News
FRONTIER NEWS / WHAT IS CHANGING NOWOct 7, 2026

Meta and Sierra Want to Give Your Customer’s Agent a Passport. Unfortunately, Everyone Else Is Printing One Too.

Personal Agent Protocol aims to solve one of the ugliest gaps in the emerging agent economy: how a business knows which software is knocking, whom it represents and what it is allowed to do. The problem is real. The standard is not yet.

Frontier editorial art for Meta and Sierra Want to Give Your Customer’s Agent a Passport. Unfortunately, Everyone Else Is Printing One Too.

What changed

Meta and Sierra have proposed a new open standard for a problem the agent market has been pretending browser automation would somehow solve forever.

Announced October 6 by Sierra co-founders Bret Taylor and Clay Bavor, Personal Agent Protocol is meant to define how a consumer’s AI agent discovers a business, starts a session, authenticates on behalf of a customer and completes work through a channel the business actually supports.1 Sierra names Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as participants. Meta’s David Singleton, who leads engineering and consumer products inside Meta Superintelligence Labs, separately named NiCE and Decagon as part of the working group around Meta’s Muse and Meta Business Agent efforts.2

The basic shape is sensible. A personal agent can begin as a guest, the customer can authenticate using an OAuth-style flow, and the customer can grant read-only or write access. The business decides what it exposes and how: its ordinary website, structured APIs built on standards such as MCP or OpenAPI, or a business-side agent capable of handling conversational tasks such as service issues or claims.1

That is a materially different model from today’s dominant workaround, where personal agents often impersonate human browsing behavior, click through pages, inherit whatever credentials the user has handed them and hope the target site does not decide they are a bot.

The current arrangement is already breaking down in public. Amazon blocked Meta’s Muse from shopping on Amazon in September, saying the agent had not been authorized and did not identify itself while browsing.3 Amazon’s earlier fight with Perplexity reached the Ninth Circuit, which in August vacated a preliminary injunction that had restricted Perplexity’s user-directed browsing agent; the court’s reasoning turned in part on whether the user, rather than Perplexity, was the party accessing Amazon’s systems.4 Whatever one thinks of that legal result, it demonstrates the underlying architectural mess: the web has no clean, universal way to represent “this software is acting for this person, for this purpose, with this much authority.”

PAP is trying to put a handshake where today there is mostly ambiguity.

But an important caveat belongs near the top of the story: there is no published v0.1 specification yet. Sierra says the first draft will arrive later in October, followed by design workshops and a reference implementation.1 Payments, richer permissions and push notifications are described as future areas rather than settled parts of the first announcement.1

So this is not an adopted standard. It is a coalition announcing its intention to write one.

And it is entering a market that already has no shortage of people with pens.

Why it matters

The protocol matters because the missing enterprise problem is not really “agent interoperability.” We already have several answers to that phrase.

Anthropic’s Model Context Protocol, now widely adopted and donated to the Linux Foundation’s Agentic AI Foundation, standardizes how AI applications connect to tools and data.5 Google’s Agent2Agent protocol addresses how agents built by different vendors communicate and collaborate.6 OpenAI and Stripe’s Agentic Commerce Protocol focuses on merchant and shopping flows.7 8 Google’s Agent Payments Protocol handles agent-led payments.9 Visa’s Trusted Agent Protocol gives merchants a cryptographic way to distinguish approved shopping agents from malicious automation and to receive information about agent intent and the underlying consumer.10

Those are adjacent problems.

PAP is aiming at a more awkward boundary: delegated customer authority at the front door of the enterprise.

That distinction matters. When a human arrives at a website, a business has decades of machinery for identity, session state, authentication, fraud controls, authorization, consent, auditing and customer-service routing. When an AI agent arrives on that person’s behalf, much of that machinery becomes ambiguous.

Who is the principal: the human, the agent provider, the model provider, or all three?

Did the user authorize the agent to read an order, cancel it, negotiate a refund, change an address or sign a new contract?

Does the business know it is dealing with software at all?

Can the business revoke the agent without revoking the customer?

Can the agent carry the conversation from the website to an API or from one company agent to another without losing the customer’s identity and consent state?

Can the enterprise later reconstruct exactly what the agent was permitted to do and what it actually did?

Those questions are the hole.

The protocol’s most useful idea is therefore not a new wire format. It is the recognition that agent access needs to become an explicit policy relationship, not an accidental side effect of handing software a browser and a password.

