Contents
  1. Participants and purpose
    1. Commercial decisions through agents
    2. Who benefits from the choice
    3. Turning points in automated commerce
  2. Discovery and valid offers
    1. The market an agent can inspect
    2. Compare purchases, not headline prices
    3. Validity, reservations, and promises
  3. Purchasing authority
    1. Exact approval and standing mandates
    2. Check the transaction being submitted
    3. Budgets include outstanding commitments
  4. Orders, payments, and uncertainty
    1. Checkout and merchant acceptance
    2. What payment states establish
    3. Resolve unknown outcomes
  5. Fulfillment and remedies
    1. Track the obligations still open
    2. Cancellation, returns, and money back
    3. Disputes and accountable recourse
  6. Choosing the degree of delegation
    1. Choose the useful commercial boundary
  7. Check understanding
  8. Open questions
  9. Selected talks
  10. References
  11. Talk library
← All topics

Agentic Commerce: Delegating Purchases From Intent to Fulfillment

Agentic commerce delegates parts of buying and selling to software. An agent may discover products, compare offers, prepare a cart or complete a permitted purchase, but those steps must preserve what the buyer wants and what the seller actually offers. This chapter connects product discovery and negotiation to purchasing authority, checkout, payment and fulfillment. It explains what an agent can decide, when a person must intervene and how to track the outcome beyond the payment request.

Participants and purpose

Commercial decisions through agents

Agentic commerce uses software agents to make commercial choices or take actions for buyers and sellers. A merchant is the business selling goods or services. A buyer's agent can research alternatives and prepare a purchase; a seller's agent can answer inquiries and propose terms. The organization operating either agent is another participant, whose responsibilities need not match those of the person or business it represents.

Moving work into software does not settle who may make each decision. Recommending an item leaves the buyer's permission to purchase unresolved. Checkout assembles and submits purchase details, but its result must distinguish what the merchant accepted from what happened to the payment. The merchant still has fulfillment work: supplying the promised goods or service. If participants contest the authority, terms, payment, or performance, they have a dispute to resolve. A single conversation may coordinate all this work without making one participant responsible for every decision.

Keep commercial decisions separate from the software performing the work.
ParticipantWork an agent can performDecision that still needs an owner
BuyerCompare offers and prepare purchase detailsWhat may be purchased and under which limits
MerchantPresent terms and coordinate an orderWhich terms it accepts and what it must supply
Agent operatorRun the service and preserve transaction recordsWhether its software acts within delegated authority

The September 2025 Instant Checkout launch illustrates this separation: users confirmed order, shipping, and payment details; merchants retained order acceptance, fulfillment, returns, and support. A recommendation therefore was not itself a purchase. Likewise, personal assistance can retain preferences across tasks, but remembering a preferred brand does not confer permission to spend.

Who benefits from the choice

Buyers care about suitability, complete cost, and dependable delivery. Sellers also care about margin, inventory, and repeat business. An intermediary may earn money when a transaction happens, regardless of whether it was the buyer's best option. The principal–agent problem is the possible divergence between a represented party's interests and those of its representative. Applied to software, it concerns the incentives of operators and businesses—not personal motives attributed to a model. Jensen and Meckling's economic account of agency explains why monitoring and incentive alignment themselves have costs.

A buyer-appointed assistant, a merchant's sales assistant, and a merchant-funded intermediary consequently have different starting positions. An affiliate commission is compensation linked to a referred purchase; paid placement buys exposure. Neither is inherently the same as purchasing advice. U.S. FTC guidance on endorsements calls for clear disclosure of relevant affiliate relationships near recommendations. Disclosure helps readers understand the arrangement; it does not establish unbiased selection.

Consider an intermediary that receives its shopping task from a buyer and purchase-linked compensation from a merchant. If it also controls the shortlist, commercial incentives can affect which alternatives receive attention before comparison even begins. In its Instant Checkout launch account, OpenAI stated that merchant fees did not affect product results, while enabled checkout could influence ranking among merchants for a selected product. Product selection and merchant selection are distinct decisions.

Information asymmetry means participants have unequal access to decision-relevant information. In Daylian Cain's adviser experiment, advisers inspected coin jars more closely than estimators, and some were rewarded for inducing high estimates. Disclosing that conflict increased advice exaggeration and estimation error in the experiment. This laboratory result does not predict shopping-agent outcomes, but it explains why transparency alone cannot substitute for sound incentives and independent checks.

Seller automation needs boundaries too. Authority to answer a product question is different from authority to grant a discount or promise delivery. A merchant should distinguish terms an agent may propose from commitments it may make; quote approval provides one concrete way to express that distinction.

Turning points in automated commerce

Commerce automation developed along complementary lines: exchanging business records, finding comparable products, and delegating choices. Electronic data interchange, or EDI, exchanges agreed business documents between systems. UNECE traces its trade-document standardization work to a 1957 Swedish initiative supported by other Nordic countries. Shared layouts and definitions helped make later electronic messages interpretable across organizations.

These landmarks automated different parts of commerce, rather than successive versions of one complete purchasing system.
DevelopmentContribution and boundary
UN/EDIFACT — 1987 and 1989ISO approved its syntax in 1987; invoice and order messages followed in 1989. Standardized exchanges improved communication between businesses without delegating purchasing judgment.
BargainFinder — June 30, 1995Bruce Krulwich's Andersen Consulting experiment queried online CD stores, compared prices, and linked users to merchants. It addressed fragmented catalogs, but purchasing remained a subsequent human action.
Kasbah — 1996Chavez and Maes's marketplace prototype negotiated within user-specified price boundaries and deadlines, with optional final approval. Its playing-card experiment used play money; people still conducted the physical exchange.
WebShop — 2022Shunyu Yao, Howard Chen, John Yang, and Karthik Narasimhan's benchmark evaluated language-guided search, product inspection, and variant selection in a simulated store. Selecting Buy ended a task episode, not a real paid and fulfilled order.

Merchant incentives were already visible in BargainFinder: some stores sought inclusion, while others blocked requests because price-only comparison obscured service investment or imposed processing costs. Kasbah made a different issue explicit: negotiation needed user-defined limits. Modern language interfaces make less standardized requests easier to express, but they do not remove either problem. Flexible selection still has to connect to explicit terms, authority, and commercial records.

Discovery and valid offers

The market an agent can inspect

Search selects candidates from an accessible collection; it does not automatically inspect the whole market. A merchant catalog describes one seller's products, a product feed distributes records to another service, and a marketplace brings multiple providers together. An approved supplier is eligible under a buyer organization's purchasing policy. Public discovery and private supplier collections can both help, but access and purchasing eligibility are separate conditions. Acquisition Guarantees explains the underlying collection boundaries.

The distinction affects both publishing and searching. Shopify's discovery documentation separates catalog syndication, crawling, and independently supplied feeds: disabling one channel need not disable the others. Intershop catalog views can limit visibility by customer group, but changed configuration affects the storefront only after publication. Neither visible products nor configured restrictions alone establish the buyer's effective purchasing permissions.

A comparison should preserve these distinct source dispositions.
AccessEligibilityTreatment
AvailableEstablishedInspect current offers before including them in the comparison
AvailableNot establishedKeep as a candidate; do not treat it as purchasable
UnavailableEstablishedReport missing coverage, not an empty catalog
Available listingEstablishedIf terms remain uninspected, do not count it as a fully compared offer

Maintaining merchant interfaces is an old problem. Doorenbos, Etzioni, and Weld's 1997 ShopBot learned symbolic descriptions of store interfaces offline, then used them for online comparison. This reduced hand-coded adapters under assumptions about search forms and consistent layouts. A modern API can simplify acquisition, but it still needs the commercial fields the task requires. The Ionic feed discussion in 2024 highlighted stock and shipping information missing from the advertising feeds it described.

