{
  "api_contract": "sourcey.catalog-api/v1",
  "release_id": "sha256:d1cb219c8f6be3606007166b616e13fb46fee27507930122f428f1d5487097e1",
  "artifact_sha256": "sha256:87212334630b6cafa0454a71349079c604bd4373a0518fb676c7623bfd194016",
  "data": {
    "revision_contract": "sourcey.agent-readiness-revision/v1alpha1",
    "agent_readiness_profile_id": "arp_01m0ewej9qyk04qypr2mvmwmh1",
    "entity_id": "ent_01kyh8fpe3xgjjktffez1t34rn",
    "scope": {
      "product": {
        "key": "github-enterprise-server-3-21",
        "name": "GitHub Enterprise Server 3.21"
      },
      "funnel": {
        "key": "repository-operations",
        "name": "Repository operations"
      }
    },
    "catalog_binding": {
      "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
      "entity_revision_digest": "sha256:984e9d33ce299c5093b358d8578a6892e03ca295907002f6ef6d3a48014088b2"
    },
    "declaration_revision_digest": "sha256:f80d143253c99b4aef0ea4f747461a772f76950176b5c97759cc7ddc798ecd8a",
    "declaration": {
      "declaration_id": "declaration_github_enterprise_server_repository_operations",
      "provenance": {
        "repository": "sourcey/agent-ready-services",
        "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
        "path": "vendors/gi/github.yaml",
        "git_blob_oid": "335c7680d7edc2b4188a612523bb3cf710fab2ee",
        "blob_digest": "sha256:3cc453de44b8d230a24664a0f083f70389cfea67252045815e8feb046b863ef0"
      },
      "status": "community_declared"
    },
    "lifecycle": "active",
    "effective_from": "2026-08-20T06:20:00.000Z",
    "signals": [
      {
        "stage": "evaluate",
        "signal_code": "eligibility_decidability",
        "selector_group_id": "eligibility_decidability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:12.768Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-combined-use"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:05763cb089bc4cd8a5c458e2fe6e8b13ece2cd487437c8c2432c791d4afe749c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:14818b80933e25b2ee150d9f9892c1321ee4e22b5eeab8811e190937041c4361",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:62d9da3f4258a8525df8360630a3910f71f9403c09ba0d5b0e18c7b526b37387",
              "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-combined-use"
            },
            "locators": [
              {
                "artifact_digest": "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d",
                "start_byte": 10017,
                "end_byte": 10817,
                "value_digest": "sha256:0f9868a556869d8ba342063c329897fdc9f00d9ec04c600e1f1524ac81202ee6"
              },
              {
                "artifact_digest": "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d",
                "start_byte": 11613,
                "end_byte": 12410,
                "value_digest": "sha256:ec2c1c54f441ac65bb7c5430de82ddaabff4eb4194364cf6c7cca73e382a59eb"
              }
            ]
          }
        ],
        "note": "GitHub Enterprise Server eligibility conditions and required inputs are explicit: users are entitled to use GitHub Enterprise Server with the GitHub Enterprise plan, with deployment options including GHE Usage-based (requiring active assignment to a GitHub Enterprise Cloud organization) or Volume/Subscription licensing."
      },
      {
        "stage": "evaluate",
        "signal_code": "pricing_decidability",
        "selector_group_id": "pricing_decidability-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:12.768Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-billing"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-combined-use"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-pricing"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:05763cb089bc4cd8a5c458e2fe6e8b13ece2cd487437c8c2432c791d4afe749c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:62d9da3f4258a8525df8360630a3910f71f9403c09ba0d5b0e18c7b526b37387",
              "sha256:90484c2bb698649cb3afdb6923ed27c5747703b6cc91b017d45f14e5f676fcee",
              "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-combined-use"
            },
            "locators": [
              {
                "artifact_digest": "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d",
                "start_byte": 10017,
                "end_byte": 10817,
                "value_digest": "sha256:0f9868a556869d8ba342063c329897fdc9f00d9ec04c600e1f1524ac81202ee6"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ac304d58128e4068539c625f511482ec9d957213475803a4d3df98c01ee12eb0",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:a592df7b04e11f8fa95255034f96634c413da6944fefb4db4717951b8806c830",
              "sha256:d5b88bf71d8169ba9526ad27b2b5755851a5eaa3ee4b389fa68297d950ccff78",
              "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-pricing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498",
                "start_byte": 15247,
                "end_byte": 16042,
                "value_digest": "sha256:de9c44039e23f32275861c4cedf7174d7a4f16e380ff2929ab8d96e3e1aa1b81"
              }
            ]
          }
        ],
        "note": "The evidence outlines the pricing mechanisms (such as active user monthly billing for metered licenses and GitHub Codespaces rates starting at $0.18/hr compute and $0.07/GB storage), but volume subscription terms require contacting GitHub Sales, leaving fixed-cost volume variables contextual."
