{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8fpe29kn3bm05h7kyqyka",
    "entity_slug": "digitalocean",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4x8r3etq6ck2b79hsw5",
      "entity_id": "ent_01kyh8fpe29kn3bm05h7kyqyka",
      "scope": {
        "product": {
          "key": "digitalocean-cloud",
          "name": "DigitalOcean Cloud"
        },
        "funnel": {
          "key": "api-resource-management",
          "name": "API resource management"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:ae848b42b55678a40e1d909ec75667458026e40dffc7076f7915db2281bfd38a"
      },
      "declaration_revision_digest": "sha256:ec84b3e7f119c2b117abff158cc1820dfd054cceafe2b1e9875474505a61e347",
      "declaration": {
        "declaration_id": "declaration_digitalocean_api_resource_management",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/di/digitalocean.yaml",
          "git_blob_oid": "95356d66f9bab01aa3b8bed56ccdd73b7a121a3f",
          "blob_digest": "sha256:75034ceaee567f1ad8fa8609d45fab7e73409f97a8e8578bff92efb33f6ca418"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Create and manage DigitalOcean Droplets through the API",
            "interface_ids": [
              "resource-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "digitalocean",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8fpe29kn3bm05h7kyqyka"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "account-access-guide",
            "uri": "https://docs.digitalocean.com/products/droplets/getting-started/recommended-droplet-setup/",
            "roles": [
              "access",
              "documentation"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "api-overview",
            "uri": "https://docs.digitalocean.com/reference/api/",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "api-reference",
            "uri": "https://docs.digitalocean.com/reference/api/reference/public-apis/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://docs.digitalocean.com/platform/billing/manage-payment-methods/",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "cloud-signup",
            "uri": "https://cloud.digitalocean.com/registrations/new",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "droplet-provisioning",
            "uri": "https://docs.digitalocean.com/products/droplets/how-to/create/",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "personal-access-tokens",
            "uri": "https://docs.digitalocean.com/reference/api/create-personal-access-token/",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "pricing",
            "uri": "https://www.digitalocean.com/pricing",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://www.digitalocean.com/legal/terms-of-service-agreement",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://docs.digitalocean.com/support/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "digitalocean-api",
            "uri": "https://api.digitalocean.com/v2",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "endpoint_id": "registration",
            "uri": "https://cloud.digitalocean.com/registrations/new",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "api-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [],
            "resource_ids": [
              "personal-access-tokens"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          },
          {
            "interface_id": "resource-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "digitalocean-api"
            ],
            "resource_ids": [
              "api-overview",
              "api-reference",
              "droplet-provisioning"
            ],
            "operated_by_participant_id": "digitalocean",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "overview-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-overview"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "provisioning-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "droplet-provisioning"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "resource-api"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "cloud-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "separate-eligibility-resource",
            "role": "eligibility",
            "rationale": "Applicable access conditions are published within the service terms; no separate eligibility resource is declared."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:f3dc9be655c53ad792dc8fc3553746239289c051cedf9de9cd24c815d6f4d5c0",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "sign_up",
        "stage_label": "Sign up",
        "public_state": "limited",
        "finding": {
          "signal_code": "delegated_identity_access",
          "condition": "Can an agent obtain scoped, revocable authority for this service?",
          "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
          "context": "DigitalOcean documentation details personal access tokens that provide scoped, revocable machine credentials with customizable expiration and scopes, but token generation requires manual steps in the Control Panel."
        }
      },
      "limitations": [
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "DigitalOcean documentation details personal access tokens that provide scoped, revocable machine credentials with customizable expiration and scopes, but token generation requires manual steps in the Control Panel."
          },
          "remediation": {
            "signal_code": "delegated_identity_access",
            "code": "improve.sign_up.delegated_identity_access",
            "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "When creating a personal access token in the Control Panel, DigitalOcean displays the secret key only once upon generation and directs the user to save it. Custom scope details are displayed and managing actions like rename, regenerate, or delete are available, but delivery requires manual user transfer of the single-display secret."
          },
          "remediation": {
            "signal_code": "access_material_delivery",
            "code": "improve.provision.access_material_delivery",
            "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "provisioning_completion",
            "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
            "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
            "context": "When creating a Droplet in the Control Panel, a progress bar displays how close the Droplet is to being ready, and once fully set up, the Control Panel displays its IP address. However, the evidence does not establish asynchronous failure reconciliation, retry bounds, or failure state contracts."
