Agents can find your store. They cannot buy from it.
Most small D2C brands are already being found by AI agents and are already shutting them out with blanket bot blocking. Neither of those is a strategy. This dossier is about the gap in between: seeing which agents arrive and what they were allowed to do, governing the side effects, and converting the human being through a chat the brand controls.
Customer: Small independent D2C brands selling on their own storefront, usually on Shopify. Everything below is a working argument for what to build next — not a claim about what already exists.
What we are actually deciding
A thesis is only useful if it changes what gets built. This is the call, the reasoning, and the condition that would reverse it.
Build the visibility and governance layer for the agents already reaching small D2C storefronts, and prove the governed conversion path on the brand's own storefront. Do not build a protocol, a marketplace, or a general agent platform.
If small brands will only take the visibility layer free and will not pay for governance separately from the conversion tool, the two collapse into a single product and the standalone governance layer is not a business.
- The traffic already exists. Brands are being reached through the product feeds and catalog syndications they already run, and referral traffic from AI assistants is arriving now and converting at a reported multiple of ordinary organic search.
- The purchase does not happen. An independent run of 183 agent journeys against 43 ranked D2C storefronts found that 88 per cent of stores never let an agent reach a payment screen, and a large merchant survey puts agent readiness among small businesses at 11 per cent.
- The brand's current answer is to block, which does raise reported conversion while removing any ability to learn from the traffic it is refusing.
- The prize is already priced by the market. Conversational AI is repeatedly reported to lift human conversion, so the conversion half of this thesis at least has directional evidence behind it even though the governance half does not.
If the gate is not met, the honest move is to stop or narrow — not to build a broader product to justify the work already spent.
The brand is found, blocked, and blind.
Every figure below is sourced to a card further down this page. It is the combination, not any one of them, that leaves a small brand with no good option.
Brands are already being reached through direct product feeds and catalog syndication, without building separate integrations. Referral traffic from AI assistants is arriving now, converting at a reported multiple of ordinary organic search, from a base most retailers still measure below one per cent.
Only 11 per cent of small and mid-sized merchants qualify as agent-ready, against 19 per cent of large merchants, and only 15 per cent of merchants overall have the structured product data agents need. Expectation is running far ahead of the plumbing.
In 43 ranked storefronts, 88 per cent of stores never let an agent reach a payment surface. Platform policy reinforces this: the hosted rule blocks buy-for-me agents and any end-to-end flow that completes payment without a final human review step.
Only around 23 per cent of merchants can clearly distinguish AI-driven traffic. Brands report actively blocking agents because it distorts the conversion metric — which makes the number look better while removing the ability to see what was actually happening.
What the 2026 evidence does and does not show
The readiness gap is documented. Willingness to pay for a third party to close it is not evidenced at all, and is treated throughout as a hypothesis.
The drop-off is present at every one of the six stages, and it is largest at the cart: of 43 ranked stores, 36 were reached at discovery (84 per cent), 30 at product (70), 17 at cart (40), 9 at checkout (21), 6 at a form (14) and 5 at payment (12). The largest single collapse is the cart, not the checkout. The published findings also name the specific walls behind individual stores, including an OTP wall at Foxtale and a broken payment flow at Blue Tokai Coffee.
It does not show that a governance layer is what these stores would buy. The sample is small, self-selected and Indian D2C storefronts, and one agent was used rather than a population of them.
A large merchant and consumer survey puts SMB agent readiness at 11 per cent versus 19 per cent for large merchants, with 15 per cent of merchants holding agent-ready structured data, while 68 per cent expect agents to be at least 5 per cent of digital sales within two years. Fraud protection is the top stated condition for merchant participation, and only around 23 per cent of merchants can clearly distinguish AI-driven traffic at all.
It does not show that SMBs will pay a third party for readiness tooling, and the gap it describes is one the platforms themselves are actively closing.
The platform already ships per-partner controls deciding whether an agent may read product data, may complete checkout, or neither, alongside least-privilege and secure-action-layer guidance aimed squarely at this merchant segment.
Platform-native controls are configuration inside one platform. They are not an independent cross-surface view, and they do not give a brand a record it holds or can audit without the platform.
The default posture at the largest commerce platform is to block automated agents outright — including buy-for-me agents and any end-to-end flow that reaches payment without a final human review step — on the stated grounds that no one wants to be where the agents are shopping. Blocking is a platform policy decision, not a merchant one.