      },
      {
        "stage": "evaluate",
        "signal_code": "service_discovery",
        "selector_group_id": "service_discovery-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:37.058Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-overview"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-rest"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:3735116a4d7814705e45ffbe146ee20aa33e7b20058874ed6df832e086ca6c60",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:53027a28c0e99d78d3a7800659808c97c533c71c8b4b87ede623c476ecdbf4b1",
              "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
              "sha256:fb71e70e2ecf200e35966b6bfac0bf9178495c46b295770ce3b33fe27c632bf6"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-rest"
            },
            "locators": [
              {
                "artifact_digest": "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
                "start_byte": 16429,
                "end_byte": 17220,
                "value_digest": "sha256:0b92119d71979464ec7ec509b83ecec540de10f3fc34b14143f07e8421fceeee"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:3f1ecc0fdd8cb30a33b0a01e4b578f1c248ca0cccb4715de9ebcd127d5efabd0",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1b2e53f9fffc166a1e41a2a868014476ab4eeb534a859049c3e1a3ebd2799526",
              "sha256:324148c4817154ec00d059316479afba145caef60054ff90262727176b183543",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:aab011c822b232c164432cc4bb5a77d1d111569792c52bd0bf5e4a8ee1c7746d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-overview"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1b2e53f9fffc166a1e41a2a868014476ab4eeb534a859049c3e1a3ebd2799526",
                "start_byte": 51946,
                "end_byte": 52746,
                "value_digest": "sha256:b6b774965fce393d311a2421a391d13e2fb58d798acacd771ff6a3da21bd7b41"
              }
            ]
          }
        ],
        "note": "GitHub Enterprise Server is documented as a self-hosted platform deployment option, and the GitHub REST API documentation provides quickstart guides, OpenAPI descriptions, and endpoints for managing integrations and workflows."
      },
      {
        "stage": "evaluate",
        "signal_code": "terms_access",
        "selector_group_id": "terms_access-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:21.721Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-terms"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:09a79ceb013c949be761d5b053b4aa3cb49ae7f32520280893e709aad7102e0b",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0ca2f4e8a30313534239ab78b32eba615f15b13cbad59120512ad3f1fbf8bb75",
              "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:7bfd89a57f5e3ad8283f515b259ccc091de62b6f718fd460b0dfb577d1bb91a3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-terms"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                "start_byte": 12651,
                "end_byte": 13446,
                "value_digest": "sha256:2437eceedc60d78840c78f21b0f18a7db41b8c07928f6456dd6b2f3644d32803"
              },
              {
                "artifact_digest": "sha256:1e52a79d1f8a550c870fe881bafa24724c2acec14d52bb0d8429a7511dd5f042",
                "start_byte": 38259,
                "end_byte": 39055,
                "value_digest": "sha256:7a00637cecadc781e49decd903df62050324bfe1f277e937f142f8caec52f9f0"
              }
            ]
          }
        ],
        "note": "The GitHub Terms of Service are retrievable, but Section J.1 states that if the use of the service is governed by a GitHub Customer Agreement or volume licensing agreement, specific enterprise terms apply rather than the general individual terms."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_control_operability",
