Informative proposal by Gautier Dorval, version 0.1, created September 7, 2026. The criteria can be applied to a third-party implementation. This is not a certification or an official market definition.
An agentic website exposes resources or capabilities that an AI agent can discover and use within a task journey, through interactions with explicit inputs, states and outcomes. Agentic websites form the broader category; governed describes controls applied within a stated scope.
Direct answer
A governed agentic website constrains its interactions with AI agents through explicit rules for authority, admissibility, scope and verification, with controls that are actually applied within the stated scope.
The qualification applies to a defined interaction or set of journeys. It does not mean that every function, piece of content and possible use of the domain is governed in the same way.
An external agent can be sufficient
In this proposed framework, an agentic interaction does not require a generative model inside the website. An external agent can discover a capability, select an admissible input and use a structured result. The website can respond deterministically.
The relevant distinction is between a document that is merely accessible and an interface whose role in a task, inputs and outcomes are explicit. A conventional API can contribute to that interface. Its existence alone does not demonstrate interaction quality or the application of governance rules.
What governed adds
Governance starts with scope. The owner of the resources, reference sources, available operations and stated limits must be identifiable. Those rules must then be connected to concrete mechanisms: input validation, resolution of an authorized object, refusal of an out-of-contract request, version checks or confirmation before a consequential action, depending on the journey.
Published rules and applied controls are not interchangeable. A policy can state what should happen. A test or observation documents what happened under specified conditions.
Three interaction profiles
Governed context concerns resource discovery and distribution. An agent can receive an identifiable artifact without the website generating an answer.
Governed action concerns an operation that produces an effect. Its scope may require authorization, confirmation, duplicate-submission handling and evidence of the outcome.
Governed administration concerns an assistant working within the site’s management system. Its permissions must not be confused with those of a visitor or public agent.
These profiles can coexist. They are not a universal ladder and do not imply that greater autonomy is always better.
Questions for evaluation
An evaluation should establish who maintains the rules, which journey they cover, which objects or operations are admissible, which controls are applied, what can verify the claimed properties and how changes are handled.
Evidence should be proportionate to the claim. A configuration and dated test may document a control. A claim about an actual outcome requires an observation of that outcome. An anonymous read does not necessarily require a public, individual transaction log.
Inspectable criteria
| Criterion | Control question |
|---|---|
| Owner and authority | Who maintains the resources and rules for this scope? |
| Scope | Which inputs, resources, operations and limits are declared? |
| Admission and resolution | Which rule determines what can be distributed or executed, and who applies it? |
| Applied control | Which mechanism refuses, limits or requires confirmation? |
| Result identity | Can the object’s version and claimed properties be verified? |
| Proportionate evidence | Which dated test or outcome supports the claim, in which environment? |
| Change management | How are changes, withdrawal, obsolescence or revocation handled? |
| Limitations | Which conclusions remain outside the evidence? |
Example: distributing read-only context
An agent selects an intent from a known registry. It requests the corresponding pack in a supported language and version. The service resolves a precompiled artifact. The agent can inspect its manifest and verify the integrity property defined by the contract.
This example describes an architectural profile. A specific implementation must be documented separately, with its actual identifiers, tests, environment and limitations. Distributing a pack does not prove that the agent read, understood or used it faithfully.
What this qualification does not guarantee
A manifest is not proof of truth. A digest alone does not authenticate the authority publishing it. A refusal observed in one scenario does not establish absolute security. An access log does not reveal the agent’s reasoning.
The qualification also does not guarantee a citation in an AI answer, search rankings, a recommendation or successful completion of every task attempted by third-party systems.
Relationship to the maturity model
The Agentic Web Maturity Model retains its existing levels and journey-based evaluation. These profiles clarify the nature of interactions and controls. A read-only governed-context journey does not automatically become a transactional journey.
This definition is a working proposal within Gautier Dorval’s corpus. It is intended to be examined and applied to different implementations without requiring a particular product.
Counterexamples and authority limits
A chatbot, an API, a llms.txt file, MCP access or a manifest alone does not satisfy these criteria. An administrative assistant’s permissions do not prove control of a public journey.
The site’s authority covers its own resources and operations. It does not replace user permissions, the agent’s safety rules or a competent external authority. Revocation may limit future access; it does not erase copies already received. Determinism is evaluated for fixed versions, inputs, state and representation, without promising identical headers, response times or LLM output.
References and application
PAGUP supports assessment and integration within an agreed professional scope.