Meta and Sierra propose a Personal Agent Protocol - what to do while Muse is already on your site
A proposed standard for how AI agents sign in to businesses, announced as Muse quietly reaches half the sites one security firm studied.
On 6 October, Sierra and Meta announced the Personal Agent Protocol, a proposed open standard for how AI agents acting for a customer sign in to a business and get permission to do things. Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are listed as partners. A day later, the bot-security firm Cequence published data showing that Meta's Muse agent is already visiting many business sites without saying what it is.
Put those two together and you have the real story. Personal agents are already showing up at your website. The rules for how they should behave are still being written.
What was announced
According to Sierra's announcement, the protocol builds on OAuth, the same standard behind "Sign in with Google". An agent starts as a guest. The customer then decides whether it gets read-only access to their account or write access too. The business decides what it exposes to agents, and can route them through its website, an API (MCP or OpenAPI) or its own customer-service agent. The business also gets visibility into what the agent did.
That is the whole of it so far. There is no published spec yet. Sierra says the v0.1 specification is due later this month, followed by design workshops and a reference implementation. Payments, push notifications such as shipping updates, and finer-grained permissions are listed as future work.
Bret Taylor, Sierra's co-founder, put the case plainly: "It is kind of chaos until such a standard exists," as quoted by Implicator.
Why now: Muse is already at the door
Meta launched Muse on 8 September. On 1 October it added Muse for Small Business, which Retail Dive reports connects to Shopify, Stripe, QuickBooks, Asana, Box, Canva and Zoom, with paid plans from $20 to $100 a month in the US and Canada.
Cequence's report, released 7 October, covers its own customers in financial services, retail, travel and software between 1 and 24 September. It found Muse reached more than half of them within two weeks. At the median customer, Muse traffic grew nearly sixfold in about two weeks. Cequence says Muse runs a real Chrome browser in the cloud, routes through consumer VPNs and sends no header identifying itself as an agent. One travel customer ended up blocking nearly one in five Muse requests.
Cequence sells a product for exactly this problem, so read its framing with that in mind. The traffic pattern it describes is still the thing to check on your own site.
Amazon has already chosen its side. Implicator reports Amazon blocked Muse on 20 September, citing the lack of disclosure.
What it means for a business
If customers book, order, reschedule or ask for refunds through your website, some of that traffic will soon come from agents. The practical questions change.
Today an agent like Muse looks like a person in a browser. It fills your forms, clicks your buttons and breaks when you redesign a page. You cannot tell it apart from a customer, so you cannot give it a faster path or a narrower one.
A protocol like this would let you do something better. Offer a small set of actions to agents directly: check order status, rebook an appointment, update an address. Those run through an API with permissions the customer granted, and you get a log of each action. That is cheaper to serve than a headless browser crawling your checkout, and much easier to audit when something goes wrong.
The same logic applies in reverse. If you run automations that act on suppliers' or partners' portals, the same scope-based model is where that work will end up. Browser scraping of other people's sites gets less tolerated every month.
The honest caveat
Do not build to this protocol yet. There is nothing to build to. The spec is not out, there is no named governing body, and the parts most businesses care about, such as payments and granular permissions, are deferred.
It is also one standard among several. Implicator notes that OpenAI, Anthropic, Google and Amazon are not on the partner list. Google is working on its own Universal Commerce Protocol. Stripe and Shopify also back Visa's Trusted Agent Protocol. Whichever wins, there will probably be more than one in use for a while.
And a protocol only helps with agents that choose to use it. Agents that pretend to be browsers will keep doing so as long as that works.
What to do this month
Find out whether agents are already on your site. Ask whoever runs your hosting, CDN or bot protection to pull a sample of recent traffic and flag automated browser sessions that complete real actions: bookings, checkouts, account changes. Note which flows they use and where they fail.
Then write down the three or four actions you would be happy for a customer's agent to do through a clean, logged API rather than your front end. That list is useful whichever protocol wins. When the v0.1 spec lands, you will be checking it against a real need, not reading it in the abstract.
Want this kind of system in your business? Book a free scoping call.