It does not quantify what a blocked agent would have converted at, and it is trade-press reporting of a policy rather than a measured market outcome.
A named brand blocks agent traffic specifically because it distorts the conversion metric, and reports that blocking does raise conversion. This is the clearest available statement of the trade a small brand is being forced into.
One brand, self-described as early-stage in its understanding. It does not size the revenue forgone, and a cleaner conversion number is not the same as a better business.
Brands are already tracking referral traffic arriving from AI interfaces, and that traffic is converting at up to six times the rate of ordinary organic search — from an absolute base most retailers still measure below one per cent. The direction is real; the volume is not yet material.
It does not establish that the base will grow, that a small brand captures any of it, or that the multiples hold outside the retailers surveyed.
Almost every abandonment traces to a small number of concrete failures — edge bot rules, a different page served to the agent, a buy action that only exists after JavaScript runs — and a store that blocks crawlers cannot score well however good the rest of it is.
It is a vendor describing a product that scans for these failures, and the severity ceilings in its rubric are its own construct rather than an industry standard.
Price, image and in-stock is the gate: miss any one and an agent cannot sell the product at all, regardless of how good the storefront looks. A well-designed store in the documented example still left 47 per cent of products unready.
A vendor scoring rubric, not an independent benchmark, and readiness scores are not revenue.
Direct product feeds give agents structured, current product data that web crawling alone does not, and agentic commerce suites let retailers syndicate a catalog across supported agents without building separate integrations. Retailers are running explicit test-and-learn programmes to track how products are found, recommended and purchased across AI surfaces. This is the mechanism by which a small brand becomes reachable without building separate integrations.
It does not establish that any of those surfaces will send a paying customer, and a catalog being readable is not the same as a purchase being completable.
The control pattern is settled: a dedicated agent principal with a named owner and purpose, task-scoped least-privilege roles, just-in-time elevation rather than standing access, allowlisted tools, and end-to-end auditability of the action rather than the response.
It is written for enterprise identity estates. A two-to-thirty-person D2C brand has no such estate, which is the gap this thesis is about.
Agent identities are treated as distinct verifiable entities with their own provisioning and decommissioning, scopes are task-bound and ephemeral rather than broad and persistent, and accountability runs through a human delegation chain recorded in a tamper-evident trail.
The framework assumes an identity platform already in place. It does not address a merchant who has none and is currently deciding between blocking everything and admitting everything.
Across enterprise roundtables, roughly nine in ten reported agents running with no governance visibility and eight in ten reported shadow AI already present — the identification problem is widespread, not exotic.
Enterprise roundtable sentiment. It says nothing about small merchants, and it is evidence that visibility is wanted, not evidence of what anyone will pay for it.
The sale is lost in the cart, not the checkout
Discovery is close to solved. The interesting failure is in the middle, and almost none of it is visible if you audit your own product markup.
Reach rates for all six stages come from the independent Agent Readiness Index run against 43 ranked D2C storefronts. The first three causes are the failure modes catalogued in the AgentReady teardown; the last two are walls recorded against named stores in the ARI findings column.
The agent finds the store. This step is largely working.
The offer is legible enough to describe.
The largest single collapse. Building a cart is where intent becomes a transaction.
Slightly more than half of the stores that could build a cart could start one.
Account, address and contact walls cluster here.
Almost nobody gets here. This is the number that matters and the one brands cannot currently see.
A crawler refused at the edge never reaches the application, so nothing about the storefront itself is wrong and nothing in the markup says so.
Server logs and the agent's own report — never in a markup audit.
Some stores serve declared AI user-agents a thinner or altered page, so the agent can see the product and still not find the price, the stock or the buy action it just watched a human version display.
A differential fetch: once as a browser, once as a declared agent, then diff.
The agent can describe the product perfectly and still have no machine-readable way to act on it. A perfectly good page is not a transactable one.
Raw HTML inspection — hidden from any rendered-page audit.
An account-level control applied to all automation. In the ARI run, Foxtale stopped at checkout on an OTP wall despite being reached at every other stage.
Nowhere in the storefront. It is an account setting, not a page.
