{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyh8fpe5dk9hex187x4g03fn",
    "entity_slug": "vercel",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4xn2p7wd9g3a5rt8zq6",
      "entity_id": "ent_01kyh8fpe5dk9hex187x4g03fn",
      "scope": {
        "product": {
          "key": "vercel-rest-api",
          "name": "Vercel REST API"
        },
        "funnel": {
          "key": "deployment-operations",
          "name": "Deployment operations"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:2ca7db4f429b3bb813bb1ac6d59c8cb5213e3c16a9096dfaa1455909f7b73e13"
      },
      "declaration_revision_digest": "sha256:d7568bddb1b91a95870247219d2342d2acddb595cc98a292645a4704be00b472",
      "declaration": {
        "declaration_id": "declaration_vercel_api_deployment_operations",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/ve/vercel.yaml",
          "git_blob_oid": "8b524c33bb76fe518f088b6fa2af9b78111ddf45",
          "blob_digest": "sha256:97e1000513c54771bc5e6e7170d76d7bd91f4e1768c0f9028a1f023f4c98fafc"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Create and inspect deployments through the REST API",
            "interface_ids": [
              "deployment-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "vercel",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8fpe5dk9hex187x4g03fn"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "access-tokens",
            "uri": "https://vercel.com/guides/how-do-i-use-a-vercel-api-access-token",
            "roles": [
              "authentication",
              "descriptor",
              "documentation",
              "provisioning"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "account-signup",
            "uri": "https://vercel.com/signup",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "api-errors",
            "uri": "https://vercel.com/docs/rest-api/errors",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "api-reference",
            "uri": "https://vercel.com/docs/rest-api",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "billing-checkout",
            "uri": "https://vercel.com/docs/plans/pro-plan/billing",
            "roles": [
              "checkout",
              "documentation",
              "pricing"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "deployment-operations",
            "uri": "https://vercel.com/docs/rest-api/reference/endpoints/deployments/create-a-new-deployment",
            "roles": [
              "documentation",
              "operations",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "pricing",
            "uri": "https://vercel.com/pricing",
            "roles": [
              "pricing"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64",
            "uri": "https://vercel.com/docs/plans/pro-plan",
            "roles": [
              "checkout",
              "documentation"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609",
            "uri": "https://vercel.com/docs/cli/tokens",
            "roles": [
              "authentication",
              "documentation"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://vercel.com/legal/terms",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://vercel.com/help",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "registration",
            "uri": "https://vercel.com/signup",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "endpoint_id": "vercel-api",
            "uri": "https://api.vercel.com",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "api-authentication",
            "modality": "network_api",
            "functions": [
              "authentication"
            ],
            "endpoint_ids": [],
            "resource_ids": [
              "access-tokens"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          },
          {
            "interface_id": "deployment-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "vercel-api"
            ],
            "resource_ids": [
              "api-errors",
              "api-reference",
              "deployment-operations"
            ],
            "operated_by_participant_id": "vercel",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "deployment-api"
            }
          },
          {
            "relation_id": "deployments-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "deployment-operations"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "deployment-api"
            }
          },
          {
            "relation_id": "reference-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "deployment-api"
            }
          },
          {
            "relation_id": "relation-describes-6d02ed10c0b4e2431680d2306b1792c88939522d69d3aff8487cdc71565ad520",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "account-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "separate-eligibility-resource",
            "role": "eligibility",
            "rationale": "Applicable access conditions are published within the service terms; no separate eligibility resource is declared."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:574d1fbcd53d0646a8e51bb4de3abad38c72876e5af3057e9a7e9bcfbd4f6fed",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "B",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "sign_up",
        "stage_label": "Sign up",
        "public_state": "limited",
        "finding": {
          "signal_code": "delegated_identity_access",
          "condition": "Can an agent obtain scoped, revocable authority for this service?",
          "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
          "context": "Vercel API access tokens can be created in personal account settings or via the CLI and scoped to user accounts, teams, or single projects. However, newly created tokens are shown in plaintext only once and require manual copying and storage into secret managers or environment variables."
        }
      },
      "limitations": [
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Vercel API access tokens can be created in personal account settings or via the CLI and scoped to user accounts, teams, or single projects. However, newly created tokens are shown in plaintext only once and require manual copying and storage into secret managers or environment variables."
          },
          "remediation": {
            "signal_code": "delegated_identity_access",
            "code": "improve.sign_up.delegated_identity_access",
            "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Tokens can be created via the account settings page or using the `vercel tokens` CLI command. The CLI displays the plaintext token value only once upon creation, requiring manual copy and storage in a secret manager or environment variable."
          },
          "remediation": {
            "signal_code": "access_material_delivery",
            "code": "improve.provision.access_material_delivery",
            "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "provisioning_completion",
            "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
            "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
            "context": "Deployment creation returns an object and exposes pollable progress and terminal states, but the retained evidence does not establish a documented completion bound."
          },
          "remediation": {
            "signal_code": "provisioning_completion",
            "code": "improve.provision.provisioning_completion",
            "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation establishes generic error responses (such as `forbidden`, `rate_limited`, `bad_request`, `internal_server_error`, and `not_found`) along with rate limit headers and error payloads. However, safe failure handling semantics such as explicit request idempotency, retry procedures, cancellation, and reconciliation are not fully documented in the evidence."
