{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyyts97tdz1rtzzt919cthny",
    "entity_slug": "slack",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4xj3k8sa6c2w9nq4vf7",
      "entity_id": "ent_01kyyts97tdz1rtzzt919cthny",
      "scope": {
        "product": {
          "key": "slack-web-api",
          "name": "Slack Web API"
        },
        "funnel": {
          "key": "workspace-app-operations",
          "name": "Workspace app operations"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:6bf818ed8305ea50197752914eecaa92ffd3a14f68afe01712b18be0cb13a2eb"
      },
      "declaration_revision_digest": "sha256:f3bb080b1f1ccd9b33d2c66000ce4bed9c7f7cfaad35a873ade0d539884631cf",
      "declaration": {
        "declaration_id": "declaration_slack_web_api_workspace_operations",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/sl/slack.yaml",
          "git_blob_oid": "0c925deda45198c49d0b1fe24dca223bf7ae42cb",
          "blob_digest": "sha256:c23d5db2bdae763eaf453367cb98b1c01de06dd67c126ff4d4f8337c1729f083"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Install an app and post messages through the Web API",
            "interface_ids": [
              "workspace-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "slack",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyyts97tdz1rtzzt919cthny"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "authentication",
            "uri": "https://docs.slack.dev/authentication/",
            "roles": [
              "descriptor",
              "documentation"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://slack.com/help/articles/218915087-Manage-your-Slack-plan-and-billing-details",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "message-operations",
            "uri": "https://docs.slack.dev/reference/methods/chat.postMessage/",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "oauth",
            "uri": "https://docs.slack.dev/authentication/installing-with-oauth/",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "describes"
              }
            ]
          },
          {
            "resource_id": "pricing",
            "uri": "https://slack.com/pricing",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "rate-limits",
            "uri": "https://docs.slack.dev/apis/web-api/rate-limits/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-5cf60e6ed44cb7227b1e801c24793d749277f1ac820a2a2d1a2e3aaea9e3ae94",
            "uri": "https://slack.com/help/articles/202035138-Slack-plans-and-features",
            "roles": [
              "documentation",
              "eligibility"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://slack.com/terms-of-service",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://slack.com/help",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "web-api",
            "uri": "https://docs.slack.dev/apis/web-api/",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "resource_id": "workspace-signup",
            "uri": "https://slack.com/get-started",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "oauth-token",
            "uri": "https://slack.com/api/oauth.v2.access",
            "transport": "http",
            "roles": [
              "authorization",
              "token"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "implements"
              }
            ]
          },
          {
            "endpoint_id": "registration",
            "uri": "https://slack.com/get-started",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          },
          {
            "endpoint_id": "slack-api",
            "uri": "https://slack.com/api",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "app-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [
              "oauth-token"
            ],
            "resource_ids": [
              "authentication",
              "oauth"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": [
              {
                "namespace": "oauth",
                "version": "2.0",
                "relation": "uses"
              }
            ]
          },
          {
            "interface_id": "workspace-api",
            "modality": "network_api",
            "functions": [
              "events",
              "service_operation"
            ],
            "endpoint_ids": [
              "slack-api"
            ],
            "resource_ids": [
              "message-operations",
              "rate-limits",
              "web-api"
            ],
            "operated_by_participant_id": "slack",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "app-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "workspace-api"
            }
          },
          {
            "relation_id": "messages-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "message-operations"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "workspace-api"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "workspace-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "app-authentication"
            }
          },
          {
            "relation_id": "web-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "web-api"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "workspace-api"
            }
          }
        ],
        "surface_exclusions": []
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:95ce8c5fa061c757e09eeb33b07bd2579455a3dd5ce6c244d5e34879daf2aa3c",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B+",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "evaluate",
        "stage_label": "Evaluate",
        "public_state": "limited",
        "finding": {
          "signal_code": "terms_access",
          "condition": "Can an agent retrieve and understand the applicable commitment terms?",
          "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
          "context": "Slack provides a legal terms index page identifying applicable agreements such as the Main Services Agreement, User Terms of Service, and API Terms of Service, but defers the full binding text of the Main Services Agreement to an external Salesforce link."
        }
      },
      "limitations": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "terms_access",
            "condition": "Can an agent retrieve and understand the applicable commitment terms?",
            "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
            "context": "Slack provides a legal terms index page identifying applicable agreements such as the Main Services Agreement, User Terms of Service, and API Terms of Service, but defers the full binding text of the Main Services Agreement to an external Salesforce link."
          },
          "remediation": {
            "signal_code": "terms_access",
            "code": "improve.evaluate.terms_access",
            "instruction": "Publish complete applicable terms at a stable public URL."
          }
        },
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "According to Slack's help documentation, by default any member of a Slack workspace can install apps and all members are eligible to use workspace app features across all subscriptions. However, workspace owners can turn on app approval to require admin authorization, restricting members from directly installing or using certain apps."
