B2A (business to agent) is how a business serves the personal AI agents that act for its customers. These agents research, recommend, buy, cancel and contact support on a person's behalf, and a B2A setup gives them a sanctioned way to ask questions and get things done under the same rules a customer would get, instead of treating them as bots to block.
For customer support, B2A means a new channel for the customers you already have. The contact still comes from your customer. It just arrives through their assistant, at machine speed, on whatever channel the assistant picks: your website, an API, chat or a phone call. The support team's job is the same as it has always been, answer accurately and resolve the issue within policy, but the tools, limits and identity checks have to work for software as well as people.
Most businesses still treat agent traffic as a scraping problem. That made sense when the only thing hitting your site at 3am was a scalper script. It makes less sense when the thing hitting your site is your own customer's assistant, trying to give you money or trying to fix a problem on their account.
Key takeaways
B2A is a channel, not a segment. The agents acting on your site and in your queue belong to your existing customers. Blocking them blocks the customer.
Personal agents already act on their own. Consumer agents such as Instinct, Muse, Grok bot and Town research, compare, buy, cancel and make phone calls for their users today.
Blanket blocking bans real people. In September 2026 Resy deactivated a customer's account because his agent behaved like a bot, then reinstated it two days later.
The fix is the same concierge, reachable by agents. Agents should get answers from the same knowledge, workflows and actions that serve human customers, not a separate bot FAQ that goes stale.
Agents get the customer's authority and no more. Same identity checks, same guardrails, same action policies, plus rate limits and check-back instructions built for machine traffic.
Every agent conversation should be visible. If agent contacts land as normal tickets sorted by topic, you can see what agents want and fix the gaps.
1. Why B2A matters now
Personal agents have moved from demos to daily use. Consumer products like Instinct, Muse (from Meta), Grok bot and Town act for their users, and general assistants such as ChatGPT, Claude and Perplexity increasingly do the same. Robbie Tilleard's post Personal agents are coming, and no one is ready collects what users are already posting about them. Four patterns matter for any business that talks to customers.
1.1 Agents research before the customer does
An agent reads your site, compares you with two competitors and hands its user a shortlist. One user asked Muse to shop for cheaper car insurance while he was at the gym. "15 min later I'm saving $1156 a year," he wrote. If your pricing, eligibility rules and policies aren't clear to a machine, you aren't on the shortlist, and you won't know you were ever considered.
1.2 Agents complete the purchase
Agents now finish the job. One user's agent reported back: "The Progressive policy is bound. Policy is effective at 6pm today." That is a regulated product, bought end to end by software acting on a person's instructions. The customer never visited a quote page.
1.3 Agents switch for a few dollars
Instinct's founder lists "cancelled hundreds of dollars of subscriptions" as a top use. One user's agent took a bill from $80 to $40 a month, plus three months free. Agents don't get tired of hold music and don't feel awkward asking for a retention offer. Retention, cancellation and billing contacts are exactly where support teams will meet them first.
1.4 Agents use every channel and push the rules
Instinct started making phone calls for users: restaurant bookings, cancellation lists, cable bills. One agent that couldn't sign in with a saved password used the one-time-code path instead ("read the code from your Gmail, signed in as you"). Another user's agent "went to war with AT&T over the phone bill". Agents aren't limited to your website, and they will take whatever path works, including the ones you designed for humans.
1.5 The Resy ban: the whole problem in one screenshot
On 6 September 2026, JC Bahr-de Stefano posted Resy's email deactivating his account and canceling his reservations. His agent, Instinct, had sent Resy about 200 API requests an hour while hunting for a table, polling every 10 minutes and every 0.4 seconds around the daily table release.
His summary: "Of course, this account got flagged for spam, because it was acting like a bot." Resy reinstated the account on 8 September.
The agent was doing exactly what its user asked. The business had no way to tell a verified personal agent from a bot farm, so it banned a real customer. As Bahr-de Stefano put it, "most of these sellers or providers need to get to a point where they can understand the difference between a verified agent acting on someone's behalf versus a bot farm."
That is the gap B2A closes. The choice isn't only block or allow. There is a third option, serve with rules, and we cover the trade-offs in blocking vs serving AI agents. If you suspect agents are already in your queue, these seven signs will tell you where to look.
Steve Hind put the stakes plainly when Lorikeet launched B2A: "If your business cannot engage those agents effectively, you will lose control of your customer relationships. The B2A (business to agent) channel will be the most important and fastest growing channel in 2027."
