Meta is joining Walmart, Shopify, Stripe, and other major technology and commerce companies to establish common rules for how personal AI agents interact with businesses.
The companies are backing the Personal Agent Protocol, an open standard being developed by Meta and enterprise AI startup Sierra with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. The framework is designed to help businesses identify AI agents, control what they can access, and give customers more say over what agents can do on their behalf. For channel partners, adoption could create new work around identity, APIs, security, customer experience, and commerce integrations.
Proposed protocol would give businesses control of agent access
Sierra said the protocol is built around a division of control: customers decide what access to give their agents, while businesses determine which actions those agents are allowed to perform.
A personal agent could initially connect as a guest to check whether a product is available or review a return policy. For tasks involving a customer account, the user could authenticate through the company’s website or use credentials already configured with the agent.
Customers would also choose whether an agent receives read-only or write access.
The session uses OAuth and can continue across different ways of interacting with a business.
| Connection method | How agents could use it | Potential partner role |
| Website | Navigate existing pages and customer workflows | Test agent compatibility and secure access |
| APIs | Connect through interfaces built on MCP, OpenAPI, or similar standards | Build integrations and manage API permissions |
| Company agent | Handle conversational tasks such as warranty claims | Connect CX platforms with back-end business systems |
Sierra plans to publish version 0.1 of the specification later in October, hold design workshops, and release a reference implementation for developers. Sierra also outlined possible extensions for more detailed permissions, push notifications, and payments, without specifying when they might become available.
Businesses want to know which bots they can trust
The protocol comes as AI agents increasingly act directly on users’ behalf, raising questions about authentication, permissions, and access to company systems.
Meta executive David Singleton told CNBC that Muse already had millions of US users following its September launch. At the same time, businesses have taken different approaches to agent access. Amazon has blocked Muse over concerns about website scraping and has previously challenged Perplexity over automated access to its services.
Sierra co-founder Bret Taylor described the current environment as “kind of chaos until such a standard exists.”
A shared protocol could give businesses a clearer way to determine whether an agent is acting for an authorized customer rather than operating as an unidentified bot. OpenAI and Anthropic are not currently among the named participants, however, leaving broader industry adoption unresolved.
Shopify brings agentic commerce into the picture
Shopping provides an early example of where the standard could matter.
According to Yahoo Finance, Meta and Shopify announced in September that Muse users would be able to complete purchases through Shop Pay. The integration extends AI agents beyond finding and recommending products into completing transactions.
Shopify is also helping develop the Personal Agent Protocol. Mani Fazeli, the company’s vice president of product, described the ambition for agents to help merchants answer product questions and support purchases, returns, and exchanges.
Stripe’s involvement adds another part of the commerce stack. Sierra’s announcement quoted Stripe Head of Payments Kevin Miller as saying businesses need a standard way to recognize customer agents, interact with them, and manage those customer relationships.
Channel partners could connect agents to enterprise systems
For MSPs, systems integrators, security providers, and commerce specialists, the opportunity may sit between the protocol and the systems customers already use.
Potential areas for partner involvement include:
- Integration: Connect personal agents with e-commerce, CRM, customer experience, identity, payment, and other enterprise systems.
- Security and governance: Configure OAuth access, read and write permissions, logging, and controls around sensitive actions.
- Managed services: Monitor agent access, maintain integrations, and help customers adjust policies as agent capabilities change.
Security could become one of the more important service areas. Businesses will need to understand which systems agents can reach, what information they can access, and which actions should continue to require human approval.
Partners could also help customers decide whether existing websites and APIs are ready for agent traffic or whether new interfaces are needed to support these interactions reliably.
The Personal Agent Protocol is still at an early stage and has not become an industry-wide standard. Its next test will be whether more AI providers and enterprise platforms adopt it after the v0.1 specification arrives.
For now, partners can identify customer-facing workflows that could benefit from authorized agent access and assess the specification and reference implementation when available. Any new integration or managed services offering will depend on adoption and the final technical requirements.
Also read: Anthropic, OpenAI, and Google are discussing a common AI standards body that could set shared rules for testing advanced models before release.