          },
          "remediation": {
            "signal_code": "provisioning_completion",
            "code": "improve.provision.provisioning_completion",
            "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "DigitalOcean API documentation specifies HTTP status codes (200, 400, and 500 ranges), JSON error response structure (id, message, request_id), rate limits, and the retry-after header for burst limits. It also specifies DELETE idempotency, but omits complete cancellation and reconciliation semantics."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "DigitalOcean documentation explicitly states that if a personal access token becomes compromised, deleting it will revoke that token's access, and notes that tokens should be rotated rather than hard coded. However, the evidence does not detail full programmatic credential recovery or rotation lifecycle mechanisms."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "service_discovery",
            "condition": "Can an agent find the exact service and its stable entrypoints?",
            "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
            "context": "DigitalOcean's API documentation provides stable public routes and entrypoints to programmatically manage Droplets, Spaces, and other cloud infrastructure resources using conventional RESTful HTTP requests, doctl CLI commands, and inference APIs."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "DigitalOcean's legal Terms of Service Agreement is publicly retrievable, readable, and incorporates related terms by reference, including the Data Processing Agreement, Acceptable Use Policy, Privacy Policy, and Service Terms."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "context": "DigitalOcean's Terms of Service explicitly outline material eligibility conditions prior to commitment: users must be at least 18 years old (or have sufficient legal consent/capacity), agree to the TOS directly or represent an entity with authority to bind it, and create an account with required information such as name, email address, and a valid form of payment."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "DigitalOcean provides explicit pricing details for its cloud solutions before commitment, including AI/ML inference starting at $0.05/M tokens, GPU Droplets starting at $1.91/GPU/hour (or $0.76/GPU/hour on-demand), App Platform starting at $0/month, and Droplets starting at $4/month with per-second billing ($0.01 minimum)."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:18.008Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:03288e55261871b415ce55a9448d791d0de6998b18200b960c03bd7e93f85882",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                    "sha256:dc2f9ca7b8174c216a1a6cab6cf8c553492dafbdfdf303fcd57448c2b4c073b0",
                    "sha256:dfb65800a4beb7d30ba279473faf813b6a6cfb3f02eb488b029a4a65ce8a9406"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                      "start_byte": 11680,
                      "end_byte": 12473,
                      "value_digest": "sha256:0606021edad9b53baad07d3e02496330f69023006b00c56ea94c21680064ec63"
                    },
                    {
                      "artifact_digest": "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                      "start_byte": 7639,
                      "end_byte": 8485,
                      "value_digest": "sha256:78b7de19695ed2852173eaa287e4c0d8a45f1ff8882beee1fed6f7d99a4efcbc"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean's Terms of Service explicitly outline material eligibility conditions prior to commitment: users must be at least 18 years old (or have sufficient legal consent/capacity), agree to the TOS directly or represent an entity with authority to bind it, and create an account with required information such as name, email address, and a valid form of payment."
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.992Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:82b22c0c8f9de1c6e2341c8aaa85cb5aa8ca5b33ca335087a5958537457798bd",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1445123d77919b8ca5954823bfd658093ec0cdc539896f1161f9e17b3eba71bd",
                    "sha256:46b41c4db6c66974e17d88d3a37871b29d01a4356506512ed1d4621b57b7cb84",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:ff02fdb915f3b2d24d774e0b4eb296f13d17133437c16a7f999fe27fa7929b85"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1445123d77919b8ca5954823bfd658093ec0cdc539896f1161f9e17b3eba71bd",
                      "start_byte": 9431,
                      "end_byte": 10208,
                      "value_digest": "sha256:d3d2a27603cdcbf7488e5707f6fd573319b7430c8ed0d0264d2dcd2ba878c043"
                    },
                    {
                      "artifact_digest": "sha256:1445123d77919b8ca5954823bfd658093ec0cdc539896f1161f9e17b3eba71bd",
                      "start_byte": 7854,
                      "end_byte": 8637,
                      "value_digest": "sha256:f1607aedde4767c9bc4eae43ae18e55928e53127123edd01ea5c6daa0869f098"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean provides explicit pricing details for its cloud solutions before commitment, including AI/ML inference starting at $0.05/M tokens, GPU Droplets starting at $1.91/GPU/hour (or $0.76/GPU/hour on-demand), App Platform starting at $0/month, and Droplets starting at $4/month with per-second billing ($0.01 minimum)."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.061Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a349a32f6962634055a3567f56d4c88210d99ec372b44d396cf3a92f1cf907ef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:024b3f515afb76d49ce37841132e90b992a0c22bd8faa78826462cd1dd026e75",
                    "sha256:19a3865a93c26d52ba8abc67c7c1b60d9554233dc666be527a22ec00770f036f",
                    "sha256:35059511542f2f4c80292a93cc1e3c012aa38e8fe74c657e69d4930f6d4444ae",
                    "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                      "start_byte": 141105,
                      "end_byte": 141892,
                      "value_digest": "sha256:362b8ee33090aa543f38cc7ada3d5dfaedc158a07dcb4a7b384e52454eb12c38"
                    },
                    {
                      "artifact_digest": "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                      "start_byte": 0,