A store can be fully transactable and still fail at the final step because a payment option is broken or unsupported. In the ARI run, Blue Tokai Coffee was recorded with a broken payment flow.
Only at the moment of payment, after everything else has already succeeded.
Governance is five controls
Not a policy document. Each step is a control the brand can hold us to, and each one is a place where a prompt is explicitly not good enough.
Every agent gets a first-class identity, not a shared service account and not an allowlisted crawler.
- A unique, verifiable identity per agent, distinct from the human and service accounts it operates alongside
- A named owner and an explicit purpose recorded against that identity
- Registration in a registry the brand can query itself, not one we hold on their behalf
Permission is task-scoped, time-boxed, and re-evaluated on every action rather than assumed from the start of a session.
- Least-privilege roles scoped to the specific resources and data the task needs
- Just-in-time elevation for the duration of a workflow, never standing access
- Downstream authorisation verified on each call, not only at the orchestrator
- An allowlist of permitted tools and actions, with everything else denied by default
Reads and writes are separated, and the human stays in the loop at the single point where consequence lands.
- Read and write authority held as distinct roles, so an agent that can look cannot also change
- Explicit human approval on the final order or payment action
- Capacity limits on rate, value and scope, bounding what a confused agent can do before anyone notices
One tamper-evident ledger recording the decision, not a log that merely records the model output.
- Agent identity, role used, effective scope, resource, action, timestamp and a correlation ID per entry
- The human delegation chain: who asked, which agent acted, and on whose authority
- Tool invocations and downstream authorisation decisions, not only the response text
- Append-only and queryable by the brand without asking us for an export
A standing, readable answer to "can an agent do this?" that the founder can check in one place without phoning anyone.
- Per-agent, per-action answers instead of one global policy page nobody reads
- Expiring grants that force re-approval rather than allowing silent permission drift
- Revocation paths that are tested on a schedule, not merely documented
Chat is reported to convert. The direction is consistent
The governance problem is unsolved. The reason a small brand should care anyway is that conversational AI is repeatedly reported to change human conversion by a multiple — across several separately sourced studies, none of them an independent trial.
Conversion among shoppers who engage with AI chat, against those who do not
Aggregate vendor figure. Selection effects are not controlled for.
Chat-to-order conversion for AI shopping assistants, against a 5–15% industry benchmark
Vendor-reported across self-selected customers on one platform. The 58 per cent is a best case, not an average, and the 5–15 per cent benchmark is the vendor's own comparison rather than an independent control.
Conversion when shoppers use interactive product discovery, in apparel and footwear
Live customer data, but consultative sessions select for high intent.
Michaels Ask Mike assistant conversion against traditional search on the same site
The brand itself states the lift cannot be separated from intent-driven self-selection.
Conversion and average order value for a luxury skincare brand with an AI assistant, against its own pre-assistant baseline
Vendor-published customer story with no independent control group.
Conversion increase from AI-powered shopping assistance across 144 retail brands
Aggregate. Does not isolate the assistant from the merchandising around it.
AI-driven cart recovery, against roughly 10.7% for conventional abandonment email
Vendor-reported, and the recovery windows behind the two figures differ.
Every figure above is a vendor or brand number rather than an independent trial, and the same caveat recurs: shoppers who choose to start a conversation are already more intentful than shoppers who do not. The direction is consistent across seven numbers from six sources. The magnitude is not established, and this dossier does not treat it as a forecast.
Governed conversion, end to end
This is the only path the thesis is proposing. The visibility layer and the conversion agent are the same system, not two products that happen to share a customer.
- ArrivalThe agent identifies itself
An external agent requests a capability and declares who it is. The brand sees who is asking, and what it has been granted, before any of its own systems are touched.
- EvaluationPolicy decides, per action
The request is evaluated against that identity, its scope and the specific action requested. A read passes. A write needs more. A payment needs the human.
- ConversationThe brand's own agent talks to the human
A storefront agent running under the same policy answers the shopper, recommends from the brand catalog, and builds the cart — on a surface the brand owns, with the customer record intact.
- AuthorisationThe human authorises the action
The shopper confirms the final step. That confirmation is captured as an explicit authorisation event, not inferred after the fact from the conversation having gone well.
- ExecutionThe order executes under limits
The order is placed through the brand's existing checkout, bounded by the rate, value and scope limits the policy set in advance.
