The useful difference between ecommerce agents is where their autonomy stops. PayPal's demo stops at payment, a Shopify store agent left spending and design to a person, and an ad tool waits for approval in Slack. Before giving any agent access, ask what it can see, what it can change and what needs approval.

  • The demo: In a video shared on September 9, an agent compared products, picked sizes, filled the cart and opened checkout, then stopped at the payment step while PayPal pushed an approval request to the shopper's phone, according to @paypaldev. This is PayPal presenting its own product.
  • Other tools stop at other points: An agent called Helena ran a Shopify dropshipping store for about eight weeks, doing product research, storefront builds and browser checks of live pages, while a person kept spend approvals and design decisions (@thekuchh, @chesny); the posts report $10k+ in revenue, not profit. Creatify's Max prepares ad changes for a team to approve in Slack, per @Nozelcode.
  • Agents marketed as fully autonomous: @EXM7777 promotes an ad agent that builds creatives, pushes them into a Meta ad account and runs "24/7, no human input required." The post is a marketing claim and shows no results.
  • A checklist before giving access: Ask three things of any agent, whether it touches Shopify, Meta or Google Ads, payments or publishing: what can it see, what can it change, and what requires approval? In a sponsored Search Engine Land article on September 15, Optmyzr describes similar layers for ad accounts: better grounding, a policy layer that keeps changes inside set limits, and a review step before anything goes live (source).

Is agent autonomy all or nothing?

No. In the examples above, the stop point sits at payment, at spending, at design decisions or at ad changes, and one tool claims none. Optmyzr's article describes permissions that separate what a connector may do on its own, what it can never do and what it can do with human approval.

Is a fully autonomous ad agent safe to run?

None of the posts above shows results for an agent without an approval step, so there is no public basis to judge it. Automation can also miss business context: on Search Engine Land, Mike Ryan described Google's AI Max expanding a client into a large competitor's searches that the advertiser had deliberately avoided (source).

Where should the limits live?

Optmyzr argues that a rule set on the account holds whichever way a change arrives, which makes it sturdier than instructions written into a prompt. @biektive adds that if an agent can move its own brief into an approved folder, it can approve itself, so approval should sit outside the agent's write permissions (source).

Sources