          },
          "remediation": {
            "signal_code": "eligibility_decidability",
            "code": "improve.evaluate.eligibility_decidability",
            "instruction": "State every material eligibility condition and required input explicitly."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation defines rate limits, the HTTP 429 Too Many Requests status code, and the Retry-After response header instructing how long to wait before retrying. Full failure handling including idempotency, cancellation, and reconciliation semantics is not fully established in the evidence."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Documentation explicitly describes token revocation via the auth.revoke method and mentions token rotation with refresh tokens. However, evidence for full compromised credential handling and recovery within delegated authority is incomplete."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "terms_access",
            "condition": "Can an agent retrieve and understand the applicable commitment terms?",
            "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
            "context": "Slack provides a legal terms index page identifying applicable agreements such as the Main Services Agreement, User Terms of Service, and API Terms of Service, but defers the full binding text of the Main Services Agreement to an external Salesforce link."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "context": "According to Slack's help documentation, by default any member of a Slack workspace can install apps and all members are eligible to use workspace app features across all subscriptions. However, workspace owners can turn on app approval to require admin authorization, restricting members from directly installing or using certain apps."
            },
            {
              "signal_code": "service_discovery",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "context": "The Slack Web API is publicly discoverable as an interface for querying information and enacting changes in a Slack workspace, featuring HTTP RPC-style endpoints under the base URL https://slack.com/api/METHOD_FAMILY.method over HTTPS."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Slack explicitly provides subscription pricing details, confirming a Free tier at $US0 free forever that includes up to ten apps, alongside paid subscription tiers."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:46.230Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "readiness-5cf60e6ed44cb7227b1e801c24793d749277f1ac820a2a2d1a2e3aaea9e3ae94"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a5a71f1e25363202106e976111b85eb69af9ec4bdd3d7ee5576d7a2b7ed2d811",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4d8fba200d44dda42d8d4ef95f61fbb034f321bc0cad8e6c15398080c4adac25",
                    "sha256:582a993f51388d974b61feaf0830e8a2c1b8a944e05b4f9cc1903ce8a29ae042",
                    "sha256:b81f869486b3475b2646d381526efee899706f719be6b9ed0bd33e377f3365ad",
                    "sha256:f686fc75b12cfda883659992ee63c1eb82fd6d411e7ddd1bf9969906b6026c88"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-5cf60e6ed44cb7227b1e801c24793d749277f1ac820a2a2d1a2e3aaea9e3ae94"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4d8fba200d44dda42d8d4ef95f61fbb034f321bc0cad8e6c15398080c4adac25",
                      "start_byte": 13091,
                      "end_byte": 13891,
                      "value_digest": "sha256:2474be0837078c98ebce543faddbf82e97d52e0783dd382d30fc7c60417f5df5"
                    },
                    {
                      "artifact_digest": "sha256:4d8fba200d44dda42d8d4ef95f61fbb034f321bc0cad8e6c15398080c4adac25",
                      "start_byte": 17126,
                      "end_byte": 17930,
                      "value_digest": "sha256:a547db0b04699fb78336bdfa236c375fe482b48df954f2e138121ede520497e1"
                    }
                  ]
                }
              ],
              "note": "According to Slack's help documentation, by default any member of a Slack workspace can install apps and all members are eligible to use workspace app features across all subscriptions. However, workspace owners can turn on app approval to require admin authorization, restricting members from directly installing or using certain apps.",
              "remediation": {
                "signal_code": "eligibility_decidability",
                "code": "improve.evaluate.eligibility_decidability",
                "instruction": "State every material eligibility condition and required input explicitly."
              }
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:39.748Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:931df2d4291388908866525e610450e33740d66abd3c248dc1e48c024f0f97d2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:25940934ae44047df07640822c0aafdf0b1b88d3f04ecd99227bfd2ec8bd5b5b",
                    "sha256:2d87358e7a6238584230dff0ef8efce21dbe19ac02ea3b19cbf809327fc84f16",
                    "sha256:628fa553e9e4ba0778153c9d703ee604edcf5cb556b32c9ba7a520424bb56735",
                    "sha256:aa8bac44a7337104d7ffda52d381bd536f84245cc7c873f70621d6242bee2307"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:aa8bac44a7337104d7ffda52d381bd536f84245cc7c873f70621d6242bee2307",
                      "start_byte": 16003,
                      "end_byte": 16807,
                      "value_digest": "sha256:e84b2ebd25eadac26dda7028cbef24758d2136e2d6d56acdde62421404c6c569"
                    }
                  ]
                }
              ],
              "note": "Slack explicitly provides subscription pricing details, confirming a Free tier at $US0 free forever that includes up to ten apps, alongside paid subscription tiers."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:13.150Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "web-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:12696dca3b5b572c7637c91f3350edf8f67fdcf053069a5aaaab73eeca5f6774",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                    "sha256:4d21e854f82ebc598f1b3dbbbada4efa88daa961a2144f6a19b68a9a8353787c",
                    "sha256:c3eceff7ca94c446188c661c486025b06852f8d8cec7234f667ff2e2a7859e2b",
                    "sha256:c60f3d28dd728dd7c939783376f0e40eabed117aea6cbdde4f92b0e4cb4ee5f3"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "web-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                      "start_byte": 4635,
                      "end_byte": 5448,
                      "value_digest": "sha256:b99fa92af2a9c9241eb591165ba34b6dfda285cc04a3d089156d558f494f8b7a"
                    },
                    {
                      "artifact_digest": "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                      "start_byte": 5449,
                      "end_byte": 6247,