Participation, geographic restrictions, incomplete retrieval, and stale information all narrow the comparison. OpenAI's shopping documentation explicitly notes incomplete product coverage and delayed price or shipping updates. A defensible result identifies the inspected, eligible offers and unavailable sources. Calling one offer best within that set is a narrower claim than calling it best anywhere.

Compare purchases, not headline prices

A product variant is a particular configuration, such as a size or memory capacity. A shared product family does not make its variants interchangeable: Google's product-feed example represents three shirt sizes in three colors as nine variants. A stock-keeping unit, or SKU, is a merchant-specific identifier. An offer combines the item with a seller's proposed commercial terms; Schema.org's Offer vocabulary represents price, quantity, availability, shipping, and other conditions separately from the item.

Establish required identity, condition, and quantity before ranking offers. Then compare currency, mandatory charges, destination eligibility, delivery promises, return conditions, and any recurring charge—a repeated payment obligation rather than a one-time price. Total delivered cost should name the comparison boundary: the applicable charges to get the purchase to the intended destination. For cross-border purchases, even a landed-cost estimate can stop at the destination port rather than include inland delivery. Estimates and unknown charges must remain distinguishable from confirmed amounts.

In this illustrative comparison, both sellers offer one new unit of the same exact variant to the same destination. Taxes and all other mandatory charges are included in the displayed item amount; only the stated delivery charge remains.
OfferItem amountDelivery chargeDelivered total
Seller AUSD 40USD 8USD 48
Seller BUSD 43UnknownUnknown

Seller A has the lower item amount, but the cheaper delivered offer is not yet established. Seller B would cost less with delivery below USD 5 and more with delivery above it. The missing term changes the decision; assigning it zero would invent an advantage. Timing needs similar care: dispatch lead time concerns preparation before shipping, not arrival at the destination.

Checking that fields meet domain requirements is semantic validation, developed in Structured Outputs and Tool Calling. Procurement adds another useful distinction. A request for quotation, or RFQ, asks suppliers to propose terms against requirements. Oracle's sourcing workflow supports both price-only and weighted multiattribute ranking, while leaving the buyer able to select another supplier. A ranking summarizes chosen criteria; it is not itself an award or authorization.

Validity, reservations, and promises

Comparable terms can still become unusable before purchase. A quote states proposed price and terms under specified conditions. A counteroffer proposes changed terms rather than accepting the earlier proposal. In Oracle's quote workflow, internal approval, customer acceptance, and conversion to an order are separate stages. Version history and expiration preserve which proposal was available for acceptance. The practical lesson is to bind a decision to identified terms, not merely to a conversation about them.

Availability also has several meanings. A backorder accepts orders for temporarily unavailable merchandise; a preorder concerns an unreleased product. Google's merchant availability rules distinguish these from in-stock offers and require availability dates for both. A listing must also match supported shipping locations. Being discoverable does not mean an item is ready to dispatch to this buyer.

An inventory reservation temporarily holds stock; a price freeze preserves specified charges. commercetools documents them as separate operations. Reservations can expire and release stock to other carts. Its HardFreeze mode preserves prices, discounts, and shipping costs, while order creation commits reserved inventory. If expired stock cannot be reacquired, ordering can fail. Thus stock, price, and quote validity need their own checks and lifetimes; none alone establishes payment or delivery.

A protected price does not hold stock

Submission checkQuote validityStock reservationPrice protectionEarlierLater →
Quote: still validStock hold: expiredPrice: still protected

End caps mark each condition’s separate expiry. At submission, stock must be reacquired; ordering can fail if it is unavailable. Active quote and price protection establish neither purchasing authority nor payment or delivery.

Illustrative ordering of independently managed conditions, not one vendor’s unified workflow. The unnumbered positions show relative order, not elapsed durations or default expiration values.

A seller-facing agent must respect these distinctions when speaking. In Stop Writing Tone Instructions. Layer Them., an assistant offered an already-booked date without calendar access. Checking proposed dates against authoritative allowed values can block that claim. It does not itself hold the date or grant authority to promise it. Accurate statements and authorized commitments are separate requirements.

Purchasing authority

Exact approval and standing mandates

Delegated authority is permission from an entitled person or organization to act on its behalf. A purchasing mandate describes the boundaries of that permission. Exact approval covers an identified purchase; a standing mandate allows future choices within specified limits. The convenience of standing authority comes from permitting variation, so its usefulness depends on making that variation explicit.

A mandate specifies what may vary and what must remain fixed. The implementation must check which of these purchasing requirements its protocol and enforcement mechanisms can support.
BoundaryExact purchase approvalStanding mandate
Goods, services, and quantitiesIdentified items and quantitiesAllowed items, quantities, and explicit substitutes
Participants and destinationIdentified merchant, payment recipient, and delivery beneficiaryPermitted merchants, recipients, and destinations
MoneySpecified currency and approved totalCurrency, per-purchase limit, and cumulative budget
Time and repetitionValidity interval for this purchaseExpiry, recurrence, and maximum occurrences
Material changesRenew approval of changed termsRecheck every change against the allowed variation

Agentic Payment Protocol (AP2) v0.2 separates linked Checkout and Payment Mandates. Direct mode obtains approval for a specific checkout; autonomous mode allows an agent to complete one under approved constraints. Its Checkout Mandate example allows either of two shoe styles together with specified socks. Permission to substitute one shoe style does not permit buying both or omitting the socks. A set of alternatives is not permission to change the composition arbitrarily.

Standing instructions can be narrower than general shopping discretion. Amazon's documented auto-buy feature lets eligible Prime members set a target price for a selected item and uses default payment and shipping details. Requests last six months or until canceled. This illustrates a bounded continuing instruction, not comprehensive shared-budget enforcement.

Granting, amending, and revoking permission must belong to an authorized participant. Target's April 2026 terms require both customer and Target approval of a commerce agent and allow customer revocation through account settings. Revocation ends permission to act; it should not be interpreted as confirmation that earlier orders were canceled. Those existing transactions need their own status and remedy decisions.

Check the transaction being submitted

Authentication establishes an actor's identity; authorization decides what that actor may do. Preserve the represented buyer separately from the executing agent, and distinguish the merchant from the permitted payment recipient. A replacement agent or a redirected destination cannot inherit permission merely by appearing in the same conversation. Do not collapse the actors develops the identity distinction.

Time-of-check/time-of-use failures occur when approved terms change before execution. Compare the submitted transaction with the approved version. OWASP requires a final server-side authorization gate immediately before execution.

For example, reject a changed payment recipient even when the buyer, agent, merchant, and amount match. See action-boundary enforcement and protected-operation authorization.

AP2 requires mandate verification in deterministic code: explicit rules check the transaction rather than asking a model whether it seems authorized. Its authorization framework requires unknown constraints to fail evaluation. If conformity cannot be established, the workflow can request direct approval or return control to the buyer. Ignoring an unsupported delivery or substitution condition would broaden the authority rather than implement it.

External content cannot supply missing permission. Indirect prompt injection embeds instructions in retrieved material—for example, a merchant page that tells the agent to change the payment destination. Such material remains transaction data, not authority; AI Security explains the attack. Nor does signing the material make its claims true. The W3C Verifiable Credentials standard separates verification of authenticity from validation against business requirements. An authentic assertion can still describe an unsuitable deal or uncompleted delivery. A payment credential’s ceiling constrains payment access; it does not approve changed purchasing terms.

At this conceptual implementation boundary, a changed recipient stops submission despite an unchanged amount within the payment credential ceiling. Credential limits constrain payment access; they do not expand purchasing authority.

Budgets include outstanding commitments

A per-purchase limit bounds one purchase. A cumulative budget bounds several purchases over a defined scope and period. An outstanding commitment is exposure already incurred but not fully resolved. These controls answer different questions: an individually permitted payment can still exceed the remaining shared allowance. Recurring permission also needs rules about timing and count, not merely a reusable credential.