        "selector_group_id": "access_control_operability-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:55.229Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-trial"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:dd07ac1d5aa72477252ad168003bec68abb29edc9f5b6107eea33c9b48574cde",
                "capture_rung": "headless"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:768181b043e5025815e5fcaab3fdac8f203e7b60931ca3f4b07e4ffd034c6fd4",
              "sha256:8954dc90d0225f116addc35b369d3512baf299441f02ab2b49b41d0f8c2cb3fd",
              "sha256:aec64d7f3e65cc5c9e4603fb8e0066bab6638bc1b44163fe17c95d3b722d1ef3",
              "sha256:bac78677c8e59e7a6c1cd0ee2e4908079109d71a5cd1a1a1091cf2011817506f",
              "sha256:e8b834e9e3cdcc8e38f2e6c9b29a739ce30950bb76759f7052c1a319dc4cda73"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-trial"
            },
            "locators": [
              {
                "artifact_digest": "sha256:aec64d7f3e65cc5c9e4603fb8e0066bab6638bc1b44163fe17c95d3b722d1ef3",
                "start_byte": 53744,
                "end_byte": 54541,
                "value_digest": "sha256:1c682999956c2b441d56d52ddd6aebb0d08ba814dfb5e3db03e516730b0ece3b"
              },
              {
                "artifact_digest": "sha256:aec64d7f3e65cc5c9e4603fb8e0066bab6638bc1b44163fe17c95d3b722d1ef3",
                "start_byte": 54542,
                "end_byte": 55337,
                "value_digest": "sha256:113a2611ab57155bae6481e0c5650ed44171078d896aa38e2e5295b7ca2ea4ec"
              }
            ]
          }
        ],
        "note": "Setting up a trial of GitHub Enterprise Server requires submitting a trial request to obtain a link by email to set up an account for the GitHub Enterprise Web portal, followed by downloading and uploading a license file."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_entrypoint_stability",
        "selector_group_id": "access_entrypoint_stability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:55.229Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-trial"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:dd07ac1d5aa72477252ad168003bec68abb29edc9f5b6107eea33c9b48574cde",
                "capture_rung": "headless"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:69e24a90379b177d3891ed9fbdb50d0514d1a25b9675ab3f0a2b14d9b2e92f28",
              "sha256:768181b043e5025815e5fcaab3fdac8f203e7b60931ca3f4b07e4ffd034c6fd4",
              "sha256:8954dc90d0225f116addc35b369d3512baf299441f02ab2b49b41d0f8c2cb3fd",
              "sha256:aec64d7f3e65cc5c9e4603fb8e0066bab6638bc1b44163fe17c95d3b722d1ef3",
              "sha256:e8b834e9e3cdcc8e38f2e6c9b29a739ce30950bb76759f7052c1a319dc4cda73"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-trial"
            },
            "locators": [
              {
                "artifact_digest": "sha256:aec64d7f3e65cc5c9e4603fb8e0066bab6638bc1b44163fe17c95d3b722d1ef3",
                "start_byte": 48188,
                "end_byte": 48978,
                "value_digest": "sha256:e742bd2f2b605832d2b4742e78eca2073a5e0effc84c5eef18ffc44da9308372"
              }
            ]
          }
        ],
        "note": "A stable canonical trial request route is available to begin setting up a trial of GitHub Enterprise Server."
      },
      {
        "stage": "sign_up",
        "signal_code": "captcha_compatible_access",
        "selector_group_id": "captcha_compatible_access-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:55.229Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-trial"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [],
        "note": "Current admissible evidence does not contain explicit declarations or direct observations regarding CAPTCHA requirements during the trial or license acquisition flows."