          },
          "remediation": {
            "signal_code": "failure_contract",
            "code": "improve.operate.failure_contract",
            "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "First-party documentation states that Vercel access tokens can be created inside account settings or via the Vercel CLI (`vercel tokens add`), listed, and revoked/removed using `vercel tokens rm <token-id>`. However, evidence does not document full agent-executable automated credential rotation, compromise handling, or recovery semantics."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "service_discovery",
            "condition": "Can an agent find the exact service and its stable entrypoints?",
            "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
            "context": "The Vercel REST API documentation explicitly provides the service details, HTTP/1 and HTTP/2 SSL architecture support, and the base entrypoint URL at https://api.vercel.com."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "Vercel's Terms of Service agreement is retrievable, readable, and materially complete, covering applicable terms, schedule additions, and commitments for using Vercel's Services."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "context": "Vercel's Terms of Service explicitly state age and eligibility conditions, requiring users to be at least 16 years of age and to use or access services through an electronic device controlled by the user."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Vercel's pricing page discloses plan options including Hobby ($0/mo) and Pro ($20/mo), with explicit usage rates, included credits, variable resource limits, and currency in USD."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.487Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:276f373b51d8d4b56d1afae71f328da7cdd33f68aa63ed3e5c7a0fb618de4cef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:8e8a0e54a0914860398b1271affba87ff76d8cdfd4b00026c388ad34b80e53a3",
                    "sha256:b8d3521bbc52ac1327616b578ce1b772dfd54977f7efa230dfaba7ebf61626a7",
                    "sha256:d7e6130a3d8dc377070d4d84225e057b1eeeabfea2e05a891fd7b6e751af7447"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b8d3521bbc52ac1327616b578ce1b772dfd54977f7efa230dfaba7ebf61626a7",
                      "start_byte": 9325,
                      "end_byte": 10119,
                      "value_digest": "sha256:89b7c06c13317b210660c52084b8f79c96ead3a733cba57d8dc9cc21ad1c1f96"
                    }
                  ]
                }
              ],
              "note": "Vercel's Terms of Service explicitly state age and eligibility conditions, requiring users to be at least 16 years of age and to use or access services through an electronic device controlled by the user."
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:01.412Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d5d8a4b4d9f75b0c0577d04bb1375c57f4df9ff5eccef3b358392e9a6137d0e9",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2e0f5a01b7b08dd200fa527eb16e120300d139eb8e989e307cfd9c4f0bfd7430",
                    "sha256:3221725ff99fcdc0dfb9ac53f960e6b5ced087dc4934b60c630905b4cf293919",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:e7cc7c45316286ba910c1991d75c290b0d84416848a251e81d9ace040efda019"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:3221725ff99fcdc0dfb9ac53f960e6b5ced087dc4934b60c630905b4cf293919",
                      "start_byte": 6983,
                      "end_byte": 7786,
                      "value_digest": "sha256:1bee2df6b749a102d156c942bacd7671fff46a2ffd5e5c9fe3e924452696967f"
                    },
                    {
                      "artifact_digest": "sha256:3221725ff99fcdc0dfb9ac53f960e6b5ced087dc4934b60c630905b4cf293919",
                      "start_byte": 8588,
                      "end_byte": 9394,
                      "value_digest": "sha256:b905f4efbaf538e96b26f63cc1e155b534b78f56e7ee51170f6c30e156eace02"
                    }
                  ]
                }
              ],
              "note": "Vercel's pricing page discloses plan options including Hobby ($0/mo) and Pro ($20/mo), with explicit usage rates, included credits, variable resource limits, and currency in USD."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:18.718Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-reference"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5fd1c5dfe9ba870693f9a82e9b76eda4c3510276df4988fed18cc9d538b309e7",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b0aaecf5f95cc4530f0c735c6fc3d526c7643d2df352c3ab96f12e4e58c6ff2d",
                    "sha256:d813415bd8abb4b66d12bc3d6782c15254b7e4328fa111520391707a9935676e",
                    "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1",
                      "start_byte": 24533,
                      "end_byte": 25333,
                      "value_digest": "sha256:885494883e0a0104262619eeb67c095ea0756a35311412a1b8f4761bb564f8b1"
                    }
                  ]
                }
              ],
              "note": "The Vercel REST API documentation explicitly provides the service details, HTTP/1 and HTTP/2 SSL architecture support, and the base entrypoint URL at https://api.vercel.com."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.487Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:276f373b51d8d4b56d1afae71f328da7cdd33f68aa63ed3e5c7a0fb618de4cef",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2b98f6d533f53426430f441ae4db7466db45b981aaa78e294567688f840dccdc",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b8d3521bbc52ac1327616b578ce1b772dfd54977f7efa230dfaba7ebf61626a7",
                    "sha256:d7e6130a3d8dc377070d4d84225e057b1eeeabfea2e05a891fd7b6e751af7447"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b8d3521bbc52ac1327616b578ce1b772dfd54977f7efa230dfaba7ebf61626a7",
                      "start_byte": 6137,
                      "end_byte": 6929,
                      "value_digest": "sha256:3959dcda0ad9cf80831fd1e7ab6e92ffd896372f1c9f3b907e04e7ceb2124cd3"
                    },
                    {
                      "artifact_digest": "sha256:b8d3521bbc52ac1327616b578ce1b772dfd54977f7efa230dfaba7ebf61626a7",
                      "start_byte": 6930,
                      "end_byte": 7729,
                      "value_digest": "sha256:5ec198c6f5a80582fdd3b3c6dde5fe6d88820f2ee80d1559ee869d083e07486e"