2. B2A vs B2B vs B2C
B2A sits alongside the two models every business already knows. The difference is who, or what, is on the other end of the conversation, and what they need from you.
B2C (business to consumer) | B2B (business to business) | B2A (business to agent) | |
|---|---|---|---|
Who you're serving | A person | A company, through its buyers and users | A person's AI agent, acting for that person |
How they reach you | Website, app, chat, email, phone | Sales, procurement, account managers, APIs | Your website, a public endpoint, WebMCP tools, and increasingly chat and phone |
What they need | A good experience and a quick fix | A good deal, a contract and reliable service | A fast, machine-readable answer, clear rules and a way to complete the task |
Pace | Human: business hours, one thing at a time | Human and slow: weeks or months | Relentless: 24/7, repeated, parallel |
Identity | Logins, one-time codes, security questions | Contracts, SSO, named contacts | Anonymous by default; must be tied back to a verified customer before any account action |
Authority | The customer's own | Whatever the contract grants | The customer's authority and no more |
What goes wrong | Friction, churn, bad reviews | Lost deals, missed renewals | Bans of real customers, blocked sales, stale answers, and lost business to whoever answers the agent first |
The row that matters most is the first one. B2A isn't a new customer segment. It's a new channel for the customers you already have, which is why it belongs with customer support and not only with security or growth.
3. What B2A means for customer support
If your customers are starting to use personal agents to contact you, the question for the support team isn't whether to allow it. Agents already read help centers and make phone calls for their users. The question is whether they get a good answer or a ban. Here is how we'd handle it, in order.
3.1 Stop treating every agent as fraud by default
Most fraud and bot rules key on exactly the behavior agents show: fast repeated requests, identical phrasing, logins at odd hours, one-time-code requests. That's why Resy's systems flagged a real customer. Keep your bot defenses for credential stuffing and scraping, but give legitimate agents a path that doesn't trip them.
3.2 Decide what an anonymous agent may be told
General questions (pricing, eligibility, opening hours, how a process works, what a policy says) are the same answers you'd put on a public page. An agent can have them without any identity check. Anything tied to an account, balance, claim, order or health record waits until the customer is verified.
3.3 Verify the customer before any account action
Agent conversations start anonymous. Before an agent can see or change anything on an account, apply the same identity verification you'd apply to a person on chat or phone. The agent relays the check to its user, the user completes it, and the conversation continues with exactly the access that customer has.
3.4 Set limits and tell agents when to check back
Polling every 0.4 seconds is what agents do when nobody tells them anything better. Rate limits cap the volume. A clear "check back in 10 seconds" replaces the polling. Retries should attach to the same conversation, not open a second ticket.
3.5 Apply the same policies to agents and people
Refund thresholds, cancellation terms, hardship processes and escalation rules shouldn't change because the customer sent software. An agent asking for a retention discount gets the same answer a person would. That keeps outcomes fair and stops agents from finding softer paths through your support.
3.6 Escalate to a human the same way you do today
Some contacts need a person: a complaint, a vulnerable customer, a dispute that doesn't fit the rules. Agents should be able to reach that path too, with the conversation history intact, so your team isn't starting from scratch.
3.7 Tag, review and learn
Treat agent contacts as normal tickets, sorted by topic. Within a few weeks you'll see which questions agents ask most, where your knowledge is thin, and which tasks they are trying to complete that your channels can't handle yet.
Regulated teams have more to decide at each step. We go deeper for lending, payments and banking in what breaks when AI agents contact fintech support, and for healthcare in personal AI agents and HIPAA.
4. How B2A works, step by step
A B2A setup has three jobs: answer agents, understand them and convert them. In practice that breaks into six steps.
Step 1: Give agents a front door
Agents need a sanctioned way in that isn't scraping your pages or pretending to be a person in your chat widget. There are two common doors today:
WebMCP tools on your website. WebMCP is a proposed web standard that lets a site expose functions as tools, with natural language descriptions and structured schemas, that AI agents running in the browser can call directly. It only works for browsers and agents that support the proposal.
A public endpoint. Every other agent can call a plain HTTP endpoint, ask a question and get a structured answer back, including instructions for follow-up questions in the same conversation.
Many sites also publish an llms.txt file, a proposed convention for a markdown file that tells language models what a site offers and where to find it. It's a signpost, not a door: it can point agents to the endpoint, but it can't answer a question or take an action. We compare all three in WebMCP vs public endpoint vs llms.txt.
