{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8fpe3n3yye39kmzvy410z",
    "entity_slug": "microsoft",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzd4bb9sf13ma4xaxb73d82x",
      "entity_id": "ent_01kyh8fpe3n3yye39kmzvy410z",
      "scope": {
        "product": {
          "key": "microsoft-azure",
          "name": "Microsoft Azure"
        },
        "funnel": {
          "key": "api-resource-management",
          "name": "API resource management"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:a569131c2422a72436aea7d8dfa1b846f87a3500dbc533c3ea06bfd806a27e2f"
      },
      "declaration_revision_digest": "sha256:09908c134571099e159f32d6a22b43bd4d2339e76a76a46a8f069eae13fc12b7",
      "declaration": {
        "declaration_id": "declaration_microsoft_azure_api_resource_management",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/mi/microsoft.yaml",
          "git_blob_oid": "5f06a651093c6af9deefb3daaa1f1d34aeaf52ca",
          "blob_digest": "sha256:a64663f982135b87d243a1279283d28360f901a89dd0c50e9314eef437d4a4a3"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "cost-visibility",
            "name": "Microsoft Azure cost visibility",
            "interface_ids": [
              "pricing-and-cost"
            ]
          },
          {
            "target_id": "service-use",
            "name": "Create and reconcile Azure resource groups through the API",
            "interface_ids": [
              "azure-resource-manager"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "microsoft",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8fpe3n3yye39kmzvy410z"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "asynchronous-operations",
            "uri": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/async-operations",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-account",
            "uri": "https://signup.azure.com/",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-legal",
            "uri": "https://azure.microsoft.com/en-us/support/legal/",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-pricing",
            "uri": "https://azure.microsoft.com/en-us/pricing/",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-product-terms",
            "uri": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftAzure/MCA",
            "roles": [
              "eligibility",
              "terms"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-rest-api",
            "uri": "https://learn.microsoft.com/en-us/rest/api/azure/",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "azure-support",
            "uri": "https://azure.microsoft.com/en-us/support/options/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/change-credit-card",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "client-credentials",
            "uri": "https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow",
            "roles": [
              "authentication",
              "descriptor",
              "documentation"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "implements"
              }
            ]
          },
          {
            "resource_id": "cost-management-permissions",
            "uri": "https://learn.microsoft.com/en-us/azure/cost-management-billing/automate/cost-management-api-permissions",
            "roles": [
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2",
            "uri": "https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/create-subscription",
            "roles": [
              "access",
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "resource-group-api",
            "uri": "https://learn.microsoft.com/en-us/rest/api/resources/resource-groups/create-or-update?view=rest-resources-2021-04-01&tabs=HTTP",
            "roles": [
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "resource-manager-limits",
            "uri": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/request-limits-and-throttling",
            "roles": [
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "resource-manager-rest",
            "uri": "https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/manage-resources-rest?tabs=azure-cli",
            "roles": [
              "documentation",
              "operations",
              "provisioning"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "retail-prices-api",
            "uri": "https://learn.microsoft.com/en-us/rest/api/cost-management/retail-prices/azure-retail-prices",
            "roles": [
              "documentation",
              "operations",
              "pricing"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "resource_id": "service-principals",
            "uri": "https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals?tabs=browser",
            "roles": [
              "authentication",
              "descriptor",
              "documentation"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "uses"
              }
            ]
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "azure-resource-manager",
            "uri": "https://management.azure.com",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "endpoint_id": "entra-token",
            "uri": "https://login.microsoftonline.com/organizations/oauth2/v2.0/token",
            "transport": "http",
            "roles": [
              "authorization",
              "token"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "implements"
              }
            ]
          },
          {
            "endpoint_id": "registration",
            "uri": "https://signup.azure.com/",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "endpoint_id": "retail-prices",
            "uri": "https://prices.azure.com/api/retail/prices",
            "transport": "http",
            "roles": [
              "service"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "azure-resource-manager",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "azure-resource-manager"
            ],
            "resource_ids": [
              "asynchronous-operations",
              "azure-rest-api",
              "resource-group-api",
              "resource-manager-limits",
              "resource-manager-rest"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "interface_id": "pricing-and-cost",
            "modality": "network_api",
            "functions": [
              "commerce",
              "service_operation"
            ],
            "endpoint_ids": [
              "retail-prices"
            ],
            "resource_ids": [
              "azure-pricing",
              "cost-management-permissions",
              "retail-prices-api"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": []
          },
          {
            "interface_id": "workload-authentication",
            "modality": "network_api",
            "functions": [
              "authentication",
              "service_operation"
            ],
            "endpoint_ids": [
              "entra-token"
            ],
            "resource_ids": [
              "client-credentials",
              "service-principals"
            ],
            "operated_by_participant_id": "microsoft",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "uses"
              }
            ]
          }
        ],
        "relations": [
          {
            "relation_id": "account-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "azure-account"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "workload-authentication"
            }
          },
          {
            "relation_id": "authentication-authenticates-resource-manager",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "workload-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "azure-resource-manager"
            }
          },
          {
            "relation_id": "client-credentials-describe-authentication",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "client-credentials"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "workload-authentication"
            }
          },
          {
            "relation_id": "pricing-docs-describe-interface",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "retail-prices-api"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "pricing-and-cost"
            }
          },
          {
            "relation_id": "resource-creation-precedes-status",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "resource-group-api"
            },
            "to": {
              "node_kind": "resource",
              "node_id": "asynchronous-operations"
            }
          },
          {
            "relation_id": "resource-manager-docs-describe-interface",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "resource-manager-rest"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "azure-resource-manager"
            }
          }
        ],
        "surface_exclusions": []
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:d45bbb78155dd2d5effd1c9fa8b38590b6854a621ceffff10799b645e3065aad",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "evaluate",
        "stage_label": "Evaluate",
        "public_state": "limited",
        "finding": {
          "signal_code": "eligibility_decidability",
          "condition": "Can an agent decide every material eligibility condition before commitment?",
          "finding": "Only some material eligibility conditions are decidable before commitment.",
          "context": "Microsoft Azure Product Terms define specific registration and compliance requirements for Limited Access Services (such as certain Azure AI Services), requiring accurate registration forms. However, generic eligibility criteria across all Azure services are not fully detailed in this excerpt."
        }
      },
      "limitations": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "Microsoft Azure Product Terms define specific registration and compliance requirements for Limited Access Services (such as certain Azure AI Services), requiring accurate registration forms. However, generic eligibility criteria across all Azure services are not fully detailed in this excerpt."
          },
          "remediation": {
            "signal_code": "eligibility_decidability",
            "code": "improve.evaluate.eligibility_decidability",
            "instruction": "State every material eligibility condition and required input explicitly."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "provisioning_completion",
            "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
            "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
            "context": "Azure Resource Manager asynchronous operations report status via response codes (201, 202) and header polling URLs (Azure-AsyncOperation), exposing progress percentComplete, terminal provisioningState values (Succeeded, Failed, Canceled), and error details on failure. However, an explicit time or delay bound and specific reconciliation properties are not fully established in the evidence."