                    }
                  ]
                }
              ],
              "note": "Vercel's Terms of Service agreement is retrievable, readable, and materially complete, covering applicable terms, schedule additions, and commitments for using Vercel's Services."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Vercel API access tokens can be created in personal account settings or via the CLI and scoped to user accounts, teams, or single projects. However, newly created tokens are shown in plaintext only once and require manual copying and storage into secret managers or environment variables."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The sign-up page displays options to continue with Google, GitHub, ChatGPT, Apple, or Email. Current admissible evidence does not resolve whether the access controls, navigation, and handoffs are fully machine-operable."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured sign-up pages display third-party login and email authentication options. Admissible evidence does not explicitly establish whether CAPTCHA challenges are present or if a supported alternative exists."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The sign-up capture presents third-party and email login options, but current admissible evidence does not explicitly document whether phone verification is required, absent, or supported through a resumable boundary."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "context": "A stable sign-up page at https://vercel.com/signup presents options to continue with third-party providers or email to begin service access."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.492Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The sign-up page displays options to continue with Google, GitHub, ChatGPT, Apple, or Email. Current admissible evidence does not resolve whether the access controls, navigation, and handoffs are fully machine-operable."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.492Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:3a28d77bd7cb104bb6acbb4dcb7908e9fd9071c172223b0c72405e3343a41a26",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2e34a529bd31c311dd4fa8cbca51a537ee38a0abeee8aa6978baebfe40ddd06a",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:9f8f8c188804bfa8aab7adfe6dbadfe7b2491409dedf49045f08bb8fba3b25f3",
                    "sha256:a1e8d53c0c3296297b269f9c884626242f586b08ee2ccf0d4b5205360a27eb20",
                    "sha256:ec92bf08363b0e8590a3ebdaa89cdbbc3feda6d11b56d6117ddb08c066e0982e",
                    "sha256:f8f024283d04fc451917ebbef9dc508070977f289d8ed03229bb8e87a4dfedaf"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:f8f024283d04fc451917ebbef9dc508070977f289d8ed03229bb8e87a4dfedaf",
                      "start_byte": 667,
                      "end_byte": 1026,
                      "value_digest": "sha256:c538a8fb7c6905b9fb8c63f9631a03c43751bf24f2a09f1588f87b809ef69f80"
                    }
                  ]
                }
              ],
              "note": "A stable sign-up page at https://vercel.com/signup presents options to continue with third-party providers or email to begin service access."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.492Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured sign-up pages display third-party login and email authentication options. Admissible evidence does not explicitly establish whether CAPTCHA challenges are present or if a supported alternative exists."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.742Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "access-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bd779ac5bd6f555ceddc9ed10385c19a2f81c103cd12566092ecbef14a2e4fd",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:f3d01f359901abde492ac4f08dece1bae1d6138066ec3582e5f6154765e739e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5962a522dd7c248106e1d517b4625a9329ec9a3dff5d77e485b1374ea679a7c3",
                    "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                    "sha256:b789ecb6c1edeef8135d93765dc634e9f53bdc62d4d5fa824a470cc41588330d",
                    "sha256:bc8f361e8ccd45ef2b4db6127b3a95c2660e0cf145c7e4da0340eb6188a12b0e",
                    "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311",
                    "sha256:f50e22b3d539ca24945a5e1d75ab26087935c686e7eb90d869d571bdb0043356"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 15071,
                      "end_byte": 15849,
                      "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
                    },
                    {
                      "artifact_digest": "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                      "start_byte": 8640,
                      "end_byte": 9424,
                      "value_digest": "sha256:1238aa895205654d881f5080362e8c404d89b37e26acd62d40a328156fb4415c"
                    }
                  ]
                }
              ],
              "note": "Vercel API access tokens can be created in personal account settings or via the CLI and scoped to user accounts, teams, or single projects. However, newly created tokens are shown in plaintext only once and require manual copying and storage into secret managers or environment variables.",
              "remediation": {
                "signal_code": "delegated_identity_access",
                "code": "improve.sign_up.delegated_identity_access",
                "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
              }
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:56.492Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "account-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The sign-up capture presents third-party and email login options, but current admissible evidence does not explicitly document whether phone verification is required, absent, or supported through a resumable boundary."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "delegated_identity_access",
              "code": "improve.sign_up.delegated_identity_access",
              "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
            }
          ]
