{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8fpe3new9gxd18qs3bskh",
    "entity_slug": "hubspot",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4xa1m8yr7cf5q2b9vn6",
      "entity_id": "ent_01kyh8fpe3new9gxd18qs3bskh",
      "scope": {
        "product": {
          "key": "hubspot-crm-api",
          "name": "HubSpot CRM API"
        },
        "funnel": {
          "key": "api-integration-lifecycle",
          "name": "API integration lifecycle"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:d834f446f341ff50dd565416a3b8489b405fe189c597bcfa66ca67249314dd03"
      },
      "declaration_revision_digest": "sha256:2538ff7b69270e0b651ecd3add7601bd2e6619766e25ce9b137579cdd014d881",
      "declaration": {
        "declaration_id": "declaration_hubspot_crm_api_integration_lifecycle",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/hu/hubspot.yaml",
          "git_blob_oid": "b54a3f8811835ed618569a25989a0f26802e868e",
          "blob_digest": "sha256:7e1172cc7a94c2b0c4f1e9431fcdd97d3d75d9b4ffdb7f87bc8b7aeb82edda58"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Create and manage HubSpot CRM records through the API",
            "interface_ids": [
              "crm-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "hubspot",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8fpe3new9gxd18qs3bskh"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "api-errors",
            "uri": "https://developers.hubspot.com/docs/api-reference/error-handling",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "api-limits",
            "uri": "https://developers.hubspot.com/docs/developer-tooling/platform/usage-guidelines",
            "roles": [
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "api-overview",
            "uri": "https://developers.hubspot.com/docs/api-reference/overview",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://knowledge.hubspot.com/account/manage-your-hubspot-subscription",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "crm-commitment",
            "uri": "https://www.hubspot.com/products/crm",
            "roles": [
              "documentation",
              "pricing"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "crm-operations",
            "uri": "https://developers.hubspot.com/docs/api-reference/legacy/crm/objects/objects/create-object",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "crm-signup",
            "uri": "https://app.hubspot.com/signup-hubspot/crm",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "oauth",
            "uri": "https://developers.hubspot.com/docs/apps/developer-platform/build-apps/authentication/oauth/working-with-oauth",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "describes"
              }
            ]
          },
          {
            "resource_id": "pricing",
            "uri": "https://www.hubspot.com/pricing/crm",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-237735cc5ba6ecc44afc3287e10b76ffb4c73481fb6a5a1f2ca6e1fa98a8ee41",
            "uri": "https://legal.hubspot.com/developer-terms",
            "roles": [
              "documentation",
              "eligibility"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c",
            "uri": "https://developers.hubspot.com/docs/api/private-apps",
            "roles": [
              "authentication",
              "documentation"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-fedf565215bcde83431a45666a9a0edc7be9032ca5dbd43956ab753094c89a09",
            "uri": "https://legal.hubspot.com/terms-of-service",
            "roles": [
              "documentation",
              "terms"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://legal.hubspot.com/legal-stuff",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "subscription-upgrade",
            "uri": "https://knowledge.hubspot.com/account-management/how-do-i-upgrade-my-hubspot-account",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://knowledge.hubspot.com/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "hubspot-api",
            "uri": "https://api.hubapi.com",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "endpoint_id": "oauth-token",
            "uri": "https://api.hubapi.com/oauth/v1/token",
            "transport": "http",
            "roles": [
              "authorization",
              "token"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "implements"
              }
            ]
          },
          {
            "endpoint_id": "registration",
            "uri": "https://app.hubspot.com/signup-hubspot/crm",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "crm-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "hubspot-api"
            ],
            "resource_ids": [
              "api-errors",
              "api-limits",
              "api-overview",
              "crm-operations"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": []
          },
          {
            "interface_id": "integration-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [
              "oauth-token"
            ],
            "resource_ids": [
              "oauth"
            ],
            "operated_by_participant_id": "hubspot",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "uses"
              }
            ]
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "integration-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "crm-api"
            }
          },
          {
            "relation_id": "crm-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "crm-operations"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "crm-api"
            }
          },
          {
            "relation_id": "overview-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-overview"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "crm-api"
            }
          },
          {
            "relation_id": "relation-describes-091810ae56e2e84f96a64120fd2a5ad4b8bc336eb4c3abbdcaca07a2bd23c18a",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "integration-authentication"
            }
          },
          {
            "relation_id": "relation-describes-b393d1b40a6a6b010018783b7b2272f9b811ed8dc1f6da3d7422cb2cec3f8fb7",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "oauth"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "integration-authentication"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "crm-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "integration-authentication"
            }
          }
        ],
        "surface_exclusions": []
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:986780b22e79c504c57a411c051874457bcd59191cdf762126879fdeeda0cb55",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B+",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "operate",
        "stage_label": "Operate",
        "public_state": "limited",
        "finding": {
          "signal_code": "failure_contract",
          "condition": "Can an agent handle applicable failure modes safely?",
          "finding": "Safe failure handling is documented only partially.",
          "context": "HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established."