          },
          "remediation": {
            "signal_code": "provisioning_completion",
            "code": "improve.provision.provisioning_completion",
            "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Azure Resource Manager documentation details status codes for tracking long-running asynchronous operations, headers like Azure-AsyncOperation and Retry-After, provisioning states (Succeeded, Failed, Canceled), and error response objects. However, explicit cancellation and idempotency semantics for all operations remain unevidenced."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Microsoft identity platform documentation describes credential security boundaries and mentions rotating/protecting client secrets or certificates. Furthermore, Entra service principal documentation details application deactivation, deletion, and recovery options, but explicit procedures for complete automated credential rotation and compromise recovery across all credential types remain unevidenced."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "Microsoft Azure Product Terms define specific registration and compliance requirements for Limited Access Services (such as certain Azure AI Services), requiring accurate registration forms. However, generic eligibility criteria across all Azure services are not fully detailed in this excerpt."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "service_discovery",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "context": "The Azure REST API reference documentation explicitly provides public documentation, HTTP methods, and guidance for discovering and calling stable Azure service REST API endpoints."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "Applicable legal terms and product conditions, including the Microsoft Customer Agreement (MCA) and Universal License Terms for Online Services, are publicly retrievable and explicitly defined on Microsoft Azure legal and product terms pages."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Azure pricing models and currencies (USD worldwide) are explicit through the Azure pricing documentation and the Azure Retail Prices REST API, which provides unauthenticated programmatic access to retail rates, SKUs, and meter details."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:15.463Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-product-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:80a2d21a964452c667661a769f7db4e95b9ea2133b29d9151a5bd0a23a012389",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1d9a3b4e2af771e4beed5f4f02c00a08a00845c6afd1a822a58e5f8ff0218a91",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:bc0e368fc06786b1e198493ad60d2d5e8f486e4ed7624512d1af3a5ea42076c6",
                    "sha256:bdcfa4543d3aa774841e206db4142b0130f2189ca816b0dc83e182e151dc7b09"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-product-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:bc0e368fc06786b1e198493ad60d2d5e8f486e4ed7624512d1af3a5ea42076c6",
                      "start_byte": 119256,
                      "end_byte": 120049,
                      "value_digest": "sha256:4a40493c86e747ce2f55bc3e94aee920367431d91e56293eb5a3735f6458fcc0"
                    }
                  ]
                }
              ],
              "note": "Microsoft Azure Product Terms define specific registration and compliance requirements for Limited Access Services (such as certain Azure AI Services), requiring accurate registration forms. However, generic eligibility criteria across all Azure services are not fully detailed in this excerpt.",
              "remediation": {
                "signal_code": "eligibility_decidability",
                "code": "improve.evaluate.eligibility_decidability",
                "instruction": "State every material eligibility condition and required input explicitly."
              }
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.534Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-pricing"
                },
                {
                  "node_kind": "resource",
                  "node_id": "retail-prices-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:573ca29fe9d943a1d3397c8b4116d80dad8fdcc4bbf35c4838dbc47403a9c781",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f6fd28fecf901b709fdfac86771bcb9f39de6b6f0b7f1de6ff96a43924099d8",
                    "sha256:bd5eec3b2693115d26badbbb0636edb861de7a9176e6068ce296a2675e62fc91"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "retail-prices-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                      "start_byte": 5231,
                      "end_byte": 6028,
                      "value_digest": "sha256:c883979935aa613b52dc9efc85753bbc532a811e1bb29198e3318e5d53592cc2"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e139df7c4aec45fe07c3c7cf93a0e548525cba00065afea115a7daa79d74bcda",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:09d4a9df29e79dd9053240f625688d1d2ee182ed644a21f3246d8d5538afb10e",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                    "sha256:975747e852ce223bc5d28c49b69dc09d28b9f6df04f3c9d3c18df748b7ac6720"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                      "start_byte": 53358,
                      "end_byte": 54158,
                      "value_digest": "sha256:eb7c6003872756ad12f5626fd0ca7ce01620b77836300baa735006d4cfa578e3"
                    }
                  ]
                }
              ],
              "note": "Azure pricing models and currencies (USD worldwide) are explicit through the Azure pricing documentation and the Azure Retail Prices REST API, which provides unauthenticated programmatic access to retail rates, SKUs, and meter details."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:21.792Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-rest-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c6b1fc853a8535b52d08ad54dd99f2575d64e67ebf8c78f81d361275857b7dc5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1a9c96414360cc08031a3b78b110bd47179abdfa45f15645b4d44e5cfcb0d4fa",
                    "sha256:9ddd24caed136fc61b359cbac00275df85396f94cfd3ba79aca56ff985800f28",
                    "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                    "sha256:ec4b68b88759b5b1046c0082c31549200c1f2bb9b637f336983ab5f24321512b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                      "start_byte": 6766,
                      "end_byte": 7551,
                      "value_digest": "sha256:0d843d1c1e910002f7e68cb2e6aa0983d01f0e1b6d26fd965b61a403d9d31dd7"
                    },
                    {
                      "artifact_digest": "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                      "start_byte": 7552,
                      "end_byte": 8349,
                      "value_digest": "sha256:6bf313b5c6f03c6c08d1e143478b62e617538ff1e08bcef0ade78d3949a11d44"
                    }
                  ]
                }
              ],
              "note": "The Azure REST API reference documentation explicitly provides public documentation, HTTP methods, and guidance for discovering and calling stable Azure service REST API endpoints."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:32.666Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-legal"
                },
                {
                  "node_kind": "resource",
                  "node_id": "azure-product-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:80a2d21a964452c667661a769f7db4e95b9ea2133b29d9151a5bd0a23a012389",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0694fe89155cb05ea1b5e2a712310fedac6672fe3a7f8723eeb63adf001b58f1",
                    "sha256:1d9a3b4e2af771e4beed5f4f02c00a08a00845c6afd1a822a58e5f8ff0218a91",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:bc0e368fc06786b1e198493ad60d2d5e8f486e4ed7624512d1af3a5ea42076c6"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-product-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:bc0e368fc06786b1e198493ad60d2d5e8f486e4ed7624512d1af3a5ea42076c6",
                      "start_byte": 32903,
                      "end_byte": 33703,
                      "value_digest": "sha256:3d057b85beee66802592baa97da41fb233c17db7309032f30803dd79e567e8f3"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:710eb1324206815c64d425bff56c6b4d2bbd1b647a42b2f109809b557414f8f9",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:319f9b56a2df730a15c8c697b238d73c6ef23df45a1d5cc9af408e3c6e3ff2ff",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:69a2d4a0fab59b55677df4e339daae2279c1686d193542f6b63eb8eebfb33fdd",
                    "sha256:90f83a25f4c27fc2514c719baa4dcd1193ad03ccff1f848822451b28ebcd547e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-legal"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:319f9b56a2df730a15c8c697b238d73c6ef23df45a1d5cc9af408e3c6e3ff2ff",
                      "start_byte": 23836,
                      "end_byte": 24635,
                      "value_digest": "sha256:e08385694a5e93949f408e2f97910312d7f527557041941ce4e1ff46b254ade2"
                    }
                  ]
                }
              ],
              "note": "Applicable legal terms and product conditions, including the Microsoft Customer Agreement (MCA) and Universal License Terms for Online Services, are publicly retrievable and explicitly defined on Microsoft Azure legal and product terms pages."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "eligibility_decidability",
              "code": "improve.evaluate.eligibility_decidability",
              "instruction": "State every material eligibility condition and required input explicitly."