      },
      {
        "stage": "sign_up",
        "signal_code": "delegated_identity_access",
        "selector_group_id": "delegated_identity_access-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:27.927Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:1fabf7b702a2442961823412ad8a20dc27af75688b70c6daef2d75a83dc7d70a",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:a5940290031b0f6b52231a1f4313cc2b826cbc5e72e43eb5749e3ab57c33958b",
              "sha256:fcf9012a3bb5abcbc94407aa2bf43789b96814493ec7716dcb8ced19d4cb5d35",
              "sha256:ff8f5378705202e1febb8868f530c73a0cc52245b3e1c45936fe94e4ccf55d42"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-token-lifecycle"
            },
            "locators": [
              {
                "artifact_digest": "sha256:fcf9012a3bb5abcbc94407aa2bf43789b96814493ec7716dcb8ced19d4cb5d35",
                "start_byte": 13012,
                "end_byte": 13804,
                "value_digest": "sha256:26be3c994c3e2ccf1f0116f341bd49ce7e83898e6e73ee8e82560b99ee3a733d"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:4d18f88850636cf4eaf3cef73d70116353f168b40833fd654588e2beec954328",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:135ff654914de24563e526ad782818361580a99b1e9bc76deb1949faa602c216",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
              "sha256:a058ed61d7307fa1ed7e7dc585abf81beda256fa62aa4d53799a42fb4e8978c1"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-authentication"
            },
            "locators": [
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 21749,
                "end_byte": 22546,
                "value_digest": "sha256:5024a930f0052fddb7235b641b0da8c0881a934bf7a4522e50efb92db1150d45"
              }
            ]
          }
        ],
        "note": "GitHub Enterprise Server REST API supports authenticating with scoped personal access tokens, GitHub App tokens, and OAuth app tokens, which can be expired or revoked by users or applications."
      },
      {
        "stage": "sign_up",
        "signal_code": "phone_verification_compatible",
        "selector_group_id": "phone_verification_compatible-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:55.229Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-trial"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [],
        "note": "Current admissible evidence does not mention phone verification requirements or supported boundaries for GitHub Enterprise Server sign-up or license acquisition."
      },
      {
        "stage": "pay",
        "signal_code": "checkout_operability",
        "selector_group_id": "checkout_operability-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:36.773Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [],
        "note": "The retained evidence shows that license files are downloaded after purchasing or upgrading from GitHub's Sales team or via GitHub Enterprise Cloud settings, but it does not establish an end-to-end deterministic checkout flow with handoff approval and resumption."
      },
      {
        "stage": "pay",
        "signal_code": "commitment_disclosure",
        "selector_group_id": "commitment_disclosure-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:12.768Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-billing"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-combined-use"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-pricing"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:ac304d58128e4068539c625f511482ec9d957213475803a4d3df98c01ee12eb0",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:13bd032a95d23a772d2f40cd5ca01adfb8d9b011408a459e5b0b0296bc982322",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:a592df7b04e11f8fa95255034f96634c413da6944fefb4db4717951b8806c830",
              "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-pricing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:e3fd83fdd8e1e39536eb5cfcd1d5fe01970403d77b99881528fca6c92f465498",
                "start_byte": 12851,
                "end_byte": 13647,
                "value_digest": "sha256:b7a8b414a2ecf387aeaca7b138abc523deb01aa23e080aab65c626c417785fa4"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:6b9a5c7cabad96751eeb748c95f353f4c0e2020ec92bb1d6647ee6a11e208724",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:27469581b47af5bf46cdcd2a6c81bbe87c20e5e90c355bd8f4696fb0ffc522c8",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:9fa87b7a23774c65234c98c5195420aa02093f58b2944ca19bb669d3e15023c1",
              "sha256:c67d31cba278f8d994038e5f5d826756a8a1fa99963b29472cde8d217dfff394"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-billing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:c67d31cba278f8d994038e5f5d826756a8a1fa99963b29472cde8d217dfff394",
                "start_byte": 7332,
                "end_byte": 8132,
                "value_digest": "sha256:4e3861bd8462b622dad7684ea6881514dcf44f4bf2f9011a41b7caef4f3b1712"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:05763cb089bc4cd8a5c458e2fe6e8b13ece2cd487437c8c2432c791d4afe749c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:62d9da3f4258a8525df8360630a3910f71f9403c09ba0d5b0e18c7b526b37387",
              "sha256:77a062d583b1cb2bf10429560ab64a1ef0a42400675cefd1c7c41ff72b9e5718",
              "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-combined-use"
            },
            "locators": [
              {
                "artifact_digest": "sha256:af5d53799b181d6b281efca99db9bdd5dc5f3d3dbe2b7c2f1ba265584415c55d",
                "start_byte": 10818,
                "end_byte": 11612,
                "value_digest": "sha256:8d567765c373246a61aea796a562cd9192da1a22de4b245f7ba293333aa35d7d"
              }
            ]
          }
        ],
        "note": "GitHub discloses enterprise licensing billing models (usage-based/metered vs. volume) and feature allowances (such as Actions minutes), but material pricing details for volume/subscription licenses require custom sales agreements or manual setup via GitHub Sales."