AP2's Payment Mandate specifies currency-aware accumulated budgets and recurrence constraints. Enforcing them requires state from earlier transactions. A strict shared allowance additionally requires the decision to consume remaining capacity to be coordinated with other decisions. Protecting shared state at acceptance explains that engineering boundary.

Two agents can each pass a local check against the same balance while their combined purchases exceed the shared allowance. Coordinated check-and-reserve makes the first commitment visible before the next admission. Counting only completed payments still omits exposure already authorized or otherwise committed.

An authorization hold reserves payment capacity before collection. Adyen's transaction rules include authorized but uncaptured transactions in available limits, releasing capacity when authorization expires or is canceled. That is a concrete accounting choice, not proof that every merchant obligation across every payment channel is covered.

Configured controls can also be weaker than strict ceilings. Stripe Issuing documents best-effort aggregation with up to 30 seconds of lag, and later tips or fees can exceed a limit. Seller-scoped tokens do not by themselves create an aggregate allowance. When strict enforcement across concurrent and uncertain commitments is not established, keep those commitments visible and use a coordinated approval route rather than promise a hard budget guarantee.

Local approval can exceed a shared allowance

Fixed shared allowance: USD 100.00

Enter 0.00–1000.00 USD with at most two decimal places. All accounting uses integer cents.

Ledger: E1 counts once at USD 0.00. Its outstanding authorization still consumes capacity.

Independent checks

A sees USD 100.00; accepts USD 60.00.

B sees USD 100.00; accepts USD 60.00.

Committed: USD 120.00

Exceeds allowance by USD 20.00.

Coordinated reservation

A sees USD 100.00; accepts USD 60.00.

B sees USD 40.00; does not admit USD 60.00.

Committed: USD 60.00

Remaining: USD 40.00.

Selected result: Both agents check the same earlier snapshot. Total USD 120.00; over by USD 20.00.

A missing response or local cancellation does not release E1. Coordination protects only commitments inside this accounting boundary; it cannot undo earlier excess exposure.

Illustrative USD accounting model, not an AP2, Stripe or Adyen implementation guarantee. Both comparisons use the same proposals and earlier exposure; only the acceptance mechanism changes.

Orders, payments, and uncertainty

Checkout and merchant acceptance

A cart holds proposed items and quantities. Checkout combines them with buyer, delivery, and payment details, then submits the purchase into the merchant's process. The merchant's system of record owns authoritative order facts; the assistant's summary is a representation of them. Preserve the checkout-to-order relationship and the agreed item identities, quantities, charges, destination, and terms. Authoritative records explains why different facts can have different owners.

Structured checkout reduces dependence on interpreting a screen. In the Agentic Commerce Protocol (ACP) presentation, the seller returns updated state as quantities or shipping choices change. ACP's documented lifecycle distinguishes missing information, readiness, processing, completion, and cancellation. During processing the session is locked; completion means payment succeeded and an order was created. Those meanings do not establish delivered goods or a universal legal acceptance event.

Merchant requirements also vary. Shopify and Google's January 11, 2026 Universal Commerce Protocol (UCP) account describes capability negotiation: participants identify supported features and use their shared capabilities. Extensions represent specialized requirements. If the agent cannot supply required information or functionality, a continuation URL hands the existing checkout to the buyer. Technical compatibility answers whether the interaction can proceed, not whether the buyer authorized it.

Returning selected items to a purchasing system need not place an order. Ariba's August 16, 1999 cXML specification made that distinction explicit. Its PunchOut workflow let buyers browse a supplier site and return a basket to their organization's system as requisition items—items in an internal purchase request. A separate OrderRequest submitted the purchase order. Even that message's immediate response confirmed receipt, not a commitment to execute the order. The supplier's checkout button therefore marked a handoff, not completion of every commercial decision.

Commercial acceptance must be interpreted under the actual terms. Apple's specified U.S. education-store policies, for example, say an order-confirmation email acknowledges receipt and does not signify acceptance. Do not invent a universal acceptance event from a familiar status label. As with other tool-result meanings, the response establishes only what its contract says.

What payment states establish

The payer supplies funds, the payee receives them, and a payment service provider processes the payment. The recipient may be the merchant or an authorized intermediary in the payment arrangement. A payment credential enables use of a payment method; possession of it does not establish permission for the particular purchase.

Stripe shared payment tokens illustrate a bounded credential substitute: access is scoped by seller, currency, maximum amount, and expiration. Payment may still require customer action such as bank authentication. These restrictions limit financial exposure but do not establish item suitability or delivery promises. In Steve Kaliski's narrated demonstration, a seller's attempted USD 50 charge exceeded the token's mandate and was rejected—an enforcement example, not validation of what the agent chose to buy.

An explicitly bounded card-payment example from Adyen's lifecycle:
State or operationFinancial meaning
AuthorizationApproval reserves capacity for a limited period; the request can instead be declined.
CaptureAn authorized amount is submitted for collection; capture may be automatic, separate, or partial.
Sent for settlementTransfer has been requested, but funds are still awaited.
SettledAdyen has received funds; merchant payout is separate.
Expired or canceled authorizationUnused authorization ends without collection.

Purchasing authorization concerns the buyer's permission; payment authorization concerns the payment arrangement. Neither is delivery evidence. Order and payment sequencing can differ: Apple's terms contemplate cancellation after payment, while ACP defines its own checkout-completion boundary. Other payment methods need their own interpretation. Settlement also does not eliminate later disputes, refunds, or other remedies.

Escrow holds funds pending agreed conditions. The USDC escrow demonstration distinguished creating an agreement from funding it: its Locked state followed settlement into contract custody, with release or return occurring later. This is another reason to name the financial event precisely. Funded does not mean released, and released does not by itself establish satisfactory work.

Resolve unknown outcomes

A lost response changes what the client knows, not necessarily what the merchant or payment provider did. Reconciliation resolves uncertainty or disagreement against authoritative records. Idempotency is the receiving service's contract for recognizing repeated attempts at one intended operation without repeating its effect. The general recovery mechanism belongs in Recover when the effect is unknown; commerce adds the need to reconcile order and payment facts separately.

Preserve the relationship between one purchase intent, its merchant order, its payment operations, and each request attempt. An agent's tool-call identifier only identifies an invocation unless the integration explicitly gives it another meaning. A receipt or provider object identifier supplies additional correlation; none should be substituted casually for the buyer's commercial intention.

After a lost response, retain the purchase intent separately from its payment operation and repeated request attempts. A permitted retry preserves the operation’s identifier and parameters. Separate merchant and provider lookups can resolve order creation and payment authorization while collection and fulfillment remain unknown.

Two attempts, one intended purchase

Purchase intent I1
Payment operation Pay1: stable identity and parameters

Request A1
Response missing
Operation Pay1

Request A2
Conditional retry; same parameters
Operation Pay1

Retry only while the receiver’s idempotency contract permits it. A missing response does not create a new purchase.

Record correlations and separate authoritative lookups—not execution arrows
Merchant record O1

Correlates with intent I1.

Observed: Order created

Provider record P1

Correlates with operation Pay1.

Observed: Payment authorized

Still unresolved: Collection and Fulfillment. A payment retry does not establish merchant-order creation.

Both requests belong to one payment operation for I1. Separate authoritative reads establish O1’s creation and P1’s authorization; collection and fulfillment remain unresolved.

The Stripe v1-style idempotency contract stores the first executed response, including server errors, and rejects changed parameters under the same key. Keys may be pruned after at least 24 hours; reuse after pruning creates a new request. Those conditions are provider- and API-specific. Do not rotate the key merely to escape a cached error.

A repeated response is not necessarily a resolved financial outcome. Stripe's low-level error guidance treats a server error as indeterminate because side effects may exist. Correlated objects and later notifications can help resolve it. If payment evidence exists but no matching order can be established, assign merchant and operator investigation rather than place another order. Keep the purchase pending, explain which facts remain unknown, and name an owner for follow-up.

