The Founding Rubric · v1.0 · April 2026 · Maintained at this URL
What qualifies as an ARM.
This is the canonical reference for the Agent Relationship Manager category. One page. Versioned. Every change logged below. Use it to evaluate a product. Use it to build one.
Agent Relationship Manager (ARM): the software layer that orchestrates a company’s relationships with AI agents and the relationships between those agents, governing their identity, permissions, behavior, and coordination with humans, the way CRM orchestrates relationships with customers.
The ten criteria
Ten criteria. One category.
Detect
The ARM identifies agent-originated activity the moment it arrives, not after the fact. Protocol-native traffic (MCP, A2A, UCP) is classified at ingestion by the protocol itself. Web-surface traffic is scored by passive behavioral signals, with active proof-of-human at the lead surface. Full credit requires detection matched to the surface: protocol classification for protocol traffic, behavioral plus active verification for web traffic.
Scoring note: detection before routing. Retrospective identification scores zero.
Deploy
The ARM meets the buyer's agent with the business's own agent. It does not route to a human first. Detection without deployment is just surveillance.
Scoring note: detect-then-handoff-to-human does not qualify.
Enforce
The ARM holds the business's pricing terms and boundaries through every transaction. No concessions outside the rules without human authorization. The business sets the terms. The ARM enforces them.
Scoring note: enforcement is parameter-based, not AI judgment. A published fixed-price posture is a valid enforcement mode; the test is that the machine cannot be moved off the business's terms.
Route
The ARM treats agent leads differently from human leads. Different questions, different triggers, different thresholds. Human leads go to the human team. Agent leads go to the ARM.
Scoring note: one workflow for all leads scores zero.
Report
The ARM reports agent activity as its own line, with the depth a CRM gives human leads. Volume, close rate, average gross, parameters triggered. You cannot manage what you cannot measure.
Scoring note: no independent breakout scores partial credit.
Adapt
The business configures its own agent's response logic and refines it on what worked. It cannot control the buyer's agent. It can prepare its own.
Scoring note: fixed logic that cannot learn scores partial credit.
Verify
The ARM checks agents against a trusted registry. A consumer advocacy agent, a scraper, and a malicious probe each get a different response. Not all agents are equal. The ARM knows the difference.
Scoring note: static bot detection without a registry scores partial credit.
Operate
The ARM runs a dedicated agentic lane alongside the business's existing stack, integrated with it, not forced through it. Agent transactions execute end to end at machine speed, drawing on the business's tools when needed. The CRM remains essential infrastructure for the human lane; the ARM is its counterpart for the agent lane. Discovery and delivery stay human, because that is where the emotion lives.
Scoring note: forcing every agent interaction through a human workflow scores low. The bar is autonomous execution in a dedicated lane that integrates with the existing stack.
Remember
The ARM keeps a persistent record of every agent, transaction, and outcome. When an agent returns, it knows. The CRM remembered every human. The ARM remembers every agent.
Scoring note: no persistent history scores zero. Memory is not optional.
Forecast
The ARM projects forward from its own data. Leadership should see not just last week but next quarter. Volume trend, close-rate trajectory, margin impact.
Scoring note: history without forward projection scores partial credit.
Version history
The record.
| Where we’ve been | Where we are | Where we’re going |
|---|---|---|
| v0.x · April 2026. Rubric drafted and published across two pages. | v1.0 · Single canonical page. Criterion 01 rewritten for protocol-native detection. Criterion 08 unified on the dedicated-lane model. | v1.1 · Candidate scoring for third-party products begins as submissions arrive. |
Changes to this page are logged here, dated, and never silent. A standard that edits itself quietly is not a standard.
Building toward this category? I will evaluate your product against this rubric and list it. Reach out before you name your product. I already named the category.