PAP ready on day onePersonal agent observability
Agents are acting for your customers.
Know who they are.
People ask ChatGPT, Gemini or Meta AI to check an order, book a table or buy shoes. The agent does it on your website, through your APIs or by talking to your support agent. Double Agent tells you which agent it is, who it is acting for, what it was allowed to do and what it did.
The problem
Most agents walk in
like any other browser.
You can’t tell who sent them, whether your customer asked for it, or what they are allowed to do. The same agent may call your MCP server or chat with your support agent next.
Where agents show up
Two doors. Same questions.
Who is it, for whom, proven how, doing what. Double Agent answers on both.
Your website
Pages and APIs on your domain
The browser script, your edge adapter and your server tell Double Agent what each visit proved.
Your public agents
MCP servers, A2A agents, your support agent
The observe recorder reports each call: who called, for whom, which tool, read or write, and how it ended.
01Identify
Who is it, and how do we know?
Human, bot or agent first. Then which agent, who runs it, and how that was proven. Every caller gets a level, so you can tell a claim from a proof.
- Human, bot or agent on every visit
- The agent, its operator and its software
- Who checked it: Double Agent or your own server
- UnknownOnly network facts
- DeclaredIt says who it is: user agent, name, Agent Card. Nothing proven
- VerifiedA signature or a published IP list proves who runs it
- AuthenticatedYour own login or OAuth signed it in
- DelegatedIt acts under a customer’s grant: scopes, read or write, expiry
02Understand
Who is it acting for, and what did it do?
When your login, your OAuth server or a grant says which customer the agent acts for, you see it. Customers are always stored as a hash.
- The customer behind it and the grant: read or write, scopes, expiry
- Intent: buying, getting support, or probing and scraping
- What it did: pages and actions on your site, tools and resources on your agents
- Agent
shopper.exampleVerified · Web Bot Auth- Acting for
customer 3f9a…c21hashed- Grant
- OAuth · write ·
orders:read orders:write· 23 h left - Intent
task/ purchase- Did
- 6 products viewed, 1 order placed
1 call outside the grantrefund_order needs refunds:write
03Control
Your rules decide. We give them facts.
Double Agent verifies and labels. It never blocks on its own. Your login, OAuth server or agent platform still decides who gets in.
Labels for your rules
Class, verification level, grant and intent on every session and every call. Use them in your own rules.
Signed verdicts
Your backend gets a signed token with the level and the grant. Check it before an order or a refund goes through.
Scope-violation webhooks
When an agent tries something outside its grant, you get
caller.scope_violation, once a day per grant.Threats
Callers probing your tools, sweeping your resources or trying prompt injection, with the evidence.
Audit export
Everything one customer’s agents did, across your site and your agents, as NDJSON or CSV.
The protocols, simply
Each one proves something different.
A signature tells you who runs the agent. Which customer it acts for comes from your login, an OAuth grant, PACT or, soon, PAP. These work with Double Agent today.
- Agent to Your site: Sends a signed request
Signature-Agent: operator.example - Your site to Double Agent: The signature goes to Double Agent
- Double Agent to Operator keys: Fetches the operator’s public key
- Double Agent: Checks the signature with that key
Verified operator: operator.example
- Customer to Agent: Signs in and allows read only
scope: orders:read - Agent to Your MCP server: Calls get_order with the token
sub: customer · act: agent - Agent to Your MCP server: Tries cancel_order
- Your MCP server to Agent: Refuses it
403 insufficient_scope · orders:write - Your MCP server to Double Agent: The recorder reports client, agent, customer and scopes
Delegated · 1 call outside the grant
- Calling agent to Your A2A agent: Sends a task, naming its Agent Card
- Your A2A agent to Double Agent: The recorder reports the call and the card
- Double Agent to Calling agent: Reads the card from the caller’s host
- Double Agent: Checks the card’s signature against a key on that host
Signed card checked
- Customer to Your API: Approves a grant for the agent
scope: orders:write - Personal agent to Your API: Calls with the grant token
- Your API to Personal agent: Does the work, returns a signed receipt
scopesUsed: orders:write - Your API to Double Agent: Your server reports the grant and the receipt
- Double Agent: Checks the receipt with the issuer’s keys
Delegated · receipt verified
Double Agent also checks ERC-8128 request signatures and reads AP2 mandate references. Details in the Callers docs.
Personal Agent Protocol
PAP ready on day one.
Sierra announced PAP on 6 October 2026, with Meta and partners such as Shopify, Stripe and Walmart. It covers how a personal agent signs in for a customer, gets read-only or write access, and works within the limits you set.
Version 0.1 is due later in October. There is no published specification yet, so the animation follows the announcement.
- Personal agent to Your business: Comes in as a guest and checks stock
- Customer to Your business: Signs in on your page and gives write access
- Your business to Personal agent: Your limits apply
orders: yes · refunds: no - Personal agent to Your business: Places the order, within the limits
- Your business to Double Agent: Your server reports the grant
Delegated: acting for a signed-in customer
Live today
- Verification levels on every caller, and who checked them
- Grants with scopes, read or write, and expiry
- Reporting from your server and from the observe recorder
- Callers, Threats, scope-violation webhooks and audit export
When PAP v0.1 is published
- We add the PAP parser and its tests the day v0.1 is published
- PAP grants then show up as delegated callers
- Nothing changes on your side beyond updating the recorder
- Until then, PAP grants are refused, never guessed
Get started
Know who is acting
for your customers.
Paste the prompt into your coding agent and it installs Double Agent on your site. Agents are labelled from the first visit, with or without any protocol.
Personal Agent Protocol guide · Callers docs · View as Markdown