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Vercel discloses that the Pro plan payments are billed at the beginning of each billing cycle in USD (if converted by the card provider) via Credit/Debit card."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence describes Pro plan checkout domain claims and payment method settings, but does not document an API, protocol, or web flow for deterministic checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The documentation mentions automatic credit card charges upon invoice issuance and adding new cards in billing settings, but does not document scoped delegation rails or human-confirmed payment authorization protocols with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "context": "A direct self-service upgrade path is documented where new subscriptions can claim a domain at checkout during the upgrade or add a payment method via team settings under Billing."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:22.271Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence describes Pro plan checkout domain claims and payment method settings, but does not document an API, protocol, or web flow for deterministic checkout construction, approval handoff, and resumption."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:22.271Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:70063f8046d2ff2ec0be3911030dc25ed356cddf91c385d9cf0a855c10619b88",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6730ba850f57c8716c49217c4275fcf2387e626d9b853f819c5d93e0678c42b4",
                    "sha256:d99976e95717a4c42acc982c073a1b46236a989109a06d064f050f5a54801f39",
                    "sha256:fc571350d579955b3e557ecf1fd25fc459de8d0026497a64bb023432401284d1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:d99976e95717a4c42acc982c073a1b46236a989109a06d064f050f5a54801f39",
                      "start_byte": 12115,
                      "end_byte": 12913,
                      "value_digest": "sha256:25caa0694bfd1c783dc17335c55e9ed3edae2b902bc5a745b796687fdc34a8cd"
                    },
                    {
                      "artifact_digest": "sha256:d99976e95717a4c42acc982c073a1b46236a989109a06d064f050f5a54801f39",
                      "start_byte": 18486,
                      "end_byte": 19284,
                      "value_digest": "sha256:79d48944c08e7d1e555ff117da9663c29efa1eb56a93abcc5b56869e2b1ca441"
                    }
                  ]
                }
              ],
              "note": "Vercel discloses that the Pro plan payments are billed at the beginning of each billing cycle in USD (if converted by the card provider) via Credit/Debit card."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:22.271Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The documentation mentions automatic credit card charges upon invoice issuance and adding new cards in billing settings, but does not document scoped delegation rails or human-confirmed payment authorization protocols with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "A documented direct purchase path reaches paid access without a vendor decision point.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:22.271Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "billing-checkout"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:70063f8046d2ff2ec0be3911030dc25ed356cddf91c385d9cf0a855c10619b88",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:d99976e95717a4c42acc982c073a1b46236a989109a06d064f050f5a54801f39",
                    "sha256:e4b8b5031138e110066c92f11e59a00fd81cb6f0cc2aafa95517e6ea23313267",
                    "sha256:fc571350d579955b3e557ecf1fd25fc459de8d0026497a64bb023432401284d1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "billing-checkout"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:d99976e95717a4c42acc982c073a1b46236a989109a06d064f050f5a54801f39",
                      "start_byte": 13710,
                      "end_byte": 14505,
                      "value_digest": "sha256:17e9f61f65d5f4c43a251d6a4aaec07f4e238191de6e5c7dc6f070b5a07b5323"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:49f79e09c0fee3c10af2d019f79a166728e29c4bebebe391bf9770fde0418c70",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7226efc03c8450a2b19a3f44bd1d57ca7e4975fefe6db41a93b478b670759737",
                    "sha256:7229ab4ed300caab983893971bdd125f3c19c4616e2d9810e9d534c29b0f27ea",
                    "sha256:bf222cd0342b07f91707574418ae39f516b2ac9f0697f232c42a74123ca5b8b4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-54635e0ef5c0510ed84229bf9da667a7aa6eae5d7bde501e7987da45a62b4c64"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7229ab4ed300caab983893971bdd125f3c19c4616e2d9810e9d534c29b0f27ea",
                      "start_byte": 18846,
                      "end_byte": 19646,
                      "value_digest": "sha256:4418433dfb66e1d2ad78a4b1d984069fa73cf28eb162c4edf2a9ccb051879be1"
                    }
                  ]
                }
              ],
              "note": "A direct self-service upgrade path is documented where new subscriptions can claim a domain at checkout during the upgrade or add a payment method via team settings under Billing."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Tokens can be created via the account settings page or using the `vercel tokens` CLI command. The CLI displays the plaintext token value only once upon creation, requiring manual copy and storage in a secret manager or environment variable."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "context": "Deployment creation returns an object and exposes pollable progress and terminal states, but the retained evidence does not establish a documented completion bound."
            },
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "Deployment provisioning can be programmatically initiated via the Vercel REST API endpoint `POST https://api.vercel.com/v13/deployments` by passing an access token in the Authorization header along with deployment file configuration in the JSON request body."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:22.881Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "access-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bd779ac5bd6f555ceddc9ed10385c19a2f81c103cd12566092ecbef14a2e4fd",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:bc8f361e8ccd45ef2b4db6127b3a95c2660e0cf145c7e4da0340eb6188a12b0e",
                    "sha256:f807197e46f6f2358ea7700449399c795e67ebcee9346f36090e0938c32b7af2"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 15071,
                      "end_byte": 15849,