                      "value_digest": "sha256:a4ca6a703b8db57dbd850ea24ca5377f5cedfdb18490dd6b4c76a39ec492ab84"
                    }
                  ]
                }
              ],
              "note": "The Slack Web API is publicly discoverable as an interface for querying information and enacting changes in a Slack workspace, featuring HTTP RPC-style endpoints under the base URL https://slack.com/api/METHOD_FAMILY.method over HTTPS."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:48.964Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1f5e81d8a1a5e37dac29f991626f94a272e2631de937defa55bf2c55931868d6",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:04c9291ba64fc5ae3aa64176b323b2cef4dcfc09cfe78c2d5d1a6298f4b513a1",
                    "sha256:090121b83bd196d3868da7b714a1306dbf9f3db3e37f356a28be527a4b25d5c0",
                    "sha256:c220636672a0b72f20ae3b331abe5ad27b686f0716599c4baeccc4864221cd5e",
                    "sha256:cb9e28c7d0dd291726488063a27e7c8c00c799182ff8cf30164023b1de20c007"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:cb9e28c7d0dd291726488063a27e7c8c00c799182ff8cf30164023b1de20c007",
                      "start_byte": 16190,
                      "end_byte": 16968,
                      "value_digest": "sha256:5c11579beec61db04f34a2929dc181cc716bfb7227971b962d62a2a1441e3deb"
                    },
                    {
                      "artifact_digest": "sha256:cb9e28c7d0dd291726488063a27e7c8c00c799182ff8cf30164023b1de20c007",
                      "start_byte": 16969,
                      "end_byte": 17782,
                      "value_digest": "sha256:ebb6105d0a5df8d79154a42944691165fb46664600af2273af547a206434d06c"
                    }
                  ]
                }
              ],
              "note": "Slack provides a legal terms index page identifying applicable agreements such as the Main Services Agreement, User Terms of Service, and API Terms of Service, but defers the full binding text of the Main Services Agreement to an external Salesforce link.",
              "remediation": {
                "signal_code": "terms_access",
                "code": "improve.evaluate.terms_access",
                "instruction": "Publish complete applicable terms at a stable public URL."
              }
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "terms_access",
              "code": "improve.evaluate.terms_access",
              "instruction": "Publish complete applicable terms at a stable public URL."
            },
            {
              "signal_code": "eligibility_decidability",
              "code": "improve.evaluate.eligibility_decidability",
              "instruction": "State every material eligibility condition and required input explicitly."
            }
          ]
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "A stable canonical route begins the required access bootstrap.",
            "context": "A stable canonical route to begin service access is available at https://slack.com/get-started, where users can log in or try for free with an email address."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence for the get-started endpoint only contains metadata and page title text ('Login | Slack') without detailing interactive access controls, validation, navigation, or handoffs."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The evidence captured from https://slack.com/get-started contains page metadata and title text, but does not explicitly confirm or rule out CAPTCHA requirements."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured evidence for the registration page does not contain explicit information regarding phone verification requirements or safe resumable boundaries."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "context": "Slack apps use a v2 OAuth 2.0 flow where apps request specific granular scopes, users grant approval, and a temporary authorization code is exchanged for an access token."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:18.396Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The retained evidence for the get-started endpoint only contains metadata and page title text ('Login | Slack') without detailing interactive access controls, validation, navigation, or handoffs."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:18.396Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "workspace-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:c3157fd9ba234cb235e3f097136abb7fd51193e7de8dbf5cadc61351ef14f9ce",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:105ecba982e92e1ff9b798f5278873867ad795d36e8d0827f0755ee08a66a1c6",
                    "sha256:3878570f4a62a0d65f57cf1754e0269e56ec797f4e36e26b44c172eb6e800401",
                    "sha256:4ab071b8b0ea7ac595d2559c980df791b801fcbfac5743d90ae2ee7d298c6169",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:bc0a4186de442d335bcdc2fb7bf4409c8435cb4399650f1db062a2fca5ab9ad3",
                    "sha256:db67cfa1d09993e6afbaec7e04fa95894a6819fb0cc0ac6dda960ecb69fa17a8"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:bc0a4186de442d335bcdc2fb7bf4409c8435cb4399650f1db062a2fca5ab9ad3",
                      "start_byte": 0,
                      "end_byte": 532,
                      "value_digest": "sha256:faf62c7f58088bfcad5af4e1971f0b67405c77edcf6547df3a5ba48fbcaeb28e"
                    }
                  ]
                }
              ],
              "note": "A stable canonical route to begin service access is available at https://slack.com/get-started, where users can log in or try for free with an email address."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:18.396Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "workspace-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The evidence captured from https://slack.com/get-started contains page metadata and title text, but does not explicitly confirm or rule out CAPTCHA requirements."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.385Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:caa55565371557fbd697a278f815a306eb8831a4d22ffea5c3d999e04f5f7a56",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:508be35770d1d57dd4905f99bd52493216b4b8e478285ff4e9ab2e5b61b61650",
                    "sha256:84e9eacc6f77d4be8879da6dfee2148c8ad1a015a9e1e30ebdc76e3ada15f40c",
                    "sha256:9943983a6a1a0a5b5cd996f2a1e8065052b0f29eaf77ef1a1bd5de0ec2e6e5c8",
                    "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 5002,
                      "end_byte": 5814,
                      "value_digest": "sha256:1f244034392c217d5c38b26935171a3a72413da79768682faa2bf9a843759294"
                    },
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 5815,
                      "end_byte": 6618,
                      "value_digest": "sha256:9c3b2537d895bac372b3b8dc989e3f6d4646192df550644db63559a8e5a04343"
                    }
                  ]