Fulfillment and remedies

Track the obligations still open

Fulfillment carries out an accepted supply obligation. Allocation assigns stock to work; shipment sends goods; delivery concerns their arrival. Partial fulfillment leaves some promised quantity outstanding. These distinctions must survive an order-wide summary. Shopify's order-management model separates order lines, location-specific fulfillment groups, and shipments; a fulfillment service can accept or reject a request.

Consider an illustrative order containing one notebook and one cable. The quantities below describe supply, not payment allocation.
Order lineOrderedDeliveredOutstandingCanceled
L1: notebook1100
L2: cable1010

Delivery evidence for L1 cannot close L2. A charge associated with the whole order also does not reveal how much was collected for each line unless the financial records provide that allocation. Retain the line identities when investigating delay, requesting cancellation, or calculating a remedy. A shipment notice supplies a different fact from delivery evidence; neither automatically resolves a complaint that the supplied item was wrong.

Completion evidence depends on what was promised. A digital entitlement identifies access a customer should receive. In Stripe's entitlement model, the seller application must still enable the corresponding feature; receiving a notification does not provision usable access. For a booked service, appointment or work records need to address the agreed service rather than merely show that payment occurred.

Delays and substitutions create new decisions. For covered U.S. merchandise, FTC guidance requires applicable delay-consent or cancellation-and-refund procedures when shipment promises cannot be met. A materially different substitute requires prior express agreement, and using a fulfillment contractor does not remove the seller's responsibility under that rule. Check the buyer's mandate before accepting changed goods, timing, or price.

A handoff transfers responsibility with the information and authority needed to continue. For merchant operations or support, record who accepted the unresolved line, what outcome they owe, and when escalation is due. Sending a message requests attention; it does not establish that another team owns the work. Explicit responsibility transfer develops that workflow contract.

Cancellation, returns, and money back

Stopping the agent prevents further execution under the stop mechanism; it does not reverse an external purchase. Order cancellation ends eligible uncompleted obligations, a return sends supplied goods back under applicable conditions, and a refund returns collected money. Authorization release instead frees unused reserved payment capacity. Each changes a different part of the transaction.

Choose the remedy from the effect that already occurred.
RemedyTargetWhat remains separate
Cancellation requestEligible work not yet completedMerchant or fulfillment-service acceptance of cancellation
ReturnGoods already suppliedEligibility, receipt, inspection, and financial outcome
Authorization releaseUnused payment holdAny money already collected
RefundCollected moneyGoods recovery, order cancellation, and customer receipt of credit

For the two-line order, requesting cancellation of outstanding L2 and seeking a return of delivered L1 are independent choices. Neither requires pretending the delivery never happened. This is compensation: a new business action addressing an existing effect, rather than database rollback. Partial completion is still real explains why compensation can have its own eligibility, costs, and failures.

HP's U.S. direct-store return process distinguishes return approval and instructions from receipt and validation of goods, refund initiation, and eventual account credit. Stripe likewise documents that a refund request can fail; initiation alone does not establish that the customer received money. Preserve the requested amount, applicable terms, progress, and traceable financial reference rather than report a generic reversal.

Recovery does not create unlimited purchasing authority. Instacart's replacement choices distinguish letting a shopper choose, naming a replacement, and requesting a refund; replacement prices can change the charge. This shopper workflow illustrates why a substitute, store credit, or replacement purchase needs its own applicable permission. A remedy request is not blanket approval for another transaction.

Financial correction can also interact with other processes. Stripe warns that overlapping bank-debit refunds and disputes can produce duplicate credits. Reconcile the existing remedy before initiating another. Fees require similar attention: Shopify's July 2026 Singapore-localized terms distinguish refunded agent-channel fees from nonrefunded Shopify Payments transaction fees. Returning the sale does not necessarily remove every transaction cost.

Disputes and accountable recourse

A dispute is a contested claim about authority, terms, payment, or performance—not simply an ordinary return request. Recourse is an available route to investigation or remedy. Trust therefore has several components: attributable identity, valid authority, credible claims, and someone able to respond when the transaction fails.

A card issuer provides the cardholder's payment account; a card network supplies rules and infrastructure connecting payment participants. A chargeback is a payment-system dispute process initiated through the issuer, distinct from a merchant voluntarily refunding money. In Stripe's described process, the initial reversal is not final adjudication: the merchant can submit evidence and a counterargument.

Records should address the contested claim and reach a participant capable of acting on it.
Contested claimRelevant recordsInvestigation or decision
The agent exceeded permissionMandate, submitted terms, transaction-time permissionsAgent operator and merchant examine authority
The amount was wrongAgreed price and itemized payment recordsMerchant investigates; issuer decides a card dispute
The purchase was not suppliedTracking, delivery, access, or work recordsMerchant investigates performance and available remedy
The supplied item differedContemporaneous offer and supplied-item evidenceMerchant assesses conformity; applicable dispute process remains available

Responsibility is transaction-specific. Stripe's April 2026 Switzerland-localized agent-service terms require auditable consent records and assign the operator responsibility, as between those parties, for transactions exceeding authority or arising from software misinterpretation. Seller terms separately allocate fulfillment and after-sales duties. These contractual allocations are not universal liability rules, but they show why an operator cannot treat every purchasing mistake as a merchant or processor problem.

Cryptographic receipts help attribution, not adjudication. Froglet's trust documentation says a signed receipt binds a provider to an outcome and result hash while correctness still needs assessment. Its hosted marketplace can suspend listings after complaints, but suspension neither invalidates artifacts nor prevents direct transactions. The receipts presentation is useful for understanding attributable records; reimbursement and correct work remain different promises.

Some remedies have statutory routes and clocks separate from merchant support. For covered U.S. open-end credit, Regulation Z's billing-error procedure includes certain nonacceptance or nondelivery claims. Qualifying written notice must reach the designated creditor address within 60 days after the first statement reflecting the error was transmitted. That category does not require first seeking merchant resolution, and it excludes quality disputes over goods already accepted. This is not a universal return or chargeback deadline.

Retention keeps necessary records available over time; data minimization limits what is collected, disclosed, and retained for the purpose. Keep mandates, relevant offer versions, external receipts, and communications under appropriate access and lifetime rules. Auditability does not justify copying credentials or every personal detail into ordinary logs. Artifact lifetimes explains how to connect each retained record to its purpose, readers, and disposal conditions.

Choosing the degree of delegation

Choose the useful commercial boundary

The useful degree of delegation depends on how clearly the purchase can be specified, how much variation is permitted, whether the limits are enforced, and how errors can be remedied. A known repeat purchase can justify narrower review than a purchase whose suitability or delivery terms remain uncertain. Automation can still save substantial effort when it stops before commitment.

Choose the boundary from the unresolved commercial decisions, not from the agent's ability to operate the interface.
ModeUseful conditionsDecision retained
Recommendation assistanceSuitability or material terms still need interpretationA person chooses the purchase and authorizes it
Prepared checkoutThe agent can establish terms, but each commitment needs reviewA person approves the actual transaction
Bounded autonomous purchasingPermitted variation is explicit; current authority, exposure, and recovery are controlledExceptions outside the mandate return for a new decision

A randomized product-research experiment gives a representative benefit and tradeoff. Participants compared SUV pairs using a specified cargo-space-to-length criterion. Estimated task duration was 3.4 minutes with traditional search and 1.6 minutes with a GPT-3.5-based tool. Routine-task accuracy was comparable, but on a deliberately difficult comparison the model confused seats-up and seats-down cargo capacity, leading to substantially more incorrect choices. These were research tasks, not completed vehicle purchases: faster comparison did not establish suitability under every specification condition.

Selection performance also depends on the commercial environment. The ACES shopping-simulator study found model-dependent responses to listing position, price, and ratings; seller edits to descriptions increased selection frequency in tested settings. Position effects also appeared in JSON-only interfaces. Its reported market shares were simulated choices, not paid sales, merchant profit, or buyer welfare. Like WebShop's Buy endpoint, the measured event must not be mistaken for a completed commercial relationship.