That is why the participating companies are more interesting than the acronym.

Meta brings consumer distribution through Muse and a business-side destination through Meta Business Agent. Its incentive is obvious: a personal agent becomes dramatically more useful if businesses stop treating it as hostile automation.

Sierra sits on the other side of the interaction. Its platform builds customer-facing enterprise agents. Bret Taylor and Clay Bavor therefore have every reason to want a clean protocol for the moment when one agent arrives at another agent’s door.

Genesys and NiCE represent the contact-center layer. If consumers increasingly delegate service work to personal agents, the contact center cannot remain an interface optimized only for humans with keyboards and phones. It needs to recognize machine callers, preserve identity and route them safely.

Decagon is attacking the same trust problem more directly. On the same day PAP was announced, Decagon open-sourced PACT — Personal Agent Consent & Trust Protocol, co-developed with Instinct, and said it was joining the PAP working group.11 PACT uses A2A and OAuth to separate agent identity from delegated customer authority, giving businesses a way to verify whom an agent represents and what the customer approved. That makes PACT potentially complementary plumbing for PAP rather than just another rival acronym.

Instinct is important because it represents the personal-agent side independent of Meta. A protocol with only one major personal-agent vendor would be a product API wearing a standards costume.

Walmart, Shopify and Rocket matter because they are destinations where agents need to perform real work. Walmart is a massive retailer, Shopify sits behind a huge merchant ecosystem, and Rocket brings a high-friction, regulated transaction domain where “the bot clicked the button” is not an adequate authorization model.

Stripe is perhaps the most strategically revealing participant. It already co-developed Agentic Commerce Protocol with OpenAI and provided input into Visa’s Trusted Agent Protocol. Its presence suggests that the eventual market may not converge on one monolithic agent protocol at all. More likely, several layers will interlock: identity and delegated authority here, tool access there, commerce and payment elsewhere.

That is probably healthy.

It is also why CIOs should resist the standard-industry reflex to treat every new protocol announcement as destiny.

Early standards in a new market fail all the time. Some solve the wrong abstraction. Some get trapped behind one vendor’s incentives. Some are technically elegant and commercially irrelevant. Some lose to an inferior standard because the company controlling the most valuable endpoint refuses to participate.

PAP already has a conspicuous test case: Amazon is not in the coalition, and Amazon has been willing to block third-party agents from its store.3 OpenAI and Anthropic were also not named as participants at launch; reporting around the announcement says Taylor expects broader industry participation, but expectation is not adoption.12

This is the central strategic problem for the protocol.

A standard for agents only becomes a standard when the parties with the most valuable agents and the parties with the most valuable destinations both decide interoperability is worth more than control.

Frontier take

The agent economy has discovered the oldest problem on the internet: strangers keep showing up at the door claiming to be somebody’s friend.

Personal Agent Protocol is an attempt to give the stranger a badge, the customer a permission slip and the enterprise a bouncer.

That is useful. It may even be necessary.

It is not yet enough.

The industry is currently producing agent protocols at roughly the rate it produced copilots two years ago: faster than anyone can prove which ones people actually need. MCP, A2A, AP2, ACP, Trusted Agent Protocol, PACT and now PAP are not all doing the same job, but the overlaps are substantial enough that architects can already see the next problem forming: an “open” agent stack made of seven open standards that each require their own gateway, policy model and conformance test.

That would be a very enterprise outcome.

The strongest reason to take PAP seriously is not the specification — because there isn’t one yet. It is the composition of the coalition.

Meta has consumer-agent distribution. Sierra, Genesys, NiCE and Decagon sit on the business-agent and service side. Walmart, Shopify and Rocket represent real destination systems. Stripe sits in the commercial middle. Instinct prevents the personal-agent side from being purely Meta-shaped.

That is enough market surface area to justify attention.

It is not enough to justify a platform bet.

The question to watch is whether PAP becomes the place where existing standards compose, or whether it becomes one more attempt to own the interaction. The winning design should not reinvent MCP for tools, A2A for agent messaging, or a payment network for settlement. Its durable contribution would be narrower and more valuable: a common contract for discovery, customer delegation, business policy, session continuity and auditability across those layers.

If PAP stays disciplined, it could become the missing “front-door protocol” for enterprises.

If it sprawls, it will become a diagram.

