There's a loud, legitimate debate happening over agent access to the web: edge providers shipping pay-per-crawl controls, platforms drawing lines over which agents may act on a user's behalf, publishers and retailers testing how much automated access they'll tolerate. It matters. It's also not the question most businesses should lead with.
Two different problems
"Should this agent be allowed here?" is an access and authorization question — and for a lot of sites, the honest answer is yes, please. A buying agent dispatched by a real customer is demand. The harder, more valuable question is the operational one: when an agent you'd happily sell to arrives, can it complete the purchase?
Blocking the wrong agents protects you from cost. Serving the right ones is how you grow.
The case against reflexive blocking
Treating all automation as a threat is a Cloudflare-shaped reflex — useful at the edge, but it walks you past the upside. The agents researching and buying on behalf of humans are the same traffic that, served well, converts. Wall them all off and you've optimized for a quieter server bill and a smaller business.
Identify honestly, ingest the signals
The durable posture isn't "block everything" or "allow everything." It's: let your infrastructure tell verified buying agents apart from abusive ones, and make the experience excellent for the former. Ingest the verification signals the edge already produces; don't try to re-fight that battle yourself. Your agents — and the ones you welcome — should identify themselves honestly, never disguised as humans. That honesty is a feature, not a constraint: it's what keeps you on the right side of the authorization questions while you build for the traffic that pays.
Where we land
Spend a little energy on access policy, and most of your energy on operability. The companies that treat the agent majority as customers to be served — not bots to be repelled — are the ones quietly compounding while everyone else argues about the gate.