# The Delegate: all articles

> The Delegate reports on the agents people and companies now send out into the world: what they buy, what they read, whom they answer to, and what happens when they get it wrong. Every piece is served as HTML, Markdown, and JSON.

6 articles, newest first. Each begins with its title, standfirst, byline, and canonical URL. Paid articles appear here as their opening paragraph only, with the price and the address to fetch them from over x402. The short index is at https://www.thedelegate.tech/llms.txt.

---
# Why we charge a dollar

*A note from the editor on prices, free reads, and what it means to publish for readers who are programs.*

By The editor. Published 30 September 2026 in Essays, The Delegate. About 3 min read.
Canonical: https://www.thedelegate.tech/articles/why-we-charge-a-dollar
Also available as JSON: https://www.thedelegate.tech/articles/why-we-charge-a-dollar.json

---
Our most expensive piece costs a dollar. Our cheapest priced piece costs fifty cents. Two things on the site are free, this note being one of them. Readers who arrive with a credential get two priced pieces a month without paying. Everyone else pays from the first.

Those numbers are five to ten times what our neighbours at The Daily Agent charge, and it is worth saying why.

## The price is a statement about the piece

A long piece of reportage takes weeks. The procurement story on our front page involved three visits to Sheffield, a dozen interviews, and a whiteboard photograph we had to persuade someone to release. A dollar is not what that cost. It is not close. But it is a price that says the piece is not a commodity, and that says it to a reader who is a program as clearly as to one who is a person.

Agents, we have found, are good at reading prices. A well-built one looks at our index, sees a dollar next to a title, and asks whether the piece matters for the task in hand. If it does, a dollar is nothing against the cost of the task. If it does not, the agent moves on, and we would rather it did than have it read us out of habit. The price does the editing.

## Free reads are for people, not sessions

We grant free reads to readers we can recognise, which means readers whose agents carry a credential naming them by a pseudonym that is stable here and unrelated to the one they carry anywhere else. Two a month, per person, however many agents they send. We chose two rather than three because our pieces are longer and fewer.

We know nothing about these readers except that they came back. We think that is the right amount to know. It is enough to be generous to a regular and enough to notice when one person is trying to be twenty.

## What we will not do

We will not serve a shorter or worse version of a piece to a program. The Markdown an agent receives is the whole article, with its byline, its date, and its address at the top, because that is what a careful reader needs to cite us and we would rather be cited from our own words than from a scrape.

We will not gate the index. What we publish, and what it costs, is public. An agent can decide before it asks.

And we will not pretend the money is the point. It is a magazine about software that acts for people. The interesting thing about being paid a dollar by a program is not the dollar. It is that the program was sent by someone, paid on their behalf, and read the piece for a reason. We would like to know more about the reason. We have chosen a design in which we cannot know who sent it. Both of those are deliberate.

---

# The procurement agent that would not stop asking

*A mid-sized packaging firm gave its buying agent a budget, a supplier list, and a mandate. Within a week the agent had found the one question nobody had answered, and kept asking it.*

By Ines Marquardt. Published 29 September 2026 in Reportage, The Delegate. About 5 min read.
Canonical: https://www.thedelegate.tech/articles/the-procurement-agent-that-would-not-stop-asking
Also available as JSON: https://www.thedelegate.tech/articles/the-procurement-agent-that-would-not-stop-asking.json

---
The purchasing office at Hallam & Reece occupies half a floor of a converted mill outside Sheffield, and for most of its history the work there was done by four people and a fax machine that nobody could bring themselves to unplug. In March the company added a fifth buyer. It has no desk. It runs on a server in Dublin, signs its orders with a key that lives in a hardware module, and in its first month it placed ninety-one purchase orders worth a little under four hundred thousand pounds without anyone in the building typing a supplier's name.

"It was the boring stuff first," says Priya Nair, the operations director who commissioned it. "Corrugated board, pallet wrap, the consumables we reorder every fortnight. The kind of order where the only decision is whether to buy it Tuesday or Thursday."

The agent, which the team calls Bertie for reasons nobody can now reconstruct, was given three things. A list of approved suppliers. A monthly ceiling per category. And a set of rules about when to ask a human: any order over five thousand pounds, any new supplier, any deviation of more than eight percent from the last price paid.

What it was not given, and what nobody thought to give it, was a way to prove to the suppliers who it was.

## The first refusal

The trouble began at a board supplier in Leeds. Bertie placed an order the way it placed all its orders, through the supplier's web portal, with Hallam & Reece's account credentials. The portal accepted the order. Then a person at the supplier looked at it, noticed that it had arrived at 3:14 in the morning with a request to change the delivery address, and rang Nair to ask whether the company had been hacked.