Measure both sides of the transaction. Buyer benefit includes effort after review and correction, suitability, complete cost, and obligations still unresolved. Seller contribution is revenue remaining after the transaction-related costs included in the stated accounting boundary. Cost to serve includes the effort and expense of completing and supporting the transaction. Fees, returns, and support can therefore change the value of additional sales. Conversion means progression to a defined event; more conversions do not by themselves establish shared benefit.

For recurring replenishment, clear item and supplier restrictions are not enough if two agents share an allowance whose pending commitments are uncertain. Automate discovery and preparation, then coordinate the commitment decision until aggregate enforcement is established. Track unauthorized spending and unresolved obligations separately rather than averaging them into sales or time savings. Whole-process measurement supplies the broader method: count the checking, correction, waiting, and recovery that make the purchase genuinely useful.

Open questions

  1. Strict shared budgets remain difficult when concurrent agents, pending merchant commitments, delayed payment records, and revocation interact. Progress would mean demonstrated enforcement and recovery across those boundaries, rather than separate controls whose gaps accumulate.

  2. Buyer benefit remains harder to establish than faster research or more selections. Useful field evidence would include review effort, suitability, delivered cost, correction, and unresolved disputes alongside seller contribution and support costs.

  3. Interoperable authorization must preserve unfamiliar commercial conditions without silently dropping them. Progress would combine verifiable constraint handling, privacy-preserving disclosure, and usable handoff when a merchant requirement cannot be met.

  4. Attributable service receipts do not settle whether subjective or complex work met its promise. Meaningful progress would connect precise acceptance criteria to independent assessment and an effective remedy, not merely stronger signatures or longer receipt histories.

Follow the curated reading path through the speakers and demonstrations behind this entry.

Explore more talks

The rest of the library, beyond the curated path. Cited talks support this entry; reviewed transcripts were processed in full. Metadata candidates have not been reviewed as sources or verified as topic members.

22 matching talks

TalkSpeakerEventYear
Sarthak AggarwalAI Engineer World's Fair 20262026
Tun Shwe, Jeremy FrenayAI Engineer Europe 20262026
Simon WillisonAI Engineer World's Fair 20242024
Isadora Martin-DyeAI Engineer World's Fair 20262026
Corey CooperAI Engineer World's Fair 20252025
Dan MasonAI Engineer World's Fair 20252025
Jia WuAI Engineer World's Fair 20262026
Adam BehrensAI Engineer World's Fair 20252025
Armanas PovilionisAI Engineer World's Fair 20262026
Jan CurnAI Engineer World's Fair 20252025
Grace IsfordAI Engineer Summit 20252025
Sonam PankajAI Engineer World's Fair 20262026
Jared HansonAI Engineer World's Fair 20252025
Sam MorrowAI Engineer Europe 20262026
Security Firewall for Agents

Transcript reviewed

Ryan DahlAI Engineer World's Fair 20262026
Vinesh GudlaAI Engineer World's Fair 20252025
Paola Estefanía de CamposAI Engineer World's Fair 20262026
Sandipan BhaumikAI Engineer Europe 20262026
Arjun Chintapalli, Bhavani KalisettyAI Engineer Summit 20252025
Rafael LeviAI Engineer Europe 20262026
Bobby Tiernay, Kam SweenAI Engineer World's Fair 20252025
Ravi MadabhushiAI Engineer World's Fair 20262026

References

Coverage and source review
Processed transcripts
26 processed in full · 4 in the curated path
Automated source review
Passed
Metadata candidates
0 unreviewed; not verified topic membership
Corpus version
1bd8e407b26a07b33815594e1b2db5f41827119a2b3cb6fbf240f9fc571fc767

Automated review checks source support; it is not publication approval.

A synthesis of selected conference talks and technical references. Citations link to the source material; they do not imply that every talk on this subject is included.

  1. Theory of the Firm: Managerial Behavior, Agency Costs, and Ownership Structure

    Jensen and Meckling define an agency relationship as engaging a representative to perform work while delegating some decision-making authority. When participants pursue their own interests, the representative need not choose what best serves the principal. Incentives and monitoring can reduce this divergence but incur costs.

  2. Agentic Payment Protocol v0.2

    AP2 separates shopping-agent, merchant, credential-provider, payment-processor, and trusted-consent-surface responsibilities. It defines linked Checkout and Payment Mandates. Direct mode obtains approval of a specific checkout; autonomous mode permits an agent to close a checkout under user-approved constraints. Mandate verification must occur in deterministic code. Checkout and payment receipts record acceptance or rejection and can be joined with mandates as dispute evidence.

  3. Agentic Commerce Protocol: Checkout lifecycle

    The documented checkout lifecycle distinguishes missing required information, readiness for payment, payment processing, completion, and cancellation. Completion means payment succeeded and an order was created. During payment processing the session is locked. A completed checkout session cannot subsequently be canceled through this session lifecycle.

  4. Shopify: Apps in order management

    Shopify separates an order from fulfillment work and shipments. A fulfillment order groups items assigned to a location; its line items track quantities requiring fulfillment. One order can contain multiple delivery methods and fulfillment groups. Fulfillment services separately accept or reject requests. Cancellation requests can also be accepted or rejected. If an accepted fulfillment cannot be completed, the merchant or app must determine the next action.

  5. Stripe: Dispute reason codes

    Stripe distinguishes disputes about authorization, duplicate charges, incorrect amounts, missing refunds, nonreceipt, and unacceptable products. Evidence should address the particular claim: agreed prices and itemized receipts for amount disagreements; tracking or signed delivery records for physical goods; access and download logs for digital products; appointment or work records for services; and contemporaneous listings for conformity disputes. The cardholder's bank decides the outcome.

  6. Buy it in ChatGPT: Instant Checkout and the Agentic Commerce Protocol

    OpenAI's launch account describes users confirming order, shipping, and payment details before purchase. The merchant accepts or declines the order and retains payment processing, fulfillment, returns, and customer support. Merchants pay a fee on completed purchases. OpenAI states that this does not influence product results, while merchant ranking for a selected product can consider whether Instant Checkout is enabled alongside availability, price, quality, and primary-seller status.

  7. Stripe Services Agreement: Agentic Commerce Agent and Seller Services

    Stripe's agent-service terms require the agent operator to retain auditable consent records and evidence of its authority at each transaction, and to cooperate in resolving disputes and refunds. As between Stripe and the operator, the terms assign responsibility for transactions exceeding authority or arising from bugs, hallucinations, or misinterpretations to the operator. The seller-service terms separately assign order fulfillment, itemized receipts, and after-sales issues to the seller or participating merchant.

  8. Machines of Buying & Selling Grace

    The proposed seller interface exposes availability, contextual offers, and strategic preferences instead of only a static product page.

  9. FTC’s Endorsement Guides: What People Are Asking

    Affiliate marketing can compensate a recommender when readers follow a link and purchase. FTC guidance calls for clear, conspicuous disclosure of that retailer relationship near the recommendation so readers can weigh it. Merely labeling a link as an affiliate link or displaying a purchase button may not communicate that compensation.

  10. The Dirt on Coming Clean — Daylian Cain dissertation

    In the coin-valuation experiment, advisers inspected jars more closely than estimators, creating unequal access to relevant information. Some advisers were rewarded for inducing high estimates rather than accurate ones. Disclosing that conflict increased advice exaggeration, and estimators made larger absolute errors than under undisclosed conflicting incentives. Disclosure therefore did not eliminate the conflict's effects in this experiment.

  11. Oracle Order Management User's Guide: Simple Negotiation

    Oracle distinguishes a draft quote, internal approval, customer acceptance, and conversion to a sales order. Its documented workflow can require supplier management approval before presentation to the customer. Prior quote versions remain available as history. An expiration date can close an unaccepted quote; copying an expired quote creates a new quote. Renegotiating a customer-rejected quote restarts the approval process.