                }
              ],
              "note": "Slack apps use a v2 OAuth 2.0 flow where apps request specific granular scopes, users grant approval, and a temporary authorization code is exchanged for an access token."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:18.396Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "workspace-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured evidence for the registration page does not contain explicit information regarding phone verification requirements or safe resumable boundaries."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Slack discloses commitment terms including USD pricing ($US8.75/month or $US7.25/month paid annually for Pro), recurrence options (monthly vs annual), and charge timing rules for credit card purchases and user additions."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Human web checkout steps are documented, but deterministic construction, bounded approval handoff, and safe resumption are not established."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "A documented rail supports scoped delegation or explicit human-confirmed authorization with receipts.",
              "context": "Slack documents payment authorization via default payment methods (credit card or ACH bank debiting for US bank accounts), where authorized workspace admins review and confirm orders by clicking 'Purchase'."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "Slack documents a direct self-service path to upgrade or manage paid subscriptions via the desktop app by navigating to Admin > Manage billing, selecting subscription details, moving through checkout, reviewing the order, and clicking Purchase."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:05.005Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "Human web checkout steps are documented, but deterministic construction, bounded approval handoff, and safe resumption are not established."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:39.748Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:931df2d4291388908866525e610450e33740d66abd3c248dc1e48c024f0f97d2",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2d87358e7a6238584230dff0ef8efce21dbe19ac02ea3b19cbf809327fc84f16",
                    "sha256:395cd80f5dde8947a062d12002773186cfdc2d296dab2680a1e55ade730eea2e",
                    "sha256:628fa553e9e4ba0778153c9d703ee604edcf5cb556b32c9ba7a520424bb56735",
                    "sha256:aa8bac44a7337104d7ffda52d381bd536f84245cc7c873f70621d6242bee2307"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:aa8bac44a7337104d7ffda52d381bd536f84245cc7c873f70621d6242bee2307",
                      "start_byte": 16808,
                      "end_byte": 17607,
                      "value_digest": "sha256:a9cfb890efddb72a4869dc8abe300153d70abc8f1353ea52ac1987cb66852c3b"
                    },
                    {
                      "artifact_digest": "sha256:aa8bac44a7337104d7ffda52d381bd536f84245cc7c873f70621d6242bee2307",
                      "start_byte": 39209,
                      "end_byte": 40012,
                      "value_digest": "sha256:153e50154e4318ef1fc89cdf238a7adb9efedf6c78194155d4cddb318e9a29bc"
                    }
                  ]
                }
              ],
              "note": "Slack discloses commitment terms including USD pricing ($US8.75/month or $US7.25/month paid annually for Pro), recurrence options (monthly vs annual), and charge timing rules for credit card purchases and user additions."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "A documented rail supports scoped delegation or explicit human-confirmed authorization with receipts.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:05.005Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d1de9ea173b5c9608e79bf54ad0cd1385001fa8a7984275a74ef224fc3b728f3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:41052326a88d5110ddd51fb64c5bf515f68559baf782d8c1be61f182c1d6f58d",
                    "sha256:58f95f844c48da9831588e68357080c228562812dc9a989551aac5b39e41c3f4",
                    "sha256:be91fbd46718884fe3c5c7e6c2b539e94549e4b006757b6daff083e399aa1f8d",
                    "sha256:f0c95d4dfac6a5f91aeefcade4b182aca3135ba5d7a710530a089787d29cb74b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:41052326a88d5110ddd51fb64c5bf515f68559baf782d8c1be61f182c1d6f58d",
                      "start_byte": 13752,
                      "end_byte": 14536,
                      "value_digest": "sha256:7ca7178e26f80ab1ce87d5daa5a5a66833ff18caae5dde00d9c6378472410379"
                    }
                  ]
                }
              ],
              "note": "Slack documents payment authorization via default payment methods (credit card or ACH bank debiting for US bank accounts), where authorized workspace admins review and confirm orders by clicking 'Purchase'."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:05.005Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d1de9ea173b5c9608e79bf54ad0cd1385001fa8a7984275a74ef224fc3b728f3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:41052326a88d5110ddd51fb64c5bf515f68559baf782d8c1be61f182c1d6f58d",
                    "sha256:58f95f844c48da9831588e68357080c228562812dc9a989551aac5b39e41c3f4",
                    "sha256:e0ba6acdf784c0b32877a1bc936d0b8645cdf4c5dd5f66dc75c8cd173489a7fb",
                    "sha256:f0c95d4dfac6a5f91aeefcade4b182aca3135ba5d7a710530a089787d29cb74b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:41052326a88d5110ddd51fb64c5bf515f68559baf782d8c1be61f182c1d6f58d",
                      "start_byte": 12950,
                      "end_byte": 13751,
                      "value_digest": "sha256:89e50afde44957ac87a71b2e607929d647ead76eee1e5c235fdda0475450343e"
                    },
                    {
                      "artifact_digest": "sha256:41052326a88d5110ddd51fb64c5bf515f68559baf782d8c1be61f182c1d6f58d",
                      "start_byte": 13752,
                      "end_byte": 14536,
                      "value_digest": "sha256:7ca7178e26f80ab1ce87d5daa5a5a66833ff18caae5dde00d9c6378472410379"
                    }
                  ]
                }
              ],
              "note": "Slack documents a direct self-service path to upgrade or manage paid subscriptions via the desktop app by navigating to Admin > Manage billing, selecting subscription details, moving through checkout, reviewing the order, and clicking Purchase."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "provisioning_operability",
            "condition": "Can provisioning be initiated within supported agent authority?",
            "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
            "context": "Provisioning can be initiated by redirecting a user to the OAuth authorization endpoint to grant scopes and exchanging the resulting code for an access token."