        }
      },
      "limitations": [
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "HubSpot documents that access tokens can be refreshed using a refresh token when expired, and private app access tokens can be rotated (either immediately or scheduled for 7 days) or revoked by deleting the app, but recovery or full agent-executable lifecycle without human intervention is not established."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "service_discovery",
            "condition": "Can an agent find the exact service and its stable entrypoints?",
            "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
            "context": "HubSpot provides stable public discovery for its date-versioned 2026-03 API endpoints using the root URL https://api.hubapi.com/ and structured resource paths such as GET /crm/objects/2026-03/contacts."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "HubSpot provides retrievable, readable, and publicly accessible Customer Terms of Service and Developer Terms outlining the governing agreements for customer and developer service use."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "context": "HubSpot's Developer Terms explicitly define eligibility and authority requirements for using Developer Tools, including authority to accept terms on behalf of an entity, legal age capacity, compliance with platform policies, and not being barred by applicable laws."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "HubSpot explicitly declares that its CRM product is 100% free with no expiration date and no credit card required."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:59.567Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "readiness-237735cc5ba6ecc44afc3287e10b76ffb4c73481fb6a5a1f2ca6e1fa98a8ee41"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b3fdfb627d1549220451735876a1771d80388d549f510f67b4a2e85af8aff2bb",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7db22c6e2df73a618ca8347b6565646dec559b2650829d79218411fbca60a8e8",
                    "sha256:99fd1b046adf6343e784896f072f605bd857206f24eeb79c3ea4f27024fe31bc",
                    "sha256:d8730816192d92830addb228ffaa41f60d6e9855b7732db2b1ecb05e3651159d",
                    "sha256:de08d98f15dfc37d351f412524ea3d8647480d12620de9de7114072ce36719bd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-237735cc5ba6ecc44afc3287e10b76ffb4c73481fb6a5a1f2ca6e1fa98a8ee41"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:de08d98f15dfc37d351f412524ea3d8647480d12620de9de7114072ce36719bd",
                      "start_byte": 20548,
                      "end_byte": 21356,
                      "value_digest": "sha256:6053b30b7f5644557b47aedaf40450c9c1452978e8052c2a3e2371204456598b"
                    }
                  ]
                }
              ],
              "note": "HubSpot's Developer Terms explicitly define eligibility and authority requirements for using Developer Tools, including authority to accept terms on behalf of an entity, legal age capacity, compliance with platform policies, and not being barred by applicable laws."
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:28.788Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-commitment"
                },
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d07fb8ac66f957cb82b9334cba97a140e5edf5d702d876ee4fa9689367e2f301",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:145d630ad16738193266f7660738e713a6dfeea2177063105cc9c9125699fd39",
                    "sha256:499ee0b63345ad1a6599d6dc00901c32d0e53203e28d02f1df2b5844f7021029",
                    "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "crm-commitment"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                      "start_byte": 28361,
                      "end_byte": 29163,
                      "value_digest": "sha256:43da9dbff6076010b8a8e63aa4a681d0b0f8108edb06cb723a3f72133a9eb76e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:fc69a1b7dfa8c40de80da446f083ec2a9a42347088bd23929e8978e766f4e0a9",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:989b02723791648ebe3ae7369e6266fdb9bee0c10470a4bf834333215ebb21d2",
                    "sha256:bf3c0d695fd07c6ca799a0412971ebe9d1e7aa55554fd5134d6a7d267954b138"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                      "start_byte": 0,
                      "end_byte": 796,
                      "value_digest": "sha256:0347e27d309bc7222defc72b4b18f0d66d7993b921b8f8275dae3cc4f6726e70"
                    }
                  ]
                }
              ],
              "note": "HubSpot explicitly declares that its CRM product is 100% free with no expiration date and no credit card required."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:33.602Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                    "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
                    "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
                    "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                      "start_byte": 5058,
                      "end_byte": 5859,
                      "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
                    }
                  ]
                }
              ],
              "note": "HubSpot provides stable public discovery for its date-versioned 2026-03 API endpoints using the root URL https://api.hubapi.com/ and structured resource paths such as GET /crm/objects/2026-03/contacts."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:46.600Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "readiness-fedf565215bcde83431a45666a9a0edc7be9032ca5dbd43956ab753094c89a09"
                },
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e7b7c0ed84f43f4abba7b11a38fb0b85a1705114b298b037e9fd3892189735c3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:119f8508e6e418f4880bb646eafce7b18a802da8be724d949fb43033f744aa06",
                    "sha256:be57a24b0bbf23344585061801b78bbfdc215deea6a5262e34a48b9a991aacc8",
                    "sha256:d704813e50f7d73032bf4bdba060a36ed280379a56221b7afb65ccb818ba6751",