            }
          ]
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "A stable canonical route begins the required access bootstrap.",
            "context": "Azure sign-up begins at signup.azure.com, and documented access route instructions direct users to sign in to the Azure portal, navigate to Subscriptions, and select Add."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained capture from signup.azure.com shows only an initial sign-up page heading without establishing agent operability for required access controls, navigation, validation, or handoffs."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured sign-up page and subscription documentation do not provide explicit evidence regarding whether a mandatory CAPTCHA challenge is present or if a verified-agent alternative exists across the flow."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The admitted captures do not state phone verification requirements or define a supported resumable boundary for phone verification."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "context": "Microsoft Entra supports the OAuth 2.0 client credentials grant flow for machine-to-machine authentication using app-only tokens, service principals, and managed identities to obtain scoped, revocable access."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:33.219Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained capture from signup.azure.com shows only an initial sign-up page heading without establishing agent operability for required access controls, navigation, validation, or handoffs."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:33.219Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-account"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d70ff743835f9ce7a3f2cedfd5f899f4559cd580522baf6ccbde7038e2c6f6da",
                      "capture_rung": "headless"
                    },
                    {
                      "retained_capture_digest": "sha256:ed3b651c15c744f8bd0fb5f69a2b14a9d00536d583f32f0a6c31733de844f84b",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0d7f17485280193aecdc4279c9fbd0e95b792f45ec209963389f2698a349965f",
                    "sha256:28406ccdcd0961e9abd03c3f6ddd59a6a033e5b2085313ecc8a9552fa27e76c7",
                    "sha256:3878570f4a62a0d65f57cf1754e0269e56ec797f4e36e26b44c172eb6e800401",
                    "sha256:399e721bbca269ca88071a7ca78d3da4b85167f38cd737fa8128ebb7451a0825",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a4511f550faafd6dc3973bcc258596dfb0581728a4f2c34c2bde3b3915b1afa",
                    "sha256:a8ce03b1d4dc6c0ed6032917e63bbf3befd89bf03996ac86376b2382804e5bd4",
                    "sha256:ae85e860e346daee6a6248097481d40049e1dd08ce0dac986f88f6f5982e5603",
                    "sha256:d330143a1600ee39cd0cfde68bd54f9a76f22ea9bd8929ffb629f0f456156b8e",
                    "sha256:d91487f698f5fd1d809959af9553c792d0884a5b117102edf4f18d768bc24894",
                    "sha256:e7be391f41c683c5dc23f110630c343e5a395230befb3d1dfe378670beb50a1b"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:5a4511f550faafd6dc3973bcc258596dfb0581728a4f2c34c2bde3b3915b1afa",
                      "start_byte": 58,
                      "end_byte": 83,
                      "value_digest": "sha256:3309d2a80bfde468d3b973949beee621b43bc65a82148d83ef2ee99f67e94db2"
                    },
                    {
                      "artifact_digest": "sha256:a8ce03b1d4dc6c0ed6032917e63bbf3befd89bf03996ac86376b2382804e5bd4",
                      "start_byte": 21721,
                      "end_byte": 22514,
                      "value_digest": "sha256:803a365a8e14bba3e0e966249890ac5f3f5e83970cc12f5b55ed0fa893fdaec0"
                    }
                  ]
                }
              ],
              "note": "Azure sign-up begins at signup.azure.com, and documented access route instructions direct users to sign in to the Azure portal, navigate to Subscriptions, and select Add."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:33.219Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "azure-account"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured sign-up page and subscription documentation do not provide explicit evidence regarding whether a mandatory CAPTCHA challenge is present or if a verified-agent alternative exists across the flow."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.989Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "client-credentials"
                },
                {
                  "node_kind": "resource",
                  "node_id": "service-principals"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:3cc787588feddf8a0435ffeb854e7b74ee011ce195c496d5373918c9543c3cc6",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:a1a095423bdfa1b5b61d561d7ec66957142c5babcdf136b18317a108a4653079",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4683447223afe123439d014d949336a8f31162259128813a730bb0a63d924266",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                    "sha256:843c236023beee02551e125ea4c50471b391d9d99e1a10b1603c4d39e29fc8d6",
                    "sha256:8a26e659150dceb05e95ce6ea21a302817aa81602ca301e6347ad8d0d3e61b5b",
                    "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                    "sha256:db294f18b53a3c264a319c05afb29ee39fec95765b0211e4777e2791e765cfa9"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                      "start_byte": 17077,
                      "end_byte": 17877,
                      "value_digest": "sha256:d52edc6968e20da6ec5f2bbcf6728c4ed2b3dc3a74ed2cab0d28a6f71ffeecfc"
                    },
                    {
                      "artifact_digest": "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                      "start_byte": 6680,
                      "end_byte": 7484,
                      "value_digest": "sha256:07e6a9632a7e59f0b3f67d8910f56847a209a90a1fbd13cbf258a83c7c601188"
                    },
                    {
                      "artifact_digest": "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                      "start_byte": 9968,
                      "end_byte": 10765,
                      "value_digest": "sha256:5d63818fa83678de1ba65b255c03d32d358d4420a5b51779c962b21c8e2d817a"
                    }
                  ]
                }
              ],
              "note": "Microsoft Entra supports the OAuth 2.0 client credentials grant flow for machine-to-machine authentication using app-only tokens, service principals, and managed identities to obtain scoped, revocable access."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:33.219Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-account"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The admitted captures do not state phone verification requirements or define a supported resumable boundary for phone verification."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Azure explicitly discloses its pay-as-you-go consumption model, USD currency default, and available commitment offers (such as reservations and savings plans) on its pricing page and through the Retail Rates Prices API."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence describes adding or replacing credit cards in the Azure portal, but does not establish a complete end-to-end flow for deterministic agent checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence details requiring account administrator or specific Microsoft Customer Agreement roles to manage payment methods, but does not state a documented rail for scoped delegation or explicit human-confirmed authorization with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "Documentation provides a direct self-service procedure in the Azure portal under Subscriptions > Add to select a billing account, billing profile, invoice section, and plan to create a new subscription immediately without vendor intervention."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:19.145Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence describes adding or replacing credit cards in the Azure portal, but does not establish a complete end-to-end flow for deterministic agent checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.534Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "azure-pricing"
