Research dossier · September 2026MSME D2C commerce · agent security, visibility and governed conversion

Agents can find your store. They cannot buy from it.

Most small D2C brands are already being found by AI agents and are already shutting them out with blanket bot blocking. Neither of those is a strategy. This dossier is about the gap in between: seeing which agents arrive and what they were allowed to do, governing the side effects, and converting the human being through a chat the brand controls.

Product
Agent Operating Environment
Lab role
Narrow discovery and prototype track
Product status
Ready for pilots · bounded capability set
Research status
Assessed internally · readiness gap documented · willingness to pay untested

Customer: Small independent D2C brands selling on their own storefront, usually on Shopify. Everything below is a working argument for what to build next — not a claim about what already exists.

The lab decision

What we are actually deciding

A thesis is only useful if it changes what gets built. This is the call, the reasoning, and the condition that would reverse it.

Decision

Build the visibility and governance layer for the agents already reaching small D2C storefronts, and prove the governed conversion path on the brand's own storefront. Do not build a protocol, a marketplace, or a general agent platform.

Reversal condition

If small brands will only take the visibility layer free and will not pay for governance separately from the conversion tool, the two collapse into a single product and the standalone governance layer is not a business.

Why
  • The traffic already exists. Brands are being reached through the product feeds and catalog syndications they already run, and referral traffic from AI assistants is arriving now and converting at a reported multiple of ordinary organic search.
  • The purchase does not happen. An independent run of 183 agent journeys against 43 ranked D2C storefronts found that 88 per cent of stores never let an agent reach a payment screen, and a large merchant survey puts agent readiness among small businesses at 11 per cent.
  • The brand's current answer is to block, which does raise reported conversion while removing any ability to learn from the traffic it is refusing.
  • The prize is already priced by the market. Conversational AI is repeatedly reported to lift human conversion, so the conversion half of this thesis at least has directional evidence behind it even though the governance half does not.
Next gate
Three brands, one agent-readable catalog, one governed action, one visible ledger.

If the gate is not met, the honest move is to stop or narrow — not to build a broader product to justify the work already spent.

The trap

The brand is found, blocked, and blind.

Every figure below is sourced to a card further down this page. It is the combination, not any one of them, that leaves a small brand with no good option.

01Found

Brands are already being reached through direct product feeds and catalog syndication, without building separate integrations. Referral traffic from AI assistants is arriving now, converting at a reported multiple of ordinary organic search, from a base most retailers still measure below one per cent.

02Not equippable

Only 11 per cent of small and mid-sized merchants qualify as agent-ready, against 19 per cent of large merchants, and only 15 per cent of merchants overall have the structured product data agents need. Expectation is running far ahead of the plumbing.

03Stopped at the last step

In 43 ranked storefronts, 88 per cent of stores never let an agent reach a payment surface. Platform policy reinforces this: the hosted rule blocks buy-for-me agents and any end-to-end flow that completes payment without a final human review step.

04Blind

Only around 23 per cent of merchants can clearly distinguish AI-driven traffic. Brands report actively blocking agents because it distorts the conversion metric — which makes the number look better while removing the ability to see what was actually happening.

Security and visibility

What the 2026 evidence does and does not show

The readiness gap is documented. Willingness to pay for a third party to close it is not evidenced at all, and is treated throughout as a hypothesis.

Agent Readiness Index — 43 ranked D2C storefronts, 183 recorded journeysIndependent benchmark
Establishes

The drop-off is present at every one of the six stages, and it is largest at the cart: of 43 ranked stores, 36 were reached at discovery (84 per cent), 30 at product (70), 17 at cart (40), 9 at checkout (21), 6 at a form (14) and 5 at payment (12). The largest single collapse is the cart, not the checkout. The published findings also name the specific walls behind individual stores, including an OTP wall at Foxtale and a broken payment flow at Blue Tokai Coffee.

Does not establish

It does not show that a governance layer is what these stores would buy. The sample is small, self-selected and Indian D2C storefronts, and one agent was used rather than a population of them.

Independent benchmark source
Global Digital Shopping Index — agentic commerce deep diveVisa Acceptance
Establishes

A large merchant and consumer survey puts SMB agent readiness at 11 per cent versus 19 per cent for large merchants, with 15 per cent of merchants holding agent-ready structured data, while 68 per cent expect agents to be at least 5 per cent of digital sales within two years. Fraud protection is the top stated condition for merchant participation, and only around 23 per cent of merchants can clearly distinguish AI-driven traffic at all.