      },
      {
        "stage": "pay",
        "signal_code": "payment_authorization",
        "selector_group_id": "payment_authorization-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:36.773Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [],
        "note": "The documentation mentions supported payment methods and invoice options for enterprise accounts, but it does not detail a payment authorization rail for scoped agent delegation or explicit human-confirmed authorization with receipts."
      },
      {
        "stage": "pay",
        "signal_code": "self_service_purchase",
        "selector_group_id": "self_service_purchase-primary",
        "value": "no",
        "observed_at": "2026-08-20T15:56:36.773Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-acquisition"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:4ea60abbbc055ab75227ae61e060955216071524f81d32c5e751ab8f1a40405d",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:abf4a296c343c83e009313f6ad72926753a1374316d9b975a12b22b319dfb933",
              "sha256:be05c6fee9ceb4e8831aa693bed68b5857510e1e38e1c6a82c9e7a5e72436b70",
              "sha256:fd44756187d965a4442841f98217a1372e0b2db57190b85e31fc6c00d2ec830c"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-license-acquisition"
            },
            "locators": [
              {
                "artifact_digest": "sha256:be05c6fee9ceb4e8831aa693bed68b5857510e1e38e1c6a82c9e7a5e72436b70",
                "start_byte": 7322,
                "end_byte": 8121,
                "value_digest": "sha256:233bccb7a32ca123849fa9bf9f216bd4e6c8a49ab2257c5e07c31586e8372a4a"
              }
            ]
          }
        ],
        "note": "Purchasing or upgrading a license for GitHub Enterprise Server explicitly requires contacting GitHub's Sales team, rather than offering a direct self-service purchase path."
      },
      {
        "stage": "provision",
        "signal_code": "access_material_delivery",
        "selector_group_id": "access_material_delivery-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:16.343Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:4d18f88850636cf4eaf3cef73d70116353f168b40833fd654588e2beec954328",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:135ff654914de24563e526ad782818361580a99b1e9bc76deb1949faa602c216",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
              "sha256:c0f1a4dbd80d9ab973f47e842f8618d56cb3c6fe947bd92c2e6bb2be106eda3f"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-authentication"
            },
            "locators": [
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 21749,
                "end_byte": 22546,
                "value_digest": "sha256:5024a930f0052fddb7235b641b0da8c0881a934bf7a4522e50efb92db1150d45"
              },
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 26541,
                "end_byte": 27336,
                "value_digest": "sha256:f05ecdc7829f538dd8c4a04da886fc574b4fdee4c2b18a98f791e8c16bb066b5"
              }
            ]
          }
        ],
        "note": "GitHub Enterprise Server REST API authentication accepts personal access tokens, GitHub App tokens, and GitHub Actions GITHUB_TOKENs, and client secrets can be generated in app settings pages. However, the evidence leaves manual token generation and dashboard client secret retrieval as human-driven transfer steps without establishing a fully programmatic delivery path for all credentials."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_completion",
        "selector_group_id": "provisioning_completion-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:23.115Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-upload"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-repositories"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fbb2be714d6a014d04a1e519bdc7a7ac060a5b004b2c2205c6d1a6b1adfb64b5",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2e5755f35159297ad188579ca40bcd64196d2e1d471261e93c6a01594e4b18a5",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
              "sha256:f3aafba538e4767117d16fad83e37d116a258225d36a24d244d0787ed780a8b3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-repositories"
            },
            "locators": [
              {
                "artifact_digest": "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
                "start_byte": 169193,
                "end_byte": 169986,
                "value_digest": "sha256:ebbe4c1f703883fef1fce778c44dbcc05a73dd29b997b664d49ef7455bcbfc55"
              },
              {
                "artifact_digest": "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
                "start_byte": 36608,
                "end_byte": 37355,
                "value_digest": "sha256:eb2114f3f142b5bb1e99099b356cd09a7846e0066580162a884f2cd0ecacf005"
              }
            ]
          }
        ],
        "note": "Creating an organization repository via REST returns a synchronous HTTP 201 Created success response. Creating a repository using a template also returns an HTTP 201 Created response along with the usable repository object in the JSON body."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_operability",
        "selector_group_id": "provisioning_operability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:23.115Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-license-upload"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-repositories"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fbb2be714d6a014d04a1e519bdc7a7ac060a5b004b2c2205c6d1a6b1adfb64b5",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:614213ee2d9452f65200bc97108d4b7bc6d1ff9580f9bcf0fba893936c18e87e",
              "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
              "sha256:f3aafba538e4767117d16fad83e37d116a258225d36a24d244d0787ed780a8b3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-repositories"
            },
            "locators": [
              {
                "artifact_digest": "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
                "start_byte": 211324,
                "end_byte": 212111,
                "value_digest": "sha256:e990e9636d7c00e76923d0d68bd49ccb2af89be3f4cc17ae66153aba98a4f1cb"
              }
            ]
          }
        ],
        "note": "Provisioning a repository for an authenticated user can be initiated directly and deterministically by an authorized agent via an HTTP POST request to /user/repos."