          },
          "secondary_context": [
            {
              "signal_code": "access_material_delivery",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "context": "At the end of the OAuth flow, calling the oauth.v2.access endpoint with the temporary authorization code and client secret returns an HTTP response containing the access token."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "context": "Calling chat.postMessage returns a synchronous HTTP response containing ok: true, the channel, the timestamp ID (ts), and the complete message object as parsed by Slack's servers."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Credentials, grants, or configuration are delivered through a documented agent-usable flow.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.385Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:caa55565371557fbd697a278f815a306eb8831a4d22ffea5c3d999e04f5f7a56",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:508be35770d1d57dd4905f99bd52493216b4b8e478285ff4e9ab2e5b61b61650",
                    "sha256:9943983a6a1a0a5b5cd996f2a1e8065052b0f29eaf77ef1a1bd5de0ec2e6e5c8",
                    "sha256:c37d138f198848b633a3746a2ccf1315cdeb12cc2e2298c20ca6f2284e7e79fb",
                    "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 14596,
                      "end_byte": 15314,
                      "value_digest": "sha256:9f18b82b39c6a3e004140947734db97125356a5d072283adc2125c04fcacb7e7"
                    }
                  ]
                }
              ],
              "note": "At the end of the OAuth flow, calling the oauth.v2.access endpoint with the temporary authorization code and client secret returns an HTTP response containing the access token."
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.599Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "message-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ceba9f7ce0590709717f67d35c2aba5ac2ad56828a7da7bd7ae757ebeb653001",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7362cfd188f0905a4c6a9d99632aa263752d4523fa88c1a4409bd1b1c3ae5789",
                    "sha256:8a603596adbde6e8eb4d24b5bf75fb88eeebd3a5cc268c3519d7a5adfbde3ced",
                    "sha256:cdf4857de220d327e51f3e2e2d75ce94705c2d72fc01334c719d600db80dbdfa",
                    "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "message-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd",
                      "start_byte": 19948,
                      "end_byte": 20740,
                      "value_digest": "sha256:f4bd5f9ed0694608f55891b9c9affb54432fc252968ddba0ed237a5d3ec545e4"
                    }
                  ]
                }
              ],
              "note": "Calling chat.postMessage returns a synchronous HTTP response containing ok: true, the channel, the timestamp ID (ts), and the complete message object as parsed by Slack's servers."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.599Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "message-operations"
                },
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ceba9f7ce0590709717f67d35c2aba5ac2ad56828a7da7bd7ae757ebeb653001",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:31996e0a46f7ec7bbc5115122a0733712ddce0e5dd5c0a37750a10c583b69e27",
                    "sha256:8a603596adbde6e8eb4d24b5bf75fb88eeebd3a5cc268c3519d7a5adfbde3ced",
                    "sha256:cdf4857de220d327e51f3e2e2d75ce94705c2d72fc01334c719d600db80dbdfa",
                    "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "message-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd",
                      "start_byte": 10332,
                      "end_byte": 11127,
                      "value_digest": "sha256:79aad13e2afdd16c93529cc838e7cf5af37f2bddb9447d608a7a2f73763f333e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:caa55565371557fbd697a278f815a306eb8831a4d22ffea5c3d999e04f5f7a56",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0350075ac572091130589f61a5c3700a0e647c6e418ba0e01bff64743bd0ba78",
                    "sha256:508be35770d1d57dd4905f99bd52493216b4b8e478285ff4e9ab2e5b61b61650",
                    "sha256:9943983a6a1a0a5b5cd996f2a1e8065052b0f29eaf77ef1a1bd5de0ec2e6e5c8",
                    "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 6619,
                      "end_byte": 7399,
                      "value_digest": "sha256:e322a055a38816dfff657509a03bb6cd9868bcaa69e568b0434a7650d8adbfff"
                    }
                  ]
                }
              ],
              "note": "Provisioning can be initiated by redirecting a user to the OAuth authorization endpoint to grant scopes and exchanging the resulting code for an access token."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation defines rate limits, the HTTP 429 Too Many Requests status code, and the Retry-After response header instructing how long to wait before retrying. Full failure handling including idempotency, cancellation, and reconciliation semantics is not fully established in the evidence."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "Documentation explicitly describes token revocation via the auth.revoke method and mentions token rotation with refresh tokens. However, evidence for full compromised credential handling and recovery within delegated authority is incomplete."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Every essential target has documented machine-operable HTTP interfaces for invocation, including Web API RPC-style methods."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "Request-time authentication with scoped authority is documented via v2 OAuth 2.0 flow using requested scopes and Bearer tokens sent in the HTTP Authorization header."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Slack Web API endpoints, including chat.postMessage, have documented request parameters, HTTP methods, rate limits, and JSON responses with an explicit top-level ok status."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.385Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:caa55565371557fbd697a278f815a306eb8831a4d22ffea5c3d999e04f5f7a56",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:508be35770d1d57dd4905f99bd52493216b4b8e478285ff4e9ab2e5b61b61650",
