Agents doing UI actuation would generally allow only 1 to interact with a site. There's a take over option for the user to take control or the Agent might delegate to the user when something explicitly requires user interaction. We need to think about how this works with WebMCP. Especially since by design WebMCP allows the site to decide when it can execute the tool itself (searchProducts) vs seek user input (makePayment).