      },
      {
        "stage": "operate",
        "signal_code": "credential_lifecycle",
        "selector_group_id": "credential_lifecycle-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:27.927Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:4d18f88850636cf4eaf3cef73d70116353f168b40833fd654588e2beec954328",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:135ff654914de24563e526ad782818361580a99b1e9bc76deb1949faa602c216",
              "sha256:1b87ce9d1e29abfde0b2afa705e505197a95cc35669ed0f910e3486ab8033397",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-authentication"
            },
            "locators": [
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 29664,
                "end_byte": 30461,
                "value_digest": "sha256:f924f927a8e84fb4a1a4a76de2edc8cc65d038aab08457ace2f28f0865120403"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:1fabf7b702a2442961823412ad8a20dc27af75688b70c6daef2d75a83dc7d70a",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:81c0b21b6bbf4f6e4ee11ca54c38176ed8e2d95ee8d6f4a0a2034ad4eab63cb1",
              "sha256:fcf9012a3bb5abcbc94407aa2bf43789b96814493ec7716dcb8ced19d4cb5d35",
              "sha256:ff8f5378705202e1febb8868f530c73a0cc52245b3e1c45936fe94e4ccf55d42"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-token-lifecycle"
            },
            "locators": [
              {
                "artifact_digest": "sha256:fcf9012a3bb5abcbc94407aa2bf43789b96814493ec7716dcb8ced19d4cb5d35",
                "start_byte": 12221,
                "end_byte": 13011,
                "value_digest": "sha256:70298c048ae1e08f673d2b2aa1abd92dbf108f951c6765b8a7dcfda72fc7df39"
              }
            ]
          }
        ],
        "note": "Documentation establishes that personal access tokens can set an expiration date after which they are automatically revoked, and tokens can be revoked manually by the user or an OAuth app. However, current admissible evidence does not document a complete agent-executable secret rotation and recovery lifecycle."
      },
      {
        "stage": "operate",
        "signal_code": "failure_contract",
        "selector_group_id": "failure_contract-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:44.681Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-errors"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:5d1379e7dae32fb89c59a971601cdde0ca74757fabb0df8d2cbbbf8a125a7ec9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1392306752e3f9c484d5a9e52e606b81aca2f9ed7dfe1004c1d561c8e07a00dc",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:9a8fbe9fc041ccaafaedc3128742b1969ddd8280b45d8bb9ee401d22a2cbabe3",
              "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418",
                "start_byte": 21347,
                "end_byte": 22141,
                "value_digest": "sha256:b304836361fae71f5569c3ebcf1e15cc1c5dca4a09c1d4c97755b26e11b419cf"
              },
              {
                "artifact_digest": "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418",
                "start_byte": 22142,
                "end_byte": 22939,
                "value_digest": "sha256:cf02792d4fd8522471e516b3b6834a712bfa095c1c0af21bd2a47bb8d07542c7"
              }
            ]
          }
        ],
        "note": "The REST API documentation defines rate limit failure modes (403 Forbidden and 429 Too Many Requests), standard response headers (retry-after, x-ratelimit-remaining, x-ratelimit-reset), and retry guidelines with exponential backoff. However, full cancellation and reconciliation semantics are not fully documented in the admitted evidence."