Step 2: Answer from the same brain as your customer service
The agent should talk to the same AI concierge that serves your customers on chat, email and voice, with the same knowledge, workflows and actions behind it. A separate "bot FAQ" drifts out of date within weeks, and then agents repeat your stale answers to your customers with total confidence. One source of truth avoids that.
Step 3: Set the rules of engagement
Machine traffic needs machine-shaped rules. Rate limits cap the volume. The agent asks, then checks back for the answer at the interval you set. A retry doesn't open a duplicate ticket. The endpoint explains the rules in its responses, so a well-behaved agent can follow them without anyone reading documentation.
Step 4: Give agents no more authority than the customer
Agents go through the same guardrails, identity verification and action policies as a person, and see only what that customer could see. An anonymous agent gets public answers. A verified customer's agent gets that customer's access. Nobody's agent gets more.
Step 5: Turn agent conversations into outcomes
Because the concierge is connected to your systems, a conversation that starts with a question can end in a booking, a sale or a resolved issue. That's the difference between B2A and a read-only FAQ. The agent came to get something done for its user, and it can.
Step 6: Watch what agents ask
Every agent conversation should land as a normal ticket, sorted by topic. That tells you what agents want, which answers they struggle with, and where agent volume is growing, alongside the rest of your support data.
5. The three ways agents reach your business
Method | What it does | Which agents can use it | Can it take actions? | Maturity |
|---|---|---|---|---|
llms.txt | Tells agents what you offer and where to go | Any agent that reads your site | No, it's a signpost | Proposed convention |
Public endpoint | Lets any agent ask a question and get a structured answer, with follow-ups | Any agent that can make an HTTP request | Yes, through the concierge's workflows and policies | Works today with plain HTTP |
WebMCP tools | Lets browser agents call tools registered on your page | Browsers and agents that support the proposal | Yes, within the tools you register | Proposed web standard |
Most businesses need more than one. llms.txt helps agents find you, the endpoint serves the widest range of agents, and WebMCP gives supported browser agents a cleaner path than clicking through your UI. For the full setup, work through our 12-point agent-ready website checklist.
6. What B2A is not
6.1 It isn't bot management
Bot management stops scrapers, credential stuffing and fake sign-ups, and you still need it. B2A starts where bot management stops: once you've decided a request is a legitimate agent acting for a customer, how do you serve it well? The two work together.
6.2 It isn't a separate bot FAQ
A static page of answers "for AI" is the most common first attempt. It can't verify a customer, can't take an action and goes out of date. B2A routes agents to the same concierge your customers use.
6.3 It isn't only agentic checkout
Payment and checkout protocols for agents are one part of the picture, and several commerce and payments companies are working on them. Most contacts from personal agents are still questions, changes, cancellations, disputes and bookings, which is support work.
6.4 It isn't only for retailers
The examples above include insurance, subscriptions, telecom bills, car finance and restaurants. Regulated industries feel B2A first, because that's where agents chase savings and where identity and authority rules matter most.
If you're comparing tools across these categories, our guide to the best platforms for handling AI agent traffic in customer support groups them by job.
7. B2A in regulated industries
Lending, insurance, payments and healthcare share three traits that make B2A both more valuable and more delicate: customers shop around on price, account actions carry real risk, and every decision needs an audit trail.
Fintech and lending. Agents compare rates, ask about fees, request payoff figures and try to cancel or refinance. Account access and one-time codes are where naive agent handling goes wrong.
Insurance. Agents already shop policies and bind them, as the Muse and Progressive examples show. Quotes, eligibility and cancellation terms need to be answerable by machine, accurately.
Healthcare. Agents book appointments, chase refills and ask billing questions. What an unverified agent may be told, and what needs patient authorization first, is the core decision.
Car finance company Carmoola explained why it is preparing now:
"Carmoola is car finance your way. You know your budget before you shop, and you manage everything in the app with no paperwork and no sales calls. More people now want their own AI agent to do that shopping and managing for them. If that's how a customer wants to do it, it should be just as fast, fair and simple as the app. That's why we're preparing for business to agent now with Lorikeet."
Amy Rushby, Co-Founder and Director of Product and Operations, Carmoola
The principle in that quote, as fast, fair and simple as the app, is a good test for any B2A setup. An agent shouldn't get a worse experience than the customer would, and it shouldn't get a looser one either.