                      "end_byte": 577,
                      "value_digest": "sha256:63da2609ea3d7fccd5624c1c96611efba060a7d57dcfabc30a534b46dd4215ec"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean's API documentation provides stable public routes and entrypoints to programmatically manage Droplets, Spaces, and other cloud infrastructure resources using conventional RESTful HTTP requests, doctl CLI commands, and inference APIs."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:18.008Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:03288e55261871b415ce55a9448d791d0de6998b18200b960c03bd7e93f85882",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                    "sha256:dfb65800a4beb7d30ba279473faf813b6a6cfb3f02eb488b029a4a65ce8a9406",
                    "sha256:e0360b18bf86c70adea54d571bd47cb0677262a552765120e3f3f9dc7459adc5"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                      "start_byte": 9292,
                      "end_byte": 10094,
                      "value_digest": "sha256:5901d0c129f109c43c7dd33e54a452d213a9d8a4bd4919f0fd8c712a5ad9d1ee"
                    },
                    {
                      "artifact_digest": "sha256:580095c03910b3d9eff87929632476bc56d846b5d5828cb820a9fee2a5e02c70",
                      "start_byte": 6834,
                      "end_byte": 7638,
                      "value_digest": "sha256:fed3c9365728c35075c2af423c5132943e3175f9ac6d1df8138c62595796a47a"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean's legal Terms of Service Agreement is publicly retrievable, readable, and incorporates related terms by reference, including the Data Processing Agreement, Acceptable Use Policy, Privacy Policy, and Service Terms."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "DigitalOcean documentation details personal access tokens that provide scoped, revocable machine credentials with customizable expiration and scopes, but token generation requires manual steps in the Control Panel."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The capture for the signup endpoint returned a 403 HTTP response from Cloudflare ('Sorry, you have been blocked'). Current admissible evidence does not resolve access control operability."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Target registration endpoint captures resulted in HTTP 403 Cloudflare block pages, and the documentation page does not explicitly declare CAPTCHA requirements or alternative agent boundaries."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The registration endpoints resulted in HTTP 403 blocks and the guide evidence does not address phone verification requirements or safe explicit handoffs."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "context": "DigitalOcean documentation provides a stable canonical route to begin obtaining service access by directing users to sign up and log in to the Control Panel."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:01.685Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The capture for the signup endpoint returned a 403 HTTP response from Cloudflare ('Sorry, you have been blocked'). Current admissible evidence does not resolve access control operability."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:09.445Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-access-guide"
                },
                {
                  "node_kind": "resource",
                  "node_id": "cloud-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d663ca2009c051e78812f868fb68bc8af8e57d135ec1dea1c9fd773fab226adb",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:25b6d01ee23e67b4ff5eca17fa9854c51b1d2e6d940c12d5919a612765c53d19",
                    "sha256:2a5da500aa008dcabcecfb6de91e4cf5ecd15f1ddbb6b46d70e498a393aff6ef",
                    "sha256:360ab59b9366bd9d0c6c8c6ca39780964456d737d4b55d65c94bb0590acab997",
                    "sha256:381bd178f117409e51da17313d2b73ec64b59766ba11f365161ce14836815e15",
                    "sha256:44f67bad854c47dcd59da01b92061355e554575dbb5b6ec5f7537ff2b05ac3c5",
                    "sha256:8b5d9f0067d1dacb9c66bc52296863e7a0a87800d2f78fa83bb2440214c4e540"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:2a5da500aa008dcabcecfb6de91e4cf5ecd15f1ddbb6b46d70e498a393aff6ef",
                      "start_byte": 10345,
                      "end_byte": 11135,
                      "value_digest": "sha256:3ae3d99ab4b50d27e411a26898a48e589f5b9506d3bf332ce70af41aea4a64d7"
                    },
                    {
                      "artifact_digest": "sha256:2a5da500aa008dcabcecfb6de91e4cf5ecd15f1ddbb6b46d70e498a393aff6ef",
                      "start_byte": 13524,
                      "end_byte": 14325,
                      "value_digest": "sha256:1356fdfccbb0704f1732a694de54d653752b7d25012ab68b28025feda4c06db6"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean documentation provides a stable canonical route to begin obtaining service access by directing users to sign up and log in to the Control Panel."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:09.445Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "account-access-guide"
                },
                {
                  "node_kind": "resource",
                  "node_id": "cloud-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "Target registration endpoint captures resulted in HTTP 403 Cloudflare block pages, and the documentation page does not explicitly declare CAPTCHA requirements or alternative agent boundaries."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:05.010Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "personal-access-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8250b12ba6ca21e5eabc1c1401b5a0156b0a5a33207d3e07e79e8d7a8abcd68e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3803155d3179173f1929df85c9ab01dbf2af49f477258c5ba98ae16b35bd29f6",
                    "sha256:8c8a45f9a09ab1da2d8d73a407dea95c4bc6abd89cae6d01829397557e3011d9",
                    "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                    "sha256:fb4485edfb5ff7613c3213c7882fce6cdd20cd14848243387d473808549667ed"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "personal-access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 166473,
                      "end_byte": 167275,