                      "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
                    },
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 15850,
                      "end_byte": 16637,
                      "value_digest": "sha256:c02b6465738b1b6f3faf890bce294a494ec613f041da4d12e046c86ed16c9b4c"
                    }
                  ]
                }
              ],
              "note": "Tokens can be created via the account settings page or using the `vercel tokens` CLI command. The CLI displays the plaintext token value only once upon creation, requiring manual copy and storage in a secret manager or environment variable.",
              "remediation": {
                "signal_code": "access_material_delivery",
                "code": "improve.provision.access_material_delivery",
                "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
              }
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Completion is observable, but an asynchronous path omits a material terminal, bound, or reconciliation property.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:54.901Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "deployment-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:abddf00df14bb608b0d9dd298b0b871168b22f9f8bf6d966faa02855ca917961",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                    "sha256:74f99352d46a23477ce75e953130ae98093b82f1b61292ede97283c3b95d55dd",
                    "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff",
                    "sha256:e0bdc8f4b2c4b9a6b6d423866003482c62667da598e7345b75d8ed12ddf48536"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "deployment-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 14618,
                      "end_byte": 15418,
                      "value_digest": "sha256:d7cbb3d4969a9d3120d0268f69ef7f45f56e25d76deb8ba5f3e44731be1d48be"
                    }
                  ]
                }
              ],
              "note": "Deployment creation returns an object and exposes pollable progress and terminal states, but the retained evidence does not establish a documented completion bound.",
              "remediation": {
                "signal_code": "provisioning_completion",
                "code": "improve.provision.provisioning_completion",
                "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
              }
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:54.901Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "access-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "deployment-operations"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:abddf00df14bb608b0d9dd298b0b871168b22f9f8bf6d966faa02855ca917961",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                    "sha256:229b86fef59038e113d8b4c79aef50ef7fa4e827a4f31d17a61c4dc08bd8273e",
                    "sha256:74f99352d46a23477ce75e953130ae98093b82f1b61292ede97283c3b95d55dd",
                    "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "deployment-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 8359,
                      "end_byte": 9126,
                      "value_digest": "sha256:86ddf84a34f8500eea7bf902a42d423332d7674d4c2a6058829bff4f01298cf7"
                    },
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 9127,
                      "end_byte": 9931,
                      "value_digest": "sha256:d3fc1d14b85360b1f9eff77f89dc3e16bba84dbcd22a46497fb9933d35d918d6"
                    }
                  ]
                }
              ],
              "note": "Deployment provisioning can be programmatically initiated via the Vercel REST API endpoint `POST https://api.vercel.com/v13/deployments` by passing an access token in the Authorization header along with deployment file configuration in the JSON request body."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "access_material_delivery",
              "code": "improve.provision.access_material_delivery",
              "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
            },
            {
              "signal_code": "provisioning_completion",
              "code": "improve.provision.provisioning_completion",
              "instruction": "Expose bounded machine-readable terminal status and reconciliation semantics."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "failure_contract",
            "condition": "Can an agent handle applicable failure modes safely?",
            "finding": "Safe failure handling is documented only partially.",
            "context": "Documentation establishes generic error responses (such as `forbidden`, `rate_limited`, `bad_request`, `internal_server_error`, and `not_found`) along with rate limit headers and error payloads. However, safe failure handling semantics such as explicit request idempotency, retry procedures, cancellation, and reconciliation are not fully documented in the evidence."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "context": "First-party documentation states that Vercel access tokens can be created inside account settings or via the Vercel CLI (`vercel tokens add`), listed, and revoked/removed using `vercel tokens rm <token-id>`. However, evidence does not document full agent-executable automated credential rotation, compromise handling, or recovery semantics."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Every essential target is accessible through agent-usable machine interfaces, specifically the Vercel REST API (`https://api.vercel.com`) and the Vercel CLI."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "Request-time authentication is documented using Vercel Access Tokens passed via the `Authorization: Bearer TOKEN` HTTP header, which can be scoped to personal accounts, specific teams, or individual projects."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Essential endpoints and error payloads are documented across all evaluated targets. For instance, creating a deployment via POST to `/v13/deployments` specifies HTTP methods, query parameters (`teamId`, `forceNew`), JSON body fields (`files`, `deploymentId`, `customEnvironmentSlugOrId`), response structures (`id`, `readyState`, `target`), and state transition flow (`QUEUED` → `INITIALIZING` → `BUILDING` → `READY`/`ERROR`)."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.742Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "access-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f3d01f359901abde492ac4f08dece1bae1d6138066ec3582e5f6154765e739e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:5962a522dd7c248106e1d517b4625a9329ec9a3dff5d77e485b1374ea679a7c3",
