FOR YOUR NEXT MEETING · 20 QUESTIONS · NO CODE

What to ask your web team about AI agents: 20 questions

Questions to bring to developers, grouped like the self-check, with the standards they will recognise.

Am I Ready for Agents? editors · Reviewed September 2026

The short of it

You do not need to know how to build any of this to ask good questions. Take the questions below to your web team, grouped by the five self-check areas. Each group names the standards and references a developer will recognise, and says what a clear answer sounds like.

HOW TO USE THIS PAGE
Start with the areas where your self-check showed no or not sure answers. Each question from the self-check links to its group here. We do not include code or step-by-step instructions: those depend on your platform, and your team or vendor will know them.
Find

Find: can agents find you?

  1. What does our robots.txt say today about GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended and Applebot-Extended, and who decided it?
  2. Does our CDN, firewall or bot protection have an AI bot rule switched on, and is it set to log, challenge or block?
  3. Is our sitemap generated automatically, and does it include the pages we most want found?
  4. Should we publish an llms.txt file, and who would keep it current?

Standards and references

A CLEAR ANSWER SOUNDS LIKE
We allow these named bots for these reasons, we refuse these, our bot protection matches that list, and we review it every quarter.
Read

Read: can agents read you?

  1. Which of our page templates deliver their main content in the first HTML response, and which need JavaScript to show it?
  2. Are any prices, stock levels, opening hours or policies shown only as images, PDFs or pop-ups?
  3. Which structured data do we publish on product, event, offer or article pages, and do we validate it?
  4. Can we give agents a markdown version of a page when they ask for one, and would we want to?

Standards and references

A CLEAR ANSWER SOUNDS LIKE
These templates are server-rendered, prices and policies are text, this structured data is validated, and here is our position on markdown.
Act

Act: can agents act on your site?

  1. Can our main task be completed end to end as a guest, and where do CAPTCHAs or other challenges appear on the way?
  2. Do we offer a documented API, an MCP server or WebMCP tools, and who maintains them?
  3. Do our sign-in and consent screens use a standard flow such as OAuth, and can a customer grant narrower permissions?
  4. If an agent fails halfway through, does it get a clear error message or a blank page?

Standards and references

A CLEAR ANSWER SOUNDS LIKE
A guest can finish the task, challenges appear only at these points, and here is what we offer agents directly, or why we do not yet.
Pay

Pay: can agents pay?

  1. Is the total price, including tax and delivery, in the page text before the last step?
  2. What does our fraud or payments tool do today with a purchase started by a verified agent?
  3. Have we looked at agent payment approaches such as x402, ACP, UCP or MPP, and what is our position?
  4. Who signs off on accepting, or declining, agent-initiated payments?

Standards and references

This edition does not review the ACP, UCP or MPP specifications; we name them because Cloudflare's scanner checks for them.

A CLEAR ANSWER SOUNDS LIKE
Totals are visible as text, our fraud rules treat verified agents this way, and we have decided to adopt, watch or skip each payment approach.
Trust

Trust: can agents be trusted, and trust you?

  1. Can we tell verified bots, for example ones that sign requests with Web Bot Auth, from bots that only claim a name?
  2. Are our returns, cancellation, privacy and terms pages public, current and readable without JavaScript or a login?
  3. What content signals, if any, do we send about AI training, search and AI input?
  4. Who owns our policy on AI agents, and where is it written down?

Standards and references

A CLEAR ANSWER SOUNDS LIKE
We verify these operators, our policy pages are public text, our content signals say this, and this person owns the policy.

What should I not ask my web team to do?

Do not ask for a score on a particular scanner as the goal. Scanners check different things, and a high score is not the same as customers' agents finishing tasks. Ask instead which of the 20 questions above have clear answers, and which do not yet.