                    "sha256:f3285072323833a7e0afd7c8204668b52a34ae03beb63ba612700ed127b9cf4c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:be57a24b0bbf23344585061801b78bbfdc215deea6a5262e34a48b9a991aacc8",
                      "start_byte": 19605,
                      "end_byte": 20403,
                      "value_digest": "sha256:44df1a28ddf6333d3e07e29bc90a89eb9e9128352d2625fb13bcea2686eb0d05"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:39a065f846b76d45e7d2dd9f0bf5ec530e25c44f7e06252eb6c3c9ab2ad425c9",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0fc0a09217c6e5d8485de0bf78812a83ab7b9982425c905c420032fe5169c809",
                    "sha256:2a2a4386207db28a785de60672f6150ba8842156766b8a89a73dafcf32dfe718",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5692bfc90aaf3305976759a5c72724d07a71ffa6b65e91eb511c8138ab41f828"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-fedf565215bcde83431a45666a9a0edc7be9032ca5dbd43956ab753094c89a09"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2a2a4386207db28a785de60672f6150ba8842156766b8a89a73dafcf32dfe718",
                      "start_byte": 0,
                      "end_byte": 515,
                      "value_digest": "sha256:e66ea6a310519485d3411f67aae70bc09079147c9a4fece6da653f7db800083d"
                    }
                  ]
                }
              ],
              "note": "HubSpot provides retrievable, readable, and publicly accessible Customer Terms of Service and Developer Terms outlining the governing agreements for customer and developer service use."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "A stable canonical route begins the required access bootstrap.",
            "context": "A stable canonical route to begin obtaining service access exists at https://app.hubspot.com/signup-hubspot/crm, presenting the 'Get started with HubSpot' entrypoint."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained page fragment for the CRM signup endpoint displays 'Get started with HubSpot' without providing detectable access controls, form fields, validation logic, or redirect handoffs."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured evidence across both evaluated surfaces shows 'Get started with HubSpot' but contains no explicit text or rendered CAPTCHA challenge confirming its presence or absence."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence for the CRM signup resource does not mention phone verification or SMS requirements."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "context": "HubSpot explicitly documents delegated OAuth authentication via authorization URLs, redirect_uri callback, and an API exchange at /oauth/v3/token to obtain access_token and refresh_token scoped to requested permissions."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.686Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained page fragment for the CRM signup endpoint displays 'Get started with HubSpot' without providing detectable access controls, form fields, validation logic, or redirect handoffs."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.686Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:69797ac3540bb84bb53ba6296bc79af51ef0a56053f2c986bd381c2084c839ab",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3878570f4a62a0d65f57cf1754e0269e56ec797f4e36e26b44c172eb6e800401",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c4c643d6f75b2ac2f863d0385d4007236bd9fbebb500cd58a97d305d5a002042",
                    "sha256:cabf4205701d6716c681f3bde84da998667c8f6f2bb9d41ac3a6fa4a37a33810",
                    "sha256:ee2c2181ae03a57bd827bb6023c934e39afcfdc542f40fafb9df519a2443c0da",
                    "sha256:f4948ca55dd2f4c9150a94dec70f218ba74a1f5949c5e67dd92fe4856916dd29"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:f4948ca55dd2f4c9150a94dec70f218ba74a1f5949c5e67dd92fe4856916dd29",
                      "start_byte": 303,
                      "end_byte": 337,
                      "value_digest": "sha256:a43aea4e70ffbd2578366bd4c5e24ac6c4529d30065d12322d84d1f932cbefd6"
                    }
                  ]
                }
              ],
              "note": "A stable canonical route to begin obtaining service access exists at https://app.hubspot.com/signup-hubspot/crm, presenting the 'Get started with HubSpot' entrypoint."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.686Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "crm-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured evidence across both evaluated surfaces shows 'Get started with HubSpot' but contains no explicit text or rendered CAPTCHA challenge confirming its presence or absence."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:20.089Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:30fe6bd22b235ea6806168eee9baf17257db336128b901cacbb402c315212fed",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                    "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 10252,
                      "end_byte": 11044,
                      "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
                    },
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 11045,
                      "end_byte": 11836,
                      "value_digest": "sha256:8d339c6a623686702506daa90ef3921fc5dc016efb33b357924e275c2d5aef09"
                    }
                  ]
                }
              ],