                    "sha256:9943983a6a1a0a5b5cd996f2a1e8065052b0f29eaf77ef1a1bd5de0ec2e6e5c8",
                    "sha256:cfa21fd7590614002330209efaa5db2a02ae40ad93d6ebce63c6196b8ea00b50",
                    "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 20903,
                      "end_byte": 21697,
                      "value_digest": "sha256:d3c6c9068fb0312a775ca4df32378539452b2c84b006fe650b1d1fc24ad75e62"
                    },
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 21698,
                      "end_byte": 22492,
                      "value_digest": "sha256:6518747b4e93207f168d9f11613a88d2bcf16e6e9fba468a2232cf28395ac7dd"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly describes token revocation via the auth.revoke method and mentions token rotation with refresh tokens. However, evidence for full compromised credential handling and recovery within delegated authority is incomplete.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:50.517Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "rate-limits"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:426b189158cc159f7d47b752457db79e692c5def3843638162a8c3f5fc523dc0",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3ee62a0180babbdf33832e1d38626812d926bcc4dbb1beee9c60dc9fb6fb2d31",
                    "sha256:6669c6e7f0dbd71bfd04628be8ff5394eb07153f615f3a0b6111d802875199f3",
                    "sha256:702aae8ea7183a62fc3ca2a66161f876f731acfec69e99cb7ef81744b397a439",
                    "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rate-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3",
                      "start_byte": 10752,
                      "end_byte": 11553,
                      "value_digest": "sha256:70267f532e39d88a031f1b33295132bb76d37ee4c7c6cacc836ff71ab7553046"
                    },
                    {
                      "artifact_digest": "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3",
                      "start_byte": 11554,
                      "end_byte": 12352,
                      "value_digest": "sha256:3b78fe7a7e5b2437ce30c536a2035f620fd8454d0cc4e48144c0a6f3da010cbd"
                    }
                  ]
                }
              ],
              "note": "Documentation defines rate limits, the HTTP 429 Too Many Requests status code, and the Retry-After response header instructing how long to wait before retrying. Full failure handling including idempotency, cancellation, and reconciliation semantics is not fully established in the evidence.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.385Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "oauth"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:caa55565371557fbd697a278f815a306eb8831a4d22ffea5c3d999e04f5f7a56",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:508be35770d1d57dd4905f99bd52493216b4b8e478285ff4e9ab2e5b61b61650",
                    "sha256:9943983a6a1a0a5b5cd996f2a1e8065052b0f29eaf77ef1a1bd5de0ec2e6e5c8",
                    "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                    "sha256:fe8ccc85e8f0f799fbac92f69dc8dd5d7ac91f6d1112077c907ed55a94c1b21e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "oauth"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 20122,
                      "end_byte": 20902,
                      "value_digest": "sha256:1fc7875031d8018106129eed9e67620f319881127f95107048fc09b5d15a36ff"
                    },
                    {
                      "artifact_digest": "sha256:f432980d2e0bdd80c75b606b22bbb845279c952eb677947ee02f4a63cf56db65",
                      "start_byte": 6619,
                      "end_byte": 7399,
                      "value_digest": "sha256:e322a055a38816dfff657509a03bb6cd9868bcaa69e568b0434a7650d8adbfff"
                    }
                  ]
                }
              ],
              "note": "Request-time authentication with scoped authority is documented via v2 OAuth 2.0 flow using requested scopes and Bearer tokens sent in the HTTP Authorization header."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.599Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "workspace-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:426b189158cc159f7d47b752457db79e692c5def3843638162a8c3f5fc523dc0",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:23ee838d57ed0bd348ca2dcdacb86b755a295cef213d7618c1c16a2c55f4ebac",
                    "sha256:3ee62a0180babbdf33832e1d38626812d926bcc4dbb1beee9c60dc9fb6fb2d31",
                    "sha256:6669c6e7f0dbd71bfd04628be8ff5394eb07153f615f3a0b6111d802875199f3",
                    "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rate-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3",
                      "start_byte": 10752,
                      "end_byte": 11553,
                      "value_digest": "sha256:70267f532e39d88a031f1b33295132bb76d37ee4c7c6cacc836ff71ab7553046"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ceba9f7ce0590709717f67d35c2aba5ac2ad56828a7da7bd7ae757ebeb653001",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2912a48cedae4b5edc0e94f36b21ea563933d082dc53323ff5b920a7756a2424",
