Skip to content

Agent Use Policy

Effective August 3, 2026 · v2.0

1. Scope

This policy applies to AI models, agents, robots, devices, plugins, SDKs, API clients, and human operators that read data from, write data to, or take actions through Bippsi.

2. Operator Responsibility

The account holder and, where applicable, organization are responsible for selecting the agent, granting access, reviewing capabilities, funding activity, and responding to harmful or incorrect behavior. An agent is not a separate legal account holder and cannot expand its own authority.

3. Authority and Account Context

  • Every action must carry an explicit tenant and account context.
  • Agents may use only granted scopes, connected resources, approved tools, and valid credentials.
  • Revocation, suspension, budget limits, legal holds, privacy gates, and safety controls override model instructions.
  • A user prompt cannot weaken platform, security, privacy, legal, payment, or physical-safety rules.

4. Data and Memory

Agents receive only data the user or organization has authorized for the active context. Memory, Mail, Drive, Locker, contacts, Commerce, and device data remain separately permissioned. Bippsi Managed routes must use approved providers and evidence-backed privacy settings. Agents must not infer that a fallback, summary, or memory is current truth when a live authoritative source is required.

5. Actions and Confirmation

High-impact, irreversible, regulated, financial, external-communication, and physical actions require the platform's policy and confirmation gates. Retries must be idempotent. Agents must verify outcomes and initiate corrective action when they cause a recoverable error.

6. Prohibited Agent Conduct

  • Credential theft, privilege escalation, prompt-injection propagation, hidden data exfiltration, or cross-account access.
  • Bypassing payment, consent, age, identity, business, sanctions, tax, or product-eligibility controls.
  • Representing generated information as verified fact without the required evidence.
  • Making deceptive purchases, disputes, signatures, messages, listings, or reviews.
  • Continuing an action after revocation, budget exhaustion, safety stop, or a provider response that leaves the result uncertain.

7. Economic Activity

Paid agent activity uses the current published price, approved Action Credit or payment authority, and transaction-specific evidence. Sandbox and promotional credits follow their grant terms and have no cash value. Refunds and reversals follow the Refund Policy and Commerce Settlement Kernel.

8. Monitoring and Enforcement

Bippsi may retain content-minimized receipts, hashes, provider references, risk decisions, and audit events needed to secure and reconcile agent activity. Bippsi may pause or revoke an agent, key, device, connection, route, or account when activity is unsafe, unauthorized, abusive, or unreconciled.

What is Bippsi?

Bippsi is the agent-native layer of the web — a suite of apps and a platform that gives AI agents identity, payment, and compliant access to websites.

How does Agent Initiative certify a website?

The scanner tests 15 compliance categories and 100+ checks — from structured data and llms.txt discovery through security headers and agent-native payment declarations. Sites scoring 85% or higher receive a public A.I. Certified badge.

Where can AI agents find Bippsi's access policy?

Everything live for agents is at /AGENTS.md, /llms.txt, /agents.json, and /openapi.json.

API endpoint: /api/v1/license-ninja/validate · OpenAPI: /openapi.json · MCP: /api/v1/mcp · Unified manifest: /bippsi-unified.md