              "note": "HubSpot explicitly documents delegated OAuth authentication via authorization URLs, redirect_uri callback, and an API exchange at /oauth/v3/token to obtain access_token and refresh_token scoped to requested permissions."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.686Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained evidence for the CRM signup resource does not mention phone verification or SMS requirements."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "The assessed free CRM is explicitly 100% free, requires no credit card, and has no expiration date."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "While documentation references clicking Buy now to begin checkout and managing subscriptions in account settings, the retained evidence does not document deterministic checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The evidence requires Billing admin permissions to make billing changes and mentions credit card charges during subscription terms, but does not document a delegated payment authorization rail or explicit human-confirmed authorization with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "Documentation explicitly states that users can visit Pricing & Features in their account, click Buy now to begin checkout, and complete a purchase to upgrade their subscription directly."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:10.312Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "subscription-upgrade"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "While documentation references clicking Buy now to begin checkout and managing subscriptions in account settings, the retained evidence does not document deterministic checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:28.788Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-commitment"
                },
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d07fb8ac66f957cb82b9334cba97a140e5edf5d702d876ee4fa9689367e2f301",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:145d630ad16738193266f7660738e713a6dfeea2177063105cc9c9125699fd39",
                    "sha256:499ee0b63345ad1a6599d6dc00901c32d0e53203e28d02f1df2b5844f7021029",
                    "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "crm-commitment"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                      "start_byte": 28361,
                      "end_byte": 29163,
                      "value_digest": "sha256:43da9dbff6076010b8a8e63aa4a681d0b0f8108edb06cb723a3f72133a9eb76e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:fc69a1b7dfa8c40de80da446f083ec2a9a42347088bd23929e8978e766f4e0a9",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6394bd7f5d8caebca0abb55bbadcdc67f42a2bea6a38c44f2cca79ec75c1f517",
                    "sha256:989b02723791648ebe3ae7369e6266fdb9bee0c10470a4bf834333215ebb21d2"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                      "start_byte": 1058,
                      "end_byte": 1088,
                      "value_digest": "sha256:d6d18fc6ea297008f5be102ae6097459575b159d8b29bdea0f122b73e188026d"
                    }
                  ]
                }
              ],
              "note": "The assessed free CRM is explicitly 100% free, requires no credit card, and has no expiration date."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:10.312Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "subscription-upgrade"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The evidence requires Billing admin permissions to make billing changes and mentions credit card charges during subscription terms, but does not document a delegated payment authorization rail or explicit human-confirmed authorization with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:10.312Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "subscription-upgrade"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c3a6e6d0223d1ac9826569e405149d9654093fa07e62000f7af3d27f364db931",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:661ff4e83b9a796b322b4741bd1edaae3b6826a5443dc43d68620efb29d93db0",
                    "sha256:b495bef7ea5ee94139f7ec76362585f7f2657d19611fcf34491fb7602917563b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "subscription-upgrade"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
                      "start_byte": 7580,
                      "end_byte": 8372,
                      "value_digest": "sha256:e9412b74d985aae8bd9ce0b5f0d7c2fae8825e041e207e545d5c3db2279cb237"
                    },
                    {
                      "artifact_digest": "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
                      "start_byte": 8373,
                      "end_byte": 9163,
                      "value_digest": "sha256:f0fb122626ecad0dd12bdd314999c268ded69c1217dfc61307c9829639af4ffa"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly states that users can visit Pricing & Features in their account, click Buy now to begin checkout, and complete a purchase to upgrade their subscription directly."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "provisioning_operability",
            "condition": "Can provisioning be initiated within supported agent authority?",
            "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
            "context": "Provisioning of CRM objects is triggerable programmatically via a direct POST request to /crm/v3/objects/{objectType}. Additionally, OAuth app installation follows deterministically from user access authorization."
          },
          "secondary_context": [
            {
              "signal_code": "access_material_delivery",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "context": "HubSpot OAuth tokens are delivered through a documented programmatic exchange endpoint (`/oauth/v3/token`), which returns an `access_token` and `refresh_token` after exchanging the authorization code."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "context": "A synchronous POST request to create a CRM object directly returns HTTP status code 201 with the created public object, including its unique ID, timestamps (createdAt, updatedAt), and property key-value pairs."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.795Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                    "sha256:6ed666e282dcffb1e568f09ada5c2e91e5bdfea05cd8b4a9cd2d33c0c57c77ca",
                    "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 9452,
                      "end_byte": 10251,
                      "value_digest": "sha256:c14641ad7b925d7a59c570c7345ef8561353d22a1876a00ee5aa8996c095014d"
                    },
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 10252,
                      "end_byte": 11044,
                      "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
                    }
                  ]
                }
              ],
              "note": "HubSpot OAuth tokens are delivered through a documented programmatic exchange endpoint (`/oauth/v3/token`), which returns an `access_token` and `refresh_token` after exchanging the authorization code."
