predictable, and keeps secrets out of third-party models. It is not a full defence, so keep least-privilege tools underneath, as covered in AI agent guardrails for production.