                },
                {
                  "node_kind": "resource",
                  "node_id": "retail-prices-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:573ca29fe9d943a1d3397c8b4116d80dad8fdcc4bbf35c4838dbc47403a9c781",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f6fd28fecf901b709fdfac86771bcb9f39de6b6f0b7f1de6ff96a43924099d8",
                    "sha256:bd5eec3b2693115d26badbbb0636edb861de7a9176e6068ce296a2675e62fc91"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "retail-prices-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                      "start_byte": 5231,
                      "end_byte": 6028,
                      "value_digest": "sha256:c883979935aa613b52dc9efc85753bbc532a811e1bb29198e3318e5d53592cc2"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e139df7c4aec45fe07c3c7cf93a0e548525cba00065afea115a7daa79d74bcda",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5a0ff1d035a5178c71dff0dd3966d7707cba544b952d0098a3889b554367dd2c",
                    "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                    "sha256:975747e852ce223bc5d28c49b69dc09d28b9f6df04f3c9d3c18df748b7ac6720"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                      "start_byte": 34280,
                      "end_byte": 35076,
                      "value_digest": "sha256:b381e3d3d218ff3de613de8d1cd09343045ef9ebf4a60d52d1449479c362ee9b"
                    }
                  ]
                }
              ],
              "note": "Azure explicitly discloses its pay-as-you-go consumption model, USD currency default, and available commitment offers (such as reservations and savings plans) on its pricing page and through the Retail Rates Prices API."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:19.145Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence details requiring account administrator or specific Microsoft Customer Agreement roles to manage payment methods, but does not state a documented rail for scoped delegation or explicit human-confirmed authorization with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:57.916Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:22f1b088451d2ed8abb58e6c113b7265544da2063dae7a29cbe6a1c9102b10cb",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:72569286367920b2440f7121cca75e28e2d8625e723bd10fe3b4a47f8e8175c8",
                    "sha256:92aacd77a5db56876e646c7fdcb36a66ad2dd2e7316dce423df61dd73aedcd5d",
                    "sha256:9a1c7515c0c9ae778fb7f0fb19925472c244bae1f5b7220f7e532a2c6386c5ec"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-2c5e3e9374587cf94c00720160f0e60599f3d9aa340b5adf2c017bf2fc97eea2"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9a1c7515c0c9ae778fb7f0fb19925472c244bae1f5b7220f7e532a2c6386c5ec",
                      "start_byte": 8893,
                      "end_byte": 9691,
                      "value_digest": "sha256:c76a19fc874b9dba8763ea539cab707b4eba1456323516aca4e4d340f5ed5c17"
                    }
                  ]
                }
              ],
              "note": "Documentation provides a direct self-service procedure in the Azure portal under Subscriptions > Add to select a billing account, billing profile, invoice section, and plan to create a new subscription immediately without vendor intervention."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "provisioning_completion",
            "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
            "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
            "context": "Azure Resource Manager asynchronous operations report status via response codes (201, 202) and header polling URLs (Azure-AsyncOperation), exposing progress percentComplete, terminal provisioningState values (Succeeded, Failed, Canceled), and error details on failure. However, an explicit time or delay bound and specific reconciliation properties are not fully established in the evidence."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "Resource provisioning can be initiated programmatically via Azure Resource Manager REST APIs, including PUT requests to create or update resource groups, storage accounts, or deploy ARM templates directly using Bearer authorization tokens."
            },
            {
              "signal_code": "access_material_delivery",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "context": "Documented agent-usable flows allow acquiring access material. The OAuth 2.0 client credentials flow supports POST requests to the /token endpoint with client_secret, certificate assertion, or federated credentials to receive an access token. Additionally, app registration and service principal creation provide client IDs and allow adding secrets or certificates programmatically."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.989Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "client-credentials"
                },
                {
                  "node_kind": "resource",
                  "node_id": "service-principals"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:3cc787588feddf8a0435ffeb854e7b74ee011ce195c496d5373918c9543c3cc6",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3f7f1ea3d01ec466dca3acd6186490b3ca1c68ad7a626f7580074f42ecc459ca",
                    "sha256:4683447223afe123439d014d949336a8f31162259128813a730bb0a63d924266",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "client-credentials"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                      "start_byte": 17077,
                      "end_byte": 17877,
                      "value_digest": "sha256:d52edc6968e20da6ec5f2bbcf6728c4ed2b3dc3a74ed2cab0d28a6f71ffeecfc"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1a095423bdfa1b5b61d561d7ec66957142c5babcdf136b18317a108a4653079",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:995c150ec761cbbd8276f7f02fde54c3dcb283b05c4192698732741177bc5680",
                    "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                    "sha256:db294f18b53a3c264a319c05afb29ee39fec95765b0211e4777e2791e765cfa9"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-principals"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                      "start_byte": 6785,
                      "end_byte": 7585,
                      "value_digest": "sha256:ecba293c95f884505416cbc109113e4074211c5b73584c250bc0026be287a3e7"
                    }
                  ]
                }
              ],
              "note": "Documented agent-usable flows allow acquiring access material. The OAuth 2.0 client credentials flow supports POST requests to the /token endpoint with client_secret, certificate assertion, or federated credentials to receive an access token. Additionally, app registration and service principal creation provide client IDs and allow adding secrets or certificates programmatically."
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:58.337Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "asynchronous-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:06ffdb7db0dc64d937f06d8ac58a901758666712e0563d03a6f436edbc5bec15",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a0dce3ff97e1e6cf4a7a14186b27535a7c30bd72c4353ab155d7da70e000cf9a",
                    "sha256:fc777a3a94946520e0ba0eb2428783897f27151baffcaaa82c36c69bc1d2e572"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "asynchronous-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 5893,
                      "end_byte": 6685,
                      "value_digest": "sha256:5a4a4c167c559c98ff76fb149c135aed00f9bb6dbdbeb3dcd4b5f228fbbc0e2b"
                    },
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 9081,
                      "end_byte": 9880,
                      "value_digest": "sha256:5856909e1cdaed92d9597fa5828a0400da360c535e04d11199c19f36564322cf"
                    }
                  ]
                }
              ],
              "note": "Azure Resource Manager asynchronous operations report status via response codes (201, 202) and header polling URLs (Azure-AsyncOperation), exposing progress percentComplete, terminal provisioningState values (Succeeded, Failed, Canceled), and error details on failure. However, an explicit time or delay bound and specific reconciliation properties are not fully established in the evidence.",