Does not establish

It does not show that SMBs will pay a third party for readiness tooling, and the gap it describes is one the platforms themselves are actively closing.

Visa Acceptance source
Agentic AI security — least privilege and per-partner controlsShopify
Establishes

The platform already ships per-partner controls deciding whether an agent may read product data, may complete checkout, or neither, alongside least-privilege and secure-action-layer guidance aimed squarely at this merchant segment.

Does not establish

Platform-native controls are configuration inside one platform. They are not an independent cross-surface view, and they do not give a brand a record it holds or can audit without the platform.

Shopify source
Hosted block on buy-for-me agents and unattended checkoutMediaPost
Establishes

The default posture at the largest commerce platform is to block automated agents outright — including buy-for-me agents and any end-to-end flow that reaches payment without a final human review step — on the stated grounds that no one wants to be where the agents are shopping. Blocking is a platform policy decision, not a merchant one.

Does not establish

It does not quantify what a blocked agent would have converted at, and it is trade-press reporting of a policy rather than a measured market outcome.

MediaPost source
Why a D2C brand actively blocks agent trafficDigital Commerce 360
Establishes

A named brand blocks agent traffic specifically because it distorts the conversion metric, and reports that blocking does raise conversion. This is the clearest available statement of the trade a small brand is being forced into.

Does not establish

One brand, self-described as early-stage in its understanding. It does not size the revenue forgone, and a cleaner conversion number is not the same as a better business.

Digital Commerce 360 source
What agentic traffic actually looks like in practiceAdyen
Establishes

Brands are already tracking referral traffic arriving from AI interfaces, and that traffic is converting at up to six times the rate of ordinary organic search — from an absolute base most retailers still measure below one per cent. The direction is real; the volume is not yet material.

Does not establish

It does not establish that the base will grow, that a small brand captures any of it, or that the multiples hold outside the retailers surveyed.

Adyen source
Why agents abandon a checkout — three concrete failure modesAgentReady
Establishes

Almost every abandonment traces to a small number of concrete failures — edge bot rules, a different page served to the agent, a buy action that only exists after JavaScript runs — and a store that blocks crawlers cannot score well however good the rest of it is.

Does not establish

It is a vendor describing a product that scans for these failures, and the severity ceilings in its rubric are its own construct rather than an industry standard.

AgentReady source
AI readiness — transactability as a hard gateSumeru
Establishes

Price, image and in-stock is the gate: miss any one and an agent cannot sell the product at all, regardless of how good the storefront looks. A well-designed store in the documented example still left 47 per cent of products unready.

Does not establish

A vendor scoring rubric, not an independent benchmark, and readiness scores are not revenue.

Sumeru source
Catalog syndication across AI surfaces, and how brands are testing itStripe
Establishes

Direct product feeds give agents structured, current product data that web crawling alone does not, and agentic commerce suites let retailers syndicate a catalog across supported agents without building separate integrations. Retailers are running explicit test-and-learn programmes to track how products are found, recommended and purchased across AI surfaces. This is the mechanism by which a small brand becomes reachable without building separate integrations.

Does not establish

It does not establish that any of those surfaces will send a paying customer, and a catalog being readable is not the same as a purchase being completable.

Stripe source
Least privilege for AI agents — identity, access and tool bindingMicrosoft Security
Establishes

The control pattern is settled: a dedicated agent principal with a named owner and purpose, task-scoped least-privilege roles, just-in-time elevation rather than standing access, allowlisted tools, and end-to-end auditability of the action rather than the response.

Does not establish

It is written for enterprise identity estates. A two-to-thirty-person D2C brand has no such estate, which is the gap this thesis is about.

Microsoft Security source
Implementing least privilege for AI agentsOkta
Establishes

Agent identities are treated as distinct verifiable entities with their own provisioning and decommissioning, scopes are task-bound and ephemeral rather than broad and persistent, and accountability runs through a human delegation chain recorded in a tamper-evident trail.

Does not establish

The framework assumes an identity platform already in place. It does not address a merchant who has none and is currently deciding between blocking everything and admitting everything.

Okta source
Agent sprawl and the governance visibility gapMicrosoft Tech Community
Establishes

Across enterprise roundtables, roughly nine in ten reported agents running with no governance visibility and eight in ten reported shadow AI already present — the identification problem is widespread, not exotic.