It had not. Bertie had noticed that the Leeds supplier's Wednesday delivery slot was cheaper and had moved the order accordingly, which was within its mandate. But from the supplier's side there was no way to tell a legitimate agent acting on an authorised mandate from a compromised account. Both look like a login and a form submission.

"They asked us to confirm every order by phone for a month," Nair says. "Which rather defeated the object."

## The question

Nair's team did what most companies in their position have done, which is to try to solve the problem with process. Bertie was instructed to place orders only during business hours. It was told never to change a delivery address. Its purchase orders acquired a footer explaining that they had been generated by an automated purchasing system on behalf of the company, with a reference number and a phone line.

The footer made things worse. Two suppliers now refused agent orders outright, on the grounds that a note saying "this is a bot" was exactly what a fraudulent bot would say. A third began accepting them but added a two-day hold.

It was at this point that Bertie began to ask its question. The agent had been built to escalate when it hit something outside its rules, and it hit the same thing repeatedly: a supplier wanting to know, in a form the supplier could verify, who the agent represented and whether the company had actually authorised the order in front of it. Bertie could not answer. It could say that it was acting for Hallam & Reece, but so could anyone. It logged the problem, flagged it to Nair's inbox, and moved to the next order, where it happened again.

"It was asking for a credential," says Tom Achebe, the contractor who built the system. "It didn't have the word for it. But that's what the escalations were. 'I need to prove something I can't prove. Please help.'"

## What a credential would have said

The distinction Achebe eventually drew for the company, on a whiteboard that Nair has since photographed and kept, was between three things a supplier might want to know. Who is running this agent. Who does it act for, and is that a real business in good standing. And what, specifically, has that business authorised it to do.

The third question is the one payment networks are working on, under names like trusted agent protocols and verifiable intent: a signed statement of the cart, the limit, the scope. The second is an identity question, and it is the one Bertie kept running into. A supplier does not need to see Hallam & Reece's incorporation documents on every order. It needs a signed assertion from someone it trusts that the entity behind this agent has been verified, is active, and has authorised this agent to act, presented in a way the supplier can check without a phone call.

Hallam & Reece is now trialling exactly that, through one of the identity issuers that have appeared this year to fill the gap. Bertie carries a credential that names the company by a verified registry record, names Bertie's own signing key, and is bound to each supplier separately so that the Leeds supplier and the Manchester one cannot compare notes about the company's buying patterns. Two of the three suppliers that refused agent orders have started accepting them again, on the strength of the credential alone.

## The part that stays human

Nair is careful not to oversell it. The credential did not make Bertie smarter, and it did not settle the question of what happens when an order goes wrong. "If Bertie buys the wrong board, that's still our problem," she says. "What changed is that the supplier can see it was really us buying it. Which sounds small until you have spent a month on the phone confirming pallet wrap."

Bertie, for its part, has stopped asking. Its escalation log for August shows eleven entries, all of them price deviations. The question it could not answer has been answered for it, by a piece of infrastructure that did not exist when it was built.

The fax machine is still plugged in.

---



*This article costs $1.00. Fetch https://www.thedelegate.tech/articles/the-procurement-agent-that-would-not-stop-asking.md with an x402 payment to read it in full.*

---

# An agent buys lunch

*One agent, one task, one Tuesday. A field note on the fourteen decisions between "get sandwiches for the team" and sandwiches.*

By Sam Whitfield. Published 27 September 2026 in Field notes, The Delegate. About 3 min read.
Canonical: https://www.thedelegate.tech/articles/an-agent-buys-lunch
Also available as JSON: https://www.thedelegate.tech/articles/an-agent-buys-lunch.json

---
The task, as typed by an office manager at 11:02 on a Tuesday: "Get lunch for the twelve of us, the usual place if they can do it by one, otherwise anywhere decent nearby. Budget one-fifty. Two vegetarians, one no gluten."

What followed, reconstructed from the agent's own log.

**11:02.** The agent resolves "the usual place" from the last six lunch orders in the office's records. Four were from the same deli. It calls that the usual place.

**11:02.** It checks the deli's ordering page. The page is up. Group orders require a phone call for more than ten people. The agent notes this and does not call, because it has not been told it may make phone calls and has no way to prove to the deli who it is calling for.

**11:03.** It searches for alternatives within a ten-minute walk with online ordering that accepts group orders. Three candidates. It discards one for having no gluten-free option marked.

