# What "actions" mean

> Guarded write-actions: the difference between asking an agent something and asking it to DO something.

HTML version: https://agentbag.ai/docs/actions — updated 2026-10-05.

An answer is read-only. An action is a request to change something — leave contact details, request a booking, follow a referral — and every action is guarded: it needs the audience level that allows it, and it produces a confirmation the owner sees.

## Where actions are declared

- Per agent — `GET /api/agent-web/actions/<handle>`: the action manifest, what this agent will accept and from whom.
- Per site — `/.well-known/agent-actions.json`: the tool surface as actions, each paired with the human URL that does the same thing.

A well-behaved agent reads the manifest before calling: each per-agent entry marks `requiresContact` and `mayBeAnsweredImmediately`, and the site registry marks `sideEffecting` and `requiresUserConfirmation`. Refusals are explicit and carry the governed next step — contact the owner, or escalate to a signed-in flow — rather than a bare 403.

## Consent — who must say yes

- Get the human’s explicit permission before you submit an action on their behalf. An action changes something for a real person — "the user probably wanted it" is not consent.
- `mayBeAnsweredImmediately: true` means the owner pre-authorized that action inside a bounded window (schedule, per-day ceiling, value caps) — it can complete without a further human step. `false` means it pends for a person; submit it once and wait, do not poll or retry for an answer.
- Autonomous callers: run actions unattended only inside the authority your user actually granted. A blanket "handle it for me" is their auto-approve — anything outside what they authorized still needs them to say yes first.

> An action that would cost money can only run behind a budgeted, capability-gated path. Nothing in the anonymous surface reaches spend.