                    "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                    "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311",
                    "sha256:f50e22b3d539ca24945a5e1d75ab26087935c686e7eb90d869d571bdb0043356"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                      "start_byte": 8640,
                      "end_byte": 9424,
                      "value_digest": "sha256:1238aa895205654d881f5080362e8c404d89b37e26acd62d40a328156fb4415c"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bd779ac5bd6f555ceddc9ed10385c19a2f81c103cd12566092ecbef14a2e4fd",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:964810117ac232aae54476ada2e4df2bcab8d763bc6ec585c2bf478c27cae459",
                    "sha256:bc8f361e8ccd45ef2b4db6127b3a95c2660e0cf145c7e4da0340eb6188a12b0e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 15071,
                      "end_byte": 15849,
                      "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
                    },
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 16638,
                      "end_byte": 17400,
                      "value_digest": "sha256:68c15c9493bbee20720bb4e9835817c785560ab1b266e4ddd1dd39d5b181bfac"
                    }
                  ]
                }
              ],
              "note": "First-party documentation states that Vercel access tokens can be created inside account settings or via the Vercel CLI (`vercel tokens add`), listed, and revoked/removed using `vercel tokens rm <token-id>`. However, evidence does not document full agent-executable automated credential rotation, compromise handling, or recovery semantics.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Safe failure handling is documented only partially.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.464Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-errors"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:cfda002dda00f8488c722d5b3efb37a7794321c9523ddda0d7ab63210b3b3500",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3600f6b4c9c8639a607eba1c4699288c195c8a1ef3ade171c3e648b13b2cc39d",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:881fd0fc71fb86bb4ffa5397e5e35373dd202d7d3472e507b40ead4831e70ae1",
                    "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff",
                      "start_byte": 6203,
                      "end_byte": 6884,
                      "value_digest": "sha256:1a0ed3cc38673966cb308caa56c2edc8849a88390d8cd09fcbf208a55c97f101"
                    },
                    {
                      "artifact_digest": "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff",
                      "start_byte": 6885,
                      "end_byte": 7682,
                      "value_digest": "sha256:872f7f5c5ce144424ee6316888391eda9bfa285dd144f1f44efd8bc1678979c4"
                    }
                  ]
                }
              ],
              "note": "Documentation establishes generic error responses (such as `forbidden`, `rate_limited`, `bad_request`, `internal_server_error`, and `not_found`) along with rate limit headers and error payloads. However, safe failure handling semantics such as explicit request idempotency, retry procedures, cancellation, and reconciliation are not fully documented in the evidence.",
              "remediation": {
                "signal_code": "failure_contract",
                "code": "improve.operate.failure_contract",
                "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
              }
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.742Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "access-tokens"
                },
                {
                  "node_kind": "resource",
                  "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bd779ac5bd6f555ceddc9ed10385c19a2f81c103cd12566092ecbef14a2e4fd",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b789ecb6c1edeef8135d93765dc634e9f53bdc62d4d5fa824a470cc41588330d",
                    "sha256:bc8f361e8ccd45ef2b4db6127b3a95c2660e0cf145c7e4da0340eb6188a12b0e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "readiness-55d5a3246b49c5978d9cd909619ea57cb2e9a92593283460fba3bdd38e64a609"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:4468f8592a48cada4e1bdb71c8cfdb5ea549f2ec34cffb5333b4bfb5f1561bac",
                      "start_byte": 15071,
                      "end_byte": 15849,
                      "value_digest": "sha256:7229ded016d0c8cda63472866c684809c40518f36814571e81c571ef004dcfae"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:f3d01f359901abde492ac4f08dece1bae1d6138066ec3582e5f6154765e739e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1b5104ac4564da9bdb873efb1a94f76853589825e8146229d5c74178b7ac036d",
                    "sha256:5962a522dd7c248106e1d517b4625a9329ec9a3dff5d77e485b1374ea679a7c3",
                    "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                    "sha256:c891c78882d6acc1d53bd941c6daf6cd41b17359aa771d7c3def9f4f5fb45311"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "access-tokens"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7c178444ea00159b38e54a30cf7c4877c1bb54c901a07f0d6138be96071f6769",
                      "start_byte": 9425,
                      "end_byte": 10224,
                      "value_digest": "sha256:7b8c3747be27106cf184ebfb41889284692306f78f1f3e993f5c304d55aac902"
                    }
                  ]
                }
              ],
              "note": "Request-time authentication is documented using Vercel Access Tokens passed via the `Authorization: Bearer TOKEN` HTTP header, which can be scoped to personal accounts, specific teams, or individual projects."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:54.901Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "deployment-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5fd1c5dfe9ba870693f9a82e9b76eda4c3510276df4988fed18cc9d538b309e7",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b0aaecf5f95cc4530f0c735c6fc3d526c7643d2df352c3ab96f12e4e58c6ff2d",
                    "sha256:d813415bd8abb4b66d12bc3d6782c15254b7e4328fa111520391707a9935676e",
