# Methodology v0.1

Version v0.1, published 3 Oct 2026. https://vouchagent.com/methodology

## What we test

Whether an AI agent can complete a task on a site for its person: buy one item, or book one slot. We record how far each agent gets, where it stops, and what it had to ask its person for along the way.

## Stop at pay

Without the owner's consent, agents go no further than the payment step (for bookings: the final confirm step) and stop. We never place orders or bookings without the owner's consent. Runners carry no real payment cards. With the owner's consent (paid audit), a run may complete with a test coupon or a capped one-time card, and the order is cancelled or refunded.

## Agent tiers

Every result is labelled with the tier that produced it.

- T1 real agent: The real consumer agent, driven through its own app or channel with our accounts.
- T2 self-hosted: The same open-source agent code people run themselves (for example OpenClaw), on our machines.
- T3 emulated: An emulation: the same model family, browser and network profile as a named agent. Always labelled as emulated.
- T4 protocol: A sanctioned protocol path, such as Shopify Storefront MCP or UCP checkout, instead of a browser.

We never forge another agent's identity or signatures. Emulated runs are always labelled as emulated.

## Networks (egress)

Runs are reported per network profile. US networks are the reference. Runs from other networks are labelled "non-US network (comparison)", because some sites treat traffic differently by location.

## Static checks

A free scan reads the home page, robots.txt, sitemap, llms.txt, well-known agent files and one product page, and checks access (bot walls, crawler rules), discovery, content, commerce data and agent capabilities. A page that blocks our scanner caps the result.

## Dates and freshness

Every fact carries the date it was verified. Results older than 30 days are stale and get re-tested. Agents change weekly, so a dated result is a fact about that day.

## Wording

Reports state facts, not grades: "reached the payment step", "blocked at /checkout by a Cloudflare challenge for unsigned browser agents".

## Disputes and re-tests

Anyone can request a re-test from a report page, once per site every 24 hours. Owners who claim their site with an email at its domain can request re-tests, opt out of testing, or stop our emails. To dispute a result, email hello@vouchagent.com with the report link; we re-run and correct or annotate the report.

## Changes

This methodology is versioned. Material changes get a new version number and date.