8. B2A readiness checklist
Answer these seven questions honestly. Each one maps to a concrete fix.
# | Question | Why it matters | Where to start |
|---|---|---|---|
1 | Can an AI agent read your key pages without a login wall or bot block? | If agents can't read your pricing and policies, they recommend someone else | Audit your bot rules and robots.txt for accidental blocks on public pages |
2 | Do you publish machine-readable guidance, such as an llms.txt file? | Tells agents what you offer and where the sanctioned door is | Publish an llms.txt that points to your key pages and your agent endpoint |
3 | Is there a sanctioned way for an agent to ask a question, other than scraping? | Scraping gets stale answers and trips your bot defenses | Offer a public endpoint, plus WebMCP tools where supported |
4 | Do agents get the same identity checks and policies as people? | Agents need the customer's authority and no more | Route agents through your existing identity verification before any account action |
5 | Do you rate-limit agents without banning the customers behind them? | This is the Resy failure mode | Set limits and return check-back intervals instead of deactivating accounts |
6 | Can an agent complete a real task (book, buy, change a plan), or only read an FAQ? | Agents come to get things done; read-only means lost conversions | Connect the agent channel to the same workflows and actions as chat and voice |
7 | Can you see how much of your traffic and contact volume comes from agents today? | You can't manage what you can't see | Log agent conversations as tickets, sorted by topic |
If most of your answers are no, your business is in Resy's position: one viral screenshot away from banning its own customers. The agent-ready website checklist turns these seven questions into twelve specific tasks.
9. How Lorikeet does B2A
Lorikeet B2A gives agents a sanctioned front door to your own AI concierge: the same knowledge, workflows, actions and guardrails that serve your human customers, with the customer's authority and no more. We launched it on 17 September 2026, so it's new, and we'd rather say that than pretend to years of production data.
Four setup steps
Create a Lorikeet account.
Build and test your concierge with Coach. Coach helps you build and test a concierge for your website, answering from your existing knowledge, so there's no backend work to start.
Turn on the agent-facing endpoint.
Paste the snippet Coach gives you into your website.
What agents get
Two ways in, one concierge. Agents that support WebMCP call tools registered on your website. Every other agent calls a public endpoint in plain HTTP and gets plain JSON back, with instructions for follow-up questions in the same conversation.
Answers built for machine traffic. An agent asks, then checks back for the answer. Rate limits cap the volume, and a retry doesn't open a second ticket.
Governed access. Endpoint conversations are anonymous by default. Before any account action, the concierge applies the same identity verification skills and policies it uses on your other channels, and agents see only what that customer would see.
Every channel. B2A runs on the Lorikeet concierge that also answers chat, email and voice, so an agent reaches the same concierge whichever way it comes in.
What your team gets
Every agent conversation lands in Lorikeet as a normal ticket, sorted by topic, next to your chat, email and voice volume. You can see what agents want, where answers fall short and which conversations turned into a booking, a sale or a resolution.
Try it on our own site
We run B2A on lorikeetcx.ai. The footer carries a notice for agents: GET https://api.lorikeetcx.ai/v1/ask/<public key>?q=..., with plain JSON responses. Our llms.txt includes "Ask our support agent (for AI assistants)" and "Book a demo (for AI agents)" sections. Point your own assistant at it and see what comes back.
What Lorikeet doesn't do
Lorikeet doesn't do bot management or payments. Keep your bot defenses for scrapers and fraud, and your payments provider for checkout. Lorikeet's job is to serve and resolve the agent conversations that belong to your customers. WebMCP also only works in browsers and agents that support the proposal, which is why the public endpoint matters: most agents today use it or read the site.
The concierge behind B2A is the same one already resolving human conversations. Wonderschool, for example, went from a 10% to a 100% answer rate in its first full month live on Lorikeet. That's proof of the concierge, not of B2A, and it's the reason we built B2A on top of it instead of beside it.
We're focused on regulated, complex industries (fintech, healthtech and insurance), where "the customer's authority and no more" and identity verification matter most.
Where to go next
Blocking vs serving AI agents: what each choice does to your support queue
8 best platforms for handling AI agent traffic in customer support
AI agents are contacting fintech support: 7 things that break
Personal AI agents and HIPAA: 8 decisions for healthcare support teams
If agents are already showing up in your queue, or you expect them to within the year, we should talk. Get a demo and we'll show you what your concierge would tell an agent today.







