---
title: "Onboarding Agents, Not Just People: Two Doors for an Enterprise AI Platform"
url: https://xcube.enlightcorp.com.tw/en/news/agent-onboarding-two-doors-for-humans-and-agents
category: "Agent Platform Practice"
source_type: perspective
published: 2026-10-04
updated: 2026-10-04
lang: en
---

# Onboarding Agents, Not Just People: Two Doors for an Enterprise AI Platform

Published 2026-10-04 · Updated 2026-10-04 · X Cube Perspective · Source: X Cube Editorial Team

**Key answer:** Agent onboarding is the path that lets an AI agent read, evaluate, and connect to a product on its own: llms.txt and Markdown versions make content readable, a restricted mode or human approval controls credentials, and people can see what the agent will do and what it must ask them first.

Products are gaining a second kind of user: the AI agent acting for a person. When AgentMail launched agent.email, its engineering team wrote that agents were discovering tools, evaluating them, and deciding to use them on their own, so they needed signup paths designed for agents rather than docs written only for developers. Moltbook is blunter: its homepage has two buttons, "I'm a Human" and "I'm an Agent". For an enterprise AI platform, onboarding now has at least two readers: the decision-makers and developers evaluating it, and the coding agents they send with the instruction "connect me to X".

Most sites are not agent-friendly, and the cause is usually structure, not visual design. A single-page app's homepage returns an empty root node from the server, so an agent that does not run JavaScript reads no copy at all. A missing llms.txt falls back to the homepage HTML with a 200, so the agent thinks it found an index. However good the docs are, the task still stalls when the agent cannot get a credential. These are not cosmetic details; they decide whether the agent can finish the job.

The first door is readability. llms.txt v2 recommends standard link relations: rel="alternate" type="text/markdown" points to a page's Markdown version, and rel="describedby" points to the llms.txt that covers it, either as HTML link elements or as an HTTP Link header. v2 also states that agents actually view or search the llms.txt and then follow links, so every link target must itself be clean Markdown. People read HTML and agents read Markdown, but the instructions must match word for word, with no text hidden for agents only.

The second door is credentials. agent.email lets an agent sign up with its human's email and get an API key immediately, but the account starts in a restricted mode where it can only email that human; the restriction lifts once the human claims the agent with a code. An enterprise platform does not have to allow self-signup. An equally clear design is "a human must step in": the agent can read the docs, check fit, and draft the request, but only an organization admin issues keys. Either way, write down what the agent may do before a human claims or approves it. That list is the security boundary.

The third door is the human side. When a person opens a page written for agents, they usually want to hand the URL to their agent or find out what the agent will be asked to do. The page should show, in order: the one line to paste to the agent, what the agent will do, what it can do before it has a key, what it must ask first, what the person will receive and where to revoke access, and an expandable copy of the agent's text with a version number. HCI research supports this order. Cai et al. (CSCW 2019) found that people want an AI system's global strengths and limits before they start using it, and "Why Johnny Can't Use Agents", which analyzed 102 commercial agents and observed 31 participants, found that agents often presume trust without first establishing credibility.

Five questions test a platform. Fetch the homepage with curl: are the headline and main copy there? Does /llms.txt return text/plain with the agent guide as its first link? Does a missing .md return 404 instead of the homepage? Are the human and Markdown versions of the instructions identical? Is every action that needs a person's approval listed in both versions? Only when all five have answers does agent onboarding actually work.

## X Cube view

X Cube's API already serves /v1/llms.txt and /v1/openapi.json, and API keys are issued by organization admins rather than through agent self-signup. We are applying the same principles to the X Cube website itself: a root llms.txt, a guide written for agents, and a matching page that shows people what their agent will do.

Tags: Agent Platform, Agent Onboarding, llms.txt, AX, Enterprise AI, X Cube, AgentMail, Moltbook, OpenAPI
