AI agents are doing things on your site. Decide which ones.
Block training. Cap purchases. Require human-in-the-loop. Set rules robots.txt can't express, in 2 minutes.
Build my policyFree · No account · 1M+ domains crawled
Working with agent builders directly so your rules get followed, not ignored.
By the time you write the rules,
the precedent is already set.
Six things AI agents do on your site today that you have no control over. Every one of them costs you something: bandwidth, brand, conversions, or trust.
They drain your bandwidth.
GPTBot, ClaudeBot and CCBot pull tens of thousands of pages per single referral. Most sites pay the bill blind.
They flood your funnel.
An agent acting on a user's behalf can sign up, accept your terms, and burn through trials. Your activation metrics are lying to you.
They spend money on your behalf.
OpenAI Operator and Comet completed transactions this quarter. There's no way today to set a ceiling, require confirmation, or flag the order.
They post in your name.
Comments, reviews, support tickets, UGC. AI-generated content lands in your moderation queue indistinguishable from real users.
They take your traffic.
Answers built on your content rarely link back. Your traffic, and your brand, disappears into the model's response.
You can't tell who is who.
User-agent strings are trivially spoofed. You can't separate a real Anthropic agent from someone pretending to be one.
domains we crawled to map the AI policy landscape
of those sites have no AI policy at all
of the existing standards control transactions
robots.txt is a switch.
Agents need a dial.
You don't want to block every agent. You want to set rules for what they can do, when they can do it, and how much it can cost you.
- ×Allow or deny. That's it.
- ×No notion of what the agent is doing.
- ×No rate limits. No transaction caps.
- ×No human-in-the-loop trigger.
- ×Trusts the user-agent string.
- ✓Block, allow, or require human confirmation.
- ✓Per action: scrape, train, transact, post, sign up.
- ✓Rate limits. Transaction-value ceilings.
- ✓Pause threshold: above $X, ask a human.
- ✓Cryptographic identity (Web Bot Auth), not strings.
Five things you'll lock down.
Content access
Rate limit. Training opt-out. Attribution.
User actions
Account creation. Forms. Uploads. Posting.
Transactions
Caps. Human-in-the-loop. Agent-flagged orders.
Per-agent rules
Override defaults for OpenAI, Anthropic, Google.
Attribution
Citations. Identity. Request logging.
2 minutes. No account.
A policy. Stored. Yours.
You'll get a real, structured document, not a marketing email. The moment you save, your rules go into the Maango registry. As agent builders start consuming it, your policy goes from saved to enforced.
No account. No subscription. Reply to any email and we'll delete it.
Build my policyThe rules don't exist yet.
You write them, or someone else will.
Two minutes. Then your site has rules built for what agents actually do.
Build my policyFree · No account · Your policy is stored the moment you save it
We don't claim agents respect your policy today. We're building the registry. You're stored. You're early. We'll email you when integrations go live.