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:53.221Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
                    "sha256:929d49a1c440333888c5d6738393daacd64d7f548717a0bc7996db44be9de8a5"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 9455,
                      "end_byte": 10255,
                      "value_digest": "sha256:24133138d75db762d8a551b8c4d358ebf7bf9d5344204d20d12dc5f31e3808cf"
                    },
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 16246,
                      "end_byte": 17059,
                      "value_digest": "sha256:f36b7933ec2251b2966945bcca313d317a5709c50e30516da7bfb31530186eb7"
                    }
                  ]
                }
              ],
              "note": "A synchronous POST request to create a CRM object directly returns HTTP status code 201 with the created public object, including its unique ID, timestamps (createdAt, updatedAt), and property key-value pairs."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:53.221Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "crm-operations"
                },
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                    "sha256:2ea829f005414a1e93b2cdc6ff239305d4a2061d09d8eec77904ee121dc79372",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                    "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
                    "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
                    "sha256:f0f4e982de78090268e4a3f78eecb631705526a1ad52cd42de9fcde37c0c9f01"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 10256,
                      "end_byte": 11041,
                      "value_digest": "sha256:627552140b273c89f019f9071fe739f28d3f52c2af5076b6ac6b5bc90210b44c"
                    },
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 6263,
                      "end_byte": 7065,
                      "value_digest": "sha256:c8851a542db785b13e57b4b57d8ae02a11ef88eda692d72d06b4ff4d002d1f22"
                    },
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 10252,
                      "end_byte": 11044,
                      "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
                    },
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 8643,
                      "end_byte": 9451,
                      "value_digest": "sha256:4f9943bd3c8df365b0a5b76ff296c9552422d65e8a3cc64143dd257deba2d619"
                    }
                  ]
                }
              ],
              "note": "Provisioning of CRM objects is triggerable programmatically via a direct POST request to /crm/v3/objects/{objectType}. Additionally, OAuth app installation follows deterministically from user access authorization."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "HubSpot documents that access tokens can be refreshed using a refresh token when expired, and private app access tokens can be rotated (either immediately or scheduled for 7 days) or revoked by deleting the app, but recovery or full agent-executable lifecycle without human intervention is not established."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "HubSpot provides machine-operable HTTP API endpoints across error handling, platform usage limits, date-versioned API overview, and CRM object creation operations."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "HubSpot documents request-time authentication using Bearer access tokens generated via OAuth or private apps with scope-restricted permissions."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "HubSpot documents stable operational contracts, endpoints, request schemas, parameters, and response structures across error handling, usage guidelines, date-versioned API reference overview, and CRM object creation operations."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.795Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                    "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
                    "sha256:ad04653f6752f60e07d22bc8134224226663c290a84ef0a203b9151905e871fb"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 11045,
                      "end_byte": 11836,
                      "value_digest": "sha256:8d339c6a623686702506daa90ef3921fc5dc016efb33b357924e275c2d5aef09"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9cf9f3f3750426a003a2f5a7cf6385fa83e0923188e65779af963621c7e848a1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:8ff0d4b2afc5bde79fb3ccd3ed9c603836a056ac2b3326949fa183cadbbe1c44",
                    "sha256:c9db578e2109ea5b2bb5b9817020fac550e28cd992ddabb224eac6fae679e157",
                    "sha256:cc609a6b00edc7cdea917e19b1ef0ee97eabdd1b10fde1d4e500a87903f30a4e",
                    "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3",
                      "start_byte": 13411,
                      "end_byte": 14214,
                      "value_digest": "sha256:b2b4ef971e343fa2d2f2f397f219e0e8ae4675405edf22b489cb21266e0a62e0"
                    }
                  ]
                }
              ],
