Ready for pilots · bounded capability setAgent Operating Environment

Let AI agents use
your business within limits you set

One SDK exposes the capabilities you approve. Agents can then search, quote, check stock and order — through your own APIs, under your policies, with every action audited and attributed.

Works around the APIs you already have. You keep the customer relationship, the margin, and the final say.

Read the research dossier behind this thesis →
illustrative session — not customer data
relayforge · agent-env — gateway
$ DISCOVER → /.well-known/agent.json ✓
$ IDENTIFY → client: gpt-5 ✓
$ AUTHORIZE → scope: [read:pricing] ✓
$ EXECUTE → checkInventory() → 200 ✓
$ PROVE → ledger: req_731 ✓
$ _
GET /.well-known/agent.json → 200POST checkInventory → availableledger: req_731 · read · attributed
01
The gap

AI agents have no safe way into your business

01✕Agents scrape your markup instead of reading a contract
02✕Capabilities are inferred, never declared
03✕Every UI change breaks their path
04✕No boundary between allowed and forbidden actions
05✕Zero visibility, zero attribution, zero revenue proof
where this is not the answer
If you want to stop agents reading your site, you need a scraping defence — not this.
This is for businesses that want an agent to act on their behalf — to find, quote, order and book — inside boundaries they control. If blocking bots is the goal, start at your edge and auth layer instead.
The second interface

Don't make agents learn your website. Give them an environment designed for agents.

Your human interface stays optimized for humans. The Agent Operating Environment is a second interface — optimized for machines. It exposes approved capabilities through structured contracts, permissions, policies, authentication, and audit, so any agent (today's or tomorrow's) can work with you safely.

HUMAN UIyour website · for people
AGENT ENVIRONMENTthe SDK · typed capabilities
BUSINESS BACKEND
What actually changes

Three layers, before and after

layertodaywith the environment
Read
Any agent may fetch public pages and scrape
Approved capabilities, declared in a manifest, with typed responses
Act
Agents guess, or call nothing at all
Bounded actions behind your policies, approvals and limits
Prove
No attribution — you cannot see or bill the demand
Every request and action recorded, attributable to a source
02
The contract

Five primitives between an agent and your systems

01
DISCOVER
Agents find your business through a machine-readable manifest — no crawling.
GET /.well-known/agent.json
02
IDENTIFY
Every request carries a verified identity before anything else happens.
client: gpt-5 · bearer: ok
03
AUTHORIZE
Policies decide what is allowed before the call ever runs.
scope: [read:pricing]
04
EXECUTE
The action runs against your existing API — nothing is rebuilt.
POST /createOrder → 200
05
PROVE
Every meaningful action lands in an auditable Agent Activity Ledger.
ledger: req_731 · ok
One request, start to finish

The interesting part is what didn't happen

An agent asks to place an order above your limit. The request is identified, checked against policy, held for approval, denied — and the whole thing is on the record. Safety is the default, not a setting you remember to turn on.

01DISCOVERGET /.well-known/agent.json → manifest returned✓
02IDENTIFYclient: gpt-5 · credential verified✓
03AUTHORIZEpolicy: purchase_limit → requires approval◷ held for approval
04EXECUTEcreateOrder held · policy denied before call✕ blocked
05PROVEledger: req_908 · denied · reason logged✓
The stack

How it works

01SDK — install once and expose capabilities that map to your existing APIs (searchProducts, checkInventory, createCart, createOrder).
02Discovery — a machine-readable manifest at /.well-known/agent.json tells agents who you are and what you allow.
03Permissions — capability-based, not all-or-nothing: each agent gets exactly the read/write scope it needs.
04Policies — programmable business rules: order limits, rate limits, approval requirements, forbidden actions.
05Audit — every meaningful action lands in an Agent Activity Ledger: who asked, under whose authority, what policy, what happened.
06Protocol-agnostic — sits above MCP, UCP and ACP as the business-side abstraction layer, not an agent-side monopoly.
03
Capabilities

Who it's for

SaaS & platforms
capability: create_project()scope: business-approved · policy: enforceable
capability: create_invoice()scope: business-approved · policy: enforceable
capability: schedule_meeting()scope: business-approved · policy: enforceable
capability: generate_report()scope: business-approved · policy: enforceable
Ecommerce
capability: search_products()scope: business-approved · policy: enforceable
capability: check_inventory()scope: business-approved · policy: enforceable
capability: create_cart()scope: business-approved · policy: enforceable
capability: track_order()scope: business-approved · policy: enforceable
Travel & hospitality
capability: search_rooms()scope: business-approved · policy: enforceable
capability: check_availability()scope: business-approved · policy: enforceable
capability: book()scope: business-approved · policy: enforceable
capability: cancel()scope: business-approved · policy: enforceable
B2B procurement
capability: search_supplier()scope: business-approved · policy: enforceable
capability: get_quote()scope: business-approved · policy: enforceable
capability: create_purchase_order()scope: business-approved · policy: enforceable
capability: track_delivery()scope: business-approved · policy: enforceable
04
The ledger

