Nick George — AI Agents & Automation

Personal Agent Protocol: how a business goes from AI-searchable to AI-bookable

Sierra and Meta announced a standard for how customers’ AI agents deal with businesses, with Walmart, Shopify, and Stripe on board. What it does, what isn’t in it yet, and the work that makes you bookable whichever standard wins.

Nick George  ·  October 8, 2026  ·  7 min read

The short answer: it’s a sign-in standard for your customers’ AI agents.

The Personal Agent Protocol is a proposed open standard for how an AI agent acting for a customer deals with a business: how it shows who it works for, what it's allowed to do, and which door it comes through. Sierra and Meta announced it on October 6, 2026, with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart as partners. The spec itself isn't out yet. Sierra says version 0.1 will be published later this month.

You don't need to wait for it. This standard, or whichever one wins, needs three things from a business: facts a machine can read, a way to book without a phone call, and something that answers in seconds. Most local shops I look at have none of the three. That work starts now, and it's what this page covers.

What's in it

What the protocol actually does

Today an AI agent uses your business the way a person does. It clicks through your site, and when that fails it falls back to your phone line or chat. The protocol gives agents a front door instead. Here's what Sierra's announcement describes.

  • It knows it’s an agent, and who sent it

    Sessions are built on OAuth, the long-standing standard for letting an app into an account. Bret Taylor, who leads the effort, compared it to signing in to a site with your Google or Facebook account: you know you’re dealing with an agent acting for a real customer, not a random bot.

  • Guest first, sign-in when it matters

    An agent can start as a guest, which is enough to check availability or ask about a policy. When a task needs the customer’s account, the customer signs in, on your page or with credentials they’ve already set up with their agent.

  • The customer picks read or write

    The customer decides whether their agent can only look, or can also make changes.

  • You pick the door

    You choose how agents reach you: your website, your APIs (Sierra names MCP and OpenAPI), or an AI agent of your own for tasks that need a conversation. One session carries across them, so a question asked as a guest and a change made after sign-in count as one visit.

  • Payments come later

    Sierra lists payments as a possible extension, along with finer permissions and push notifications, like telling an agent the moment an order ships. None of them are in the first version.

Who's in, who isn't

One standard among several, and the big AI labs haven't joined

Meta's weight matters. Its Muse agent launched in early September and is the most visible personal agent so far. But OpenAI and Anthropic, the makers of ChatGPT and Claude, aren't on board yet, according to CNBC, though Taylor said he expects them to join.

There are rival efforts too. Google has its Universal Commerce Protocol. OpenAI and Stripe built the Agentic Commerce Protocol. Visa has its Trusted Agent Protocol, and Stripe and Shopify are among the partners Visa names on that one too.

So don't pay anyone to make you “protocol-ready” before a spec exists. Build the layer every one of these standards sits on: readable facts, a booking path, and an answer. When a standard settles, connecting to it is a much smaller job on top of that work, not a rebuild.

Searchable vs. bookable

Being found by an AI isn't the same as being booked by one

A business can be easy for ChatGPT to find and still impossible for an agent to book. I think of the gap as a ladder. Here's each rung for a plumber and for a property manager.

RungAn agent canPlumberProperty manager
SearchableFind you and describe what you doNames you for “water heater replacement in Matthews”Lists your rentals and your pet policy
ReadableCheck the facts that changeSees your service area, hours, and starting priceSees which units are open, the rent, and move-in dates
BookableBook a first visit as a guestBooks a Tuesday morning slotBooks a Saturday showing
Account accessAct for a signed-in customerMoves a customer’s appointment to ThursdayFiles a tenant’s maintenance request and checks on it
Payment (later)Pay, once a payments extension existsPays the invoicePays rent

A business with a decent website is usually on the first or second rung. The third is where an agent stops being a referral and becomes a booking. The first two are covered in how to get your business recommended by ChatGPT. This page is about the next two.