      },
      {
        "stage": "operate",
        "signal_code": "operation_authentication",
        "selector_group_id": "operation_authentication-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:16.343Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "enterprise-authentication"
          },
          {
            "node_kind": "resource",
            "node_id": "enterprise-token-lifecycle"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:4d18f88850636cf4eaf3cef73d70116353f168b40833fd654588e2beec954328",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:135ff654914de24563e526ad782818361580a99b1e9bc76deb1949faa602c216",
              "sha256:3ecc202c57b039dac035a565b2aa8575b0111627899881510fadbe0d8aca47fa",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-authentication"
            },
            "locators": [
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 22547,
                "end_byte": 23338,
                "value_digest": "sha256:c7597258dac79207abdd25e58e807f37060580eed03a6140c7505ed34d69c58f"
              },
              {
                "artifact_digest": "sha256:937a6dec01bb9761acd824f166e0fd31aab6326761fedc3de4a1a8a421047da4",
                "start_byte": 27337,
                "end_byte": 28131,
                "value_digest": "sha256:82e4e918dcd61965cfe203493c019f6efa81f8467bec706c4ea740497b166359"
              }
            ]
          }
        ],
        "note": "Request-time authentication is explicitly documented for REST API operations using scoped authority such as GitHub App user access tokens, installation tokens, or fine-grained PATs passed via the Authorization header using Bearer or token syntax."
      },
      {
        "stage": "operate",
        "signal_code": "operation_contract",
        "selector_group_id": "operation_contract-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:44.681Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "enterprise-repository-api"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:3735116a4d7814705e45ffbe146ee20aa33e7b20058874ed6df832e086ca6c60",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:53027a28c0e99d78d3a7800659808c97c533c71c8b4b87ede623c476ecdbf4b1",
              "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
              "sha256:72922f959e6b95f85c41c5806fcf4b80c78ced768fea1175155cab9aa81960df"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-rest"
            },
            "locators": [
              {
                "artifact_digest": "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
                "start_byte": 20400,
                "end_byte": 21197,
                "value_digest": "sha256:e5692cc7c56351de4fc4f61aa7e2b23bba26c30f2862aff2dc258790756f57a3"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fbb2be714d6a014d04a1e519bdc7a7ac060a5b004b2c2205c6d1a6b1adfb64b5",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:6387d94c6d67a494bd746b9f68dbd39164df1bc9c992fea081b0bb47bfeb35fc",
              "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
              "sha256:f3aafba538e4767117d16fad83e37d116a258225d36a24d244d0787ed780a8b3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-repositories"
            },
            "locators": [
              {
                "artifact_digest": "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
                "start_byte": 201984,
                "end_byte": 202774,
                "value_digest": "sha256:a475b7dd1dbdc2447ba8fccfbf7bef2bf9d64efc19513e603b6a10eb49e81d7d"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:7738dea927cf5e23e4957e00a4f7d1a9d15ca116af34751911b7e484d5acaf95",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2807f87d8099d9450eda293dd2e4d752fefdf74575142ce031040635b352d5e3",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:90002513aa19b03e1a4b0660de20ee4a24e5cbbccdf517ce9aa67a22d29cc318",
              "sha256:cc4f80d9b4ebfe83721e3d2ad7f9183d9dce6e4171ff59e024c55c609a48a33d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-limits"
            },
            "locators": [
              {
                "artifact_digest": "sha256:cc4f80d9b4ebfe83721e3d2ad7f9183d9dce6e4171ff59e024c55c609a48a33d",
                "start_byte": 22436,
                "end_byte": 23089,
                "value_digest": "sha256:c6f097535a007c232140a721f347ee6da4cc465e6830f893447b328a78bb69ff"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:5d1379e7dae32fb89c59a971601cdde0ca74757fabb0df8d2cbbbf8a125a7ec9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1392306752e3f9c484d5a9e52e606b81aca2f9ed7dfe1004c1d561c8e07a00dc",
              "sha256:43b823ca8c0af6cd83e42cb688cae7417b6035955475cfeaa5a51809e9e6bc39",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418",
                "start_byte": 31717,
                "end_byte": 32517,
                "value_digest": "sha256:96e37ec1dc13b0b0a3de378eaeaa95dd95749a09df00a6a1e0c3063f07c8926f"
              }
            ]
          }
        ],
        "note": "The REST API documentation provides stable parameters, HTTP methods, request headers, error status codes (e.g., 401, 403, 422), response schemas, and cURL/JavaScript code examples across troubleshooting, rate limiting, repository, and general REST endpoints."