              "remediation": {
                "signal_code": "provisioning_completion",
                "code": "improve.provision.provisioning_completion",
                "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
              }
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:24.579Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "asynchronous-operations"
                },
                {
                  "node_kind": "resource",
                  "node_id": "resource-group-api"
                },
                {
                  "node_kind": "resource",
                  "node_id": "resource-manager-rest"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:453620f56583f5e64fb84f3a679afc4f06207f6375dfcd98db33f847e308afed",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                    "sha256:3cc83e3fb6949ce0365241cd5ce5f7a08a8dec19898c64f58b64697ef9252048",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:da9e4e5a9b0ff5cdc6b447545d6ea635ba6f3edc669e0419ab83886b4514cc54"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-manager-rest"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                      "start_byte": 9806,
                      "end_byte": 10516,
                      "value_digest": "sha256:a19523d6c8f20bbaf67569684937f3e5322c30972bbec29b647fc190d4b60045"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2e14a895bbe8486033e8e2509dc05d8f10a3dd031b3d0d1e0c99fda3e763928b",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:055151cd7e4541b00378aa0fce9903c615fd1f53ae67f44669f7165ed8aecac0",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69",
                    "sha256:f8db1e193feaa765a1af9364d17ccd80bbaaa85ded8b23ef9f410b47ad604a93"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-group-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69",
                      "start_byte": 4795,
                      "end_byte": 5594,
                      "value_digest": "sha256:8e73fccb7ab28e2aa56bd3d56795fdd6f9856a32b50d022b6a7d29d1c7ef8cd4"
                    }
                  ]
                }
              ],
              "note": "Resource provisioning can be initiated programmatically via Azure Resource Manager REST APIs, including PUT requests to create or update resource groups, storage accounts, or deploy ARM templates directly using Bearer authorization tokens."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "provisioning_completion",
              "code": "improve.provision.provisioning_completion",
              "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Azure Resource Manager documentation details status codes for tracking long-running asynchronous operations, headers like Azure-AsyncOperation and Retry-After, provisioning states (Succeeded, Failed, Canceled), and error response objects. However, explicit cancellation and idempotency semantics for all operations remain unevidenced."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "Microsoft identity platform documentation describes credential security boundaries and mentions rotating/protecting client secrets or certificates. Furthermore, Entra service principal documentation details application deactivation, deletion, and recovery options, but explicit procedures for complete automated credential rotation and compromise recovery across all credential types remain unevidenced."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Machine-operable interfaces including REST APIs, Azure CLI, Azure PowerShell, and SDKs are documented and accessible across all assessed Azure service targets."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "Microsoft identity platform and Entra ID document service operation authentication using OAuth 2.0 client credentials grant flow (shared secrets, certificates, or federated credentials) and scoped service principals to acquire Bearer tokens for server-to-server interactions without user involvement."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Across all required targets, Azure REST APIs and pricing services provide documented, stable endpoints, HTTP methods, request parameters, JSON response schemas, HTTP status codes, example payloads, and effect semantics."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.989Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "client-credentials"
                },
                {
                  "node_kind": "resource",
                  "node_id": "service-principals"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1a095423bdfa1b5b61d561d7ec66957142c5babcdf136b18317a108a4653079",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:68bd24794b8c027e73d48600534df0ee8288bd547a1dc8a1fc4850c247d25e38",
                    "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                    "sha256:db294f18b53a3c264a319c05afb29ee39fec95765b0211e4777e2791e765cfa9"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-principals"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                      "start_byte": 13153,
                      "end_byte": 13950,
                      "value_digest": "sha256:ea35599d4d630c18462c2d7c19faae966e17e6240ef6d22014c62782baf38da8"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:3cc787588feddf8a0435ffeb854e7b74ee011ce195c496d5373918c9543c3cc6",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4683447223afe123439d014d949336a8f31162259128813a730bb0a63d924266",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                    "sha256:862a715a45fc13adf2934ab3c65ad67363d161d076452fdeff68a99daacfb49e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "client-credentials"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                      "start_byte": 8282,
                      "end_byte": 9080,
                      "value_digest": "sha256:b1fd0df5795afbd1c68d8dedbd16faf25cb7b4bf1606bf05afb5ea2f35ae37ae"
                    }
                  ]
                }
              ],
              "note": "Microsoft identity platform documentation describes credential security boundaries and mentions rotating/protecting client secrets or certificates. Furthermore, Entra service principal documentation details application deactivation, deletion, and recovery options, but explicit procedures for complete automated credential rotation and compromise recovery across all credential types remain unevidenced.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:58.337Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "asynchronous-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:06ffdb7db0dc64d937f06d8ac58a901758666712e0563d03a6f436edbc5bec15",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f212ee577b8cdcd3491bce8bd80aac75bfedaa3c67c39f0c8af5b6df0da10e1",
                    "sha256:fc777a3a94946520e0ba0eb2428783897f27151baffcaaa82c36c69bc1d2e572"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "asynchronous-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 5893,
                      "end_byte": 6685,
                      "value_digest": "sha256:5a4a4c167c559c98ff76fb149c135aed00f9bb6dbdbeb3dcd4b5f228fbbc0e2b"
                    },
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 6686,
                      "end_byte": 7482,
                      "value_digest": "sha256:5f3e512ea3bd77b848b11c61b46349a5a9f29ee26317e8fc7e367b3d1d39f6c8"
                    }
                  ]
                }
              ],
              "note": "Azure Resource Manager documentation details status codes for tracking long-running asynchronous operations, headers like Azure-AsyncOperation and Retry-After, provisioning states (Succeeded, Failed, Canceled), and error response objects. However, explicit cancellation and idempotency semantics for all operations remain unevidenced.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.989Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "client-credentials"
                },
                {
                  "node_kind": "resource",
                  "node_id": "service-principals"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1a095423bdfa1b5b61d561d7ec66957142c5babcdf136b18317a108a4653079",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:84b2906cc6be6a177f3e31058196eae77bae42ac909f770f0c1b9437b5bef12c",
