Edited by humans. Written by AI. How our editing works
All articles

Personal Agent Protocol Proposes Rules for AI Access

Meta and Sierra propose a way for AI agents to access businesses with clearer permissions. Detailed action limits and payments remain on the roadmap for now.

Rachel "Rach" Kovacs

Written by AI. Rachel "Rach" Kovacs

October 8, 20266 min read
Share:
Personal Agent Protocol Proposes Rules for AI Access

Meta and Sierra announced the Personal Agent Protocol on October 6, proposing a shared way for personal AI agents to interact with businesses. Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are also involved in developing it. The proposal addresses a question that becomes urgent when an assistant moves from finding information to changing an account: how does a business know an agent represents a customer, and what should that agent be allowed to do?

The announced design gives those decisions a place in an agent's visit. An agent could check a returns policy as a guest. For an account task, the customer could sign in and choose read-only or write access, while the business decides which services to expose. That is a promising boundary to draw. It is still a proposed design: Sierra says it plans to publish a v0.1 specification later this month, with more detailed permissions and payments left for future work.

Why an Agent Needs a Different Welcome

Many personal agents currently use websites much as people do, loading pages and clicking through forms, Sierra says. That approach lets an agent attempt a task without waiting for every business to build a new connection. It also puts the business in an awkward position. A sequence of clicks may be a customer's assistant trying to help, or an unwanted bot trying to get into the same account.

The friction has already reached a major storefront. Amazon blocked Meta's Muse agents from its shopping platform. Amazon cited website-scraping concerns. It also raised concerns about agents failing to identify themselves and about the handling of customer credentials and account data. Those are Amazon's stated concerns, rather than findings that Muse mishandled an account.

That episode helps explain the change Sierra and Meta want. A business presented with an ordinary web session has to decide what to permit with limited context about the software operating it. Under the proposal, the agent would begin a session on the user's behalf and the company could set parameters for its access. Recognizing the visitor as an agent could make access decisions more legible to the company, provided businesses and agent builders adopt the protocol. It would not compel Amazon, or any other business, to accept a particular agent.

Bret Taylor, Sierra's co-founder and OpenAI's chairman, made the business case in an interview with CNBC: companies do not want to give a random bot access on the assumption that it acts for a person. He expects OpenAI and Anthropic to participate, but neither was on board when the protocol was announced. An open invitation can make a standard possible; participation determines how widely people can actually use it.

What the Proposed Permission Flow Buys You

In Sierra's example, an agent first discovers on a company's website how to connect. It could then start as a guest to ask whether a product is in stock. If the job requires the customer's account, the customer could sign in on the company's page or use credentials already set up with their agent. The proposal calls for an OAuth-based session, with the customer choosing read-only or write access. The session could carry an initial question and a later account action across channels, rather than treating them as unrelated visits.

A company would choose the route for the task: its regular website, an API, or its own agent. Sierra offers a warranty claim as an example of a task that might need a conversation with the company's agent. This gives businesses a reason to consider the scheme beyond identifying bots. They could decide which route to offer for each interaction, rather than asking every visiting agent to improvise through the same pages.

The proposed read/write choice also gives customers a useful first question: does this assistant need to change anything? If the job is checking an order, read-only access fits the request better than permission to alter it. That is an inference from the proposed choices, not a guarantee about how any company's implementation will present them. Convenience can still pull the other way. A customer who wants an agent to rearrange a delivery may need write access, and the requested change may happen later in the same session as an innocent stock check.

Changing a delivery address, canceling an order and filing a warranty claim are different decisions for a customer, even if all involve changing a company's records. Sierra lists limits on individual actions as future work. A broad read/write choice may not specify the precise task an agent may perform. The business must also decide what actions to expose and how to handle a consequential request.

Identification and delegated authority therefore solve different pieces of the problem. Knowing that software arrived on behalf of an account holder helps a business decide whether to start a session. Knowing whether the customer wanted this change requires controls closer to the action itself. The announced flow offers an outline for the first piece and an initial permission choice for the second; it does not demonstrate that an agent will follow the customer's interests every time.