                    "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1",
                      "start_byte": 24533,
                      "end_byte": 25333,
                      "value_digest": "sha256:885494883e0a0104262619eeb67c095ea0756a35311412a1b8f4761bb564f8b1"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:abddf00df14bb608b0d9dd298b0b871168b22f9f8bf6d966faa02855ca917961",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                    "sha256:6f9ad7ec2196b53f3fae6b6b18709c06561365683b83b2bc9d30e4cc18c928b5",
                    "sha256:74f99352d46a23477ce75e953130ae98093b82f1b61292ede97283c3b95d55dd",
                    "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "deployment-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 14618,
                      "end_byte": 15418,
                      "value_digest": "sha256:d7cbb3d4969a9d3120d0268f69ef7f45f56e25d76deb8ba5f3e44731be1d48be"
                    },
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 9127,
                      "end_byte": 9931,
                      "value_digest": "sha256:d3fc1d14b85360b1f9eff77f89dc3e16bba84dbcd22a46497fb9933d35d918d6"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:cfda002dda00f8488c722d5b3efb37a7794321c9523ddda0d7ab63210b3b3500",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:62dcf16e34fa6a8fd556ed80eb1640060dc19860a012be411fb6c3611b039eba",
                    "sha256:881fd0fc71fb86bb4ffa5397e5e35373dd202d7d3472e507b40ead4831e70ae1",
                    "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff",
                      "start_byte": 6203,
                      "end_byte": 6884,
                      "value_digest": "sha256:1a0ed3cc38673966cb308caa56c2edc8849a88390d8cd09fcbf208a55c97f101"
                    }
                  ]
                }
              ],
              "note": "Essential endpoints and error payloads are documented across all evaluated targets. For instance, creating a deployment via POST to `/v13/deployments` specifies HTTP methods, query parameters (`teamId`, `forceNew`), JSON body fields (`files`, `deploymentId`, `customEnvironmentSlugOrId`), response structures (`id`, `readyState`, `target`), and state transition flow (`QUEUED` → `INITIALIZING` → `BUILDING` → `READY`/`ERROR`)."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:54.901Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "deployment-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:cfda002dda00f8488c722d5b3efb37a7794321c9523ddda0d7ab63210b3b3500",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4442adf8ff62567096a8bd2dbdacffb3e443f8aea2afabf80b715545407db22f",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:881fd0fc71fb86bb4ffa5397e5e35373dd202d7d3472e507b40ead4831e70ae1",
                    "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ca908a12a5bbd1d4c9f8d68d4f15f3a4511c40c0f8480fbbfc1bdcca336f75ff",
                      "start_byte": 5398,
                      "end_byte": 6202,
                      "value_digest": "sha256:97f5e6161838d77a7c0a88b07764bfbe52fd4276f0b292e8e2f957d16c4bd4b7"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:abddf00df14bb608b0d9dd298b0b871168b22f9f8bf6d966faa02855ca917961",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                    "sha256:1fdf4d28f2b6adaf55d0195b5f8a6f96c02d2e8163b9f64100b4c1ddf3496807",
                    "sha256:74f99352d46a23477ce75e953130ae98093b82f1b61292ede97283c3b95d55dd",
                    "sha256:77e071b48b89081c5fd19fde8871b34fef15ec81fd1f93f0f77baec74d620bff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "deployment-operations"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:03fb00403a8c729880514c3fc4da9819f5d5d3da07bab7132548ea87bcbe888b",
                      "start_byte": 7565,
                      "end_byte": 8358,
                      "value_digest": "sha256:85b7b1668c1fcee1069bd68d41d36781ccf05d5e5da6b7706c6e67ba6efe8df0"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5fd1c5dfe9ba870693f9a82e9b76eda4c3510276df4988fed18cc9d538b309e7",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2235b2fe079987bfa185906e3c7f71bae01ed43a1256e96476a3fa5a9ca25f7e",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:b0aaecf5f95cc4530f0c735c6fc3d526c7643d2df352c3ab96f12e4e58c6ff2d",
                    "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:e879e37c61aee3084ce8e7bc77a90279a8e4a61a8c51c8f84b3a82b9f28429e1",
                      "start_byte": 23736,
                      "end_byte": 24532,
                      "value_digest": "sha256:608f9fe9c94f8d44f1571ba9e0f713e984c0172bdb618bbe87431f8ef97cb6fd"
                    }
                  ]
                }
              ],
              "note": "Every essential target is accessible through agent-usable machine interfaces, specifically the Vercel REST API (`https://api.vercel.com`) and the Vercel CLI."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "failure_contract",
              "code": "improve.operate.failure_contract",
              "instruction": "Document applicable structured errors, retry, cancellation, and reconciliation semantics."
            },
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:01.412Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:0487ae8f4da006ef5bba69544d755ef09d93f4eda8ce9b207b83791a3c6097aa",
          "sha256:0b7dc20909bce3643a5f056259ebeca63bcf5db07d2ecd01d8de532166586359",
          "sha256:1e4af52a28746fdf6116f3238a61783e3b54cf53abb28d026a231fba3d300d22",
          "sha256:24186a25a7a7d68108571b4cb9d2c84eee2522a44b443bcb07403a4e0b870af8",
          "sha256:2cb16eb6fa5822d3ec0cde2bafb1b029c34ca896fc123857fa63cd7e61236197",
          "sha256:33f9a68d174c2fba9de9f63a5b07667db97e063fabdecc52006848298573e34b",
          "sha256:37b9b68eaee06a16357456159c33a7f4f9d79c892971303880297a013da044d4",
          "sha256:3949308191ba4d6071374baeea5f003c81d75053e49d1a614e0bf8a191a6d54d",
          "sha256:402c82ff26fea2a2c41d81b30eb5e592a8a744d41895ee70d898734351af4326",
          "sha256:4e35d07610f08c3923c95589e4737b338e78afc5b972bcb869b2a8da7fc925ce",
          "sha256:53bc8b580fbc8edbfca0224e5ccbace66ef952e5861f020d67801fa7e0ec418e",
          "sha256:682c7dd83535bed8b9cbfb2e067fcc14e154bbd904bc2ccb33a48e9b26c281f0",
          "sha256:705a63022c8f294b29d1199ede2a2949e106f9bde0bd98b301623abee73ae83a",
          "sha256:716669c46647e94be4137a69abfcbcaf7315a03834017511146de4d5ff572f81",
