Meta and Sierra have published a plan, not a product: a draft protocol that would let a website recognise an AI assistant, check that a person sent it, and cap what it may do. Sierra announced the Personal Agent Protocol on its blog on 6 October, in a post written by Bret Taylor and Clay Bavor. The post does not state their titles.

The status matters, because the word “standard” is doing heavy lifting. The post calls it an open standard that Meta and Sierra are developing “along with industry partners” at Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. It also says Instinct “will also be joining the effort,” which suggests the list was still being assembled on the day of the announcement. The post does not say what any partner has committed to build or ship, and it describes no live deployment.

What exists today is a timetable. Sierra says a first draft, v0.1 of the specification, is due before October ends. Sierra also intends to hold workshops where interested companies can help shape the design, and to ship a reference implementation that developers can copy. Until the specification appears, “open for anyone to implement” is an invitation with nothing yet to implement.

The problem it targets is real. Today, according to the post, most personal agents treat a site as a human visitor would: they load pages, click through forms, and fall back to phoning support or opening a web chat when that fails. That is slow and error-prone. A direct, authenticated route would finish the same task in seconds.

The design works like this. A site tells an agent what it offers and how to reach it. The agent opens a session for its user, either as an anonymous guest (enough to check stock or a returns policy) or signed in, where the customer chooses whether the agent gets read-only or write access. Sessions rest on OAuth, the existing standard for granting limited access to an account, and carry across channels. The company then picks the route: its ordinary web pages, its APIs built on standards such as MCP and OpenAPI, or an agent of its own.

Here is the tension the post is candid about. It lists three parties with different wants. Consumers want things done right the first time. Agent builders want consistent, efficient access. Brands, in the post’s words, want “visibility and control,” meaning they want to know when an agent acts for a customer and to decide what it can do.

Put plainly, the same mechanism serves two masters. A site that can verify which agent is calling, and whether a human approved it, can also refuse agents it dislikes, steer them to its own assistant instead of a rival’s, or allow some actions and forbid others. The post says consumers decide what access their agents get and companies set the limits, but it does not say what happens when those two decisions collide. Nothing in it promises that a customer can bring any agent they like.

The ideas listed for later versions underline the point. Finer-grained permissions would let both sides restrict specific actions. Push notifications would let a company message an agent when a flight is delayed. Payments extensions would let an agent complete a purchase without handing over card details. Each is useful, and each gives the company another lever.

For anyone building a personal agent, the next signal is that first draft, due before the month is out: check who controls the permission model, and whether a user can override a site’s refusal.

Sierra (sierra.ai), blog post by Bret Taylor and Clay Bavor, published 6 October 2026.