The market incentives are just as important as the technical design. Personal agents threaten to disintermediate the very interfaces businesses spent two decades optimizing. A consumer agent that searches, compares, negotiates and buys without looking at the website can bypass advertising inventory, recommendation engines, upsells, loyalty mechanics and carefully engineered conversion funnels.

That means some enterprises will want agent traffic.

Others will want to meter it, constrain it or block it.

Amazon’s treatment of Muse is the reminder that interoperability is not merely a security question. It is a bargaining-power question.3 A retailer that owns the customer relationship may see a third-party personal agent not as a new channel, but as a new intermediary trying to stand between the retailer and the customer.

PAP cannot standardize that conflict away.

What it can do is make the conflict explicit.

For CIOs, that is the real opportunity. Whether PAP survives or not, the enterprise needs an agent access policy layer: a place to recognize external agents, validate delegated authority, decide which capabilities they may invoke, log what happened, revoke access cleanly and route the interaction through the safest interface available.

The bet should be on that architectural capability, not on PAP winning the standards war.

Start with boring primitives that are unlikely to become unfashionable: OAuth, scoped permissions, cryptographic identity, short-lived credentials, explicit delegation, structured APIs, auditable actions and revocation. Keep the policy layer separate from the agent vendor. Make browser automation the fallback, not the contract.

Then watch the coalition.

If OpenAI, Anthropic, Google, Amazon, Microsoft and Salesforce begin implementing PAP — not applauding it, implementing it — the protocol becomes strategically important.

If the contact-center vendors expose interoperable PAP endpoints, it becomes operationally important.

If Shopify and Walmart can demonstrate real delegated transactions with consistent identity and dispute handling, it becomes commercially important.

If the v0.1 specification produces a clear conformance model and composes cleanly with MCP, A2A, PACT and existing commerce protocols, it becomes architecturally credible.

Until then, the correct posture is interested skepticism.

Because the need is real even if this standard is not the winner.

Your customers are going to send software to do business with you. The enterprise problem is not whether to admit agents. It is how to know whose agent is at the door, what it is allowed to touch, and who gets blamed when it walks off with the furniture.

Three moves for CIOs

  1. — Build an agent front door before you pick a protocol Create a dedicated external-agent access layer that can identify automated callers, bind them to a customer or organization, enforce scoped permissions, issue short-lived credentials, record actions and revoke delegated access independently of the customer’s primary account. Keep the policy model abstract enough to support more than one protocol.

    • Decision trigger: Require this architecture for any customer-facing workflow where third-party agents can read account data, change orders, initiate transactions, submit claims, modify subscriptions or invoke business APIs.
    • Why now: PAP is targeting a real control gap, but its v0.1 specification is not yet public.1 The durable enterprise investment is the capability to govern delegated software actors, not an early commitment to one emerging standard.
  2. — Pilot read-only PAP, but make write access earn its way in When the PAP draft and reference implementation arrive, test discovery, authentication and read-only retrieval against a low-risk customer workflow. Add write actions only after the protocol demonstrates explicit delegation, revocation, replay protection, auditability, error recovery and clear responsibility when the agent exceeds its intended scope.

    • Decision trigger: Move beyond read-only only when the business can prove who authorized the action, what scope was granted, which agent performed it and how the action can be disputed or reversed.
    • Why now: The proposed model already distinguishes read-only from write access, which is the right design direction.1 The market has not yet demonstrated that the surrounding trust, liability and recovery model is mature enough for broad consequential action.
  3. — Bet on composability and adoption, not acronym count Track PAP against five evidence points: publication of a usable specification, neutral governance, interoperability with MCP/A2A and adjacent trust or payment protocols, production implementations by both personal-agent and enterprise-side vendors, and participation by major holdouts such as OpenAI, Anthropic, Google, Amazon, Microsoft and Salesforce. Avoid custom application logic that makes PAP—or any competing protocol—irreplaceable.

    • Decision trigger: Promote PAP from experiment to enterprise standard only when at least two major personal-agent ecosystems and multiple independent business platforms can interoperate through the same implementation without proprietary extensions.
    • Why now: The agent ecosystem already includes overlapping standards from Anthropic, Google, OpenAI/Stripe, Visa and Decagon/Instinct.5 6 7 10 11 Early standard battles are won by adoption and composition, not announcement-day partner logos.

Sources