                      "value_digest": "sha256:d110492be7e796c038718d53d8d76136d9193beee9602e2eef42de128c536820"
                    },
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 168052,
                      "end_byte": 168848,
                      "value_digest": "sha256:7a84f3dec1889e406d27659026e4088c9f4ac771a0c2bd7e4ef0c965cd5fc9b0"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean documentation details personal access tokens that provide scoped, revocable machine credentials with customizable expiration and scopes, but token generation requires manual steps in the Control Panel.",
              "remediation": {
                "signal_code": "delegated_identity_access",
                "code": "improve.sign_up.delegated_identity_access",
                "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
              }
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:09.445Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-access-guide"
                },
                {
                  "node_kind": "resource",
                  "node_id": "cloud-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The registration endpoints resulted in HTTP 403 blocks and the guide evidence does not address phone verification requirements or safe explicit handoffs."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "delegated_identity_access",
              "code": "improve.sign_up.delegated_identity_access",
              "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
            }
          ]
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "DigitalOcean discloses its pricing structure with monthly caps and flat rates, including specific starting rates such as $0.05 per million tokens for Inference or $0.76/GPU/hour on-demand ($1.91/GPU/hour on multi-month commitment)."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence describes accepted payment methods and steps for adding a payment method on DigitalOcean, but it does not establish a complete end-to-end checkout flow supporting deterministic construction, approval handoff, and safe resumption."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence details adding credit cards, PayPal, Google Pay, Alipay, Link, crypto wallets, and ACH direct debit, including temporary authorization charges, but does not state a delegated authorization rail or human-confirmed approval with receipt mechanics."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "DigitalOcean documentation explicitly states that users can navigate to the Billing tab in the Control Panel and add a payment method to create resources or invite team members directly without a vendor decision point."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:58.107Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence describes accepted payment methods and steps for adding a payment method on DigitalOcean, but it does not establish a complete end-to-end checkout flow supporting deterministic construction, approval handoff, and safe resumption."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.992Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:82b22c0c8f9de1c6e2341c8aaa85cb5aa8ca5b33ca335087a5958537457798bd",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1445123d77919b8ca5954823bfd658093ec0cdc539896f1161f9e17b3eba71bd",
                    "sha256:1a294426dc1018d5af2f0cf9da5b8d3df3159a2a07c3ef8125a48bd0540277ec",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:ff02fdb915f3b2d24d774e0b4eb296f13d17133437c16a7f999fe27fa7929b85"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1445123d77919b8ca5954823bfd658093ec0cdc539896f1161f9e17b3eba71bd",
                      "start_byte": 7854,
                      "end_byte": 8637,
                      "value_digest": "sha256:f1607aedde4767c9bc4eae43ae18e55928e53127123edd01ea5c6daa0869f098"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean discloses its pricing structure with monthly caps and flat rates, including specific starting rates such as $0.05 per million tokens for Inference or $0.76/GPU/hour on-demand ($1.91/GPU/hour on multi-month commitment)."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:58.107Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence details adding credit cards, PayPal, Google Pay, Alipay, Link, crypto wallets, and ACH direct debit, including temporary authorization charges, but does not state a delegated authorization rail or human-confirmed approval with receipt mechanics."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:58.107Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:afbf8cc21f82f7e81365ae4d3da81a31415df9bccde2b3f221c0c72d0607ef88",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0fb3639f8a65c3eed15f754ca293770866cabe83505557a7f2efc6516e4a0486",
                    "sha256:13b5f2e0ba63caa1a8b99e3040fb10ca6f07cbdd1887d21a1b4f46b34d21481b",
                    "sha256:82d696cfb84dc3cdc0732e1da9cfba565d9bc0e8b9085e9c3b8f64524b2752a5",
                    "sha256:cfdb6df1209ae58ae3fbc4c89c29ad2aba93888350262da1d147efc4c2abcbfd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:cfdb6df1209ae58ae3fbc4c89c29ad2aba93888350262da1d147efc4c2abcbfd",
                      "start_byte": 34487,
                      "end_byte": 35287,
                      "value_digest": "sha256:b91499ac640ab31a0ea63e7741c2cafa08a280cd23ad8dffc448e5ef4a7c3f57"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean documentation explicitly states that users can navigate to the Billing tab in the Control Panel and add a payment method to create resources or invite team members directly without a vendor decision point."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "When creating a personal access token in the Control Panel, DigitalOcean displays the secret key only once upon generation and directs the user to save it. Custom scope details are displayed and managing actions like rename, regenerate, or delete are available, but delivery requires manual user transfer of the single-display secret."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "context": "When creating a Droplet in the Control Panel, a progress bar displays how close the Droplet is to being ready, and once fully set up, the Control Panel displays its IP address. However, the evidence does not establish asynchronous failure reconciliation, retry bounds, or failure state contracts."
