**Short answer:** the Personal Agent Protocol (PAP) is an open standard that Sierra and Meta announced on October 6, 2026, for how a customer's personal AI agent identifies itself to a business and what the business lets it do. It is built on OAuth, lets an agent start as an anonymous guest to check things like availability or a returns policy, and lets the customer choose read-only or write access once they sign in, while the business sets the limits. There is no specification to build against yet. Sierra says version 0.1 is due later in October, and payments are only a proposed future extension. The detail that matters most to a small business is in Sierra's own description: personal agents today mostly use websites the way people do, loading pages and clicking through forms, and when that fails they fall back to phone support or chat. So the preparation is plain. Keep your facts clear and public, let people book without an account, and answer the phone.

Pew Research Center's February 2026 survey found that 49% of US adults say they ever use AI chatbots and 24% use them daily. Pew didn't ask how many people let an assistant book or buy for them, so nobody can say yet how much agent traffic a local business will see. What follows is what was announced, what is still undecided, and seven things worth doing that don't depend on how the standard turns out.

## Key takeaways

- PAP was announced October 6, 2026 by Sierra and Meta, with partners including Shopify, Stripe, Walmart, and Genesys.
- The first draft of the spec (v0.1) is due later in October. Until then, nothing can be built to it.
- Customers decide what access their agent gets, and the business decides what the agent may do.
- Agents today mostly work through websites and fall back to phone or chat, so the basics still decide the outcome.
- Be wary of anyone selling "PAP readiness" or a guaranteed place in agent bookings.

## What Meta and Sierra announced

Sierra co-founders Bret Taylor and Clay Bavor described the protocol in a blog post on October 6, 2026, saying Sierra and Meta are developing it with industry partners. Sierra names Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart, and says the protocol is open for anyone to implement.

The post lays out one principle: consumers decide what access their personal agents get, and companies set limits on what those agents can do. Here is how a session would work:

- The agent can start as a guest, with no sign-in, which is enough to check availability or ask about a returns policy.
- For account tasks, the customer signs in on the company's page or with credentials already stored with their agent.
- The customer chooses read-only or write access.
- Sessions use OAuth and carry across channels, so a question asked before sign-in and an order change made afterward count as one visit.

The business then chooses how the agent gets work done. It can let the agent use its regular web pages, connect through APIs built on standards such as MCP and OpenAPI, or route conversational tasks, such as a warranty claim, to the company's own agent. Sierra says it will publish v0.1 of the specification later in October, along with design workshops and a reference implementation. Finer-grained permissions, push notifications, and payments that don't expose card details are listed as possible future extensions, not commitments.

## What the terms mean

| Term | Plain meaning | Source |
|---|---|---|
| OAuth 2.0 | The industry-standard protocol for authorization | oauth.net |
| MCP (Model Context Protocol) | An open-source standard for connecting AI applications to outside systems and tools | modelcontextprotocol.io |
| OpenAPI | A specification language for describing HTTP APIs | openapis.org |

Most small businesses will never touch these directly. In our reading, they would come built into the booking, ecommerce, or customer-service software a business already pays for, so the realistic question is whether those vendors adopt the standard.

## What is still unsettled

**The spec doesn't exist yet.** Anything written about how PAP "will work" before v0.1 is a description of an announcement, including this guide.

**Big names are missing.** The Next Web and other outlets note that OpenAI and Anthropic are not part of the effort for now. CNBC, as relayed by one analysis, reports that Taylor expects them to join. We can't confirm that.

**It overlaps with other efforts.** The Next Web reports that Visa has its own Trusted Agent Protocol, which Microsoft, Stripe, Shopify, and Worldpay have joined, and that Stripe and Shopify appear in both. UCP Checker describes a separate Universal Commerce Protocol for catalogs, carts, and checkout, and says it is unclear how it will fit with PAP. In our view, when several standards compete, small businesses mostly end up following whatever their platform chooses.

**Some agents won't identify themselves.** In a companion post, Sierra writes that consumer agents could soon make up a large share of the calls businesses receive, though it offers no figures, and that some agents won't follow the protocol. It launched a model called fleming-1 to detect when a phone caller is an AI agent, so a business can decide what to do next.

## Seven things to do now

None of these depend on PAP. They are our recommendations, based on Sierra's description of how agents behave today.

### 1. Put your core facts in plain text

Services, prices or price ranges, hours, service area, deposit and cancellation rules. An agent that loads pages the way a person does can read what a person can read, so a price list that exists only as an image or a PDF scan is easy to miss.

### 2. Keep the guest path open

PAP's guest session exists because a lot of questions don't need an account. Let someone check availability, request a quote, or ask about a policy without creating a login.

### 3. Make forms and booking links work

A form that breaks on a phone, or asks for fifteen fields, can trip up an agent the way it trips up a customer. Test yours on a phone, start to finish.

### 4. Keep your facts identical everywhere

Your website, Google Business Profile, and directory listings should agree on name, address, phone, hours, and services. Agents and AI search both weigh sources that corroborate each other. Our guide to [how to get your local business recommended by ChatGPT](/blog/how-to-get-your-local-business-recommended-by-chatgpt) covers this in detail.