              "note": "HubSpot documents that access tokens can be refreshed using a refresh token when expired, and private app access tokens can be rotated (either immediately or scheduled for 7 days) or revoked by deleting the app, but recovery or full agent-executable lifecycle without human intervention is not established.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:36.345Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-errors"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
                    "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:ba1692d70cd807b1670a4fba10eabe5f4a79217bda9aad5bf5a8ee3027559771"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                      "start_byte": 8087,
                      "end_byte": 8877,
                      "value_digest": "sha256:f4ae78f34d6c6e0b68611889604d5bd75e3be8a417c6f8a538e6e84b2fe5c2a0"
                    }
                  ]
                }
              ],
              "note": "HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.795Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9cf9f3f3750426a003a2f5a7cf6385fa83e0923188e65779af963621c7e848a1",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:275ff04b67420a0d125842795895ef56b15e78216272a80813bfe19b9a667e97",
                    "sha256:c9db578e2109ea5b2bb5b9817020fac550e28cd992ddabb224eac6fae679e157",
                    "sha256:cc609a6b00edc7cdea917e19b1ef0ee97eabdd1b10fde1d4e500a87903f30a4e",
                    "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3",
                      "start_byte": 10368,
                      "end_byte": 11014,
                      "value_digest": "sha256:45bbe217e840df39d07dcf7da82157fa8f1142d0bf5edc5df1af1debd0dbe5df"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                    "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
                    "sha256:b37a68692b31de8319a34a1fca284c06f51cc194782a99a8b5ef123bb371ff0c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                      "start_byte": 13456,
                      "end_byte": 14258,
                      "value_digest": "sha256:a64966c6c67a9d011c6b60fada5e03ff36513afb0e48422220edac72cd45389d"
                    }
                  ]
                }
              ],
              "note": "HubSpot documents request-time authentication using Bearer access tokens generated via OAuth or private apps with scope-restricted permissions."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:53.221Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "crm-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                    "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
                    "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
                    "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                      "start_byte": 5058,
                      "end_byte": 5859,
                      "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
                    "sha256:963f19e001ee5cdbd089968ef9f54435555634f9437bb1ee7b12f44759825678"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "crm-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 10256,
                      "end_byte": 11041,
                      "value_digest": "sha256:627552140b273c89f019f9071fe739f28d3f52c2af5076b6ac6b5bc90210b44c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
                    "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:9079190bf6145b9368d8273b31f7a48a58086a669d91082392b38de573ced2b9"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                      "start_byte": 9678,
                      "end_byte": 10483,
                      "value_digest": "sha256:d678e52c2dca044741a094a9a8d7446de2a7edc607aff34ffc18b6a43759e28c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0d9c30b23946eac421179fee1df4d8d980426370cc004146d26f4dbaef6635ef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                    "sha256:33b82e99572b25f609fdf7ab3505e8a129b0d917c236773dcf7e5f33bd991433",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:502f14c2a483ac09e6b1e29ba7360eb1b74cd60b8c8939fe70995726207be2e2"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                      "start_byte": 15797,
                      "end_byte": 16477,
                      "value_digest": "sha256:0f82f983fd1280996544285aa84471c6893e1688a9f0aab82d05ea13e387b46d"
                    }
                  ]
                }
              ],
              "note": "HubSpot documents stable operational contracts, endpoints, request schemas, parameters, and response structures across error handling, usage guidelines, date-versioned API reference overview, and CRM object creation operations."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:53.221Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "crm-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5c84abbbc34abddb1fcf0efa188d3d91ca5fd66a6f0e5f4722825b9d59241878",
                    "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "crm-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                      "start_byte": 8654,
                      "end_byte": 9454,
