Articles

Order tracking, returns and reorders by AI agents

Usually fixed by: E-commerce platform admin

Buying is only part of what people ask AI assistants to do. "Where's my order?" "Return the shoes, they're too small." "Order the same coffee again." These after-sale tasks are frequent, they cost you nothing when customers can do them on their own, and they're often locked behind a login an agent can't use. This guide covers how to make them work for AI agents, and where the agent should hand back to the person.

Why after-sale tasks matter

"Where is my order?" is one of the most common reasons customers contact an online store. When an assistant can answer it from your site, that's a support ticket that never gets written. When it can't, the person contacts you anyway, or the assistant pieces together an answer from a carrier's site and gets it wrong.

Returns matter before the sale, too. Assistants read return policies when comparing stores, and a clear, easy returns process is part of what makes a store safe to recommend. See policy pages AI assistants can quote.

Order tracking without a login

An agent can't sign in as the person, but it can usually be given an order number and an email address. That's enough for a well-built order lookup.

  • Give order lookup its own page at a stable URL, such as /orders/lookup, linked from your footer and help pages with an ordinary link.
  • Ask for two things: the order number and the email address used at checkout. Label both fields, and say where to find the number: "It starts with NW- and is in your confirmation email."
  • Show the status in words. "Shipped on October 3 with UPS. Expected Tuesday, October 7", the tracking number as a link, and the items in the order. A progress bar alone tells an agent nothing.
  • Put a direct link in every order email that opens the order's status page without signing in. Many platforms offer one. Agents reading an email for the person can follow it straight to the answer.
  • Keep failures helpful but safe. "We couldn't find an order matching those details" is right. Don't say which of the two was wrong, which would let anyone test email addresses.
  • Limit guessing with rate limits, not a CAPTCHA on every lookup. Answer too many attempts with a 429 status. See rate limits for AI agents.

A lookup form agents can fill in:

<form action="/orders/lookup" method="post">
  <label for="order">Order number</label>
  <input id="order" name="order" autocomplete="off" aria-describedby="order-hint">
  <p id="order-hint">Starts with NW-. You'll find it in your confirmation email.</p>

  <label for="email">Email used at checkout</label>
  <input id="email" name="email" type="email" autocomplete="email">

  <button type="submit">Find my order</button>
</form>

Show only what's needed on a page reached this way: status, items, carrier and the delivery city. Leave out the full address, phone number and payment details.

Returns and exchanges

  • Start from a plain-text policy: how long customers have, what condition items must be in, who pays return shipping, how long refunds take and what can't be returned.
  • Open the returns portal with an order number and email, the same as tracking. If returns need an account, most agents stop at the door.
  • Label every choice. Items as checkboxes named with the product and size, the reason as a list of options in words, and refund, exchange or store credit as radio buttons that say what each one means: "Store credit: issued as soon as we receive the item."
  • Explain why an item isn't eligible. "This item was delivered 45 days ago. Returns close after 30 days." See error messages AI agents can understand.
  • Summarize before submitting. A review step ("You're returning 1 item for a $64.00 refund to your original payment method") lets the agent check with the person first.
  • Say what happens next in words. Where the label is (a link to the PDF, and "We've emailed it to you"), drop-off options, and when the refund will arrive.

Reorders

"Order the same again" usually needs order history, and order history usually needs an account. You can still make it easy:

  • Add a "Buy again" button to the order status page, the one reached from the email link. Name it after the item: "Buy again: Ethiopia Yirgacheffe, 340 g".
  • Put the same item back in the cart: the same size, color and quantity. Say if anything changed: "The price is now $19.00" or "This size is out of stock."
  • Keep product URLs stable. A product link in a year-old confirmation email should still work, or redirect to the replacement product with a note saying so. See canonical URLs and duplicate pages.
  • Make subscription controls clear if you sell subscriptions. "Skip next delivery" and "Change quantity" as named buttons, with the next delivery date in words.

Security, accounts and handing back to the person

These tasks touch personal details and money, so there's a real tension. Agents shouldn't need the person's password, and anyone holding an order number shouldn't be able to change an order. The answer is to match the check to the risk:

TaskWhat it should takeWho finishes it
Track an orderOrder number and emailThe agent
Check return eligibility and optionsOrder number and emailThe agent
Submit a return or exchangeOrder number and email, plus a review stepThe agent, once the person agrees
ReorderA "Buy again" link or buttonThe agent builds the cart, the person pays
Change a delivery address or cancelA one-time code or emailed linkThe person
Change email, password or saved cardsFull sign-in, ideally with two-step sign-inThe person only
  • Use step-up checks for risky actions only. A one-time code sent by email or text is a clean handoff point: the agent stops and says "Northwind has sent a code to your email", and the person takes it from there.
  • Make the handoff obvious. Browser agents typically hand control back for sign-in and payment. A sign-in form with labelled fields, and support for passkeys or password managers, makes that moment quick for the person.
  • Never ask for card details to prove who someone is. No one, human or agent, should be typing card numbers to see an order status.
  • Keep help content public. Delivery times, return policy and FAQs don't need a login. See login walls and gated content.

The same thinking applies to buying: see guest checkout and sign-up and booking forms agents can use.

How to test these journeys

  1. Try it yourself with an assistant. Place a test order, then ask an assistant that can browse to find its status using the order number and email. Watch where it stalls.
  2. Check the basics with AgentScore. It checks that AI assistants are let in and can open your key product, pricing and cart pages. It doesn't test order lookup or returns, and the free scan marks Task completion "not tested".
  3. Monitor them with Ghost Agents. Describe the journey in your own words, such as "Find the order tracking page, look up order NW-10422 with test@northwind.example, and report the delivery status", and set a pass condition that looks for text like "Shipped" on the final page. For returns, write the goal so the agent stops at the review step, without submitting.

Start with tracking. It's the most common after-sale question, it needs no new security thinking, and a public lookup page with a direct link in every order email works for customers and their agents alike.

← All articles Test your site with AgentScore →

Can AI agents finish the job on your site?

Ghost Agents work through your journeys from a plain-English goal, with a step-by-step replay of where they got stuck. Included in every plan, even Free.