### 5. Decide in advance what an agent may do

Answering questions and giving quotes is low risk. Booking is reasonable with a confirmation. Cancellations, refunds, and payments deserve a person's approval. PAP's own principle is that the company sets the limits, so write yours down before a tool sets them for you. If an AI reads customer messages and can act on them, [Claude Opus 5.5 and prompt injection](/blog/claude-opus-5-5-pricing-what-it-means-for-small-business) explains why that matters.

### 6. Answer the phone and the chat

Sierra's own account is that agents fall back to phone and chat when a website fails them, and that those channels are slow and often incomplete. A business that replies quickly can finish the task the agent started. The numbers on unanswered calls are in [missed call statistics by industry](/blog/missed-call-statistics-by-industry-verified).

### 7. Ask your software vendors

Ask your booking, ecommerce, and customer-service vendors whether they plan to support PAP or a similar standard. Don't hire anyone to build to it before the spec is published.

## Where Velora fits

Steps 1, 3, and 4 are groundwork that doesn't depend on which standard wins, and they are what Velora Media's [AI Search Visibility Package](/shop/ai-search-visibility) covers at a published price of $800: an entity and citation audit that finds where your facts disagree across the web, structured data and an llms.txt file, answer-first rewrites of your most important pages, and a baseline with a 90-day visibility report.

Two limits are worth stating. Google's guide for site owners says that "structured data isn't required for generative AI search" and that special AI files "will neither harm nor help" visibility in Google Search, so the audit and the page rewrites carry the weight. And the package does not implement PAP, because there is nothing to implement yet. Nobody can promise that an AI assistant or agent will choose or book a particular business.

## Frequently asked questions

### What is the Personal Agent Protocol?

It is an open standard from Sierra and Meta, announced October 6, 2026, for how a customer's personal AI agent authenticates with a business and what the business allows it to do. It is built on OAuth.

### Who created the Personal Agent Protocol?

Sierra, led by co-founders Bret Taylor and Clay Bavor, is developing it with Meta and partners. Sierra names Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart.

### When will the specification be published?

Sierra says version 0.1 is due later in October 2026, with design workshops and a reference implementation. Payments, push notifications, and finer permissions are listed as possible future extensions.

### Do small businesses need to do anything now?

There is nothing to build yet. The sensible preparation is plain: accurate public facts, a booking path that works without an account, forms that work on a phone, and fast replies by phone and chat.

### Will ChatGPT and Claude use the protocol?

OpenAI and Anthropic are not participating for now, according to coverage of the announcement. CNBC, as relayed by one analysis, reports that Taylor expects them to join, but that is unconfirmed.

### How is it different from MCP?

MCP is an open standard for connecting AI applications to outside systems and tools. PAP covers the session around a customer's request: how an agent identifies itself, signs in, and gets the access the customer allows. PAP lets a business route agents to APIs built on MCP or OpenAPI.

### Can anyone guarantee an AI agent will choose my business?

No. Nobody controls which business an assistant or agent picks, and anyone who guarantees it is guessing. What a business can control is how clear, consistent, and easy to use its information and booking path are.

## Related reading

For how AI assistants decide which local business to name, see [how to get your local business recommended by ChatGPT](/blog/how-to-get-your-local-business-recommended-by-chatgpt). For a plain-language look at where AI stands for small business owners, see [what small business owners need to understand about AI now](/blog/what-small-business-owners-need-to-understand-about-ai-now). For handling calls when you can't pick up, see [AI receptionist vs answering service vs hiring a receptionist](/blog/ai-receptionist-vs-answering-service-vs-hiring-a-receptionist).

## Velora Media landing pages, by industry

Each site below carries the same six pages: an overview, the services built for that industry, a shop with published prices, the engine showing how the pieces connect, results, and the questions owners in that industry ask first.

### Home services: plumbing, electrical, HVAC, and appliance repair

[homeservices.veloramedia.cloud](https://homeservices.veloramedia.cloud/) · [Services](https://homeservices.veloramedia.cloud/services.html) · [Shop](https://homeservices.veloramedia.cloud/shop.html) · [Engine](https://homeservices.veloramedia.cloud/engine.html) · [Results](https://homeservices.veloramedia.cloud/results.html) · [FAQ](https://homeservices.veloramedia.cloud/faq.html)

### AI receptionist, for any industry

[aireceptionist.veloramedia.cloud](https://aireceptionist.veloramedia.cloud/) · [Services](https://aireceptionist.veloramedia.cloud/services.html) · [Shop](https://aireceptionist.veloramedia.cloud/shop.html) · [Engine](https://aireceptionist.veloramedia.cloud/engine.html) · [Results](https://aireceptionist.veloramedia.cloud/results.html) · [FAQ](https://aireceptionist.veloramedia.cloud/faq.html)

