VouchAgent

Methodology

Version v0.1, published 3 Oct 2026. Markdown version

What we test

Whether an AI agent can complete a task on a site for its person: buy one item, or book one slot. We record how far each agent gets, where it stops, and what it had to ask its person for along the way.

Stop at pay

Without the owner’s consent, agents go no further than the payment step (for bookings, the final confirm step) and stop. We never place orders or bookings without the owner’s consent. Runners carry no real payment cards.

With the owner’s consent, as part of a paid audit, a run may complete using a test coupon or a capped one-time card, and the order is then cancelled or refunded.

Agent tiers

Every result is labelled with the tier that produced it.

T1 real agent
The real consumer agent, driven through its own app or channel with our accounts.
T2 self-hosted
The same open-source agent code people run themselves (for example OpenClaw), on our machines.
T3 emulated
An emulation: the same model family, browser and network profile as a named agent. Always labelled as emulated.
T4 protocol
A sanctioned protocol path, such as Shopify Storefront MCP or UCP checkout, instead of a browser.

We never forge another agent’s identity or signatures. Emulated runs are always labelled as emulated.

Networks

Runs are reported per network profile. US networks are the reference. Runs from other networks are labelled “non-US network (comparison)”, because some sites treat traffic differently by location.

Static checks

A free scan reads the home page, robots.txt, the sitemap, llms.txt, well-known agent files and one product page. It checks access (bot walls, crawler rules), discovery, content, commerce data and agent capabilities. A page that blocks our scanner caps the result. Our crawler is described on the VouchAgentBot page.

Dates and freshness

Every fact carries the date it was verified. Results older than 30 days are stale and get re-tested. Agents change weekly, so a dated result is a fact about that day, not a promise about tomorrow.

Wording

Reports state facts, not grades: “reached the payment step”, “blocked at /checkout by a Cloudflare challenge for unsigned browser agents”.

Disputes and re-tests

Anyone can request a re-test from a report page, once per site every 24 hours. Owners who claim their site with an email at its domain can request re-tests, opt out of testing, or stop our emails.

To dispute a result, email hello@vouchagent.com with the report link. We re-run the test and correct or annotate the report.

Changes

This methodology is versioned. Material changes get a new version number and date.