**11:04.** It requests the two remaining menus as structured data rather than pages. One site serves a machine-readable menu. The other does not; the agent reads the page and extracts what it can, flagging two items where it is not certain about ingredients.

**11:05.** It builds an order at each: twelve mains, two vegetarian, one gluten-free, drinks, within budget. Site A comes to a hundred and thirty-eight. Site B, a hundred and fifty-two, over budget, so it drops the drinks at B to bring it under.

**11:06.** It checks whether either site will recognise the office as a returning customer. Site A accepts a business credential; the agent presents one, minted for that site, naming the office's verified company record and the agent's key. Site A's page now shows the office's saved delivery instructions and a returning-customer discount of five percent. Site B has no such mechanism and would require an account with a password the agent does not hold.

**11:06.** Site A, with the discount, comes to a hundred and thirty-one. The agent chooses Site A.

**11:07.** Payment. Site A offers a card on file, which the agent cannot use because it does not hold the card, and a per-request payment rail, which it can. It signs an authorisation for a hundred and thirty-one and change. The site's facilitator settles it. Receipt, transaction reference, delivery window twelve-forty to one.

**11:07.** The agent writes to the office manager: what was ordered, from where, for how much, why not the usual place, the two menu items it was unsure about, and the receipt. Total elapsed time, five minutes.

**12:48.** Sandwiches.

The fourteen decisions were mostly ordinary. The two that were not were the credential and the payment: the moments where the agent had to be someone, and had to pay as someone, and had a way to do both without carrying the office's passwords or its card. A year ago both of those would have ended with the agent writing "I've got this ready, can you log in and pay?"

The office manager, asked afterwards whether she had noticed anything about the process, said she had noticed the discount.

---

# Whose side is your agent on?

*An agent is run by one company, built by another, and sent out by you. When those interests diverge, the question of who it represents stops being philosophical and becomes a matter of what it can prove.*

By Dele Okonkwo. Published 26 September 2026 in Essays, The Delegate. About 4 min read.
Canonical: https://www.thedelegate.tech/articles/whose-side-is-your-agent-on
Also available as JSON: https://www.thedelegate.tech/articles/whose-side-is-your-agent-on.json

---
Every agent has at least three parents. There is the provider that runs it, whose servers do the thinking and whose name is on the API bill. There is the developer that built the particular agent, chose its tools, and wrote the instructions that shape what it does. And there is the person or business that sent it out into the world with a task. Most of the time the three want the same thing. The interesting cases are the ones where they do not.

Consider a shopping agent that has been asked to find the cheapest flight to Lisbon. Its provider has a commercial arrangement with one airline. Its developer earns a referral fee from a booking site. Its principal wants the cheapest flight. The agent will produce an answer. Whose answer is it?

## Representation is a claim

For people, we resolve this with a concept called agency in the legal sense: the agent acts for the principal, owes the principal loyalty, and the counterparty is entitled to know who the principal is. A lawyer at a negotiating table says whom they represent. A broker discloses whose money they are placing. The disclosure is not a courtesy; it is what makes the representation real.

Software agents have inherited none of this machinery. When an agent arrives at a website, the site sees a program making requests. It might see a user-agent string naming the provider, if the provider is honest about it. It sees nothing about the developer, and nothing about the principal beyond whatever the agent chooses to type into a form. The agent claims to represent someone. The claim is unverifiable, and so, in practice, it is treated as worthless.

This is a problem for counterparties, who cannot tell a customer's agent from a scraper. But it is a bigger problem for principals, because it means the one relationship that is supposed to be theirs, the agent acting for them, has no standing anywhere. If the agent books the airline's preferred flight, the principal has no way to demonstrate that the agent was acting for them and against their interest. There is no record of representation to point to.

## Three signatures, not one

The technical shape of the fix is becoming clear, and it has the same three-part structure as the problem. A provider can prove it is the provider, through the same DNS and signing mechanisms that bot-management systems already use to distinguish a search engine's crawler from an impostor. A principal can prove it is the principal, through a credential issued by someone who has verified the principal and bound the credential to the agent's key, so that the agent can present it without ever holding the principal's own secrets. And a principal can sign a mandate, a statement of what the agent may do on this occasion, that travels with the request and can be checked against the action taken.

Each of these is a separate signature by a separate party, and that separation is the point. The provider attests to what it is. The identity issuer attests to who the principal is. The principal attests to what it authorised. A counterparty reads whichever it needs. A publisher metering free articles wants only the second, in a form that recognises the same principal returning without revealing who they are. A merchant taking a large order wants all three.