                    "sha256:8a603596adbde6e8eb4d24b5bf75fb88eeebd3a5cc268c3519d7a5adfbde3ced",
                    "sha256:cdf4857de220d327e51f3e2e2d75ce94705c2d72fc01334c719d600db80dbdfa",
                    "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "message-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd",
                      "start_byte": 7932,
                      "end_byte": 8734,
                      "value_digest": "sha256:987eada1fcb4f0ab8164308286e1d852cd1aad8cdcf52f8083244533d8d82b4b"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:12696dca3b5b572c7637c91f3350edf8f67fdcf053069a5aaaab73eeca5f6774",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                    "sha256:4d21e854f82ebc598f1b3dbbbada4efa88daa961a2144f6a19b68a9a8353787c",
                    "sha256:7786dae62e3519ad624523afd2367ba8c98e7c98a16c9441d98a9a2b46385dc6",
                    "sha256:c3eceff7ca94c446188c661c486025b06852f8d8cec7234f667ff2e2a7859e2b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "web-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                      "start_byte": 10239,
                      "end_byte": 11041,
                      "value_digest": "sha256:83c7952a149c3df268957c338c2237269bf87bd30b400c26c3c977b2b6159387"
                    }
                  ]
                }
              ],
              "note": "Slack Web API endpoints, including chat.postMessage, have documented request parameters, HTTP methods, rate limits, and JSON responses with an explicit top-level ok status."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.599Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "workspace-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ceba9f7ce0590709717f67d35c2aba5ac2ad56828a7da7bd7ae757ebeb653001",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2912a48cedae4b5edc0e94f36b21ea563933d082dc53323ff5b920a7756a2424",
                    "sha256:8a603596adbde6e8eb4d24b5bf75fb88eeebd3a5cc268c3519d7a5adfbde3ced",
                    "sha256:cdf4857de220d327e51f3e2e2d75ce94705c2d72fc01334c719d600db80dbdfa",
                    "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "message-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ef74f412ea86b218f208aceffb6c25a816cb5b45680f15d4bfd6dd75f29531dd",
                      "start_byte": 7932,
                      "end_byte": 8734,
                      "value_digest": "sha256:987eada1fcb4f0ab8164308286e1d852cd1aad8cdcf52f8083244533d8d82b4b"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:426b189158cc159f7d47b752457db79e692c5def3843638162a8c3f5fc523dc0",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3ee62a0180babbdf33832e1d38626812d926bcc4dbb1beee9c60dc9fb6fb2d31",
                    "sha256:6669c6e7f0dbd71bfd04628be8ff5394eb07153f615f3a0b6111d802875199f3",
                    "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3",
                    "sha256:8d0f1f5b2eed1f8133e42788a5ae90c2ac2a175f1499d988544141dc050b7ca0"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "rate-limits"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:84a5e8db1a964d18d2b5d578ce33d254f2dfd02ecf69f6ef6be93ecd48cb04d3",
                      "start_byte": 5141,
                      "end_byte": 5951,
                      "value_digest": "sha256:523019ee05f284b3c775c068309e076993f90062a99ca4219b5f96368df5d6a3"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:12696dca3b5b572c7637c91f3350edf8f67fdcf053069a5aaaab73eeca5f6774",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                    "sha256:4d21e854f82ebc598f1b3dbbbada4efa88daa961a2144f6a19b68a9a8353787c",
                    "sha256:c3eceff7ca94c446188c661c486025b06852f8d8cec7234f667ff2e2a7859e2b",
                    "sha256:c832fbef8359f5d7f8d51d83762d2d5d5d2923fbf654e8226f7aef2ccff4337a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "web-api"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:178744b81da58a96ab8a484e271c2cacdd7bfae5c537b3acc2a27846b3ff675f",
                      "start_byte": 4635,
                      "end_byte": 5448,
                      "value_digest": "sha256:b99fa92af2a9c9241eb591165ba34b6dfda285cc04a3d089156d558f494f8b7a"
                    }
                  ]
                }
              ],
              "note": "Every essential target has documented machine-operable HTTP interfaces for invocation, including Web API RPC-style methods."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 1,
        "barrier_ratio": 0.2
      },
      "last_tested_at": "2026-08-20T15:57:48.964Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:02cc523395b370e6243dec9a0813450ef0f4cc158cd3102fe29c1a08c913b7c6",
          "sha256:0313a5cc9ac80331ee15d238a4282dbc94ad811b98cca8e8220d6dada1f9f6bf",
          "sha256:1d019b226c0fc4b1e7956f4a03137aa550359b9e6954c07047646c3c20829ad1",
          "sha256:27f9e17c565874ea52c1728e19996d54b633f21cf3eddc52684ba05af45747aa",
          "sha256:3df401ab45d3629baea28d1e80ddf3002e9f9005991a4ee1910247b4a8151303",
          "sha256:3e18aa1422bfae8dcb57cd20c2408317cae2e8d97962aab1f80d7c26b636250a",
          "sha256:4b8c6e66e72e1e6b50449c4d549c3a32b7d4030480013b4866c134e9f03f6d1f",
          "sha256:4d00ce86a5ccf7fe539684569d4fe998a3c4704fb73df66598cad575421206dd",
          "sha256:4f39b7750a9348b41804cfc994e66dca97b3c2b4223022fddaf0bb6217e4b234",
          "sha256:508f4dca942c3010e9de28ad29586af168d9c89791ac6649f2460da3e9deb613",
          "sha256:514d884db282c316cb520c7aac340ea693c8ad0f9ed5d420f5fd5bb0e2147269",
          "sha256:528483ba53fea7b20f9f0fc5037a75d667844cd53e29c3733f82265c8c169ec0",