                    "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                    "sha256:db294f18b53a3c264a319c05afb29ee39fec95765b0211e4777e2791e765cfa9"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-principals"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:d294dfa0cc4b8cd4d724fbddc4dd1506441b2f3846ecfe6054bd8ddfdfcd159f",
                      "start_byte": 8385,
                      "end_byte": 9175,
                      "value_digest": "sha256:199a24d82f1db201e97f453e11d59742b8cb175877229b08889b2d8e1503d900"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:3cc787588feddf8a0435ffeb854e7b74ee011ce195c496d5373918c9543c3cc6",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4683447223afe123439d014d949336a8f31162259128813a730bb0a63d924266",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                    "sha256:52df009d3133b360d30ce7aea0fef66e96e8d19032714695f6b1fb15785c3cd4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "client-credentials"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:51bed147e6de6ae6fc7314d995ffedab16d3d4454efb939a347bfffd2393c6bf",
                      "start_byte": 6680,
                      "end_byte": 7484,
                      "value_digest": "sha256:07e6a9632a7e59f0b3f67d8910f56847a209a90a1fbd13cbf258a83c7c601188"
                    }
                  ]
                }
              ],
              "note": "Microsoft identity platform and Entra ID document service operation authentication using OAuth 2.0 client credentials grant flow (shared secrets, certificates, or federated credentials) and scoped service principals to acquire Bearer tokens for server-to-server interactions without user involvement."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.534Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "azure-resource-manager"
                },
                {
                  "node_kind": "interface",
                  "node_id": "pricing-and-cost"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:453620f56583f5e64fb84f3a679afc4f06207f6375dfcd98db33f847e308afed",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:da9e4e5a9b0ff5cdc6b447545d6ea635ba6f3edc669e0419ab83886b4514cc54",
                    "sha256:e5e277abf8118506299fa7467e7f5155d8839347647b8952ae03f3bf0f9fbe86"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-manager-rest"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                      "start_byte": 8265,
                      "end_byte": 9011,
                      "value_digest": "sha256:3fc5c85cbd6255458d14cdf4a052a6dc0c455d41555217b2a7575ad9b6dbacde"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c14e5946ac5fecc48d7e4de303f19502f4b0143f70b4798b005d540a25e55404",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0623c7d6e5e8bc508f5283eb09045d01a506883cfd1a5c2be0ecb278f4401aa2",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:9fa5dcf7e7f0b387621b300cc17bfdbc35965f51cf2484e813c1a311a3d39cc7",
                    "sha256:c59c134af95133f2c80c5c6c5c1ffb107e52b795637fcdc4ccfe75f0c044035a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "cost-management-permissions"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9fa5dcf7e7f0b387621b300cc17bfdbc35965f51cf2484e813c1a311a3d39cc7",
                      "start_byte": 6458,
                      "end_byte": 7258,
                      "value_digest": "sha256:510f2b524ee0d6fe3adc04dccd6a51b09e85afd46ebca0f2193a9dce3da44f27"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:573ca29fe9d943a1d3397c8b4116d80dad8fdcc4bbf35c4838dbc47403a9c781",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:622c1394f7a75f443a44a28a3071b9b46b8f4a8160940d509f3036ade555cf66",
                    "sha256:bd5eec3b2693115d26badbbb0636edb861de7a9176e6068ce296a2675e62fc91"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "retail-prices-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                      "start_byte": 7579,
                      "end_byte": 8371,
                      "value_digest": "sha256:8c5b3c93d9f9c971f68d43d9961b79901fae7e7ccbc7aeaa0bf6b090b8bcddad"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c6b1fc853a8535b52d08ad54dd99f2575d64e67ebf8c78f81d361275857b7dc5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:396c2d060cdcdf6fa8d4eb5a4082670a2eb028d805053f6961d267267a2a1c0b",
                    "sha256:9ddd24caed136fc61b359cbac00275df85396f94cfd3ba79aca56ff985800f28",
                    "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                    "sha256:ec4b68b88759b5b1046c0082c31549200c1f2bb9b637f336983ab5f24321512b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                      "start_byte": 9951,
                      "end_byte": 10732,
                      "value_digest": "sha256:7996b76edea0159d36223628951c3c4a35541fb5dda4ae2a9d218d42a52ce1bc"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2e14a895bbe8486033e8e2509dc05d8f10a3dd031b3d0d1e0c99fda3e763928b",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:055151cd7e4541b00378aa0fce9903c615fd1f53ae67f44669f7165ed8aecac0",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a8bc511ff0b6fce350158c396fb0678f72bec9e831c2b59448aca37ad492710c",
                    "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-group-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69",
                      "start_byte": 6395,
                      "end_byte": 7192,
                      "value_digest": "sha256:6cd98f8ce7231b84fe2c5f3205658d643f1b28d8966d4fd4e648f35de0ad1e54"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:06ffdb7db0dc64d937f06d8ac58a901758666712e0563d03a6f436edbc5bec15",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:63d131b90fb98dffb572994b3b76262dff9fa69063f5fe658dce82216c06062d",
                    "sha256:fc777a3a94946520e0ba0eb2428783897f27151baffcaaa82c36c69bc1d2e572"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "asynchronous-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 10670,
                      "end_byte": 11465,
                      "value_digest": "sha256:e066f5227002fddc3b46ad6e8a3dc7d345d41bf6b10a06e8b26c37e6ee02019f"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:adfc34e9ab6797a3e08e3de97c89d9781ccae26492fcc388101bda828db492c2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:348008f55ef26b2e6e1688fc503645f020f8f4263c7a14504de42c35c5d6f59f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c3082e0ad7533102056257e8762faa26877c483b278dfad8b779f55396a19654",
                    "sha256:e527bed1fd52ab093f16f86f10b4d4bdd86c1b34ea2aaea2633afcee5fc6d683"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-manager-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e527bed1fd52ab093f16f86f10b4d4bdd86c1b34ea2aaea2633afcee5fc6d683",
                      "start_byte": 13078,
                      "end_byte": 13875,
                      "value_digest": "sha256:08b7379e552b12f2f6938d545582d2a2038f6f583dd50459e51366257057b87f"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e139df7c4aec45fe07c3c7cf93a0e548525cba00065afea115a7daa79d74bcda",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                    "sha256:975747e852ce223bc5d28c49b69dc09d28b9f6df04f3c9d3c18df748b7ac6720",
                    "sha256:d556c619122792b5b57b3bbedc37bf6ede2cc6a6e343dccb09537fb3df73c3c8"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                      "start_byte": 33479,
                      "end_byte": 34279,
                      "value_digest": "sha256:cc620622ac9b1b756f92c497584f93b307854a3def075a345477ac45e9a93b99"
                    }
                  ]
                }
              ],
              "note": "Across all required targets, Azure REST APIs and pricing services provide documented, stable endpoints, HTTP methods, request parameters, JSON response schemas, HTTP status codes, example payloads, and effect semantics."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.534Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "azure-resource-manager"
                },
                {
                  "node_kind": "interface",
                  "node_id": "pricing-and-cost"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:573ca29fe9d943a1d3397c8b4116d80dad8fdcc4bbf35c4838dbc47403a9c781",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f6fd28fecf901b709fdfac86771bcb9f39de6b6f0b7f1de6ff96a43924099d8",