- ProofThe ledger closes
Every step becomes a tamper-evident record the brand holds: which agent asked, what it was allowed, what the human approved, and what shipped.
What gets built
The smallest thing that makes the thesis falsifiable: one brand, one governed conversion, one ledger the founder can read without us in the room.
- The brand owns the relationship. Discovery may happen on someone else's surface; the conversion and the customer record happen on the brand's own storefront.
- The agent is a principal with a name, an owner and a scope — never an anonymous allowlisted crawler.
- Authorisation is enforced at the action, not in the prompt. "The agent will only do X" is not a control, it is a hope.
- The ledger records decisions, not responses. A log of model output is not an audit trail.
- Read and browse capabilities first. Write and payment capabilities only ever behind a human gate.
- Platform-neutral: work with the commerce stack and edge provider the brand already runs, rather than asking for a migration.
One Shopify D2C brand, one storefront agent, three capabilities — search products, check stock, build a cart — with the order action behind human approval and a ledger the founder can read unaided. Three to four weeks.
- Agent identity registration and a per-agent capability grant the brand sets
- A machine-readable catalog the agent can act on: price, image, availability
- Policy evaluation per action, with the decision and its reason recorded
- A storefront chat agent that recommends and builds a cart within those grants
- Human approval on the final order action, captured as an authorisation event
- A merchant console showing which agents arrived, what they were allowed, and what they did
Who pays, for what
The buyer is a person, not a department. That shapes everything about the product and about how it has to be sold.
The founder or operator of an independent D2C brand — typically two to thirty people, selling on their own storefront — who has already noticed agent traffic and cannot tell whether it is a customer or a scraper. This is not a security buyer and will not be sold to as one.
- Know which agents reached the store, what they asked for, and what they were permitted to do.
- Stop guessing why an agent abandoned the purchase, with the failure named at the exact step it occurred.
- Convert the human that agent brought you, on a surface you own, with the final action still theirs.
- Prove authorisation when it matters: a readable record for refunds, chargebacks and disputes.
- Replace blanket blocking with per-agent grants, so protection and revenue stop being the same switch.
- Free tier: agent visibility and a read-only ledger for a single storefront
- Paid: per-storefront platform fee covering policy, governed capabilities and the ledger
- Optional: the storefront conversion agent as a usage-based module
- No transaction take rate, and no claim on the brand's customer relationship
- The activity ledger: real agent behaviour against a real catalog, accumulating over time
- Per-agent policy plus the history of what was granted, refused and changed
- The merchant console becoming the place a small team actually runs its agent surface
- Protocol neutrality: a portable record is worth more than any single integration
What would make this wrong
The next four weeks
Three brands, in sequence, each one paying. The gate is not a demo; it is a founder reading their own ledger and a second paid month.
Run the agent journey ourselves against the brand's own storefront and record exactly where it stops, with evidence rather than inference.
01Register the agents that actually arrive, grant browse capability only, and let the ledger fill with real traffic before anything can write.
02Enable the storefront agent with the order action behind human approval, and measure the change against the week-zero baseline.
03Put the ledger and the conversion number in front of the founder and ask for a paid second month.
04- At least three distinct agent identities observed reaching the storefront in week one
- A named failure step identified with evidence, not inferred from a markup audit
- A measurable change in chat-assisted conversion against the brand's own pre-period
- The founder reads the ledger unaided
- Agreement to a paid second month, rather than a delighted first demo
- Brands will not grant agent access even read-only, because blocking is less work and flatters the conversion metric
- The only thing they will pay for is the chat assistant, at a price that leaves no governance business
- Conversational conversion lift does not survive on a small catalog
- The edge or commerce provider makes agent identity and per-agent policy a free default
Evidence here is one independent agent-journey benchmark, one large merchant and consumer survey, platform security documentation, two platform policies reported by trade press, and a set of vendor-reported conversion figures. It establishes that small D2C brands are found by agents, that agents cannot currently complete a purchase with them, and that neither side can largely see why. It does not establish that they will pay for the answer. That is the entire open question, and three paid brands are the test.
Read the argument, then test it with us
Every claim on this page is falsifiable. If you run the infrastructure, or the business, this is where we would rather be corrected than impressed.
RelayForge is a product lab. SentraZero, PowerIQ and the Outbound Engine are case studies, not products.