          "sha256:835e2f84581b17e47b722b9e198d81648fe83dceb89fe08f9f304e04b9f891e3",
          "sha256:849f6e8a8720cd3e1ca5d7effb597d91a369b1f30487a04f1a642f81b04eee28",
          "sha256:8d3a8d14d503cf00c7569ef8975c8d47b12f7b85f92975ad75b4ffb9debe585c",
          "sha256:8fb94a2c6b3256abc6f388b7aae09639d543b75ccdca4b28833d1b21f51d150f",
          "sha256:9e1ebc236f88f721a16d9a448ad47e441c6085310f87dd4815aa9f334b416c09",
          "sha256:a0e8786bf0620369e63b62400f140a2445c6d640b10a0bf74b345be01a70b5c0",
          "sha256:adcf1f4a445c563a976eaa7fa2b25a8c5fd832e4eac403d73e601b02d32f42ff",
          "sha256:b83b01f3e25a60fb3a66aa90d8284642261f436a0ceaa805715cc61363933aba",
          "sha256:c2baedc44fe0ff1d6f54f42b6b1c522f1527ba83bcd474a5e6fdc32a3d6c619c",
          "sha256:cb51968c801a05b955e7ccdb51b76c2d7ec372aceb48528e3baba7d898036078",
          "sha256:cba8f47497a46a27e761ca7a9b4ca5c2d81230b99931af55145390cca9a5a3ca",
          "sha256:d1e67c65a1dd0152bb89ad740fba6c836ba9dd84b5a0693be84b81bd4587f23a",
          "sha256:d69010f777226a83ca8293242e880e4925f62881d118d0b7828109586f7bec45",
          "sha256:d6b10d1ed58f9d5299b96dd5aec4dc00c4c3168832b13ba4032d6d854414eeac",
          "sha256:d96a6e7ba02f40c7853857acfcead9793958a2f17858ec9356653bb206c3828c",
          "sha256:e3e8989abf5ec6cd0a8c27ce929d437bc8b17850a0b9ba80bf8153c67fa329c4",
          "sha256:e5ee1dfc6c6985d7642670827b96aafb22961e9e00190ae3a499ef777c96a1a5",
          "sha256:f280345937371bbffa5a70c47ecba262a95be72f27f3942fac47b840423c51c9"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:0b7dc20909bce3643a5f056259ebeca63bcf5db07d2ecd01d8de532166586359"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.487Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:402c82ff26fea2a2c41d81b30eb5e592a8a744d41895ee70d898734351af4326"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:01.412Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:2cb16eb6fa5822d3ec0cde2bafb1b029c34ca896fc123857fa63cd7e61236197"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:18.718Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:e3e8989abf5ec6cd0a8c27ce929d437bc8b17850a0b9ba80bf8153c67fa329c4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.487Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:53bc8b580fbc8edbfca0224e5ccbace66ef952e5861f020d67801fa7e0ec418e"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.492Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:835e2f84581b17e47b722b9e198d81648fe83dceb89fe08f9f304e04b9f891e3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.492Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:b83b01f3e25a60fb3a66aa90d8284642261f436a0ceaa805715cc61363933aba",
              "sha256:d96a6e7ba02f40c7853857acfcead9793958a2f17858ec9356653bb206c3828c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.492Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:24186a25a7a7d68108571b4cb9d2c84eee2522a44b443bcb07403a4e0b870af8",
              "sha256:adcf1f4a445c563a976eaa7fa2b25a8c5fd832e4eac403d73e601b02d32f42ff"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.742Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:c2baedc44fe0ff1d6f54f42b6b1c522f1527ba83bcd474a5e6fdc32a3d6c619c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:56.492Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:1e4af52a28746fdf6116f3238a61783e3b54cf53abb28d026a231fba3d300d22",
              "sha256:a0e8786bf0620369e63b62400f140a2445c6d640b10a0bf74b345be01a70b5c0"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:22.271Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:705a63022c8f294b29d1199ede2a2949e106f9bde0bd98b301623abee73ae83a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:22.271Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:cb51968c801a05b955e7ccdb51b76c2d7ec372aceb48528e3baba7d898036078",
              "sha256:e5ee1dfc6c6985d7642670827b96aafb22961e9e00190ae3a499ef777c96a1a5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:22.271Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:0487ae8f4da006ef5bba69544d755ef09d93f4eda8ce9b207b83791a3c6097aa",
              "sha256:d1e67c65a1dd0152bb89ad740fba6c836ba9dd84b5a0693be84b81bd4587f23a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:22.271Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:849f6e8a8720cd3e1ca5d7effb597d91a369b1f30487a04f1a642f81b04eee28"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:22.881Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:682c7dd83535bed8b9cbfb2e067fcc14e154bbd904bc2ccb33a48e9b26c281f0"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:54.901Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:37b9b68eaee06a16357456159c33a7f4f9d79c892971303880297a013da044d4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:54.901Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:8fb94a2c6b3256abc6f388b7aae09639d543b75ccdca4b28833d1b21f51d150f",
              "sha256:9e1ebc236f88f721a16d9a448ad47e441c6085310f87dd4815aa9f334b416c09"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.742Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:d69010f777226a83ca8293242e880e4925f62881d118d0b7828109586f7bec45"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.464Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:3949308191ba4d6071374baeea5f003c81d75053e49d1a614e0bf8a191a6d54d",
              "sha256:d6b10d1ed58f9d5299b96dd5aec4dc00c4c3168832b13ba4032d6d854414eeac"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.742Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:716669c46647e94be4137a69abfcbcaf7315a03834017511146de4d5ff572f81",
              "sha256:8d3a8d14d503cf00c7569ef8975c8d47b12f7b85f92975ad75b4ffb9debe585c",
              "sha256:f280345937371bbffa5a70c47ecba262a95be72f27f3942fac47b840423c51c9"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:54.901Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:33f9a68d174c2fba9de9f63a5b07667db97e063fabdecc52006848298573e34b",
              "sha256:4e35d07610f08c3923c95589e4737b338e78afc5b972bcb869b2a8da7fc925ce",
              "sha256:cba8f47497a46a27e761ca7a9b4ca5c2d81230b99931af55145390cca9a5a3ca"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:54.901Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/vercel/agent-readiness/vercel-rest-api/deployment-operations",
      "projection_digest": "sha256:44ea9638480511a23bf110de9baf35b88bb621719ddc9c07103de5eee9bffff1"
    }
  }
}
