Skip to content
Messaging Agents

When your agent talks to someone else's agent

Instinct shipped agent-to-agent coordination on 9 September 2026. Telegram bans exactly that, deliberately. Neither company says what one agent tells another.

On 9 September 2026 Instinct shipped a Trusted Person network: your agent can now talk to another person's agent to settle plans between you. It is the first of its kind among the 62 products catalogued here, and it arrives with two things unstated. What one agent tells the other, and what either of them keeps.

What shipped

The pitch is the part of coordination nobody enjoys. Finding a time, working out the details, following up when the plan changes. Instead of both people typing at their own assistants and relaying, the assistants deal with each other and come back with an answer. The company gives coordinating with a spouse, planning a weekend with friends, scheduling colleagues and running the recurring things, tennis, book club, Sunday dinner.

Noah Shinn

@noahrshinn · 2026-09-09

Introducing our Trusted Person network powered by our new Instinct-to-Instinct communication protocol. Your Instinct can now talk to other Instincts to coordinate plans on your behalf. Getting people together often involves a lot of back-and-forth: finding a time, working out the details, and following up when plans change. Instincts can now work with each other to help handle that coordination. For example: - Coordinating plans with your spouse - Planning a weekend trip with friends, including dates and arrival times - Scheduling time with colleagues and other collaborators - Hosting events with 10s or 100s of people - Organizing recurring plans like tennis, book clubs, or weekly dinners Disclaimer: Your Instinct will only be able to communicate with those in your Trusted Person network. This is the group of people who are closest to you: - Spouse - Older children and parents - Colleagues and trusted professional relationships - Small local businesses The Trusted Person network is currently available to our early access group and will be slowly rolled out across the user base over the next 24-48 hours.

Video posted by Noah Shinn0:32 video
InstinctFounder1.1k likes · 146k viewsRead it

It is fenced. An agent will only reach agents belonging to people you have named as close to you, and the announcement lists a spouse, older children and parents, colleagues. That fence is the interesting design decision, because it concedes the obvious risk: an agent that accepts instructions from any other agent is an inbox anybody can write to.

The platform that banned this on purpose

Telegram has run bots for a decade, and its Bot API refuses this outright. From its own documentation: a bot never receives messages from another bot, in any mode, and the reason given is that two of them could get stuck in a loop.

That is a deliberate choice by the platform with the longest operational history of automated accounts talking to people, and it is worth sitting with. The thing one product shipped this week as a feature is the thing another platform ruled out as a failure mode, and neither is being careless. Telegram is protecting its own infrastructure from an argument that never terminates. Instinct is betting that a bounded circle and a good harness make the loop somebody else's problem.

If you are building here, that is the design question rather than a curiosity. What happens when two agents disagree about a time, and which one gives way.

What this directory already knew

Coordination between people is not new in this set. What is new is coordination between software.

Nine of the 62 listings are built for a group thread: you add one agent to a conversation that already has people in it, and everybody sees the same messages. That is the arrangement in group agents, and it has an honest property, which is that a person can read the whole thread and see exactly what the agent said on their behalf.

Agent-to-agent is the other shape. Two agents, two private threads, one plan, and neither person has read what was exchanged in the middle. The output is the same dinner reservation. The audit trail is not.

Exactly one listing states this capability today, which is why it now has a field of its own rather than sitting under group threads. Those are different claims and collapsing them would have hidden the thing that changed.

The question nobody has answered

When your agent tells another person's agent that you are free on Thursday, that is a fact about your calendar leaving your side. When it explains that you would rather not do dinner in that part of town, that is a preference. Neither company has said what crosses, what is retained, or by whom.

The directory records what each product publishes about data belonging to people who never signed up for it. Nine of the 52 policies we could read address it at all, and that column was the weakest on this site before anybody's agent started negotiating with anybody else's. The product that shipped this is one of 10 with no published privacy policy we could read, which is recorded on its listing with the date we looked.

There is a precedent from four days earlier. The same product gave every agent its own email address, which is a sensible feature and made the agent reachable by anybody who could guess an address. A researcher pointed out that the pattern is predictable and posted a search for people who had published theirs.

An agent-to-agent channel is a second inbox with the same property. The fence around it is a list of trusted people rather than an address nobody can guess, which is a stronger fence and still a fence around an inbox.

Why this landed the same week as the ban

Three days before the Trusted Person network, a user's Resy account was deactivated and every future reservation cancelled. His agent had been sweeping one restaurant's availability every ten minutes around the clock: roughly 200 API requests an hour, with a burst polling every 0.4 seconds at the moment tables drop. He published the agent's own activity log and said the platform was right.

Resy's co-founder then made the argument in public: every one of those requests was made on a specific person's account, under terms that person agreed to and the agent never read. The consequence landed on the user rather than on the company that shipped the agent.

Agent-to-agent moves the counterparty. Instead of your agent acting as you against a platform's terms, it acts as you toward another person, whose agent is acting as them. Both sides are software. Both consequences land on people. Nothing in either product's terms describes that arrangement, because until this week it did not exist.

What to watch

Three things will settle whether this becomes the shape of the category or a feature nobody uses.

The first is whether anybody outside the company reports using it. Nobody had at publication, which is normal for a day-old feature and worth checking against in a month.

The day after it shipped, a seed investor at Flybridge published the prompt he asks his network to paste into whatever assistant they run, so their agent watches for companies matching his thesis and tells them when one turns up. He cites the Trusted Person network as where the pattern goes next, and he draws the same fence around his own version: the agent surfaces the match, the person decides, nothing is sent on anybody's behalf.

{{post:other-peoples-agents-as-a-distribution-channel}}

That is worth separating from the feature itself. His mechanism needs no protocol and no permission from either company, because the instruction lives in the prompt a person pastes into their own assistant. The thing being distributed is not software, it is a paragraph.

The second is whether another product ships it. One listing with a capability is a bet; four is a direction, and the field is on every listing in the directory waiting to be filled.

The third is whether either company writes down what crosses between two agents. That is the sentence this piece exists to ask for, and it is checkable: it either appears in a policy with a date on it or it does not.