Last month the AI industry's big names were fighting over whose chatbot is smartest. This month, quietly, they agreed on something that will affect your business more than any benchmark: customers' AI agents need a standard way to show up at your door.
Two announcements in two weeks, each from the same direction. At Sierra Summit on October 6, Sierra and Meta published the Personal Agent Protocol — an open standard co-developed with Shopify, Stripe, Walmart, Genesys, and Instinct — defining how a personal agent signs in, identifies itself, and completes tasks with a business. That same month, Dataiku's Agent Management — announced September 24, with general availability planned for October — began scanning the platforms enterprises already use (AWS Bedrock, Microsoft Copilot Studio, Salesforce Agentforce) into a single inventory of agents, each with a named owner, named risks, and scheduled tests.
Enterprises read those as governance announcements. If you run a small business, read them differently: the agents are coming to you, with standardized ID in hand, and nobody is building the small-business side of that handshake. Nobody is telling you how to prepare to receive them.
Why an "agent registry" matters even if you have three employees
Here's the shift worth internalizing: for two years, AI agents were something you deploy. In 2026 the direction flipped — the highest-volume agents touching your business are deployed by someone else: your customers' assistants, your vendors' order-processing agents, your bookkeeper's categorization bot. You don't control them. You may not even know they're there.
The protocol solves the ID problem: how a customer's agent proves it's acting for that customer, what scopes the customer granted it, and what your business is allowed to ask it. Dataiku's registry solves the enterprise inventory problem. What neither solves — what nobody ships out of the box — is your side of the door: knowing which agents already touch your systems, what they're allowed to do, and what you'd do if one misbehaved.
The audit: five lines you already have
You don't need a registry product. You need a list. Here's how to build the small-business version this afternoon, from data you already possess.
1. Your inbox: who is allowed to email you as you?
Check your email delegation and forwarding rules. If your assistant or a tool has send-as access, it's an agent in your registry. Jot down: what it can send, as whom, and how you'd revoke it.
2. Your bank and cards: who can move or see money?
List every app with read or write access: accounting tools, subscription managers, expense-categorization bots. Include the new wave — consumer AI agents are already paying with virtual card numbers on their users' behalf, and those transactions arrive with a card name that matches no human. Your books need to recognize them.
3. Your booking and CRM systems: who can write customer records?
Shared calendar links, booking tools, lead intake forms. Any of them can be operated by a machine acting for a person. If your intake only works when a human types slowly, it will start failing quietly as agent-filled submissions increase. (This connects to a pattern covered in "When the Customer's AI Books You" — audit your sales path for machine-filled forms; here we're inventorying the agents, not the form.)
4. Your tools' connections page: every OAuth grant you've made
Every SaaS tool you've ever clicked "Connect" on holds a standing grant to act somewhere on your behalf. Open each tool's "connections" page and list what you find: what's connected, what scopes, when it was last used. Anything you don't recognize gets revoked, not researched later.
5. Your customer-facing channels: where could an agent knock?
List the doors: booking link, intake email, web form, chat widget, phone. For each, note whether a machine acting for a person could currently get through and complete a task — book, ask, buy — without a human on your side noticing. That's your agent readiness map.
Two rules that keep the registry honest
Grant like an employer. When a new integration asks for access, decide the tier now: read-only, or act-on-your-behalf. If it asks to do things, it gets an owner and a review date — even if the owner is you.
Review on a schedule, not on vibes. A registry is only as good as its last review. Put a recurring calendar reminder — quarterly is plenty for a small shop — to re-walk the five lines. Kill anything unused.
What the protocol will ask of you, eventually
The Personal Agent Protocol is a proposal published days ago, not a deployed standard — treat timelines with respect. But the direction is legible. When it lands, a business receiving agent traffic will want to be able to answer three things: who is this agent, what is it allowed to do here, and who granted that? Your five-line registry answers those today. The enterprise products will answer them at scale with connectors and certification trails. The underlying questions are identical; only the price tag differs.
One more honest caveat: standards with this many co-signers (Shopify, Stripe, Walmart) have real weight, but rival protocols exist — some of the same partners are reportedly also backing Visa's effort in this space, per The Next Web's coverage. Small businesses shouldn't pick a winner. Build the registry; let the standards fight it out on your behalf.
The pattern underneath
Notice the shape of these announcements: ID, scope, registry, audit trail. That's not accidental — that's the same design pattern as app permissions on your phone, and before that, network access control. Every wave of automation eventually grows an identity layer, and the businesses that adopt it early treat agent access like employee access: granted deliberately, reviewed periodically, revocable instantly.
Your three-employee shop won't buy a governance product this year. But the five-line registry — inbox, bank, CRM, OAuth grants, customer-facing doors — costs one afternoon and a text file. When a customer's agent shows up with its standardized ID and asks to book the Tuesday slot, you'll know exactly which door it came through, and what it's allowed to do once inside.
If you're assembling your first AI agent roster and want the full framework — the permission ladder, the boring first assignment, the one-page process format that keeps your playbooks portable — it's all in The AI Agent Owner's Playbook — $49 CAD, instant download.
Top comments (0)