            },
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "Droplet provisioning can be initiated programmatically within supported agent authority by sending a POST request to https://api.digitalocean.com/v2/droplets or using API client libraries such as PyDo droplets.create()."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:05.010Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "personal-access-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8250b12ba6ca21e5eabc1c1401b5a0156b0a5a33207d3e07e79e8d7a8abcd68e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:760a66b7eb10b4d8232f6e7bec3ae5b8bde558c05169ac2809c0b848086e2b18",
                    "sha256:8c8a45f9a09ab1da2d8d73a407dea95c4bc6abd89cae6d01829397557e3011d9",
                    "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                    "sha256:fb4485edfb5ff7613c3213c7882fce6cdd20cd14848243387d473808549667ed"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "personal-access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 169647,
                      "end_byte": 170446,
                      "value_digest": "sha256:fcc1df8b085c4c42ca70d3cbeed8de22335390c99cf32e46729cd6a421a37225"
                    },
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 170447,
                      "end_byte": 171232,
                      "value_digest": "sha256:d25992fdc99cb55d3688b428a0f023554fd28ec2443326fb1612ac0267665c09"
                    }
                  ]
                }
              ],
              "note": "When creating a personal access token in the Control Panel, DigitalOcean displays the secret key only once upon generation and directs the user to save it. Custom scope details are displayed and managing actions like rename, regenerate, or delete are available, but delivery requires manual user transfer of the single-display secret.",
              "remediation": {
                "signal_code": "access_material_delivery",
                "code": "improve.provision.access_material_delivery",
                "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
              }
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:06.398Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "droplet-provisioning"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bfc61cf692c08ddd7e80af7ad1c550f184736144811e09cbc054f51358d88003",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3f19ca3dba73576eaf84a4b6534e854d1d85f6a34383960279f6deaa6ac76ddb",
                    "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                    "sha256:67299375fe77a9832582956167d20f5ef02741a1f547b8817b41ef320913b992",
                    "sha256:9e68c42b893acc34e7af0d05b573e412eeafab8232fbed1c6f63e6aa7ab6a150"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "droplet-provisioning"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                      "start_byte": 23644,
                      "end_byte": 24441,
                      "value_digest": "sha256:c74902d11ae0137b981ff7dbc232b61cb30642de9805272e4ee3df962223d255"
                    }
                  ]
                }
              ],
              "note": "When creating a Droplet in the Control Panel, a progress bar displays how close the Droplet is to being ready, and once fully set up, the Control Panel displays its IP address. However, the evidence does not establish asynchronous failure reconciliation, retry bounds, or failure state contracts.",
              "remediation": {
                "signal_code": "provisioning_completion",
                "code": "improve.provision.provisioning_completion",
                "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
              }
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:05.010Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "droplet-provisioning"
                },
                {
                  "node_kind": "resource",
                  "node_id": "personal-access-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bfc61cf692c08ddd7e80af7ad1c550f184736144811e09cbc054f51358d88003",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3f19ca3dba73576eaf84a4b6534e854d1d85f6a34383960279f6deaa6ac76ddb",
                    "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                    "sha256:8346cb2ce4eb82a660851fc783aa8dc6b8ea0c452288fb31ad08e270da4c1e58",
                    "sha256:9e68c42b893acc34e7af0d05b573e412eeafab8232fbed1c6f63e6aa7ab6a150"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "droplet-provisioning"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                      "start_byte": 26034,
                      "end_byte": 26714,
                      "value_digest": "sha256:217aa3dfbb0684e718f91c2c1ddb44be95c59b78e78dc1d63c47e6da5b207bc3"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8250b12ba6ca21e5eabc1c1401b5a0156b0a5a33207d3e07e79e8d7a8abcd68e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:8c8a45f9a09ab1da2d8d73a407dea95c4bc6abd89cae6d01829397557e3011d9",
                    "sha256:984f556aad596b41c3cb3e98cbba01d87361c161b1e177a9f180ebe7205434d2",
                    "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                    "sha256:fb4485edfb5ff7613c3213c7882fce6cdd20cd14848243387d473808549667ed"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "personal-access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 155284,
                      "end_byte": 156084,
                      "value_digest": "sha256:d258973ef8dd46dfb31883bcf082ad085bef9e97253713f4494b5306508bb7ff"
                    }
                  ]
                }
              ],
              "note": "Droplet provisioning can be initiated programmatically within supported agent authority by sending a POST request to https://api.digitalocean.com/v2/droplets or using API client libraries such as PyDo droplets.create()."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "access_material_delivery",
              "code": "improve.provision.access_material_delivery",
              "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
            },
            {
