Methodology
What we test
Whether an AI agent can complete a task on a site for its person: buy one item, or book one slot. We record how far each agent gets, where it stops, and what it had to ask its person for along the way.
Stop at pay
Without the owner’s consent, agents go no further than the payment step (for bookings, the final confirm step) and stop. We never place orders or bookings without the owner’s consent. Runners carry no real payment cards.
With the owner’s consent, as part of a paid audit, a run may complete using a test coupon or a capped one-time card, and the order is then cancelled or refunded.
Agent tiers
Every result is labelled with the tier that produced it.
- T1 real agent
- The real consumer agent, driven through its own app or channel with our accounts.
- T2 self-hosted
- The same open-source agent code people run themselves (for example OpenClaw), on our machines.
- T3 emulated
- An emulation: the same model family, browser and network profile as a named agent. Always labelled as emulated.
- T4 protocol
- A sanctioned protocol path, such as Shopify Storefront MCP or UCP checkout, instead of a browser.
We never forge another agent’s identity or signatures. Emulated runs are always labelled as emulated.
Networks
Runs are reported per network profile. US networks are the reference. Runs from other networks are labelled “non-US network (comparison)”, because some sites treat traffic differently by location.
Static checks
A free scan reads the home page, robots.txt, the sitemap, llms.txt, well-known agent files and one product page. It checks access (bot walls, crawler rules), discovery, content, commerce data and agent capabilities. A page that blocks our scanner caps the result. Our crawler is described on the VouchAgentBot page.
Dates and freshness
Every fact carries the date it was verified. Results older than 30 days are stale and get re-tested. Agents change weekly, so a dated result is a fact about that day, not a promise about tomorrow.
Wording
Reports state facts, not grades: “reached the payment step”, “blocked at /checkout by a Cloudflare challenge for unsigned browser agents”.
Disputes and re-tests
Anyone can request a re-test from a report page, once per site every 24 hours. Owners who claim their site with an email at its domain can request re-tests, opt out of testing, or stop our emails.
To dispute a result, email hello@vouchagent.com with the report link. We re-run the test and correct or annotate the report.
Changes
This methodology is versioned. Material changes get a new version number and date.