Does not establish

Enterprise roundtable sentiment. It says nothing about small merchants, and it is evidence that visibility is wanted, not evidence of what anyone will pay for it.

Microsoft Tech Community source
Where journeys die

The sale is lost in the cart, not the checkout

Discovery is close to solved. The interesting failure is in the middle, and almost none of it is visible if you audit your own product markup.

Reach rates for all six stages come from the independent Agent Readiness Index run against 43 ranked D2C storefronts. The first three causes are the failure modes catalogued in the AgentReady teardown; the last two are walls recorded against named stores in the ARI findings column.

Discovery
36 of 43 · 84%

The agent finds the store. This step is largely working.

Product page
30 of 43 · 70%

The offer is legible enough to describe.

Cart
17 of 43 · 40%

The largest single collapse. Building a cart is where intent becomes a transaction.

Checkout
9 of 43 · 21%

Slightly more than half of the stores that could build a cart could start one.

Form
6 of 43 · 14%

Account, address and contact walls cluster here.

Payment
5 of 43 · 12%

Almost nobody gets here. This is the number that matters and the one brands cannot currently see.

Why each one is invisible in a markup audit
Edge bot rule or WAF rejection

A crawler refused at the edge never reaches the application, so nothing about the storefront itself is wrong and nothing in the markup says so.

Server logs and the agent's own report — never in a markup audit.

A different page for the agent

Some stores serve declared AI user-agents a thinner or altered page, so the agent can see the product and still not find the price, the stock or the buy action it just watched a human version display.

A differential fetch: once as a browser, once as a declared agent, then diff.

The buy action only exists after JavaScript

The agent can describe the product perfectly and still have no machine-readable way to act on it. A perfectly good page is not a transactable one.

Raw HTML inspection — hidden from any rendered-page audit.

OTP or CAPTCHA at checkout

An account-level control applied to all automation. In the ARI run, Foxtale stopped at checkout on an OTP wall despite being reached at every other stage.

Nowhere in the storefront. It is an account setting, not a page.

Broken or unsupported payment method

A store can be fully transactable and still fail at the final step because a payment option is broken or unsupported. In the ARI run, Blue Tokai Coffee was recorded with a broken payment flow.

Only at the moment of payment, after everything else has already succeeded.

Governance

Governance is five controls

Not a policy document. Each step is a control the brand can hold us to, and each one is a place where a prompt is explicitly not good enough.

01
Identify

Every agent gets a first-class identity, not a shared service account and not an allowlisted crawler.

  • A unique, verifiable identity per agent, distinct from the human and service accounts it operates alongside
  • A named owner and an explicit purpose recorded against that identity
  • Registration in a registry the brand can query itself, not one we hold on their behalf
02
Authorise

Permission is task-scoped, time-boxed, and re-evaluated on every action rather than assumed from the start of a session.

  • Least-privilege roles scoped to the specific resources and data the task needs
  • Just-in-time elevation for the duration of a workflow, never standing access
  • Downstream authorisation verified on each call, not only at the orchestrator
  • An allowlist of permitted tools and actions, with everything else denied by default
03
Execute

Reads and writes are separated, and the human stays in the loop at the single point where consequence lands.

  • Read and write authority held as distinct roles, so an agent that can look cannot also change
  • Explicit human approval on the final order or payment action
  • Capacity limits on rate, value and scope, bounding what a confused agent can do before anyone notices
04
Prove

One tamper-evident ledger recording the decision, not a log that merely records the model output.

  • Agent identity, role used, effective scope, resource, action, timestamp and a correlation ID per entry
  • The human delegation chain: who asked, which agent acted, and on whose authority
  • Tool invocations and downstream authorisation decisions, not only the response text
  • Append-only and queryable by the brand without asking us for an export
05
Attest

A standing, readable answer to "can an agent do this?" that the founder can check in one place without phoning anyone.

  • Per-agent, per-action answers instead of one global policy page nobody reads
  • Expiring grants that force re-approval rather than allowing silent permission drift
  • Revocation paths that are tested on a schedule, not merely documented
The conversion prize

Chat is reported to convert. The direction is consistent

The governance problem is unsolved. The reason a small brand should care anyway is that conversational AI is repeatedly reported to change human conversion by a multiple — across several separately sourced studies, none of them an independent trial.

12.3% vs 3.1%

Conversion among shoppers who engage with AI chat, against those who do not

Fin AI, 2026

Aggregate vendor figure. Selection effects are not controlled for.

