The Front Door Has Been Unlocked

The Front Door Has Been Unlocked
PAP tells you whether an agent can enter. AIVO tells you whether it wanted to.

On 6 October 2026, Meta and Sierra announced Personal Agent Protocol, a proposed open protocol for how personal AI agents enter a business. It turns the Access gate of agentic commerce into infrastructure. In doing so it moves the decisive contest upstream, to the moment an agent chooses which business to visit, where brands still have no protocol and no visibility.

What was announced

Personal Agent Protocol (PAP) is being developed by Meta and Sierra with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. Sierra's founders, Bret Taylor and Clay Bavor, describe it as an open standard they are developing to define how personal agents interact with businesses, open for anyone to implement. It is an announced protocol, not yet an established standard: the v0.1 specification is due later in October, followed by design workshops and a reference implementation.

The problem it addresses is familiar. Personal agents today use websites the way people do, loading pages, filling in forms and calling support lines when they get stuck. Tasks are slow and often fail.

Under PAP, an agent first reads a company's website to discover what it offers and how to connect. It begins a session as a guest or signs in to the customer's account, and the customer grants read-only or write access. The session runs on OAuth and persists across channels, so the company decides whether the agent works through its website, its APIs (MCP, OpenAPI) or its own agent. Sierra lists finer permissions, push notifications and a payments extension as likely next steps.

PAP and the Three Gates

In "Chosen, Then Blocked", the AIVO Journal described agentic commerce as three gates a brand must pass: Access, Choice and Execution. PAP is designed to standardise the first gate and lays foundations for the third. The second gate, Choice, sits outside its scope.

Gate

The question

What PAP changes

Access

Can the agent read and enter the business?

Designed to be standardised. Discovery on the website, guest or signed-in sessions, OAuth, customer-set permissions.

Choice

Does the agent select this business over its rivals?

Unchanged. Selection can happen before the agent reaches any site, outside the brand's observable environment.

Execution

Can the agent complete the task once inside?

Improved. Direct routes through APIs and company agents, with payments to follow.

As Access and Execution become standardised infrastructure, they become less useful as sources of competitive advantage. Implementation quality will still vary, but the interaction layer itself will be shared. The differentiator moves upstream, to Choice.

The visibility paradox

Sierra names what brands want from PAP: visibility and control, knowing when an agent acts for a customer and deciding what it may do. PAP can give brands visibility once an agent arrives: which agents came, what they asked and what they were permitted to do. It does not give them visibility into the alternatives the agent considered before arriving.

The agents that never arrived leave no trace. When a personal agent weighs five insurers or three banks and visits one, the other four see nothing in their logs. AIVO's own research puts the scale of this blind spot in view. Across more than 25,000 multi-turn probes covering 240+ brands, AIVO observed an 87.3% Linkage Gap: brands recognised or surfaced during the journey appeared in only 12.7% of final recommendations (WP-2026-14).

PAP will therefore make the loss easier to feel and no easier to see. Brands will watch agent traffic grow and have no way to tell whether they are winning their share of it.

Relevance to AIVO Win Rate

AIVO Win Rate measures the Choice gate directly. It sends AI agents to act on realistic customer briefs and records whether they select a given business against named competitors. PAP raises the diagnostic value of that number because it removes one major alternative explanation for losing: failure at the access layer.

Before PAP, a brand that agents ignored could blame a site they could not parse. Once a business implements the protocol, that excuse narrows. Price, availability, product fit and reputation still matter, but with Access working, a low Win Rate becomes a much cleaner signal of what happens at Choice.

The free check in AIVO Win Rate, which tests whether agents can read a site, maps onto PAP's discovery step and should evolve to test PAP readiness once v0.1 is published. The paid Full Test stays where it is, on Choice. For agencies, this gives a clean two-part diagnosis to bring a client: the door is open, and here is how often the agent chooses you.

Relevance to AIVO Brand Alpha

AIVO Brand Alpha values the AI layer of a brand using the L.E.V. method: category TAM multiplied by the AI-mediated purchase influence rate (APIR) and the brand's AI Win Rate. PAP affects two of those three terms.

The first is APIR. PAP removes one of the infrastructure constraints on agent-led purchasing. If that accelerates adoption, APIR rises with it, increasing the economic value exposed to AI-mediated choice.

The second is measurement. No published figure for APIR exists today, which is why the first Brand Alpha tables carry it as a scenario range. Sierra says brands want to know when a personal agent is acting for a customer. If PAP sessions are consistently identifiable at the transaction layer, businesses will eventually be able to measure the share of transactions arriving through personal agents, a credible route to a measured APIR.

The partner list also lines up with Brand Alpha's first sectors. Shopify and Walmart bring consumer goods into scope from day one, and Rocket's participation, with its Muse agent moving from home search to financing, puts financial services in the same frame.

What brands should do now

PAP readiness is likely to become table stakes for businesses that want to participate reliably in agent-mediated commerce. That work is necessary and it is the easier part.

The harder task is establishing a baseline for Choice before agent volumes rise. A brand that knows its Win Rate today can read its PAP session data in context. A brand that does not will see agent traffic arrive and have no benchmark for whether it is gaining or losing share.

Three things are worth watching when v0.1 lands later this month. The first is whether sessions disclose which agent and which platform referred them. The second is whether the protocol carries any signal of intent or comparison, such as how many businesses an agent considered. The third is how the payments extension treats attribution. Together, those three decisions will determine how much of the Choice gate becomes observable from inside the door.

PAP makes the distinction between Access and Choice commercially visible. Once the doorway is standardised, what happens before it becomes the thing worth measuring.

PAP tells you whether an agent can enter. AIVO tells you whether it wanted to.

Sources

Introducing Personal Agent Protocol, Sierra, 6 October 2026

AIVO Brand Alpha methodology working paper, AIVO Standard, Zenodo

WP-2026-14, The Linkage Gap, AIVO Standard (DOI to be added)

"Chosen, Then Blocked: The Three Gates of Agentic Commerce", AIVO Journal (link to be added)