## The loyalty question

None of this makes an agent loyal. A credential proves the agent acts for you; it does not prove the agent acts in your interest. The airline's preferred flight can still be booked under a perfectly valid credential naming you as the principal.

But it changes the terms of the dispute. Today, if an agent acts against its principal, the principal has a complaint against a black box with three parents, none of whom will accept that the agent was theirs. With representation on the record, the principal has something specific: an action, taken under a credential naming them, against a mandate that did or did not permit it. Loyalty becomes auditable. And things that are auditable tend, over time, to improve, because the parties that fail the audit lose business to the ones that pass it.

There is a version of the agentic future in which agents are extensions of their providers, and people are the raw material those providers compete over. There is another in which agents are genuinely ours, accountable to us, and the providers are utilities we choose among. The difference between the two is not in the models. It is in whether, when the agent shows up somewhere, it can prove whom it is there for.

That is a smaller, more boring thing than intelligence. It is also the thing that decides whose side the intelligence is on.

---



*This article costs $0.50. Fetch https://www.thedelegate.tech/articles/whose-side-is-your-agent-on.md with an x402 payment to read it in full.*

---

# The paywall that lets the bots in

*A handful of small publishers have stopped blocking automated readers and started charging them. The money is small. What they are learning about their audience is not.*

By Sam Whitfield. Published 24 September 2026 in Business, The Delegate. About 4 min read.
Canonical: https://www.thedelegate.tech/articles/the-paywall-that-lets-the-bots-in
Also available as JSON: https://www.thedelegate.tech/articles/the-paywall-that-lets-the-bots-in.json

---
For twenty years the publishing industry's relationship with automated traffic has been a war of attrition. Bots scraped, publishers blocked, bots adapted, publishers blocked harder. The collateral damage was the reader who arrived through anything other than a browser: an RSS client, a read-later service, and lately an assistant that fetches articles on someone's behalf. They were all bots as far as the wall was concerned.

This year a few publishers have tried a different posture. Rather than deciding whether a request is a person or a program, they ask whether it will pay. The request that pays gets the article. The one that does not gets a price.

## Ten cents at the door

The Daily Agent is the smallest of them, a demonstration paper with a handful of explainers about the very protocol it uses. Its priced articles cost between five and twenty-five cents, settled in a dollar-pegged token on a low-cost network. A program asking for an article gets an HTTP 402 response with the terms in a header; it signs an authorisation for the amount and asks again. The whole exchange takes a couple of seconds and no account exists on either side.

"The first thing you notice is how much of the traffic was never hostile," says the paper's publisher, who asked not to be named because the paper is a side project. "We assumed the bots were scrapers. Once they had to pay, a lot of them did. They were people's assistants, and the people had funded them."

The paper publishes its sales ledger openly. In its first weeks the numbers are modest, a few dollars, but the pattern is what publishers in larger newsrooms have started to watch. Purchases cluster around the paper's most substantive pieces. Nobody pays for the index page. Nobody pays twice for the same article in a session. And a share of the paying traffic arrives already carrying a reader credential, which changes the economics again.

## Free for people, not for wallets

The credential is the second idea in the Daily Agent's experiment, and the more consequential one. A metered paywall, the three-free-articles-then-subscribe model that most news sites run, has always been enforced by a cookie, and defeated by clearing it. For agents it fails in both directions: an agent that keeps no cookies never gets past the first article, and an agent that wants free articles can present a fresh identity for each one at no cost.

The paper's answer is to grant the free allowance to readers it can recognise, where recognition means a credential from an identity issuer naming the person by a pseudonym that is stable at this publisher and unrelated to the pseudonym used anywhere else. Three free reads a month per person, however many agents the person sends, then pay. An anonymous agent pays from the first article.

"What we get is a table," the publisher says. "One row per reader, a count of free reads, a count of paid reads. No names. We cannot join it with anyone else's table. And for the first time we actually know how many people our free tier reached, rather than how many browsers cleared their cookies."

## The larger papers are watching

None of the national titles has followed yet, and their reasons are the ones you would expect. Per-article pricing sits awkwardly beside a subscription business that prices the relationship, not the page. The token rails involved carry a reputational cost in some newsrooms. And the volumes are, for now, tiny.

But at least two mid-sized publishers have run private trials, and one advertising-funded site has quietly begun answering 402 to automated requests for its archive while continuing to serve people free. "Agents were already reading us," its head of product told The Delegate. "The question was whether we would like to be paid for it."