      },
      {
        "stage": "operate",
        "signal_code": "target_interface_access",
        "selector_group_id": "target_interface_access-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:44.681Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "enterprise-repository-api"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:3735116a4d7814705e45ffbe146ee20aa33e7b20058874ed6df832e086ca6c60",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:53027a28c0e99d78d3a7800659808c97c533c71c8b4b87ede623c476ecdbf4b1",
              "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
              "sha256:72922f959e6b95f85c41c5806fcf4b80c78ced768fea1175155cab9aa81960df"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-rest"
            },
            "locators": [
              {
                "artifact_digest": "sha256:6eae793425d1397a838e91a79b91c1054eca5e7aa8221ff7a2637a2d1e4c9e6e",
                "start_byte": 20400,
                "end_byte": 21197,
                "value_digest": "sha256:e5692cc7c56351de4fc4f61aa7e2b23bba26c30f2862aff2dc258790756f57a3"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fbb2be714d6a014d04a1e519bdc7a7ac060a5b004b2c2205c6d1a6b1adfb64b5",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:61475acc2e86af302023929b16c7a1ec1b2265d1d78678c0873f1095ecf2ec80",
              "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
              "sha256:f3aafba538e4767117d16fad83e37d116a258225d36a24d244d0787ed780a8b3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-repositories"
            },
            "locators": [
              {
                "artifact_digest": "sha256:88b7efd35966c6ba27477fc9ccfc7149c39516817c329aea4df83fd25f2b0c1e",
                "start_byte": 128103,
                "end_byte": 128896,
                "value_digest": "sha256:fe1e45d40c282b376476cfa37048173ab9c6cd3dd2adad6c98d9e7f67d26e5bd"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:7738dea927cf5e23e4957e00a4f7d1a9d15ca116af34751911b7e484d5acaf95",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:2807f87d8099d9450eda293dd2e4d752fefdf74575142ce031040635b352d5e3",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:90002513aa19b03e1a4b0660de20ee4a24e5cbbccdf517ce9aa67a22d29cc318",
              "sha256:cc4f80d9b4ebfe83721e3d2ad7f9183d9dce6e4171ff59e024c55c609a48a33d"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-limits"
            },
            "locators": [
              {
                "artifact_digest": "sha256:cc4f80d9b4ebfe83721e3d2ad7f9183d9dce6e4171ff59e024c55c609a48a33d",
                "start_byte": 22436,
                "end_byte": 23089,
                "value_digest": "sha256:c6f097535a007c232140a721f347ee6da4cc465e6830f893447b328a78bb69ff"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:5d1379e7dae32fb89c59a971601cdde0ca74757fabb0df8d2cbbbf8a125a7ec9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1392306752e3f9c484d5a9e52e606b81aca2f9ed7dfe1004c1d561c8e07a00dc",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418",
              "sha256:dfdeb31ba86b7b5e346cb4a9ed0cf6faa0c96d06e2dbe0c70dbc5bb756b9f2d0"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "enterprise-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:a10752d9db15b2d79b7e67c8aa7bef4b848dfefd1f2377ea886b1300f72f6418",
                "start_byte": 30918,
                "end_byte": 31716,
                "value_digest": "sha256:0d908c3a78b2043d77921e15ee8be7b65daf55000f090a160d3d3479a46779f5"
              }
            ]
          }
        ],
        "note": "Every essential target is accessible through documented machine-operable REST API endpoints, supported by code samples in cURL, JavaScript, and GitHub CLI."
      }
    ],
    "revision_digest": "sha256:1f0db61918985db99729c73923137ed5806fba47d9b90b07c15a47a398b5f8cc"
  }
}