Getting bookable

Open the doors the protocol names

The protocol lets you choose how agents reach you: your website, an API, or an agent of your own. You don't need all three. My advice is to start with the website, because it helps the people booking today too, and add the others as volume pays for them.

  1. 01

    Your website: a booking page a stranger can finish

    If a first-time customer can’t book on your site without calling, an agent can’t either. Check four things. Real open times, not “request a time and we’ll call you.” No account needed for a first booking. Prices, service area, and policies written as text, not inside photos or PDFs. And a bot check that stops spam without stopping every automated visitor.

    That last one is now a choice you make on purpose. Amazon has blocked Meta’s agents over scraping worries, CNBC reports. A plumber who blocks every agent is turning away customers who sent one.

  2. 02

    Your API: let agents talk to your booking system

    Clicking through a website is the slowest, most fragile way for an agent to book. The protocol names MCP and OpenAPI for the faster door. If your scheduling, field service, or property management software has an API, an MCP server can sit in front of it and offer agents a short list of actions: check open times, book, reschedule. You decide which actions exist and which need a signed-in customer.

    No API? Ask your software vendor whether one is coming, and whether they plan to support this protocol or one like it. The answer tells you a lot about where they’re headed.

  3. 03

    Your own agent: an answer in seconds

    Some tasks need a conversation. Sierra’s example is a warranty claim. For a contractor it’s “is this an emergency?”, and for a property manager it’s a tenant describing a leak. A customer’s agent won’t wait until tomorrow for a reply when it can try the next business in seconds.

For the API door, here's how MCP and an API differ. For the third, an agent of your own can answer questions on your site and book through your booking link, or text back a missed call in seconds, and hand anything it can't settle to a person.

If you make the software, the booking app or the property management system, this lands on you more than on your customers. They'll start asking whether agents can book through you. Plan for the API door, and read the v0.1 spec when it's published.

Set the rules first

Decide what an agent may do before one asks

The protocol splits control: the customer decides what their agent can reach, and you decide what agents can do. Write your side down now. Here's where I'd start for a service business. Adjust it to your own risk.

AccessLet an agentKeep for a person
GuestSee open times, prices, service area, and policies. Book a first visit or showing.Quotes for custom work
Signed in, read-onlySee that customer’s appointments, invoices, and request updatesNothing extra, as long as it sees only that customer’s records
Signed in, writeReschedule, cancel, and add details or photos to a requestRefunds, contract or lease changes, and anything that sounds like an emergency

Payments aren't in the protocol yet, so keep money on your existing checkout for now. And keep a record of every action an agent takes. The protocol promises businesses that visibility; whatever you build before it ships should keep the same log.

This month

Four things to do before the spec ships

  1. 01Try to book on your own site from your phone without calling. If you use an AI tool that can browse for you, ask it to book a slot and watch where it gets stuck.
  2. 02Put your prices, service area, hours, and policies on your site as plain text.
  3. 03Ask your booking or property management software vendor two questions: do you have an API, and will you support the Personal Agent Protocol or a standard like it?
  4. 04Write down what a guest agent, a read-only agent, and a write agent may do, using the table above as a draft.

Your next customer might not call you. Their agent will, and it books whoever it can book. If that isn't you yet, start with the booking page.

Sources

The announcement, and who else reported on it

Everything above about the protocol comes from these, all published October 6, 2026. The spec they describe wasn't out yet when I wrote this.

Keep reading

Make your booking system something an agent can use

We build MCP servers that sit in front of the software you already run, so an AI agent can check open times and book. You decide what agents can read, what they can change, and what needs a signed-in customer, and every action can be logged. Builds start with the one-week operations audit ($4,500), credited toward the build.

How MCP server builds work →

Work together

Book a call with Nick

Pick a timeA 30-minute call with Nick. The calendar opens in a new tab.

Nick replies within one business day.Systems in production at Bank of America, Cotton Holdings, and a mid-market reverse logistics-tech company.

Or email nick@nickgeorgeai.com