### Real estate agents

[realestateagents.veloramedia.cloud](https://realestateagents.veloramedia.cloud/) · [Services](https://realestateagents.veloramedia.cloud/services.html) · [Shop](https://realestateagents.veloramedia.cloud/shop.html) · [Engine](https://realestateagents.veloramedia.cloud/engine.html) · [Results](https://realestateagents.veloramedia.cloud/results.html) · [FAQ](https://realestateagents.veloramedia.cloud/faq.html)

### Real estate wholesalers

[wholesale.veloramedia.cloud](https://wholesale.veloramedia.cloud/) · [Services](https://wholesale.veloramedia.cloud/services.html) · [Shop](https://wholesale.veloramedia.cloud/shop.html) · [Engine](https://wholesale.veloramedia.cloud/engine.html) · [Results](https://wholesale.veloramedia.cloud/results.html) · [FAQ](https://wholesale.veloramedia.cloud/faq.html)

### Med spas and aesthetic clinics

[medspaaesthetics.veloramedia.cloud](https://medspaaesthetics.veloramedia.cloud/) · [Services](https://medspaaesthetics.veloramedia.cloud/services.html) · [Shop](https://medspaaesthetics.veloramedia.cloud/shop.html) · [Engine](https://medspaaesthetics.veloramedia.cloud/engine.html) · [Results](https://medspaaesthetics.veloramedia.cloud/results.html) · [FAQ](https://medspaaesthetics.veloramedia.cloud/faq.html)

### Physicians and medical practices

[physicians.veloramedia.cloud](https://physicians.veloramedia.cloud/) · [Services](https://physicians.veloramedia.cloud/services.html) · [Shop](https://physicians.veloramedia.cloud/shop.html) · [Engine](https://physicians.veloramedia.cloud/engine.html) · [Results](https://physicians.veloramedia.cloud/results.html) · [FAQ](https://physicians.veloramedia.cloud/faq.html)

### Auto body and collision repair

[autobody.veloramedia.cloud](https://autobody.veloramedia.cloud/) · [Services](https://autobody.veloramedia.cloud/services.html) · [Shop](https://autobody.veloramedia.cloud/shop.html) · [Engine](https://autobody.veloramedia.cloud/engine.html) · [Results](https://autobody.veloramedia.cloud/results.html) · [FAQ](https://autobody.veloramedia.cloud/faq.html)

### Law firms and attorneys

[lawfirms.veloramedia.cloud](https://lawfirms.veloramedia.cloud/) · [Services](https://lawfirms.veloramedia.cloud/services.html) · [Shop](https://lawfirms.veloramedia.cloud/shop.html) · [Engine](https://lawfirms.veloramedia.cloud/engine.html) · [Results](https://lawfirms.veloramedia.cloud/results.html) · [FAQ](https://lawfirms.veloramedia.cloud/faq.html)

### Florists and flower shops

[florist.veloramedia.cloud](https://florist.veloramedia.cloud/) · [Services](https://florist.veloramedia.cloud/services.html) · [Shop](https://florist.veloramedia.cloud/shop.html) · [Engine](https://florist.veloramedia.cloud/engine.html) · [Results](https://florist.veloramedia.cloud/results.html) · [FAQ](https://florist.veloramedia.cloud/faq.html)

## Sources

- Sierra, "Introducing Personal Agent Protocol," October 6, 2026. [sierra.ai](https://sierra.ai/blog/introducing-personal-agent-protocol)
- Sierra, "Caller ID in the age of agents." [sierra.ai](https://sierra.ai/blog/caller-id-in-the-age-of-agents)
- PYMNTS, "Meta and Sierra Build Standard for How Personal Agents Interact With Businesses," October 6, 2026. [pymnts.com](https://www.pymnts.com/news/artificial-intelligence/2026/meta-and-sierra-build-standard-for-how-personal-agents-interact-with-businesses/)
- The Next Web, "Sierra announces Personal Agent Protocol, an open standard for personal AI agents." [thenextweb.com](https://thenextweb.com/news/personal-agent-protocol-sierra-meta)
- UCP Checker, "Personal Agent Protocol (PAP) Explained: Meta, Sierra, UCP." [ucpchecker.com](https://ucpchecker.com/blog/personal-agent-protocol-meta-sierra-ucp)
- Pew Research Center, "Americans and AI 2026: Chatbots, Smart Devices and Views on Impact," June 17, 2026. [pewresearch.org](https://www.pewresearch.org/internet/2026/06/17/americans-and-ai-2026-chatbots-smart-devices-and-views-on-impact/)
- Google Search Central, "Optimizing your website for generative AI features on Google Search." [developers.google.com](https://developers.google.com/search/docs/fundamentals/ai-optimization-guide)
- OAuth.net, "OAuth 2.0." [oauth.net](https://oauth.net/2/)
- Model Context Protocol, "What is MCP?" [modelcontextprotocol.io](https://modelcontextprotocol.io/docs/getting-started/intro)
- OpenAPI Initiative, "What is OpenAPI?" [openapis.org](https://www.openapis.org/what-is-openapi)