  12. UNECE: Fifty years of trade facilitation — Twenty years of electronic business standards

    Electronic data interchange, or EDI, grew from efforts to standardize trade documents and their data. UNECE traces its trade-document work to a 1957 Swedish initiative supported by other Nordic countries. Shared document layouts and definitions provided a foundation for electronic messages. ISO approved the UN/EDIFACT syntax rules as ISO 9735 in 1987; invoice and order messages followed in 1989. These developments standardized how organizations exchanged commercial information rather than delegating purchasing judgment to software.

  13. Information Integration Agents: BargainFinder and NewsFinder

    Bruce Krulwich's Andersen Consulting report dates BargainFinder's public experiment to June 30, 1995. Given an album, it queried online CD stores, extracted prices, and linked users to the corresponding merchant pages, where purchasing remained a subsequent action. The system addressed fragmented, form-accessed catalogs that ordinary search engines did not expose well. Merchant responses revealed competing incentives: some sought inclusion, while others blocked requests because price-only comparison obscured their service investment or imposed query-processing costs.

  14. Kasbah: An Agent Marketplace for Buying and Selling Goods

    Chavez and Maes's 1996 prototype separates buyer and seller agents with conflicting objectives. Users specify the item, desired price, acceptable price boundary, and deadline, and can require approval before finalizing a deal. Agents negotiate within these controls and retain negotiation histories. After agreement and user approval, people must conduct the physical transaction. The paper describes a playing-card experiment using play money, with further testing still underway.

  15. WebShop: Towards Scalable Real-World Web Interaction with Grounded Language Agents

    Shunyu Yao, Howard Chen, John Yang, and Karthik Narasimhan introduced WebShop at NeurIPS 2022 to study language-guided interaction with automatically computable task feedback. Agents search a simulated store, inspect products, select variants, and choose an item matching a natural-language request. Rewards evaluate product attributes, type, options, and price. Agents combining pretrained language and image models with imitation or reinforcement learning outperformed the studied heuristic baseline but remained below the human experts in the same evaluation.

  16. Shopify Catalog and product discovery for agentic storefronts

    Shopify distinguishes catalog syndication from web crawling and separately supplied product feeds. Disabling catalog access does not necessarily remove products from other discovery channels, while blocking crawlers does not stop enabled catalog syndication. Merchants with product attributes in custom fields may need explicit data mapping. Agentic storefronts support direct-to-consumer sales; identifiable wholesale-only products are excluded, and shared consumer/business products display consumer prices. Custom access controls can prevent Shopify from correctly identifying wholesale-only products.

  17. Intershop: Concept — Catalog Views

    A catalog view controls which products and categories particular customers or customer segments can see. Intershop documents administrator-defined inclusions, exclusions, and group assignments, allowing organizational roles to receive different catalog visibility. Configuration and publication are separate: a changed filter does not affect the storefront until published, and publication may be scheduled. The documented implementation displays all products when no valid catalog views exist.

  18. A Scalable Comparison-Shopping Agent for the World-Wide Web

    Doorenbos, Etzioni, and Weld's University of Washington ShopBot paper appeared in the 1997 Agents proceedings. It addressed the cost of hand-coding a separate interface for each merchant. An offline learner inferred symbolic descriptions of vendor sites; an online shopper used those descriptions to retrieve and compare product information. The implemented system combined heuristic search, pattern matching, and inductive learning, and was tested on software and music-CD stores. Its operation depended on regularities such as search forms and consistent product-description layouts within a store.

  19. Ionic Launch: Opening the economy to AI agents

    The described static ad feeds support human discovery but omit operational information an agent needs to complete a purchase.

  20. Shopping with ChatGPT Search

    OpenAI documents that shopping results need not include every available product. Generated descriptions and labels can simplify or interpret provider information; labels are not verified guarantees, and reviews are not verified by OpenAI. The initial displayed price can come from the first merchant rather than the cheapest offer. Merchant price and shipping changes can appear with delay. Users can clarify preferences when the model misinterprets their intent.

  21. Google Merchant Center: Availability

    Google distinguishes in-stock offers, unavailable products, preorders for unreleased products, and backorders for temporarily unavailable products that merchants still accept orders for. Preorders and backorders require availability dates. Availability must agree across feeds, landing pages, checkout, and supported shipping locations. The guidance explicitly warns that price and availability change frequently.

  22. Google Merchant Center: Item group ID

    Variants differ in attributes such as size, color, memory, or processor. Google requires distinct product identifiers for variants while a shared item-group identifier connects the family. Its published example represents three shirt sizes and three colors as nine separate variants. Variant attributes, price, availability, and images must match the corresponding landing-page selection.

  23. Schema.org: Offer

    An Offer describes a proposed transfer of rights or provision of a service, separate from the item offered. Its vocabulary represents seller, item, quantity, price, currency, availability, eligible regions, shipping, return policy, and validity dates. Detailed price specifications can describe unit prices and delivery or payment charges. A SKU is explicitly a merchant-specific product or service identifier. Delivery lead time describes delay before dispatch or pickup preparation, rather than arrival at the buyer.

  24. International Trade Administration: Import Tariffs & Fees Overview and Resources

    The cost of a landed shipment includes purchase price, freight, insurance, and applicable taxes and other charges up to the destination port. A tariff rate alone therefore does not represent the buyer's complete cost. The International Trade Administration distinguishes estimated import charges from the final determination made by customs officials in the importing country.

  25. Oracle Sourcing User Guide

    A request for quotation solicits supplier proposals for specified goods or services and can proceed through revised rounds. Oracle's sourcing workflow collects price, quantity, delivery dates, and item-specific attributes. Price-only ranking ignores other attributes when ordering responses; multiattribute scoring incorporates buyer-defined weights and desirability scores. The buyer can still award business to a supplier other than the highest-ranked response.

  26. commercetools: Reserve stock on demand and freeze prices

    The tutorial treats stock reservation and price freezing as separate operations. Reservations hold specified line items until ordering or expiry; expired stock can become available to other carts. HardFreeze preserves prices, discounts, and shipping costs during checkout. Creating the order commits the reserved inventory. The system can attempt to reacquire expired reservations, but ordering fails if stock cannot be obtained.

  27. Stop Writing Tone Instructions. Layer Them.

    Validate generated offers against authoritative allowed values before sending them; tone instructions cannot establish availability.

  28. Target Terms & Conditions: Agentic Commerce and Delegated Access

    Target's terms require approval of a commerce agent by both the customer and Target. Customer-approved permissions can include account access, cart changes, orders, and initiating returns, subject to approved limits. Customers can revoke access through account settings, after which the agent is no longer permitted to act. Target states that disputes involving agents are evaluated using permissions in effect at transaction time, authorization evidence, account protections, and applicable law. Customer authorization does not make the agent Target's representative.

  29. AP2: Checkout Mandate

    An open Checkout Mandate can constrain permitted merchants and required line items, including acceptable alternative item identifiers and quantities. The published example permits either of two shoe styles together with one specified pair of socks; buying both shoes or omitting the socks fails its requirements. A closed mandate binds to a merchant-signed checkout through its hash. Checkout receipts reference the mandate and distinguish success from error.

  30. AP2: Payment Mandate

    Payment Mandate constraints cover permitted payees and payment instruments, amount ranges, execution dates, recurrence frequency, occurrence limits, and cumulative budgets. Budget evaluation requires the proposed amount plus amounts from previously closed mandates to remain within the maximum; approved amounts must be added to the accumulated total. The budget explicitly specifies currency. Recurrence requires tracking prior presentations rather than checking a single payment in isolation.

  31. OWASP Transaction Authorization Cheat Sheet

    Transaction authorization should let the user acknowledge significant transaction data, such as destination and amount, and bind approval to that transaction rather than an unrestricted session. The server controls authorization data and permitted state transitions. Changes to transaction data invalidate prior authorization or restart the process. Credentials should be unique per operation and valid only for a limited interval. A final server-side gate immediately tied to execution verifies that the transaction was properly authorized, preventing skipped checks and substitution between approval and use. For an agent, approving a draft action therefore must not silently authorize a changed target, payload, or scope.

