Klaviyo has gone headless, exposing 260-plus tools and 490-plus APIs so external AI agents can read and write a brand's CRM without anyone logging in. For Australian operators whose email is their best channel, agent access is a security decision first.
The Take: Klaviyo has made its entire platform callable by AI agents, so the software you use to reach customers can now be driven by a machine that never opens the app. This is not a feature update. It is a change in what gets to touch your customer data.
What changed: At its K:BOS conference on 9 September, Klaviyo went headless, exposing more than 260 tools and over 490 APIs so an outside agent running on Claude, ChatGPT or another system can read and write a brand's account with no human logged in.
The detail: As B&T reported, an agent can now pull live data, build a dashboard, run a weekly performance review and drop the summary into Slack on its own. Klaviyo is also putting SQL inside the platform, so a marketer can ask a question in plain English and get back both the answer and the query that produced it.
The number of Klaviyo APIs now open to external AI agents, which can run your email and SMS program without opening the interface
The signal: Owned channels are where Australian operators hold their richest first-party data, and email still does the heaviest lifting on it. Giving an agent write access to that data is not the same as letting it draft a subject line. Something that can send, segment and suppress can also break a flow, damage a sender reputation or leak a list. It will move faster than a person can catch it. The upside is real too. A weekly review that used to cost an analyst an afternoon now runs on its own.
For Australian operators: Decide what an agent may write, not just what it may read, before you connect one. Give it a scoped key rather than a master login. Log every action it takes and review that log weekly, the way you would with a new hire holding the keys to your database. If email is your best channel, and for most Australian DTC brands it is, treat agent access as a security decision first and a productivity gain second. The brands that come out ahead will treat this as granting database access, because that is exactly what it is.