                      "value_digest": "sha256:664c44f6c3a1e8e9c5c6d96f54ab232e18dc757695800be045d1bfb8cb444377"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                    "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
                    "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
                    "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                      "start_byte": 5058,
                      "end_byte": 5859,
                      "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
                    "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:af0f7c906ab713ce61017091a9afe018b31cca371b1ed98484cb97e080bce5d7"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                      "start_byte": 5688,
                      "end_byte": 6492,
                      "value_digest": "sha256:643bd4ee76d90d39b7d2420278ac3aa33a0e893bd9939b91219bf8c483e8a9a6"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0d9c30b23946eac421179fee1df4d8d980426370cc004146d26f4dbaef6635ef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:502f14c2a483ac09e6b1e29ba7360eb1b74cd60b8c8939fe70995726207be2e2",
                    "sha256:faf3f8e7dce0e3875b88fdaf4548b31aa56a9d2febcf82a837fb9eca79479f05"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                      "start_byte": 8574,
                      "end_byte": 9372,
                      "value_digest": "sha256:86db9d7762823f78e6ddd5a45d43a168a8f6516303db6455a0112536c72479c5"
                    }
                  ]
                }
              ],
              "note": "HubSpot provides machine-operable HTTP API endpoints across error handling, platform usage limits, date-versioned API overview, and CRM object creation operations."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:53.221Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:0d7fecfe0addc0de8d4005dab6d5f11106a2459b923c56efd56350ee5fe26b10",
          "sha256:16aab8a0bd4fc7b61cc9191f8ebf1e364a4dc0ca1536908028382e60ce79c3ce",
          "sha256:1848730abfe547eb8467e9aed6f21a3445a00351bdc1ff6434dd8883be6c6956",
          "sha256:1d54f0e6a0739c9ff926e32f5f17ca8011aec8eac11007ae7d60319d9231476d",
          "sha256:25c439600c752bf76ca744658e664e3fb277db2bbf7e744dd7be7d04bce36b1c",
          "sha256:27070d0713737b6b1f6aec7cf303f61e5444558ddc4f7985c73ee09c2b096d51",
          "sha256:305a35a90469fd2f8ed150ffb6036a44133dd849da56862b2cd8385d93b8e8cc",
          "sha256:41f450d0216dd64b8185a4969b41e06b8218bebc66179257a809950d70610a56",
          "sha256:50d4a07c2e0911481c5a2bb212780b814601492becf8be83d7b186299890015b",
          "sha256:54a3459f5a827bd915f2723c79dd7a4a80010c5299517d822bfc79ea00527a63",
          "sha256:54f0c718496e8007a253a2d074a2a2c780c2aab0ca42dd5b1e760de6c08dc2f6",
          "sha256:65121df6197d2c12c235813ed11a4568607fccdbfc3d8cde137c9591bf11bbfe",
          "sha256:6757655d9fea384610c4a88746e55f1ad431e8e25310314ed7efe346fc681c9a",
          "sha256:6b3adac73609d0987bd73fc922e36dd429425479c22c49d6d576404ab99b45b8",
          "sha256:7e1b5f5564a02e6192871c3bf1784c770a4522101954282dbe289950ed206f0a",
          "sha256:8c33fd14a100a5c76987c072669bd65ec94e368ad49e761439babec8c3ea6425",
          "sha256:8e95c09a86aa0e2aa0172bb97c8b7e1fdf552c37e0c672c1d3beac5911cd70b7",
          "sha256:95762d2fc287047b24f84596c84fccad4e1609adfebf663ec46932388a2984d5",
          "sha256:960e1b20393bbee78ad262ec9e83caef53f8670702c64c55f6a825c187de32a3",
          "sha256:9acf41559ed250b9cf5628c2ab2800c4fb80237eaf7e7790600aec8adbca3ed3",
          "sha256:9cf5d123ba2edd0f61a449c8160d39664e9519d1cfc9fe4ce89709a1e64de9be",
          "sha256:a15bb16c0c27c58d03578d1e953874a0eead7806bdcf80f6181507811965dd95",
          "sha256:a6726a251ca7b95ee91d06ef377a7ffc819f622bc75b33b38939a53c3857dd89",
          "sha256:abb63143704ea00779eedb42fe6dc9fecc67da23897fb51c4a2a2ca4ee080eef",
          "sha256:af727143a252cbda7dd11d37e4b70ba2874539cfc93ef1de2003878f168e6eca",
          "sha256:b4621a81733fd4a5b544cca639e656cee62b5f3d8ba03760eb425e18ab7259dd",
          "sha256:c3b4f87f622565915c03f5ce1666bec84ce8bb2b3f939b5f4a0f9aa28192b508",
          "sha256:d59376b3908ff6af3fc8b5a70a782dd7bb0589137881c53c344561abc901d550",
          "sha256:daf8d5c907937ac5f55c491cff3ad10205978bdf2d04f77779c2ebae3085d9b5",
          "sha256:db4a39663378c6425770187eeffb9cc6b9475a4b4b68e10a9bd5038c8de7c11e",
          "sha256:dddf19476b68717a9b47ab905d261f4c5357be3d9a622738df396ac1e02b982e",
          "sha256:e3cede3f204a125a15b5adb19a6368531d3e872f9a6a5f283d8de6a168eb2a93",
          "sha256:e66993c3e9ba98cd08b56d69a5a11d0b93bdc71fee5c924c767fd27038cfb2e2",
          "sha256:ee5ce670f6f607756fc6f42627f569a79251184780208c3608b115568963ad17",
          "sha256:f83d65a9ae9fedcb4cd5d2d194d4074b13b9dbfaf2931d81e399d681483e26d0",
          "sha256:fd7dccce913232dae2c4cadb623ff4b0def04d2f92259fcc9406f65553d4654e",
          "sha256:ffcd33b39d7aa572436bb7696946d526530c094fd1e9821b6ea2f27f7c647ac5"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:25c439600c752bf76ca744658e664e3fb277db2bbf7e744dd7be7d04bce36b1c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:59.567Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:16aab8a0bd4fc7b61cc9191f8ebf1e364a4dc0ca1536908028382e60ce79c3ce",