  32. Amazon's next-gen AI assistant for shopping

    Amazon distinguishes preparing a cart for customer review from a requested automatic purchase. Its documented auto-buy feature lets eligible Prime members choose a target price; the assistant monitors prices and purchases using the default payment method and shipping address. Requests remain active for six months or until canceled. Amazon describes purchase notifications and a free 24-hour cancellation opportunity after ordering. The page notes that Rufus was renamed Alexa for Shopping on May 13, 2026.

  33. OWASP Access Control

    Authentication establishes identity; authorization decides which actions that identity may perform on particular resources. A user allowed to initiate a transfer must still be authorized for the source account. Least privilege limits the authority of running code and service accounts, while centralized checks reduce inconsistent enforcement. In an AI application, tool availability and a model-produced argument are therefore insufficient grounds to execute a business operation; the application must apply resource- and action-level policy.

  34. IT Admin for the AI Workforce — Sarthak Aggarwal, Decawork

    Represent the agent actor, accountable owner, represented subject, and delegation context separately.

  35. AP2: Agent Authorization Framework

    AP2 requires the verifier to check that a transaction-bound mandate preserves the original approved values and satisfies every applicable constraint. Unknown constraints must fail evaluation. If conformity cannot be verified, the documented error can trigger a directly approved mandate or a non-agentic flow. Selective disclosure lets an agent reveal applicable authorization conditions while withholding unnecessary information; the specification requires choosing disclosures to maximize privacy while still establishing authorization.

  36. Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

    Indirect prompt injection places attacker instructions in material an application is likely to retrieve, rather than in a direct user request. The paper demonstrates how applications can confuse external data with instructions, allowing retrieved text to redirect behavior or influence subsequent API calls. This makes the provenance and trust level of a context item separate from its relevance to a query: useful retrieved material can still be adversarial.

  37. W3C Verifiable Credentials Data Model v2.0

    A verifiable credential is a tamper-evident statement whose authorship can be checked cryptographically. Verification checks authenticity, currency, conformance, securing mechanisms, and applicable status. It does not evaluate whether the encoded claims are true. Validation separately determines whether claims from an issuer satisfy the verifier's business requirements.

  38. Stripe: Shared payment tokens — Agents

    Shared payment tokens grant a seller scoped access to a customer's payment method. The agent issues a token for a transaction and seller profile with currency, maximum amount, and expiration limits; the seller uses it for payment processing. A token can require additional customer action, including bank authentication, before payment completes.

  39. Adyen: Use transaction rules

    Adyen transaction rules can evaluate individual transactions or accumulated activity at scopes including a card, card group, balance account, or account holder. Available amount and count limits include authorized transactions even before capture. When an authorization expires or is canceled, its amount or count is released back into the available limit.

  40. Your Agent Didn’t Fail. Your Harness Did.

    Provide one ordered commit path per mutable state boundary while allowing independent work to run concurrently.

  41. Stripe: Issuing spending controls

    Stripe supports spending limits at card and cardholder levels; a cardholder limit applies across their cards. However, spending aggregation is best effort and can lag spending by up to 30 seconds. Later tips and fees can also cause a limit to be exceeded. Category-specific amount limits do not themselves prohibit spending in other merchant categories.

  42. Building safe Payment Infrastructure for the autonomous economy

    The Q&A describes subsequent credential usage through an OAuth access/refresh analogy, but does not establish a complete recurring budget mechanism.

  43. Building safe Payment Infrastructure for the autonomous economy

    The Agentic Commerce Protocol (ACP) represents products and checkout state as structured data and returns updated seller state after checkout changes.

  44. Your Agent Didn’t Fail. Your Harness Did.

    Delivery alone is insufficient: a named system of record must persist the fact and support replay into future work.

  45. Shopify: Building the Universal Commerce Protocol

    Shopify's January 11, 2026 engineering account describes UCP, co-developed with Google, as addressing variation among merchants' checkout and fulfillment requirements. Merchants and agents publish supported capabilities, then determine which capabilities they share. Extensions represent specialized requirements without putting every merchant feature into a single checkout definition. When the merchant requires information or functionality the agent cannot supply, the workflow supports handing the existing checkout to the buyer through a continuation URL. The account distinguishes missing information, required escalation, and readiness for programmatic completion.

  46. cXML 1.0 Specification — August 16, 1999

    Ariba's August 16, 1999 cXML specification distinguishes browsing a supplier site from submitting a purchase order. PunchOut establishes a supplier browsing session and returns selected shopping-basket items to the originating system, where they become requisition items. A separate OrderRequest represents the purchase order. Its synchronous response confirms correct receipt, not a commitment to execute the order or an item-level statement about shipment and backorders. The specification therefore preserves commercial boundaries even when the supplier page presents a checkout button.

  47. Apple Shopping Help: Policies

    Apple's U.S. education-store terms state that an order-confirmation email acknowledges receipt and does not signify acceptance. Apple can decline or cancel an order and refunds payment if it cancels after payment. The terms also warn that returning a product with wireless service does not necessarily cancel the separate wireless agreement or associated fees.

  48. Building safe Payment Infrastructure for the autonomous economy

    Shared payment tokens constrain a delegated credential by seller, currency, amount, and time, with enforcement performed by Stripe.

  49. Adyen: Payments lifecycle

    Payment authorization follows payment-detail and risk checks and reserves funds for a limited period. Depending on the payment method, capture can follow automatically or occur separately, including partial capture. SentForSettle records a transfer request while funds are still awaited. Settled means Adyen received the funds, which is distinct from payout to the merchant. Uncaptured authorization can expire or be canceled.

  50. Stripe: Disputes

    A card dispute begins when a cardholder questions a payment with the card issuer. To process a chargeback, the issuer creates a formal dispute through the card network, reversing the payment and causing the payment amount and applicable dispute fees to be debited through the processor. The merchant can submit evidence and a counterargument.

  51. Automating Escrow with USDC and AI

    The described workflow distinguishes agreement creation from actual funding, and moves to a Locked state only after funds settle in the contract.

  52. Making retries safe with idempotent APIs — Amazon Builders' Library

    A caller-provided request identifier expresses that repeated requests represent the same logical operation. Identical parameters alone cannot establish this: a user may intentionally request two identical resources. The server must coordinate recording the identifier with performing the mutation atomically, return a semantically equivalent result for a retry, and reject reused identifiers paired with different intent or parameters. Retention of identifiers also needs a defined lifetime. These semantics let an agent runtime retry an uncertain tool response without silently turning one authorized operation into two.

  53. Resolving an ambiguous payment request

    A timeout can leave the client unable to tell whether Stripe received or executed a request. Stripe documents retrying with the same key and parameters until a server result is obtained, using backoff. An HTTP 500 remains indeterminate: side effects may exist even though the cached response stays unchanged. Stripe may reconcile partial mutations and emit webhook events for resulting objects. Supplying a local operation identifier in metadata lets the application correlate these objects with its own pending operation. Engineering consequence: preserve pending state until authoritative provider evidence resolves it; do not infer failure solely from a timeout.

  54. Your Agent Didn’t Fail. Your Harness Did.

    Trace one real run from trigger identity through inherited state, authority, execution attempts, and surviving external evidence.

  55. Stripe retry keys and retention boundaries

    For a mutation, send an idempotency key and reuse that key with identical parameters when retrying an ambiguous connection failure. Stripe stores the first executed request's status and response body, including failures such as HTTP 500, and returns that result for repeated requests. Parameter mismatches produce an error. Keys may be pruned after they are at least 24 hours old; reuse after pruning creates a new request. Results are saved only after endpoint execution begins, so validation failures and conflicts with concurrently executing requests do not create a saved result.

