Blog

Who owns agent readiness?

Ask who owns agent readiness and you'll often get a pause. SEO thinks it's a developer problem. Developers think it's a security setting. Security thinks it's marketing's call. Meanwhile AI agents are turned away, or get lost, and nobody hears about it. The work is spread across several teams by its nature. What it needs is one clear owner and a clear split of the rest.

Why it falls between teams

Agent readiness touches four layers of a website, and each layer has its own team.

  • The door: robots.txt, bot protection, CDN rules and rate limits decide whether an agent gets in.
  • The content: titles, descriptions, product data and policies decide whether it understands what it finds.
  • The page: buttons, forms, pop-ups and rendering decide whether it can move around and act.
  • The transaction: cart, checkout and accounts decide whether it can finish the job.

No one team sees all four. Each sees its own layer working, and the failure shows up somewhere else: a lost recommendation, or an order that never happened.

Who usually fixes what

In the Ghost Agent Labs app, each AgentScore finding names a suggested owner under “Usually fixed by”, and the CSV export includes it too. Grouped together, the defaults look like this.

TeamWhat they usually ownAgentScore checks
SEO or content teamThe rules and text agents read firstrobots.txt lets AI assistants and search agents in; llms.txt guide for AI; Clear page title, description, and headings; Images have text descriptions; Valid sitemap
Bot protection or CDN adminWho gets through the door, and whereBot protection lets AI agents through; No CAPTCHA or challenge on arrival; AI agents can open your product, pricing and cart pages; AI agents aren't blocked or shown a CAPTCHA at the cart and checkout
DeveloperHow pages are built and renderedContent loads without JavaScript; Structured data describes your business and products; Product pages give price and stock in a form agents can read; Prices are in the page HTML; every Navigability check, from named buttons and labelled fields to pop-ups and checkout fields; Agents can use your site through MCP or WebMCP
E-commerce platform adminHow the store and checkout are configuredShoppers can check out without an account; Agents can check out through an agentic commerce protocol

Task completion, which comes from real agents running journeys, usually lands with developers once a test shows where an agent gets stuck. But the decision about which journeys matter belongs to the business.

These are defaults, not rules. On a hosted platform, the "developer" fixes for a product page may really be theme settings an e-commerce manager can change. At a small company, one person may hold three of these roles.

The roles in more detail

E-commerce and digital leaders

They own the outcome: whether AI agents can find, choose and buy from the site. That makes them the natural overall owner. They decide which journeys matter, set priorities when fixes compete for developer time, and own the platform settings that shape checkout, such as guest checkout. See guest checkout: why AI shopping agents need it.

Marketing and SEO

They own most of what agents read before they act: robots.txt, titles and headings, alt text, sitemaps and llms.txt. They also own measurement, because AI referrals belong next to search and social in channel reporting. See SEO got you found. Agent readiness gets you chosen and tracking visits and sales that come from AI assistants.

Developers

They own the largest number of fixes: rendering content and prices in the HTML, structured data, named controls, labelled fields, dismissible pop-ups and checkout fields. Much of this overlaps with accessibility, so the same people and practices often apply. See accessibility work is agent readiness work. Developers also run agent tests as part of release checks, and evaluate newer interfaces such as MCP and WebMCP.

Security and CDN

They own the door. Bot protection, WAF rules, challenge pages and rate limits are where agents are most often blocked by accident, because those rules were written to stop scrapers. This team's job isn't to let everything in. It's to tell real agents from impostors, by verified identity rather than by name alone, and to treat the agents the business wants accordingly. See bot protection and CAPTCHAs, how to tell if an AI crawler is real and rate limits for AI agents.

Legal

Legal doesn't fix findings, but it shapes several decisions the other teams can't make alone:

  • Whether to allow AI training crawlers, which is a content-licensing question as much as a technical one. See should you block AI crawlers?
  • What your terms of service say about automated access, and whether they accidentally forbid the agents you want.
  • The terms and liability around purchases made by an agent for a customer, before you adopt an agentic commerce protocol.
  • Accessibility obligations, which often share fixes with agent readiness.

Making it work in practice

  1. Name one accountable owner. Usually the head of e-commerce or digital. They don't make every fix; they make sure each one has someone.
  2. Route findings by owner. Export the findings as CSV and send each group to its team. Each finding explains why it matters in plain language, which helps when the team receiving it doesn't think of AI agents as its problem.
  3. Agree the policy decisions once. Training crawlers, verified agents through bot protection, and guest checkout are decisions, not tickets. Settle them in one meeting with SEO, security, e-commerce and legal in the room.
  4. Make failures visible to the owner. Run Ghost Agent tests on your money journeys and send alerts to the person who can act, not a shared inbox.
  5. Review monthly. AgentScore by category, Ghost Agent pass rates, agent traffic and AI referrals, on one page.

A simple test: if an AI assistant started being blocked from your product pages tomorrow, who would find out, and how? If the answer is "nobody" or "eventually", that's the gap to close first.

For a phased version of this, see our 90-day agent readiness plan. Or start by running AgentScore and seeing whose name comes up most.

← All blog Test your site with AgentScore →

Can AI agents use your site?

Get your free AgentScore in under a minute. No sign-up needed.