                    "sha256:bd5eec3b2693115d26badbbb0636edb861de7a9176e6068ce296a2675e62fc91"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "retail-prices-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:167a95c819f5a8b1175de5eb871ac1d5f07e35cdf617111aa77be64b38f33b82",
                      "start_byte": 5231,
                      "end_byte": 6028,
                      "value_digest": "sha256:c883979935aa613b52dc9efc85753bbc532a811e1bb29198e3318e5d53592cc2"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c14e5946ac5fecc48d7e4de303f19502f4b0143f70b4798b005d540a25e55404",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0623c7d6e5e8bc508f5283eb09045d01a506883cfd1a5c2be0ecb278f4401aa2",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:9fa5dcf7e7f0b387621b300cc17bfdbc35965f51cf2484e813c1a311a3d39cc7",
                    "sha256:c59c134af95133f2c80c5c6c5c1ffb107e52b795637fcdc4ccfe75f0c044035a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "cost-management-permissions"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9fa5dcf7e7f0b387621b300cc17bfdbc35965f51cf2484e813c1a311a3d39cc7",
                      "start_byte": 6458,
                      "end_byte": 7258,
                      "value_digest": "sha256:510f2b524ee0d6fe3adc04dccd6a51b09e85afd46ebca0f2193a9dce3da44f27"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c6b1fc853a8535b52d08ad54dd99f2575d64e67ebf8c78f81d361275857b7dc5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4ebf011a70740bc362818bd6f5c54cc4035d493f9d0f29b990c717e4bf97ebc1",
                    "sha256:9ddd24caed136fc61b359cbac00275df85396f94cfd3ba79aca56ff985800f28",
                    "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                    "sha256:ec4b68b88759b5b1046c0082c31549200c1f2bb9b637f336983ab5f24321512b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-rest-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e6cc844f30449fa916a92024ffc63f7ac04489533a9f2d582d52b0b6fca63bf6",
                      "start_byte": 7552,
                      "end_byte": 8349,
                      "value_digest": "sha256:6bf313b5c6f03c6c08d1e143478b62e617538ff1e08bcef0ade78d3949a11d44"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:adfc34e9ab6797a3e08e3de97c89d9781ccae26492fcc388101bda828db492c2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:348008f55ef26b2e6e1688fc503645f020f8f4263c7a14504de42c35c5d6f59f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7c98eb7ad7cc31c11ebf56d6b685c66cc55909969f3f3ad12ff32b69d7227128",
                    "sha256:e527bed1fd52ab093f16f86f10b4d4bdd86c1b34ea2aaea2633afcee5fc6d683"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-manager-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e527bed1fd52ab093f16f86f10b4d4bdd86c1b34ea2aaea2633afcee5fc6d683",
                      "start_byte": 8318,
                      "end_byte": 9117,
                      "value_digest": "sha256:d261d9dc1d921a09f6121d53ef237cb01952cde9f05af8fdb6f35b533267f9f9"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:453620f56583f5e64fb84f3a679afc4f06207f6375dfcd98db33f847e308afed",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:d7fc99f4ab2d469ba730cf791021230d095b6bf130be1b160503a9432ee4dfe5",
                    "sha256:da9e4e5a9b0ff5cdc6b447545d6ea635ba6f3edc669e0419ab83886b4514cc54"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-manager-rest"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1e11cbc08ec10cc8211592e7e356c6d990562d19b8d66d0012a2ff509fd1c8c5",
                      "start_byte": 7556,
                      "end_byte": 8264,
                      "value_digest": "sha256:67f101ba1f3d5445a7edde2b75589c54c13043e24324ff3eebfd5e691e170819"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:06ffdb7db0dc64d937f06d8ac58a901758666712e0563d03a6f436edbc5bec15",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b304b31bee082de9aad4f6abb7d7da7a3e2c7c829541224b0c347af0c5d644a4",
                    "sha256:fc777a3a94946520e0ba0eb2428783897f27151baffcaaa82c36c69bc1d2e572"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "asynchronous-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:140620001c4b8a24e16b3bb066e195b4f1a4d420192825537dbe02f2fd89599f",
                      "start_byte": 5100,
                      "end_byte": 5892,
                      "value_digest": "sha256:d6a962d8299c28c89592b8ebfdb58670f545ad90fd628e2bd7356e1cea947ff6"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:e139df7c4aec45fe07c3c7cf93a0e548525cba00065afea115a7daa79d74bcda",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:37d29852502f8ddef051520e50d2bbd3ff59e036de95459d750de8d69b6ac868",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                    "sha256:975747e852ce223bc5d28c49b69dc09d28b9f6df04f3c9d3c18df748b7ac6720"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "azure-pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7873dd76744a79ada1a644844fa5f8da10415cd36760910d1644885dfd69d7e7",
                      "start_byte": 35860,
                      "end_byte": 36658,
                      "value_digest": "sha256:d62e5a86d2072fcf7f8c44ccbbe8d29cfedecc6854119b8b038c51bf3109ec81"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:2e14a895bbe8486033e8e2509dc05d8f10a3dd031b3d0d1e0c99fda3e763928b",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:055151cd7e4541b00378aa0fce9903c615fd1f53ae67f44669f7165ed8aecac0",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69",
                    "sha256:f8db1e193feaa765a1af9364d17ccd80bbaaa85ded8b23ef9f410b47ad604a93"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "resource-group-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b1c68376ef85739904a38ba476f251de2777b8eea5059d56a92ac5d2d5fd5d69",
                      "start_byte": 4795,
                      "end_byte": 5594,
                      "value_digest": "sha256:8e73fccb7ab28e2aa56bd3d56795fdd6f9856a32b50d022b6a7d29d1c7ef8cd4"
                    }
                  ]
                }
              ],
              "note": "Machine-operable interfaces including REST APIs, Azure CLI, Azure PowerShell, and SDKs are documented and accessible across all assessed Azure service targets."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:04.534Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:006c63fc730ea311553b901142deaec7d3872c3cbadcf336a5da620193a52ad5",
          "sha256:0155e280770055c99bb044219abbe9b80d6fd8efd9fd4d3cb83b450a369c51bb",
          "sha256:095fce4c96bf349c766aafffa5d5475380d6725fa2e0f222a27370034d923182",
          "sha256:0a762fc2cbb870d2a4e2180b2cf962d04265cd310e7110340830462ac716a28f",
          "sha256:1350834783fa925eee169272a9d22d75f7d12b19740b04f5a07c7be1ff847853",
          "sha256:18cc0d5a4f43cc8abde205801aaa9cd2fe49453072a795203874e283d279eaa0",
          "sha256:27db1b5154d3eb235c3fdd359cf64102452779fc7d640e293b492f27abab18a0",
          "sha256:2baf02274089a5a0cb502195c3a7d505d9cc687f33b22408985187bfd5eb822b",
          "sha256:2d80867c9b8dccdb235d38e45271d8a9b776305bd4ee82f4cebd8b47dc276c6d",
          "sha256:30c8aea71c6d76183d719efcc72caaec6034485aa9395a3654ea8282f69e0130",
          "sha256:36b535d794f1238b1b1e8c940ff9727f57c6f675df2d9b98732bfdb25366b407",
          "sha256:379b69ae9012014711031d4985185131a028febea246ef6e8d2782aed96929fe",
          "sha256:3da713023da5cec8927934161b1d29414cf877d4c0678103bdf709cf36c5afb9",
          "sha256:3e692c73b7c2d578936dfc313f66a692e7b914b2ca4af306f5ddcc9c88b4784d",
          "sha256:47ae4b3bcea605756682a07c47447dfc9a3052337a4bba2875ec8983f68db54e",
          "sha256:4c30531e344a795360a5d1115afd49b2d2ad214af343bf8c9ef2e1308f67db55",
          "sha256:52ff01555e705c4db0a8535460e788c950498edd61a6a5ee08061cf3402c6eba",
          "sha256:5c7f9bb978be27e4242610474d138f1c3c4c70258d201ed347c89da7ba790773",
          "sha256:5ca009698a55194381e2aa3e61bd98ea327afd406a63aeee72603e04d5750736",
          "sha256:71c9f6ee3d329098cb09cacd89ed63e562c6f1cd757a89aad1b864ff9d460605",
          "sha256:822a6ebb54b79ac26d842b8276758c380c59c10afe2f1e22d98326b2cd0f0b02",
          "sha256:85ae86243487a07b2dbfd46ea2d9bea6423c7ebb221d0c53dc1abfd6e99365cb",
          "sha256:85d06b9a7eb97c918310b193b8aa637de381a5124c8e93fff5ac02bd74d1d282",