24% avg · 58% peak

Chat-to-order conversion for AI shopping assistants, against a 5–15% industry benchmark

Crescendo, NRF January 2026

Vendor-reported across self-selected customers on one platform. The 58 per cent is a best case, not an average, and the 5–15 per cent benchmark is the vendor's own comparison rather than an independent control.

15–22%

Conversion when shoppers use interactive product discovery, in apparel and footwear

Fast Simon, Q1 2026 Conversational Commerce Report

Live customer data, but consultative sessions select for high intent.

more than 2x

Michaels Ask Mike assistant conversion against traditional search on the same site

Michaels, July 2026

The brand itself states the lift cannot be separated from intent-driven self-selection.

3x, +38% AOV

Conversion and average order value for a luxury skincare brand with an AI assistant, against its own pre-assistant baseline

Alhena AI customer data, 2026

Vendor-published customer story with no independent control group.

+46%

Conversion increase from AI-powered shopping assistance across 144 retail brands

Bluecore analysis, 2026

Aggregate. Does not isolate the assistant from the merchandising around it.

20–35%

AI-driven cart recovery, against roughly 10.7% for conventional abandonment email

Alhena AI, 2026

Vendor-reported, and the recovery windows behind the two figures differ.

Read these as a direction, not a forecast

Every figure above is a vendor or brand number rather than an independent trial, and the same caveat recurs: shoppers who choose to start a conversation are already more intentful than shoppers who do not. The direction is consistent across seven numbers from six sources. The magnitude is not established, and this dossier does not treat it as a forecast.

How it fits together

Governed conversion, end to end

This is the only path the thesis is proposing. The visibility layer and the conversion agent are the same system, not two products that happen to share a customer.

  1. Arrival
    The agent identifies itself

    An external agent requests a capability and declares who it is. The brand sees who is asking, and what it has been granted, before any of its own systems are touched.

  2. Evaluation
    Policy decides, per action

    The request is evaluated against that identity, its scope and the specific action requested. A read passes. A write needs more. A payment needs the human.

  3. Conversation
    The brand's own agent talks to the human

    A storefront agent running under the same policy answers the shopper, recommends from the brand catalog, and builds the cart — on a surface the brand owns, with the customer record intact.

  4. Authorisation
    The human authorises the action

    The shopper confirms the final step. That confirmation is captured as an explicit authorisation event, not inferred after the fact from the conversation having gone well.

  5. Execution
    The order executes under limits

    The order is placed through the brand's existing checkout, bounded by the rate, value and scope limits the policy set in advance.

  6. Proof
    The ledger closes

    Every step becomes a tamper-evident record the brand holds: which agent asked, what it was allowed, what the human approved, and what shipped.

What gets built

What gets built

The smallest thing that makes the thesis falsifiable: one brand, one governed conversion, one ledger the founder can read without us in the room.

Component path
Agent identity registry→Capability and policy evaluation→Brand-owned storefront agent→Human approval gate→Tamper-evident activity ledger→Merchant console and API
Non-negotiable principles
  • The brand owns the relationship. Discovery may happen on someone else's surface; the conversion and the customer record happen on the brand's own storefront.
  • The agent is a principal with a name, an owner and a scope — never an anonymous allowlisted crawler.
  • Authorisation is enforced at the action, not in the prompt. "The agent will only do X" is not a control, it is a hope.
  • The ledger records decisions, not responses. A log of model output is not an audit trail.
  • Read and browse capabilities first. Write and payment capabilities only ever behind a human gate.
  • Platform-neutral: work with the commerce stack and edge provider the brand already runs, rather than asking for a migration.
MVP shape

One Shopify D2C brand, one storefront agent, three capabilities — search products, check stock, build a cart — with the order action behind human approval and a ledger the founder can read unaided. Three to four weeks.

In scope
  • Agent identity registration and a per-agent capability grant the brand sets
  • A machine-readable catalog the agent can act on: price, image, availability
  • Policy evaluation per action, with the decision and its reason recorded
  • A storefront chat agent that recommends and builds a cart within those grants
  • Human approval on the final order action, captured as an authorisation event
  • A merchant console showing which agents arrived, what they were allowed, and what they did
Explicit non-goals
Building or hosting a consumer shopping agentOur own payment rails, wallet or checkoutReplacing the brand's commerce platform, storefront theme or analyticsModel training, fine-tuning, or an agent marketplaceMulti-brand aggregation or a marketplace of any kindAny claim that an agent-assisted sale is more profitable than a direct one
Who pays

Who pays, for what

The buyer is a person, not a department. That shapes everything about the product and about how it has to be sold.