              "sha256:abb63143704ea00779eedb42fe6dc9fecc67da23897fb51c4a2a2ca4ee080eef"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:28.788Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:8e95c09a86aa0e2aa0172bb97c8b7e1fdf552c37e0c672c1d3beac5911cd70b7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:33.602Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:af727143a252cbda7dd11d37e4b70ba2874539cfc93ef1de2003878f168e6eca",
              "sha256:c3b4f87f622565915c03f5ce1666bec84ce8bb2b3f939b5f4a0f9aa28192b508"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:46.600Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:dddf19476b68717a9b47ab905d261f4c5357be3d9a622738df396ac1e02b982e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.686Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:41f450d0216dd64b8185a4969b41e06b8218bebc66179257a809950d70610a56"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.686Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:0d7fecfe0addc0de8d4005dab6d5f11106a2459b923c56efd56350ee5fe26b10",
              "sha256:1d54f0e6a0739c9ff926e32f5f17ca8011aec8eac11007ae7d60319d9231476d"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.686Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:d59376b3908ff6af3fc8b5a70a782dd7bb0589137881c53c344561abc901d550"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:20.089Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:a6726a251ca7b95ee91d06ef377a7ffc819f622bc75b33b38939a53c3857dd89"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.686Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:a15bb16c0c27c58d03578d1e953874a0eead7806bdcf80f6181507811965dd95",
              "sha256:db4a39663378c6425770187eeffb9cc6b9475a4b4b68e10a9bd5038c8de7c11e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:10.312Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:8c33fd14a100a5c76987c072669bd65ec94e368ad49e761439babec8c3ea6425",
              "sha256:95762d2fc287047b24f84596c84fccad4e1609adfebf663ec46932388a2984d5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:28.788Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:960e1b20393bbee78ad262ec9e83caef53f8670702c64c55f6a825c187de32a3",
              "sha256:9cf5d123ba2edd0f61a449c8160d39664e9519d1cfc9fe4ce89709a1e64de9be"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:10.312Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:1848730abfe547eb8467e9aed6f21a3445a00351bdc1ff6434dd8883be6c6956"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:10.312Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:27070d0713737b6b1f6aec7cf303f61e5444558ddc4f7985c73ee09c2b096d51",
              "sha256:54f0c718496e8007a253a2d074a2a2c780c2aab0ca42dd5b1e760de6c08dc2f6"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.795Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:daf8d5c907937ac5f55c491cff3ad10205978bdf2d04f77779c2ebae3085d9b5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:53.221Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:e3cede3f204a125a15b5adb19a6368531d3e872f9a6a5f283d8de6a168eb2a93",
              "sha256:ffcd33b39d7aa572436bb7696946d526530c094fd1e9821b6ea2f27f7c647ac5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:53.221Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:50d4a07c2e0911481c5a2bb212780b814601492becf8be83d7b186299890015b",
              "sha256:6b3adac73609d0987bd73fc922e36dd429425479c22c49d6d576404ab99b45b8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.795Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:6757655d9fea384610c4a88746e55f1ad431e8e25310314ed7efe346fc681c9a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:36.345Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:54a3459f5a827bd915f2723c79dd7a4a80010c5299517d822bfc79ea00527a63",
              "sha256:9acf41559ed250b9cf5628c2ab2800c4fb80237eaf7e7790600aec8adbca3ed3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.795Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:b4621a81733fd4a5b544cca639e656cee62b5f3d8ba03760eb425e18ab7259dd",
              "sha256:e66993c3e9ba98cd08b56d69a5a11d0b93bdc71fee5c924c767fd27038cfb2e2",
              "sha256:ee5ce670f6f607756fc6f42627f569a79251184780208c3608b115568963ad17",
              "sha256:f83d65a9ae9fedcb4cd5d2d194d4074b13b9dbfaf2931d81e399d681483e26d0"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:53.221Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:305a35a90469fd2f8ed150ffb6036a44133dd849da56862b2cd8385d93b8e8cc",
              "sha256:65121df6197d2c12c235813ed11a4568607fccdbfc3d8cde137c9591bf11bbfe",
              "sha256:7e1b5f5564a02e6192871c3bf1784c770a4522101954282dbe289950ed206f0a",
              "sha256:fd7dccce913232dae2c4cadb623ff4b0def04d2f92259fcc9406f65553d4654e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:53.221Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/hubspot/agent-readiness/hubspot-crm-api/api-integration-lifecycle",
      "projection_digest": "sha256:84d418ca7f69282903be7bc9169615e2e84d9c809e83c5626f3d702ada104859"
    }
  }
}
