Personal Agent Consent & Trust Protocol

PACT gives agents scoped consent. AffixIO proves the action should run.

PACT lets a personal agent contact a brand's support agent with verifiable identity and only the permissions the user granted. AffixIO fits around that consent flow by proving whether the next action should be allowed, denied or reviewed before the business changes an account, cancels an order, issues a refund or calls a protected tool.

Direct answer: AffixIO does not claim to own PACT or be a Decagon or Instinct partner. This page explains how AffixIO can add proof-before-action, signed decision evidence and audit context around PACT-style identity, consent and delegation flows.

Compare with PAP

What PACT solves

PACT separates which agent is calling from what the user allowed it to do.

Decagon's announcement says PACT is built on Agent2Agent and OAuth 2.0. The open docs describe a personal agent registering with a provider, discovering a brand Agent Card, signing requests with a short-lived JWT, asking the user to consent through the brand's login page, then carrying a short-lived delegation token for later actions.

1

Verifiable agent identity

The provider checks the personal agent's signed JWT against published public keys before treating the request as agent-authenticated.

2

User-granted scopes

The user signs in with the brand, approves specific scopes such as orders:read or orders:cancel, and never gives the agent the password.

3

Delegated action context

Later requests carry agent identity and delegation. The provider verifies both before the brand's support agent acts.

Architecture

Where AffixIO sits in a PACT flow.

PACT can say who is calling and which scopes were granted. AffixIO sits at the final action boundary, where a business must decide whether this exact request should run under current policy.

1

Agent Card

The brand or provider advertises endpoint, auth requirements and available scopes.

2

Signed request

The personal agent sends a JWT, plus conversation context where relevant.

3

User consent

The user signs in with the brand and approves the requested scope.

4

AffixIO check

The controlled action is checked against policy, scope, account state and risk.

5

Receipt

The business keeps signed decision evidence alongside PACT receipt context.

Working model

Choose a PACT scope and see the AffixIO enforcement question.

This model turns PACT identity and consent into an action-level decision. It does not move money, expose customer credentials or claim a live PACT integration.

Use cases

Where PACT plus AffixIO becomes useful.

The strongest fit is customer service, account support and post-purchase operations where a personal agent needs to act for a user but the brand still needs enforcement, evidence and recourse.

A

Order visibility

Allow read-only order status checks while recording which personal agent asked and which account context was used.

B

Cancellation and returns

Check whether the cancellation window, order state, user scope and business policy all support the action.

C

Refund creation

Route higher-risk refunds to review when value, fraud indicators or account rules require human control.

D

Account changes

Prevent broad write scopes becoming blanket permission for sensitive customer profile changes.

E

Signed receipts

Bind PACT receipt context to an AffixIO decision proof so support and disputes share the same action record.

F

Multi-agent support

Support Muse, Instinct, dots and other personal agents without treating every agent message as anonymous chat.

Clear boundaries

PACT, A2A, OAuth and AffixIO do different jobs.

LayerQuestion it answersAffixIO role
A2AHow do agents communicate and keep conversation state?Use conversation context as one input to the action decision.
PACTWhich personal agent is calling and what customer consent was granted?Verify the requested action is within scope and policy at execution time.
OAuthHow does the customer log in and grant scopes without sharing credentials?Use approved scopes as inputs, not as automatic permission for every action.
AffixIOShould this exact action run now?Return yes, no or review evidence with audit context.

FAQ

PACT FAQ for AffixIO buyers and builders.

Is AffixIO claiming a PACT partnership?

No. This page references public Decagon and Open PACT Protocol materials. It does not claim a Decagon, Instinct, A2A or PACT working group partnership.

Is this the same as PAP?

No. PAP and PACT are related market movements around personal agents, but PACT focuses on consent and trust for personal agents contacting brand support agents through A2A and OAuth.

Does AffixIO replace PACT?

No. AffixIO can complement PACT by proving whether an action under a granted scope should execute under business policy.

Can AffixIO use PACT receipts?

Yes, conceptually. A PACT receipt can become evidence context for an AffixIO decision record. The business should still enforce policy before the controlled action runs.

Does a scope mean the agent can do anything inside it?

No. A scope narrows permission, but the business still needs action-level checks, risk routing and audit evidence.

Which PACT does this page cover?

This page covers Personal Agent Consent & Trust Protocol from Decagon and Open PACT Protocol, not unrelated projects using the PACT acronym.

Sources

Public PACT references used for this page.

Decagon announced Personal Agent Consent & Trust Protocol on 6 October 2026 and described it as open sourced, co-developed and supported by Instinct, built on Agent2Agent and OAuth 2.0. The Open PACT Protocol docs explain signed personal-agent requests, brand Agent Cards, OAuth user consent, delegation tokens and action receipts.

Decagon announcement ยท Open PACT docs