          "sha256:53fcf7db4e3ffcde1ddc7d12368f30ef1076776ca837119dacfb94a430b45e48",
          "sha256:5ea1babebeeb8891daed40d975ec368457c80c1bfdd57ae7d8d5030811ea9835",
          "sha256:695247912b490ac9def1a2f676d911dba9460193ff75e37ff102cfff3ff54303",
          "sha256:83948ae63066c916824160683808c7eb52554e10a97d6020be54bcd87ccb4a9c",
          "sha256:853137c7fc77638588d64000a3d806bfe8bea559ee90382f2b05d07c14954929",
          "sha256:8a53e8db6dcdf2d43af218b5fc2b9f3ef855b93de22bfe62e36949d0aaa16554",
          "sha256:a7185552802a360557cc96df5fbb706fcf35cf980084442f9b1d0ab26be5edde",
          "sha256:a83442675fbf3139c0bbdd9998eebb306e0b53ffc85c9756b70a1b78514930a1",
          "sha256:a9a5fee0f3abef5b572255343eaf3c6a43eff20530a99569ddae63d787aafd11",
          "sha256:be765cd6ced1de1e314619fb3263a4f17a3f44d2a71d252abc5951fdf1a440d7",
          "sha256:cb35556b9cc4409fb2bae93075da45a193acc46b2f43ce96433f5fd60c1082a7",
          "sha256:d10497b82b18b588738d6e2dce30d2a3602e63c93708e9e8e539d58bb0a50543",
          "sha256:d35553c79b675649ba9b64af899e57409356a99886afdc06774d937f366b636c",
          "sha256:d3ded7083a0b75da35d3d790814331553710b731d10b337e0218b0b40e0d243d",
          "sha256:edb794f0c7edd0e96c439609a4b704368a0b601b2eea194dcd5b4be1b5f3c17b"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:be765cd6ced1de1e314619fb3263a4f17a3f44d2a71d252abc5951fdf1a440d7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:46.230Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:8a53e8db6dcdf2d43af218b5fc2b9f3ef855b93de22bfe62e36949d0aaa16554"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:39.748Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:a83442675fbf3139c0bbdd9998eebb306e0b53ffc85c9756b70a1b78514930a1"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:13.150Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:4d00ce86a5ccf7fe539684569d4fe998a3c4704fb73df66598cad575421206dd"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:48.964Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:d10497b82b18b588738d6e2dce30d2a3602e63c93708e9e8e539d58bb0a50543"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:18.396Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:695247912b490ac9def1a2f676d911dba9460193ff75e37ff102cfff3ff54303"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:18.396Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:4f39b7750a9348b41804cfc994e66dca97b3c2b4223022fddaf0bb6217e4b234",
              "sha256:508f4dca942c3010e9de28ad29586af168d9c89791ac6649f2460da3e9deb613"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:18.396Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:3df401ab45d3629baea28d1e80ddf3002e9f9005991a4ee1910247b4a8151303"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.385Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:1d019b226c0fc4b1e7956f4a03137aa550359b9e6954c07047646c3c20829ad1"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:18.396Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:5ea1babebeeb8891daed40d975ec368457c80c1bfdd57ae7d8d5030811ea9835"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:05.005Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:4b8c6e66e72e1e6b50449c4d549c3a32b7d4030480013b4866c134e9f03f6d1f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:39.748Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:53fcf7db4e3ffcde1ddc7d12368f30ef1076776ca837119dacfb94a430b45e48"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:05.005Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:d35553c79b675649ba9b64af899e57409356a99886afdc06774d937f366b636c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:05.005Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:0313a5cc9ac80331ee15d238a4282dbc94ad811b98cca8e8220d6dada1f9f6bf"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.385Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:853137c7fc77638588d64000a3d806bfe8bea559ee90382f2b05d07c14954929"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.599Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:3e18aa1422bfae8dcb57cd20c2408317cae2e8d97962aab1f80d7c26b636250a",
              "sha256:83948ae63066c916824160683808c7eb52554e10a97d6020be54bcd87ccb4a9c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.599Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:514d884db282c316cb520c7aac340ea693c8ad0f9ed5d420f5fd5bb0e2147269"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.385Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:a9a5fee0f3abef5b572255343eaf3c6a43eff20530a99569ddae63d787aafd11"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:50.517Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:edb794f0c7edd0e96c439609a4b704368a0b601b2eea194dcd5b4be1b5f3c17b"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.385Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:528483ba53fea7b20f9f0fc5037a75d667844cd53e29c3733f82265c8c169ec0",
              "sha256:a7185552802a360557cc96df5fbb706fcf35cf980084442f9b1d0ab26be5edde",
              "sha256:d3ded7083a0b75da35d3d790814331553710b731d10b337e0218b0b40e0d243d"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.599Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:02cc523395b370e6243dec9a0813450ef0f4cc158cd3102fe29c1a08c913b7c6",
              "sha256:27f9e17c565874ea52c1728e19996d54b633f21cf3eddc52684ba05af45747aa",
              "sha256:cb35556b9cc4409fb2bae93075da45a193acc46b2f43ce96433f5fd60c1082a7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.599Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/slack/agent-readiness/slack-web-api/workspace-app-operations",
      "projection_digest": "sha256:a590dbfd3dcc819702a6aa4e32b3d8a5b2710941db32963795d4aed0cce4c3f6"
    }
  }
}