              "signal_code": "provisioning_completion",
              "code": "improve.provision.provisioning_completion",
              "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "DigitalOcean API documentation specifies HTTP status codes (200, 400, and 500 ranges), JSON error response structure (id, message, request_id), rate limits, and the retry-after header for burst limits. It also specifies DELETE idempotency, but omits complete cancellation and reconciliation semantics."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "DigitalOcean documentation explicitly states that if a personal access token becomes compromised, deleting it will revoke that token's access, and notes that tokens should be rotated rather than hard coded. However, the evidence does not detail full programmatic credential recovery or rotation lifecycle mechanisms."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Every essential target is accessible through stable, documented agent-usable interfaces including the DigitalOcean REST API (via HTTP/cURL) and the doctl CLI, as well as SDKs like godo (Go) and pydo (Python)."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "DigitalOcean API authentication is documented using personal access tokens sent in a bearer-type Authorization header, supporting custom scopes for specific permissions."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "DigitalOcean API and Droplet documentation specify essential operations, HTTP methods (GET, DELETE, PUT, HEAD), request parameters, JSON responses, idempotency semantics, and explicit POST requests to endpoints like /v2/droplets with defined body schemas."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:05.010Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "personal-access-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8250b12ba6ca21e5eabc1c1401b5a0156b0a5a33207d3e07e79e8d7a8abcd68e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:063e35ae1472dfa4eae47d241785cf55b53bac6d67cf99fdfcf29627b21e5d5b",
                    "sha256:8c8a45f9a09ab1da2d8d73a407dea95c4bc6abd89cae6d01829397557e3011d9",
                    "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                    "sha256:fb4485edfb5ff7613c3213c7882fce6cdd20cd14848243387d473808549667ed"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "personal-access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 166473,
                      "end_byte": 167275,
                      "value_digest": "sha256:d110492be7e796c038718d53d8d76136d9193beee9602e2eef42de128c536820"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean documentation explicitly states that if a personal access token becomes compromised, deleting it will revoke that token's access, and notes that tokens should be rotated rather than hard coded. However, the evidence does not detail full programmatic credential recovery or rotation lifecycle mechanisms.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:02.125Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-reference"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bbef4b1363d03a721f2c9152d987ae27012156459dfc5b989c03d3d744973958",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                    "sha256:2b777fe95bfaa9387646d1aec67c385c6c3a1fef19697e5e9adb9a28d65617c1",
                    "sha256:66054a6f391a97e87fe779916bf00a8a1d7fa96ab6673a300c43218a60ab35d7",
                    "sha256:726e9340931236aabb4fc9baacafb1cee74923be4e10bd9c719e0a156889314f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                      "start_byte": 171825,
                      "end_byte": 172624,
                      "value_digest": "sha256:4e05301f16a2be013f5d35fb230c4d62727d1c552d16e940978d0e6ce96d3761"
                    },
                    {
                      "artifact_digest": "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                      "start_byte": 177425,
                      "end_byte": 178223,
                      "value_digest": "sha256:14b56efb49224651664d3ee62e152b19e3823557ab2d3f9409f9a9d0bb3e2983"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean API documentation specifies HTTP status codes (200, 400, and 500 ranges), JSON error response structure (id, message, request_id), rate limits, and the retry-after header for burst limits. It also specifies DELETE idempotency, but omits complete cancellation and reconciliation semantics.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:05.010Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "personal-access-tokens"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:8250b12ba6ca21e5eabc1c1401b5a0156b0a5a33207d3e07e79e8d7a8abcd68e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:063e35ae1472dfa4eae47d241785cf55b53bac6d67cf99fdfcf29627b21e5d5b",
                    "sha256:8c8a45f9a09ab1da2d8d73a407dea95c4bc6abd89cae6d01829397557e3011d9",
                    "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                    "sha256:fb4485edfb5ff7613c3213c7882fce6cdd20cd14848243387d473808549667ed"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "personal-access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:dbac6c7f7aae30ebc112f89d03f7aab6b93d2403f3a7a09698d64ddc82541ade",
                      "start_byte": 166473,
                      "end_byte": 167275,
                      "value_digest": "sha256:d110492be7e796c038718d53d8d76136d9193beee9602e2eef42de128c536820"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean API authentication is documented using personal access tokens sent in a bearer-type Authorization header, supporting custom scopes for specific permissions."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:02.125Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "resource-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a349a32f6962634055a3567f56d4c88210d99ec372b44d396cf3a92f1cf907ef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:024b3f515afb76d49ce37841132e90b992a0c22bd8faa78826462cd1dd026e75",
                    "sha256:19a3865a93c26d52ba8abc67c7c1b60d9554233dc666be527a22ec00770f036f",