Buyer

The founder or operator of an independent D2C brand — typically two to thirty people, selling on their own storefront — who has already noticed agent traffic and cannot tell whether it is a customer or a scraper. This is not a security buyer and will not be sold to as one.

Value
  • Know which agents reached the store, what they asked for, and what they were permitted to do.
  • Stop guessing why an agent abandoned the purchase, with the failure named at the exact step it occurred.
  • Convert the human that agent brought you, on a surface you own, with the final action still theirs.
  • Prove authorisation when it matters: a readable record for refunds, chargebacks and disputes.
  • Replace blanket blocking with per-agent grants, so protection and revenue stop being the same switch.
Pricing
  • Free tier: agent visibility and a read-only ledger for a single storefront
  • Paid: per-storefront platform fee covering policy, governed capabilities and the ledger
  • Optional: the storefront conversion agent as a usage-based module
  • No transaction take rate, and no claim on the brand's customer relationship
Moat
  • The activity ledger: real agent behaviour against a real catalog, accumulating over time
  • Per-agent policy plus the history of what was granted, refused and changed
  • The merchant console becoming the place a small team actually runs its agent surface
  • Protocol neutrality: a portable record is worth more than any single integration
Risks

What would make this wrong

The commerce platform ships this natively.
Response · Platforms will ship toggles, because they have to. They will not ship an independent cross-surface ledger a founder can audit, and neutrality is the entire wedge. If they ship the ledger too, this is a feature.
Brands keep blocking and never look.
Response · Lead with the conversion number rather than the security number. A brand that will not open the door cannot be given visibility, and the security argument alone will not move them.
The conversion half turns out to be a commodity.
Response · Chat assistants are a crowded market. Own the governed action and the proof of it, which the assistant vendors structurally do not have.
A confused agent places a bad order and the brand eats a chargeback.
Response · Human approval on the final action, capacity limits, and a reversal path that does not depend on our involvement. The brand stays merchant of record.
Liability for an agent-initiated purchase stays undefined.
Response · Capture the authorisation event explicitly and keep the brand as merchant of record. Do not position as an insurer or a guarantee, because we cannot be one yet.
Someone compromises our own layer.
Response · The ledger is the product, so an attacker who can write to it destroys the product. Append-only storage, signed entries, least privilege on our own operators.
Validation

The next four weeks

Three brands, in sequence, each one paying. The gate is not a demo; it is a founder reading their own ledger and a second paid month.

Week 0
Baseline the store

Run the agent journey ourselves against the brand's own storefront and record exactly where it stops, with evidence rather than inference.

01
Weeks 1–2
Open a read-only door

Register the agents that actually arrive, grant browse capability only, and let the ledger fill with real traffic before anything can write.

02
Week 3
Convert under policy

Enable the storefront agent with the order action behind human approval, and measure the change against the week-zero baseline.

03
Week 4
Ask for the renewal

Put the ledger and the conversion number in front of the founder and ask for a paid second month.

04
Gates that must pass
  • At least three distinct agent identities observed reaching the storefront in week one
  • A named failure step identified with evidence, not inferred from a markup audit
  • A measurable change in chat-assisted conversion against the brand's own pre-period
  • The founder reads the ledger unaided
  • Agreement to a paid second month, rather than a delighted first demo
Stop or narrow if
  • Brands will not grant agent access even read-only, because blocking is less work and flatters the conversion metric
  • The only thing they will pay for is the chat assistant, at a price that leaves no governance business
  • Conversational conversion lift does not survive on a small catalog
  • The edge or commerce provider makes agent identity and per-agent policy a free default

Evidence here is one independent agent-journey benchmark, one large merchant and consumer survey, platform security documentation, two platform policies reported by trade press, and a set of vendor-reported conversion figures. It establishes that small D2C brands are found by agents, that agents cannot currently complete a purchase with them, and that neither side can largely see why. It does not establish that they will pay for the answer. That is the entire open question, and three paid brands are the test.

Agent Operating Environment

Read the argument, then test it with us

Every claim on this page is falsifiable. If you run the infrastructure, or the business, this is where we would rather be corrected than impressed.

RelayForge is a product lab. SentraZero, PowerIQ and the Outbound Engine are case studies, not products.