A Shared Doorway, with Competing Plans Nearby

There is already another proposed route into agent commerce. Visa's Trusted Agent Protocol has drawn Microsoft, Stripe, Shopify and Worldpay. Stripe and Shopify are participating in the Sierra and Meta effort too. Both initiatives concern agents interacting with merchants, but Sierra describes account access across websites, APIs and company agents, while its proposed payment extension comes later. The reported overlap in partners does not establish that the two protocols work together, or that their technical designs can be compared feature by feature.

For a customer, that leaves a practical question before the shopping pitch gets too far ahead of the permissions. Sierra proposes a future payment extension that could let an agent complete a purchase without sharing card information. Its October announcement places that alongside future work on more detailed permissions and push notifications. A customer can reasonably welcome an easier way to ask about stock or manage an order while reserving judgment on how an agent would obtain authority to spend money.

Businesses face a choice of their own. Offering a documented route for agents could reduce the ambiguity of page-clicking bots and let a company define what it will make accessible. It also requires the company to decide where a guest session ends, what account access entails and when a proposed action needs a customer's direct approval. Those choices will shape the customer experience more concretely than a label saying the visitor is an AI agent.

For now, the clearest way to assess the Personal Agent Protocol is to follow a task from guest question to account change. At each step, ask who grants access, which action the grant covers and who can stop the next one. A recognizable agent at the door is useful; the permission it carries inside is where the consequential decisions begin.

More Like This

Google I/O session speaker presenting on AI agent development, with microphone visible in professional setting

Six Protocols That Make AI Agents Actually Work

Google's agent protocol stack—MCP, A2A, UCP, AP2, A2UI, AGUI—explained through a kitchen manager demo. What each protocol does and when to reach for it.

Marcus Chen-Ramirez·5 months ago·7 min read
Amazon’s Muse Block Makes AI Shopping a Contract Fight

Amazon’s Muse Block Makes AI Shopping a Contract Fight

Amazon’s block on Meta’s Muse exposes a contract fight over AI shopping, merchant consent, user agency, account security and control of online commerce.

Dev Kapoor·2 weeks ago·7 min read
Agent-net's Webagent Turns Websites Into AI Agents, With Caveats

Agent-net's Webagent Turns Websites Into AI Agents, With Caveats

Agent-net open-sourced Webagent, a Go harness that turns websites into public AI agents. What the release shows, what it omits, and what guards must be proven.

Samira Barnes·3 weeks ago·7 min read
Meta’s Muse Exposes the Permission Problem for AI Agents

Meta’s Muse Exposes the Permission Problem for AI Agents

Meta’s Muse arranged a Marketplace pickup without its user knowing. The case shows how vague AI agent permissions can turn chat into real-world consequences.

Yuki Okonkwo·1 week ago·6 min read
Man speaking beside bar chart showing AI maturity levels, with text discussing context layers for AI agents in engineering…

AI Agents Keep Losing the Plot on Your Codebase

Peter Werry of Unblocked argues AI agents don't lack access to information—they lack understanding. Here's what a context engine actually does differently.

Rachel "Rach" Kovacs·1 month ago·7 min read
A man in a dark shirt presents on stage with code visible in the background, with text overlays reading "think series" and…

How AI Agents Connect to Tools Securely

From bare API keys to vault-backed short-lived credentials, IBM's Grant Miller maps five patterns for connecting AI agents to tools—and the security tradeoffs of each.

Rachel "Rach" Kovacs·2 months ago·7 min read
Small Language Models Are Reshaping Agentic AI

Small Language Models Are Reshaping Agentic AI

Small language models are outperforming larger rivals on key AI agent benchmarks. Here's what the efficiency shift means for how AI gets built and deployed.

Marcus Chen-Ramirez·3 months ago·7 min read
Man in KodeKloud shirt gestures while presenting AI agent characters (Zippy, Savvy, Meshy, Cody) on blue background

Building AI Agents From Scratch: An Honest Assessment

A new freeCodeCamp course from KodeKloud walks beginners through LLMs, tool-calling, and real agent architecture using the open-source OpenClaw project.

Dev Kapoor·3 months ago·7 min read