                    "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                    "sha256:e92ab171b760265cec6229963048eb505248b7f2a06e411e7b29dafc1b44a0a9"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                      "start_byte": 0,
                      "end_byte": 577,
                      "value_digest": "sha256:63da2609ea3d7fccd5624c1c96611efba060a7d57dcfabc30a534b46dd4215ec"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bfc61cf692c08ddd7e80af7ad1c550f184736144811e09cbc054f51358d88003",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3f19ca3dba73576eaf84a4b6534e854d1d85f6a34383960279f6deaa6ac76ddb",
                    "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                    "sha256:8346cb2ce4eb82a660851fc783aa8dc6b8ea0c452288fb31ad08e270da4c1e58",
                    "sha256:9e68c42b893acc34e7af0d05b573e412eeafab8232fbed1c6f63e6aa7ab6a150"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "droplet-provisioning"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                      "start_byte": 26034,
                      "end_byte": 26714,
                      "value_digest": "sha256:217aa3dfbb0684e718f91c2c1ddb44be95c59b78e78dc1d63c47e6da5b207bc3"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bbef4b1363d03a721f2c9152d987ae27012156459dfc5b989c03d3d744973958",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                    "sha256:2b777fe95bfaa9387646d1aec67c385c6c3a1fef19697e5e9adb9a28d65617c1",
                    "sha256:2d820016f2e234cb53962f7b942f26b41f77639b14918bc4842b2564073480b2",
                    "sha256:66054a6f391a97e87fe779916bf00a8a1d7fa96ab6673a300c43218a60ab35d7"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                      "start_byte": 170235,
                      "end_byte": 171026,
                      "value_digest": "sha256:ffeb543c1d03af986fb86adda8e68bc23d8a0960915ae84d39207fc256af0158"
                    }
                  ]
                }
              ],
              "note": "DigitalOcean API and Droplet documentation specify essential operations, HTTP methods (GET, DELETE, PUT, HEAD), request parameters, JSON responses, idempotency semantics, and explicit POST requests to endpoints like /v2/droplets with defined body schemas."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:02.125Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "resource-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bbef4b1363d03a721f2c9152d987ae27012156459dfc5b989c03d3d744973958",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                    "sha256:2b777fe95bfaa9387646d1aec67c385c6c3a1fef19697e5e9adb9a28d65617c1",
                    "sha256:66054a6f391a97e87fe779916bf00a8a1d7fa96ab6673a300c43218a60ab35d7",
                    "sha256:94068432e9db76ebfcf5a993d78eab0039033bd5ac731102bdeac1e12d7b8bfa"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:220869f9cc1ba302e52b30b0c9adc06684b1ffd159d3971fec454232540199df",
                      "start_byte": 169437,
                      "end_byte": 170234,
                      "value_digest": "sha256:170c1efa674ab9d92c38ff204e32937368be9b61c91c8e4ed4e9746f5b72365c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:bfc61cf692c08ddd7e80af7ad1c550f184736144811e09cbc054f51358d88003",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3f19ca3dba73576eaf84a4b6534e854d1d85f6a34383960279f6deaa6ac76ddb",
                    "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                    "sha256:8346cb2ce4eb82a660851fc783aa8dc6b8ea0c452288fb31ad08e270da4c1e58",
                    "sha256:9e68c42b893acc34e7af0d05b573e412eeafab8232fbed1c6f63e6aa7ab6a150"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "droplet-provisioning"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:40d4274df3d7386dd856d32a8f25e67dcfab5612c86d31f831fccfd9410813a7",
                      "start_byte": 26034,
                      "end_byte": 26714,
                      "value_digest": "sha256:217aa3dfbb0684e718f91c2c1ddb44be95c59b78e78dc1d63c47e6da5b207bc3"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a349a32f6962634055a3567f56d4c88210d99ec372b44d396cf3a92f1cf907ef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:024b3f515afb76d49ce37841132e90b992a0c22bd8faa78826462cd1dd026e75",
                    "sha256:19a3865a93c26d52ba8abc67c7c1b60d9554233dc666be527a22ec00770f036f",
                    "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                    "sha256:ff7a73966f910f063a52ca61a7013d026be951c461eecf532a2fb508e3ffb420"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9d10ebc45df5e71df32d3f92ee0b0cb60ba54e6117760880c7694c1d69f33a98",
                      "start_byte": 167020,
                      "end_byte": 167822,
                      "value_digest": "sha256:e6b8704e7d9ff731c42cc80354f971347c0d50692e5f8ff43fa8e1620c621691"
                    }
                  ]
                }
              ],
              "note": "Every essential target is accessible through stable, documented agent-usable interfaces including the DigitalOcean REST API (via HTTP/cURL) and the doctl CLI, as well as SDKs like godo (Go) and pydo (Python)."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:09.445Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:2c7d4654b593c2fd14eb9c955b1949442077d6b47e30bb07ddc43342a8d4c8f2",
          "sha256:36f91d4d70966ea1ed1f150f76094bfcc0005286bf0593a25678a489ca772919",
          "sha256:37dbbeabc0db576a0e39e6815b59ae208fbce703fabdb5d9d5971f44e116b544",
          "sha256:38651c450bf8b9883c443b68d449060e8d24ddcb86bd878d6d822bb2c24924d3",
          "sha256:3dcaa86de545903adfd2f872c7f5426ed41b7707e2f4660776dc972be8b20ae7",
          "sha256:3ed73b07ef936b438c5299ca5a9c8bda36b1dda192c3fb8b928b9b22f0e80798",
          "sha256:4037bdd050bde58dc5d843cf69086b0734e406707442f733cfdec08908ab632c",
          "sha256:46b11630ae4c0ab9a4aea8d665c9e8d496d3c86bd07b5ee3b96d954b7bc97d22",
          "sha256:5275f51d4c985e9cef6e485495e6c5cd70a6cabf7a079a95568d29e5b167afc9",
          "sha256:69cf272a020c209506305845822206e0f4f51b973c30acc9969f7edc4fed7548",
          "sha256:6c047f26223d7d0bd4fccc304e118440428675fd718f6c07b7f9f8dc0528c6f3",
