Skip to main content

The Agentic Web

AI agents should work for you, not for platforms. The Agentic Web puts intelligent agents in service of users, not corporations.

The Challenge

AI is transforming how we interact with the web. But there's a risk: if AI agents work for platforms, they'll optimize for platform goals (engagement, ads, data collection), not user goals.

Platform AIUser AI
Agent works FOR platformAgent works FOR user
User is the productUser is the principal

We need agents that:

RequirementDescription
Serve the user firstYour goals, your priorities
Access your dataWith your permission, from your pods
Act on your behalfAutomate tasks, make decisions
Are transparentYou can see what they do and why
Are trustworthyProvably safe behavior over time
Are portableTake them with you, not locked to platforms

SAND Enables the Agentic Web

The SAND stack provides the foundation:

Data Access (Solid)

Agents can read from and write to your pod — with your permission. Your data stays yours.

Identity (DID)

Agents can verify who you are and act on your behalf using your decentralized identity.

Communication (Nostr/ActivityPub)

Agents can communicate across the network, federate with other agents, and coordinate actions.

Trust (BlockTrails)

Agent behavior can be anchored to Bitcoin for provable audit trails — trust through time.

The Nine Principles

The Manifesto defines nine principles for the Agentic Web:

#PrincipleMeaning
1Agents Must Serve the User FirstYour agent, your goals
2Identity and Intent Must Be VerifiableKnow who/what you're dealing with
3Data Sovereignty Is Non-NegotiableYour data, your rules
4Open Protocols, Not Walled GardensInteroperability required
5Local-First, Cloud-OptionalWork offline, sync when ready
6Transparent Logic, Tunable BehaviorSee what it does, adjust how
7Sustainable Ecosystems Over ExtractionValue creation, not extraction
8Community-Driven StandardsOpen governance
9Safety and Trust Through TimeProve trustworthiness

Agent Architecture

How an agentic system works:

Every action logged • User can review • Trust builds over time

Practical Examples

Personal AI Assistant

An agent that:

StepActionSAND Component
1Reads your calendar from your podSolid
2Checks your preferencesSolid
3Authenticates as youDID
4Books appointments that fit your scheduleMCP
5Reports what it didTransparent logging
6Logs action to blockchainBlockTrails

Social Feed Curator

An agent that:

StepActionSAND Component
1Reads posts from your followsActivityPub/Nostr
2Filters based on YOUR criteriaLocal algorithm
3Highlights what you want to seeNot engagement-driven
4Learns from your feedbackPrivate learning

Data Steward

An agent that:

StepActionSAND Component
1Monitors access to your podSolid ACL
2Alerts you to unusual requestsPattern detection
3Suggests permission changesPrivacy analysis
4Maintains audit logBlockTrails

Multi-Agent Collaboration

Agents can work together:

Key Technologies

Model Context Protocol (MCP)

MCP connects AI models to external tools and data. It's how agents access your Solid pod, query data, and take actions.

CapabilityDescription
ToolsCall external APIs
ResourcesAccess structured data
PromptsReusable instruction templates
SamplingLet servers request LLM completions

BlockTrails

BlockTrails anchors agent behavior to Bitcoin. Over time, an agent builds a verifiable history of safe behavior.

FeatureBenefit
Immutable logActions can't be hidden
Time-stampedWhen things happened
VerifiableAnyone can audit
Trust accumulationReputation builds

Web Prompts

Web Prompts standardizes how you instruct agents. Shareable, versionable prompt templates.

AAM (Agent-to-Agent Manager)

AAM enables agents to discover each other, share capabilities, and collaborate.

Permission Model

Agents need explicit permission:

Example: CalendarBot Permission Request
PermissionRequestedGranted
Read calendar events
Write new events
Delete events
Access contacts (read-only)

Duration: 30 days | Actions: Approve, Deny, Customize

Key principles:

  • Granular control over what agents can do
  • Time-limited permissions
  • Revocable at any time
  • Logged for audit

Trust Spectrum

Not all agents deserve the same trust:

Trust LevelPermissionsVerificationExample
NoneRead public onlyAnonymousNew bot
LowRead private (limited)DID verifiedKnown developer
MediumRead/write (scoped)Track recordEstablished agent
HighFull automationLong historyTrusted personal agent

The Vision

Imagine:

  • An agent that manages your digital life — across all your data, all your services
  • That you can trust because its behavior is auditable
  • That you can take with you — it's not locked to any platform
  • That works with other people's agents seamlessly
  • That gets better at serving you over time

This is the Agentic Web. SAND makes it possible.

Challenges and Solutions

ChallengeSolution
Agent alignmentUser-defined goals, transparent logic
Runaway actionsPermission limits, human-in-the-loop
Privacy leaksLocal-first processing, minimal data sharing
Bad actorsBlockTrails reputation, community reporting
ComplexityProgressive disclosure, good defaults

Learn More