          "sha256:8c2a5f987d6776e055a666c18ac14813ca3ef39d052c55dbca578de28b3bec81",
          "sha256:8fe914e3d3bbf362cf7e47cd358f92ab05677cf8186bdabdeed90e7186c2c4a4",
          "sha256:92f994ab17568021405f39a7d35787db4088254ff7dba6c1a83f1b9ffbcca036",
          "sha256:99c5d308bd8cd9ee908d1e46b06fdb7014cdc2442736d1b008eb937ad7282069",
          "sha256:a5306ccfe3842c3a0f9962e405979d354c824079c79cc9b0840ee92fa2188c6d",
          "sha256:a62766092dbe9b207a81f7e038b5d2f1b25362bef8a045f707fbab55c67f4521",
          "sha256:ac600eb75f46c6bfbb535c44de4db655b479ab08ac278d2732314ae29009b782",
          "sha256:bae60eec04f56eea216706666da6a068f1b9ddede8198167900b624ff1173e59",
          "sha256:c6dbe8c079956591a7ae92e73bb8a55fec518c958e72dbaaf357855b59c07e43",
          "sha256:ca4e25467e43fbd907bf1e56ad8011666ca47780c9bd994121d56088863e4bac",
          "sha256:d28d29297950c46d73e260282b02accf3901fe8a576aa54b579ce0852712155a",
          "sha256:d9481be6b33bcc3837fb3733a7e81f6620f036a7752d3650fb322edeb022f679",
          "sha256:da1c90fc07e5fbc47dce77441d641c024293e08104d50d7cea735216c8e5d928",
          "sha256:dcc96da15340dca52e27a0c2f02cfdee8f78ed52b59ddf4bb8c16c4a91f8ea6b",
          "sha256:e36c1dfb878c88ebf92fa871ef9bcbcd13c69e64577a94d604696f458428c11e",
          "sha256:ee3fffbdb3fd37c77f30fcb52d6b9e2cbeba472d767f1e64bcb5c88df3efbbf2",
          "sha256:ef6c90657581bdfcde874300caba26ac7ab47b9be21d7d37d9875ca39140978b",
          "sha256:f0569ebbc7dd21d0cd6863160724dd31a847a447ee7dd3888d42bf51895a913f",
          "sha256:f0b60624f714213806c3e1900e6d3d4f06ffb1d783c2042e2a2aba1eec56119a",
          "sha256:f225eeaa08af3556fc1021257c67f920bcec6435f434821ac84172e509b99337",
          "sha256:f512855c24d69db30313c41b0aa842a1b6784983f4947321b8e0a7a2300d7e08",
          "sha256:faf8a23287919a60c4148b2f1a7dacaf85f9add38f4f040bcf7c81654cafc5ad",
          "sha256:fb43a6460b6763c9a00ca6d50bdaef374b3cb86260c1af295337ab01c2f2bd86",
          "sha256:fd409122260ac8a2f01e0697c8b1d5e6174e023aa00b8e37cf9739936c916b07"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:71c9f6ee3d329098cb09cacd89ed63e562c6f1cd757a89aad1b864ff9d460605"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:15.463Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:bae60eec04f56eea216706666da6a068f1b9ddede8198167900b624ff1173e59",
              "sha256:f0b60624f714213806c3e1900e6d3d4f06ffb1d783c2042e2a2aba1eec56119a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.534Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:3e692c73b7c2d578936dfc313f66a692e7b914b2ca4af306f5ddcc9c88b4784d"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:21.792Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:0155e280770055c99bb044219abbe9b80d6fd8efd9fd4d3cb83b450a369c51bb",
              "sha256:e36c1dfb878c88ebf92fa871ef9bcbcd13c69e64577a94d604696f458428c11e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:32.666Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:f225eeaa08af3556fc1021257c67f920bcec6435f434821ac84172e509b99337"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:33.219Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:379b69ae9012014711031d4985185131a028febea246ef6e8d2782aed96929fe",
              "sha256:3da713023da5cec8927934161b1d29414cf877d4c0678103bdf709cf36c5afb9"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:33.219Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:2baf02274089a5a0cb502195c3a7d505d9cc687f33b22408985187bfd5eb822b",
              "sha256:52ff01555e705c4db0a8535460e788c950498edd61a6a5ee08061cf3402c6eba",
              "sha256:8c2a5f987d6776e055a666c18ac14813ca3ef39d052c55dbca578de28b3bec81"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:33.219Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:1350834783fa925eee169272a9d22d75f7d12b19740b04f5a07c7be1ff847853",
              "sha256:d28d29297950c46d73e260282b02accf3901fe8a576aa54b579ce0852712155a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.989Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:85d06b9a7eb97c918310b193b8aa637de381a5124c8e93fff5ac02bd74d1d282",
              "sha256:fd409122260ac8a2f01e0697c8b1d5e6174e023aa00b8e37cf9739936c916b07"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:33.219Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:ac600eb75f46c6bfbb535c44de4db655b479ab08ac278d2732314ae29009b782"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:19.145Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:095fce4c96bf349c766aafffa5d5475380d6725fa2e0f222a27370034d923182",
              "sha256:92f994ab17568021405f39a7d35787db4088254ff7dba6c1a83f1b9ffbcca036"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.534Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:dcc96da15340dca52e27a0c2f02cfdee8f78ed52b59ddf4bb8c16c4a91f8ea6b"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:19.145Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:a62766092dbe9b207a81f7e038b5d2f1b25362bef8a045f707fbab55c67f4521"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:57.916Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:30c8aea71c6d76183d719efcc72caaec6034485aa9395a3654ea8282f69e0130",
              "sha256:47ae4b3bcea605756682a07c47447dfc9a3052337a4bba2875ec8983f68db54e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.989Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:da1c90fc07e5fbc47dce77441d641c024293e08104d50d7cea735216c8e5d928"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:58.337Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:8fe914e3d3bbf362cf7e47cd358f92ab05677cf8186bdabdeed90e7186c2c4a4",
              "sha256:c6dbe8c079956591a7ae92e73bb8a55fec518c958e72dbaaf357855b59c07e43"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:24.579Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:36b535d794f1238b1b1e8c940ff9727f57c6f675df2d9b98732bfdb25366b407",
              "sha256:5c7f9bb978be27e4242610474d138f1c3c4c70258d201ed347c89da7ba790773"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.989Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:0a762fc2cbb870d2a4e2180b2cf962d04265cd310e7110340830462ac716a28f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:58.337Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:d9481be6b33bcc3837fb3733a7e81f6620f036a7752d3650fb322edeb022f679",
              "sha256:fb43a6460b6763c9a00ca6d50bdaef374b3cb86260c1af295337ab01c2f2bd86"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.989Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:27db1b5154d3eb235c3fdd359cf64102452779fc7d640e293b492f27abab18a0",
              "sha256:2d80867c9b8dccdb235d38e45271d8a9b776305bd4ee82f4cebd8b47dc276c6d",
              "sha256:5ca009698a55194381e2aa3e61bd98ea327afd406a63aeee72603e04d5750736",
              "sha256:99c5d308bd8cd9ee908d1e46b06fdb7014cdc2442736d1b008eb937ad7282069",
              "sha256:a5306ccfe3842c3a0f9962e405979d354c824079c79cc9b0840ee92fa2188c6d",
              "sha256:ef6c90657581bdfcde874300caba26ac7ab47b9be21d7d37d9875ca39140978b",
              "sha256:f512855c24d69db30313c41b0aa842a1b6784983f4947321b8e0a7a2300d7e08",
              "sha256:faf8a23287919a60c4148b2f1a7dacaf85f9add38f4f040bcf7c81654cafc5ad"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.534Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:006c63fc730ea311553b901142deaec7d3872c3cbadcf336a5da620193a52ad5",
              "sha256:18cc0d5a4f43cc8abde205801aaa9cd2fe49453072a795203874e283d279eaa0",
              "sha256:4c30531e344a795360a5d1115afd49b2d2ad214af343bf8c9ef2e1308f67db55",
              "sha256:822a6ebb54b79ac26d842b8276758c380c59c10afe2f1e22d98326b2cd0f0b02",
              "sha256:85ae86243487a07b2dbfd46ea2d9bea6423c7ebb221d0c53dc1abfd6e99365cb",
              "sha256:ca4e25467e43fbd907bf1e56ad8011666ca47780c9bd994121d56088863e4bac",
              "sha256:ee3fffbdb3fd37c77f30fcb52d6b9e2cbeba472d767f1e64bcb5c88df3efbbf2",
              "sha256:f0569ebbc7dd21d0cd6863160724dd31a847a447ee7dd3888d42bf51895a913f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.534Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/microsoft/agent-readiness/microsoft-azure/api-resource-management",
      "projection_digest": "sha256:83d1d7853cc62f203b01b3ce8253cd5b8e43a7a2a4e3d15cb7fb780c72d9fb0a"
    }
  }
}