          "sha256:6e1c8cf0ca684da143e46452af08fe7d02acd6c65e2a8f0b2f781bdc4b16bb5c",
          "sha256:718af0f775702d18b367d3c2fe1c68f4f6c3a717b466e3e4843267313812e226",
          "sha256:82ccc1c543eb585cd28871613b63e7b7c46d0425d06a8b54afb0cddaac1c3b86",
          "sha256:855305c2e1ac1f6b4b4137a18bb5f70f73f3937e4a09690d3ac637d8c1fcf9dd",
          "sha256:8ff0b28a048c299bf7d6aba5f5baece89d26b0cb83040772201bd08e30ec89c7",
          "sha256:929788c00b1abccdf883d039ecb57acf78efb428d165c7a177c53fb641bcd50c",
          "sha256:961f3f5d81d3d106432d3188944be5d29092b390ccfd734b673cde93fef2825b",
          "sha256:978ae8dc37ffbe3b5e015f75f638dc5bfc309b7cb22e7cab00b3fd4e2097428a",
          "sha256:a4a3df3cdbd2660ffe4504e10280a3677ffb681bf3aafb9c9372d5e210081e60",
          "sha256:a72d8c966f1d01355c6dff8079a904416f4d5265f75cc213ec22f444419d54ed",
          "sha256:ab1589e70b55ae33eb3b0ff3207c97c08f98f7c228aa90db357e36562e814948",
          "sha256:bc68ff97dce8324d257afc5f1d35d7d1a2ccb3a20d7b4499b04e8214d70a8fd4",
          "sha256:d5f15bd491f8ecd092e51ad7ba85e4343a44daf55621795bed8a6bfd385febe9",
          "sha256:ea1aaa6007814d3af320ade216c80d29f69665e7bc296452ba2dcb405e184299",
          "sha256:eb2c48631f0c8400bbde0faadf27c2e9f87bc2a5959e87795c6c1bfc73c4d94d",
          "sha256:f1402ba69ab1e4806a7a8a6664f5c633cb0f3fd5191b1f2b450fd13a085bc760",
          "sha256:f2107a8177121e94efed68f608962938587780f0a400ec2c0143aeac88b29f0a",
          "sha256:f7b7124b85ee83be13feb26b1168deb3f526d4bffd29a3ef88de56389d206212"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:82ccc1c543eb585cd28871613b63e7b7c46d0425d06a8b54afb0cddaac1c3b86"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:18.008Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:ea1aaa6007814d3af320ade216c80d29f69665e7bc296452ba2dcb405e184299"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.992Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:2c7d4654b593c2fd14eb9c955b1949442077d6b47e30bb07ddc43342a8d4c8f2"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.061Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:eb2c48631f0c8400bbde0faadf27c2e9f87bc2a5959e87795c6c1bfc73c4d94d"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:18.008Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:3dcaa86de545903adfd2f872c7f5426ed41b7707e2f4660776dc972be8b20ae7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:01.685Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:8ff0b28a048c299bf7d6aba5f5baece89d26b0cb83040772201bd08e30ec89c7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:09.445Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:38651c450bf8b9883c443b68d449060e8d24ddcb86bd878d6d822bb2c24924d3",
              "sha256:5275f51d4c985e9cef6e485495e6c5cd70a6cabf7a079a95568d29e5b167afc9",
              "sha256:bc68ff97dce8324d257afc5f1d35d7d1a2ccb3a20d7b4499b04e8214d70a8fd4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:09.445Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:f1402ba69ab1e4806a7a8a6664f5c633cb0f3fd5191b1f2b450fd13a085bc760"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:05.010Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:69cf272a020c209506305845822206e0f4f51b973c30acc9969f7edc4fed7548",
              "sha256:d5f15bd491f8ecd092e51ad7ba85e4343a44daf55621795bed8a6bfd385febe9"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:09.445Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:978ae8dc37ffbe3b5e015f75f638dc5bfc309b7cb22e7cab00b3fd4e2097428a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:58.107Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:a72d8c966f1d01355c6dff8079a904416f4d5265f75cc213ec22f444419d54ed"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.992Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:37dbbeabc0db576a0e39e6815b59ae208fbce703fabdb5d9d5971f44e116b544"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:58.107Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:a4a3df3cdbd2660ffe4504e10280a3677ffb681bf3aafb9c9372d5e210081e60"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:58.107Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:855305c2e1ac1f6b4b4137a18bb5f70f73f3937e4a09690d3ac637d8c1fcf9dd"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:05.010Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:929788c00b1abccdf883d039ecb57acf78efb428d165c7a177c53fb641bcd50c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:06.398Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:f2107a8177121e94efed68f608962938587780f0a400ec2c0143aeac88b29f0a",
              "sha256:f7b7124b85ee83be13feb26b1168deb3f526d4bffd29a3ef88de56389d206212"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:05.010Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:3ed73b07ef936b438c5299ca5a9c8bda36b1dda192c3fb8b928b9b22f0e80798"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:05.010Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:718af0f775702d18b367d3c2fe1c68f4f6c3a717b466e3e4843267313812e226"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:02.125Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:46b11630ae4c0ab9a4aea8d665c9e8d496d3c86bd07b5ee3b96d954b7bc97d22"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:05.010Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:4037bdd050bde58dc5d843cf69086b0734e406707442f733cfdec08908ab632c",
              "sha256:961f3f5d81d3d106432d3188944be5d29092b390ccfd734b673cde93fef2825b",
              "sha256:ab1589e70b55ae33eb3b0ff3207c97c08f98f7c228aa90db357e36562e814948"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:02.125Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:36f91d4d70966ea1ed1f150f76094bfcc0005286bf0593a25678a489ca772919",
              "sha256:6c047f26223d7d0bd4fccc304e118440428675fd718f6c07b7f9f8dc0528c6f3",
              "sha256:6e1c8cf0ca684da143e46452af08fe7d02acd6c65e2a8f0b2f781bdc4b16bb5c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:02.125Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/digitalocean/agent-readiness/digitalocean-cloud/api-resource-management",
      "projection_digest": "sha256:89e2b7216246f99d39d624c525fc1b89c55b0bb1439e850d49150f9209b28892"
    }
  }
}