  56. Stripe Billing: Entitlements

    Stripe maps subscription products to features and maintains customers' active entitlements as subscriptions change. An entitlement identifies feature access the customer should receive. The seller's application must actually enable or disable the corresponding features; Stripe's notification does not perform that application change. The documentation also supports retrieving current entitlements to reconcile access after a missed webhook.

  57. FTC Business Guide to the Mail, Internet, or Telephone Order Merchandise Rule

    For covered U.S. merchandise orders, sellers need a reasonable basis for promised shipment times. If they cannot ship on time, they must follow the rule's delay-consent or cancellation-and-refund procedures. A materially different substitute requires the customer's prior express agreement, even if the seller considers it better. The seller remains responsible for rule violations caused by its fulfillment house or drop-shipper. The guide recommends records connecting orders, delay notices, customer responses, shipments, and refunds.

  58. PagerDuty: Incidents

    PagerDuty separates triggering, acknowledging, and resolving an incident. Assignment and notification follow an escalation policy; acknowledgment records that a responder claims ownership and is working on the unresolved issue. Without acknowledgment, escalation continues. An acknowledgment timeout can return the incident to triggered status and resume escalation. Incident timelines record status changes, actions, and notifications. This supplies an operational example in which requesting attention, accepting responsibility, and resolving work are distinct events.

  59. Temporal Activity Execution

    An Activity Execution can comprise multiple task attempts. Temporal relies on timeouts to detect lost work, including worker crashes after invocation, and retries according to policy; limiting attempts to one prevents retry but does not prove an external effect failed. Cancellation is cooperative: activities receive service cancellation through heartbeats, can ignore it, and workflows may proceed without waiting for acceptance. A timed-out attempt may therefore continue while another attempt runs. Application consequence: treat an unconfirmed external mutation as uncertain, retain its operation identifier, reconcile against the receiving system, and use enforced idempotency or explicit recovery before repeating it. Timeout or cancellation is not evidence that a payment, message, or write was reversed.

  60. HP U.S. Store: Returns & Exchanges

    HP's U.S. direct-store workflow checks return eligibility, approves a return authorization number, supplies return instructions, and receives and validates the goods before initiating a refund. It tells customers to retain the carrier receipt. Eligible defective-product returns receive free return labels without a restocking fee. Replacements ordinarily require return of the original product first. Refund confirmation and the credit appearing in the customer's account are separate stages.

  61. Stripe: Refunds

    After refund initiation, Stripe submits a request to the customer's bank or issuer; customer-visible credit occurs later. Refunds can fail, returning funds to the merchant's Stripe balance. Available transaction references can help the customer's bank trace the refund. A reversal can instead remove the original charge without creating a separate credit. Payment cancellation is status-dependent, and a succeeded PaymentIntent cannot be canceled.

  62. Instacart Help Center: Adding item and replacement instructions

    Instacart offers three replacement choices: let the shopper select a match, specify a replacement, or request a refund. Under the refund choice, a shopper can still suggest an alternative, but the customer receives an approval or rejection request. Replacement instructions carry into future orders, and replacement price differences are charged or refunded. For eligible unavailable items, a second-store order can create another authorization hold and may not preserve the original promotions.

  63. Stripe: Refund and cancel payments

    Stripe warns that bank-debit refunds overlapping bank disputes can produce duplicate credits. If a pending refund fails because the charge was disputed, Stripe recommends accepting or challenging that dispute instead of issuing another refund.

  64. Shopify Agentic Storefronts Supplemental Terms of Service

    Shopify warns that an AI channel may not reproduce the merchant's checkout customizations, delivery options, or payment methods; merchants must decide whether missing required capabilities warrant disabling that channel. Channel transaction fees can supplement existing fees. On cancellation or refund, applicable Agentic Storefronts fees and associated tax are refunded, but Shopify Payments transaction fees are not. Ending participation leaves the merchant responsible for obligations connected to earlier transactions.

  65. Froglet: Trust & Economics

    Froglet distinguishes attributable service outcomes from correct service results. A signed receipt binds the provider to an outcome and result hash, but someone must still assess correctness. Its hosted marketplace's operator handles complaints and can suspend provider listings; suspension neither invalidates signed artifacts nor prohibits direct protocol transactions. Receipt histories can be inflated through self-dealing. The documented fee model makes the base fee nonrefundable when execution fails, while the success fee is conditional. Staked identity is explicitly described as designed but not live.

  66. Agents Need Receipts, Not More Tool Calls

    Froglet describes a signed transaction chain covering descriptors, offers, quotes, deals, invoices, and receipts.

  67. CFPB Regulation Z: Section 1026.13 — Billing Error Resolution

    For covered U.S. open-end credit, the billing-error procedure includes goods or services not accepted or not delivered as agreed, including wrong quantities, late delivery, and delivery to the wrong location. The official interpretation excludes quality disputes about goods the consumer accepted from this particular category. A qualifying written notice must reach the creditor's designated address within 60 days after transmission of the first statement reflecting the alleged error. Consumers need not first seek merchant resolution for the nonacceptance or nondelivery category. The creditor generally acknowledges within 30 days and completes resolution within two billing cycles, no later than 90 days.

  68. NIST Privacy Framework 1.0: lifecycle and minimized audit evidence

    The framework inventories data elements, processing purposes, actions, owners and flows. Policies define permitted uses and retention periods; the data lifecycle aligns with system development and operations. Authorizations must be maintained and revocable, access limited by least privilege, and deletion and destruction performed under policy. Audit records themselves must incorporate data minimization. Engineering application: define the decision evidence needed for review, its purpose, authorized readers, retention trigger and disposal method before logging. Retain the necessary decision, model and policy versions and relevant evidence without indiscriminately copying personal data into logs, prompts or backups. Where review requires sensitive evidence, constrain fields, access and retention rather than treating auditability as permission to keep everything. Assess removal and disclosure across downstream copies and service providers.

  69. Building safe Payment Infrastructure for the autonomous economy

    Separate nondeterministic discovery and planning from constrained credential handling, payment, and checkout.

  70. Comparing Traditional and LLM-based Search for Consumer Choice: A Randomized Experiment

    In a randomized online experiment, participants compared pairs of SUVs using a specified cargo-space-to-length criterion. The authors estimated task durations of 3.4 minutes with traditional search and 1.6 minutes with their GPT-3.5-based tool. Accuracy was comparable on routine tasks. On a deliberately selected difficult comparison, the model confused seats-up and seats-down cargo capacity, and participants using it made substantially more incorrect choices.

  71. What Is Your AI Agent Buying? Evaluation, Biases, Model Dependence, & Emerging Implications for Agentic E-Commerce

    ACES isolates product selection in a controlled shopping simulator. Randomized experiments vary listing positions and product attributes. The authors find model-dependent responses to position, price, and ratings; seller-agent edits to descriptions can increase the focal product's selection share in tested settings. Position effects also appear in tested JSON-only interfaces. The study defines its reported market shares as selection frequencies in simulated trials.

  72. X12: Supply Chain Transaction Flow

    X12 separates product-data alignment, ordering, shipment notification, invoicing, and payment into distinct exchanges between trading partners. Data alignment gives buyer and seller a common understanding of the item before ordering; unique product identifiers help prevent mismatches. A functional acknowledgment confirms receipt and usability of a message, while purchase-order acknowledgment is a separate business exchange. Shipment notices, invoices requesting payment, and payment or remittance messages likewise communicate different facts. X12 describes industry development of these transaction sets during the 1970s–1990s and subsequent adaptation to consumer ecommerce.

  73. Your Agent Didn’t Fail. Your Harness Did.

    Approval must remain bound to one specific action and its scope, identity, arguments, and lifetime; expiration should terminate the approval path.

  74. Ionic Launch: Opening the economy to AI agents

    Ionic describes combining merchant product feeds with editorial content and reviews through an agentic enrichment workflow, then exposing the consolidated information through an API.