Letting agents finish the task: forms, sign-in and consent
Reading is half the job. The other half is completing the form.
Am I Ready for Agents? editors · 14 September 2026 · Reviewed September 2026
The act area asks whether an agent can complete your main task: buy, book, subscribe or request a quote. That depends on standard forms, clear errors, a guest path or a standard sign-in flow and, for some businesses, a documented interface built for agents.
What is your main task?
Every site has one task that matters most: a purchase, a booking, a subscription, a quote request or, for a publisher, reading and citing an article. Start there. An agent working for a customer will attempt that task, and the act area is about whether it can finish without a person stepping in.
Why do standard forms matter?
Agents working in a browser use the same forms and buttons people do. Standard fields with clear labels are predictable. Custom widgets that only respond to a mouse, steps that reset on error and fields with no label are where agents stall. An error message that says what went wrong and how to fix it lets the agent try again; a blank page ends the task.
Challenges are the other common wall. A CAPTCHA at every step is meant to stop automation, and it stops the agents acting for real customers too. The useful question is where challenges appear, and whether they can be kept for visitors you cannot verify.
Guest path or sign-in?
A guest path removes a step an agent may not be able to complete. Where an account is needed, a standard flow such as OAuth lets the person approve access without sharing a password, in a form an agent can recognise.
Permissions matter as much as the flow. In August 2026 Cloudflare introduced optional OAuth scopes, so a person can untick permissions they do not want to grant on the consent screen, citing agent tools that ask for broad access. For a booking business, the question is whether a customer can let an agent book without also letting it change their profile or payment details.
What are MCP, WebMCP and A2A, in one line each?
- MCP, the Model Context Protocol: an open standard for connecting AI applications to tools and data. A business can run an MCP server so agents use its services directly. The 2026-07-28 specification made connections stateless.
- WebMCP: a proposal at the W3C Web Machine Learning Community Group that lets a web page offer its own tools, such as search or book, to an agent working in the visitor's browser, including by turning existing HTML forms into tools.
- A2A: a protocol that lets one organisation's agent find another agent and hand it a task. It joined the Agentic AI Foundation in August 2026.
None of these is required for a site to be usable by agents. They give agents a direct, described way to act instead of clicking through pages, and your web team will know whether one suits your platform.
What should you ask?
From the act group on ask your web team: can the main task be completed end to end as a guest, and where do challenges appear; do we offer a documented API, an MCP server or WebMCP tools; do sign-in and consent use a standard flow with narrower permissions; and what does an agent see when it fails halfway.