What the business gets

1
SDK install
5
primitives
0
rebuilds of your backend
req_731·createOrder·policy: purchase_limit·approval: approved·200 OK
01
Agent analytics — a new analytics category: AI-attributed revenue, agent sources, and the agent funnel from discovery to purchase.
02
An Agent Activity Ledger that answers: who asked for what, under whose authority, what policy was applied, and what happened.
03
Full control — kill switches, rate limits, approval workflows, revocation. An arbitrary agent is never trusted just because it is an AI agent.
04
A new acquisition channel — be discoverable to ChatGPT, Claude, Gemini, Perplexity, enterprise agents, and agents that don't exist yet.

Start with one capability

One function, one policy, one agent path. We expose it read-only first, and nothing goes live until you have seen the policy evaluation yourself.

Book a pilot scoping call →
05
The pilot

One capability, fully governed

A bounded, reversible pilot. We start with one capability from your existing backend, expose it read-only, then add a single governed write action behind your policy. Ten to fifteen business days once access is in place.

You provide
Read access to the APIs you choose to expose, plus write access only for the bounded actions in scopeYour permission model: who may see what, who may execute what, and what always requires approvalA named technical owner for the pilot
We provide
A hosted Agent Activity Ledger your team can read at any timePolicy configuration — capacity limits, value thresholds, approval queues, blocklistsA written capability contract for every exposed actionA pilot report on agent requests, actions, blocked actions and outcomes
This pilot is for you if
You have an existing API that agents would genuinely use today — product search, inventory, quotes, booking, order statusYou can name at least one high-value action you would not want an agent taking unattendedYou have someone technical who can give us one week of access and answer questions
how the pilot runs
Days 1–3
Capability scoping and identity handshake with your existing auth.
Days 4–7
SDK integration against staging. Read-only only, deny-by-default.
Days 8–12
Policy design and approvals on your real permission model. Write access granted last.
Days 13–15
Live evaluation, then a written readout on what to expand, change or stop.
You leave with
A working agent-accessible path to your chosen capabilities, behind your policiesA complete activity ledger of every request, decision and actionA written report on what agent traffic is worth pursuing — and what to leave human
What we do not do in a pilot
We do not drive consumer traffic to your business during the pilotWe do not take custody of funds, issue credit, or handle payment instrumentsWe do not change your customer-facing experienceWe do not claim third-party compliance certification in the pilot
Data handling

What we hold, and what we don't

We hold · Identifiers and policy decisionsNot retained · Kept as our own copy of your order or customer data
We hold · Action references and outcomesNot retained · Stored payment instruments or long-lived credentials
We hold · Activity records you can exportNot retained · A second system of record for your orders
How it is priced

Fixed scope first. Usage-based only after the pilot proves value.

The pilot is a fixed fee with a defined scope. Production pricing follows the work only if the pilot demonstrates agent-attributed demand you could not otherwise have served.

Pilot
Fixed fee. Bounded capability set, fixed duration, fixed deliverable.
Platform
Monthly platform fee for the environment, policy engine, dashboard and ledger.
Governed actions
Tiered by verified executed action volume. Read-only discovery is not billed per call.
Advanced governance
Optional. Multi-tenant policy groups, capacity-based permissions, external audit export.

No mandatory transaction take rate. Payment, fulfilment and the customer relationship stay on your side of the transaction.

Questions buyers ask first

Boundaries, data, and what we won't promise

Will this stop AI agents from scraping our site?
No. We are not a scraping defence. If your goal is to stop unwanted automated reads, you need rate limiting, authentication and access control at the edge — and we can point you at better places to start. This product is for the case where you want an agent to act on your behalf, inside limits you set.
Do we have to rebuild our backend to expose capabilities?
No. The SDK wraps APIs that mostly already exist. If an action is not exposed today, wrapping it is a small job — usually thinner than the integration work around it.
Do you guarantee agent traffic or revenue?
No. Consumer agents choose which businesses to use. We can make your business discoverable and safely usable, and report on what happened. We cannot promise a request volume, and any vendor that does is selling you a number, not a system.
What happens to customer data?
We retain identifiers, policy decisions and activity records. Request data passes through the gateway to execute a capability, but we do not keep our own copy and never become the system of record. Your order, payment and customer records stay in your systems.
Is this production-grade and certified?
We build it as infrastructure and design for failure, but we make no third-party compliance or uptime certification claims. If a certification is a procurement requirement, treat the pilot as the evidence-gathering step.
Do you take a cut of transactions?
Not by default. You keep the margin and the merchant relationship. Where we do take a share, it is negotiated per engagement — not hidden in the platform fee.

Be the business an agent
can safely act on

Pick one capability you would be comfortable letting an agent use. We will show you exactly how it would be governed before anything goes live — and we will be straight with you about whether agent demand is likely to be worth it for your business.