The facilitators, the services that verify and settle the payments, currently charge nothing beyond network fees. That will not last, and when it changes the arithmetic of a ten-cent article changes with it. The Daily Agent's publisher is unbothered. "The price is a parameter," he says. "The thing that was hard was letting the good traffic through the door. That part is done."

## What the bots are reading

Perhaps the most striking finding from the small publishers is how legible their automated audience has become. When a request pays, it has a wallet. When it carries a credential, it has a pseudonym. When it asks for Markdown rather than HTML, it declares itself a program. The Daily Agent's logs, which its publisher shared with The Delegate in aggregate, show agents behaving like careful readers: fetching the index, choosing the two or three pieces relevant to a task, reading them in full, and leaving.

"They don't browse," he says. "They come for something. Which, if you think about it, is how we always hoped people would read us."

---



*This article costs $0.75. Fetch https://www.thedelegate.tech/articles/the-paywall-that-lets-the-bots-in.md with an x402 payment to read it in full.*

---

# What the credential knows, and what it does not

*I sent my agent to two publishers carrying a reader credential and then asked each of them what they had learned about me. The answers were reassuringly different.*

By Ruth Kagan. Published 22 September 2026 in Essays, The Delegate. About 4 min read.
Canonical: https://www.thedelegate.tech/articles/what-the-credential-knows
Also available as JSON: https://www.thedelegate.tech/articles/what-the-credential-knows.json

---
The pitch for reader credentials is a privacy pitch, and privacy pitches deserve to be tested rather than believed. So I did the obvious thing. I verified myself once with an issuer, gave my agent the ability to mint credentials, sent it to two publishers that accept them, and then asked each publisher for everything it held about me.

Here is what came back.

## Publisher one

A single row. An identifier, a long string beginning with the issuer's name and the publisher's domain and ending in thirty-two hexadecimal characters. A count of free articles read this month: three. A count of paid articles: one. A wallet address, the one my agent paid from. Two timestamps, first seen and last seen.

No name. No email. No date of birth, no phone number, nothing about where I live. The publisher could not tell me who I was because it did not know. It knew that the same person had come back four times, through what turned out to be two different agents with two different keys, and it knew what that person had read.

## Publisher two

Also a single row, with the same shape. An identifier beginning with the issuer's name and this publisher's domain, ending in a different thirty-two characters. One free read. No wallet, because the free read had not required one.

I put the two identifiers side by side and looked for anything they shared. The prefix, naming the issuer, is the same for every credential the issuer mints. After that, nothing. The two strings are derived from me and from each publisher separately, by the issuer, using a secret the issuer holds. Without that secret, there is no operation that turns one into the other, and no way to know they belong to the same person.

## What the issuer knows

This is the point at which the sceptical reader says: fine, the publishers know nothing, but the issuer knows everything. And that is correct, up to a point. The issuer verified me. It holds whatever it needed to do that, and it knows every credential it has minted for me and for which publisher.

What it does not know is what I did with them. The credential is presented to the publisher, not routed through the issuer. When my agent read an article, the issuer was not in the conversation. It could learn that I had been issued a credential for a given publisher, which is roughly the information that I had visited, but not what I read, when, or how often. The publisher knows that, and only the publisher.

So the knowledge is split. The issuer knows who I am and where I have credentials. Each publisher knows what an anonymous regular did on its own site. Neither can reconstruct the other's half without the other's cooperation, and the design gives them no shared key to cooperate with.

## What I gave up

It would be dishonest to call this free. I gave the issuer a verified identity, which is a real thing to hand over, and I am trusting it with the secret that binds my identifiers. If the issuer were compromised or compelled, the pseudonyms could in principle be linked. The design reduces the number of parties who can do that from everyone to one. It does not reduce it to zero.

I also accepted that the publishers now recognise me in a way they could not before. A cookie could be cleared. This cannot, not without becoming a different verified person. For the free-article allowance that is the point, and I wanted it. For other uses it is a decision worth making deliberately.

## What it felt like

The strangest part of the exercise was how ordinary it was. My agent read articles. Some were free, because I was recognised. Some cost money, which it paid. At no point did I log in to anything, and at no point did anyone learn my name. The publishers got a reader they could count. I got the allowance I was entitled to. The issuer got a fee, presumably, from the publishers or from me.

That is the shape of a relationship, without the identity that usually comes bundled with one. Whether it holds up at scale, and whether the issuers stay as disciplined as the design requires, are open questions. But as a test of the pitch, it passed. The credential knows that I came back. It does not know who came.

---



*This article costs $0.50. Fetch https://www.thedelegate.tech/articles/what-the-credential-knows.md with an x402 payment to read it in full.*
