How to run a 30-minute agent readiness review with your team
A meeting agenda for leaders who want answers, owners and a written position, not a technical project.
Am I Ready for Agents? editors · 19 September 2026 · Reviewed September 2026
Invite four or five people, ask each to take the self-check alone beforehand, and use the meeting to compare answers. Disagreements and not sure answers are the findings. Leave with three decisions: your position on AI bots, one fix for readability, and one named owner.
Why a meeting, and why only 30 minutes?
Most agent readiness questions sit between teams. Marketing owns the pages, engineering owns the platform, security owns bot protection and finance owns payments and fraud rules. Nobody has the whole picture, which is why the most common self-check answer is not sure.
A short meeting is enough to find out what you know and what you do not. It is not enough to fix anything, and it should not try to. The goal is a shared list of open questions, each with an owner.
Who should be in the room?
- The marketing, ecommerce or digital lead who owns the outcome, as chair.
- Whoever runs the website platform or its hosting.
- Whoever manages the CDN, firewall or bot protection, often in security or infrastructure.
- Someone from payments or fraud, if you sell or take bookings online.
- For publishers, whoever sets the policy on how content may be reused.
Keep it to five people. Anyone else can read the notes.
What should everyone do before the meeting?
Ask each person to take the self-check on their own, without comparing notes. It takes about five minutes, and the answers stay in their browser, so ask them to write down their level, their five area percentages and the questions they answered no or not sure.
Different answers to the same question are useful. If marketing says your robots.txt welcomes AI crawlers and security says the firewall blocks them, you have found your first action.
Minutes 0 to 5: what is the one task an agent should be able to do?
Name the main task a customer's agent would attempt: buy a product, book a table or a room, request a quote, subscribe, or read and cite an article. Everything else in the meeting is judged against that task.
Cloudflare describes the web it is building for agents as readable, discoverable, callable and payable. Your main task tells you which of those matter most to you.
Minutes 5 to 15: where do your answers disagree?
Go through the five areas in order: find, read, act, pay, trust. For each, read out the questions where people gave different answers or said not sure. Do not debate the fix. Agree only on what is true today, or that nobody knows.
Two questions usually take the most time. The first is which AI visitors you allow: training crawlers, search crawlers, fetchers acting on a user's question and agents acting for a person are different visitors with different names, and most can be treated separately. The second is what happens at checkout or booking when the visitor is software acting for a real customer.
Minutes 15 to 25: who owns each open question?
Turn every not sure into a question with a name next to it. The questions to ask your web team page groups them by area and names the standards a developer will recognise, so the owner knows what to look up.
Set a date, two or three weeks out, for the answers. Most will be short: a setting in the CDN dashboard, a template that does or does not render on the server, a fraud rule that does or does not recognise verified bots.
Minutes 25 to 30: which three decisions do you take today?
- Your position on AI bots: allow all, refuse training but allow search and user requests, or refuse all, and the reason.
- One readability fix to investigate, for example prices or policies that appear only in images or only after scripts run.
- One named owner for your agent policy.
Write the three decisions down in the meeting notes before anyone leaves.
What should the written policy say?
One page is enough. It should list which AI visitors you allow and refuse and why, what content signals you send, how verified agents are treated at checkout or booking, who owns the policy, and when it will be reviewed. Standards and bot names are changing month by month, so a review date matters more than completeness.
Keep in mind that robots.txt expresses a preference. The standard, RFC 9309, says its rules are not a form of access authorization, so your written position also needs to match what your bot protection enforces.
When should you run a scanner?
After the meeting, not before. A scanner checks your public pages against its own list, and it is most useful once you know which questions you want it to answer. Scanners can only see public URLs; ora.ai, for example, states that it cannot scan login-gated content. Our list of tools that check describes what each one looks at.
Do not set a scanner score as the goal. Scores from different tools measure different things, and none of them measures whether customers' agents complete tasks on your site. Your own analytics are the place to look for that.