Yesterday at its Dialogues event, Decagon announced PACT — Personal Agent Consent & Trust — a protocol that lets a person's agent act on their behalf under permissions the service defines and the person grants. Unite.ai, 2026-10-01
Read that again: consent is now a protocol. Not a checkbox. Not a terms-of-service link. A machine-readable standard for delegated authorization.
What PACT actually does
The setup: personal agents — Meta's Muse, OpenAI's dots, phone-calling Instinct agents — already book, buy, cancel, and negotiate on their owners' behalf, and they're already showing up in customer-support queues. Decagon's answer is a Personal Agent Gateway that detects whether a human or an agent is on the other end, routes the agent to a dedicated channel, and — the critical part — requires approval from the owner behind the agent for sensitive actions, declining if the owner can't be reached. Unite.ai, 2026-10-01
PACT builds on the Agent2Agent protocol — how agents find and message each other — and adds delegated authorization on OAuth 2.0, so an agent can prove which person it represents and what that person allowed it to do. Permissions live inside Agent Operating Procedures: a business defines the scopes an agent can request, and sections requiring a scope are never exposed to an agent that lacks it. Decagon's example: a traveler's agent asks to view and rebook flights; the traveler approves viewing only; the airline's agent shows options but cannot change anything until the traveler authorizes rebooking. Unite.ai, 2026-10-01
The spec is published. Decagon says it's working with personal agent providers and enterprise customers to shape it.
The gap it closes
A budget is not a permission. PYMNTS reported last month on the Legal Context Protocol — launched in June by the American Arbitration Association and Integra Ledger, with Google, IBM, Circle, Wayfair, and UiPath as founding contributors — which exists because "until now no record existed of which decisions the shopper approved and which the agent made alone." Retailers like Target already treat an agent's choices as the customer's own, while only 23% of US consumers trust AI to handle payments. PYMNTS, 2026-09-23
Two independent protocols, one month apart, both attacking the same gap: when an agent acts, what exactly did the human authorize?
Why this validates the thesis
Authorization is the load-bearing step in every governed chain. Intent means nothing without it. Evidence is inert. Audit is just a record of what happened — it can't stop what shouldn't.
Solomon's chain is Intent → Evidence → Governance → Decision → Authorization → Audit. PACT is the Authorization half of that chain, becoming an external, interoperable standard. That's the important sentence. The industry isn't just agreeing that agents need consent — it's standardizing the machinery of consent: who authorized what, under which scope, provable by the agent in real time.
For a business owner, the takeaway is concrete. Your customers' agents are coming to your systems. They will book, buy, cancel, and negotiate — on channels you didn't design, at machine speed. The question is whether your side has a consent protocol or a contact form.
Think about what that means for the systems you actually run. Your custom CRM holds your customer list, your pipeline, your money movement. When a customer's agent arrives asking to change an order, issue a refund, or renegotiate terms, "the agent said the customer approved it" is not an authorization. It's a claim. PACT gives the industry a way to verify that claim — which person, which scope, provable in real time. Without it, you're either trusting vibes or blocking agents entirely, and blocking them means losing customers to whoever accepts them safely. Unite.ai, 2026-10-01
We built Solomon on the principle that nothing moves without authorization and everything leaves a trail. The industry is now publishing specifications for it.
Consent was a checkbox. Now it's infrastructure.
— Ronin Inc. DMs open. ronininc.org.



